00:00:00.959 --> 00:00:01.600
All right.
00:00:01.760 --> 00:00:02.640
Well, here we are.
00:00:02.879 --> 00:00:03.759
I guess welcome back.
00:00:04.000 --> 00:00:04.240
Welcome.
00:00:04.719 --> 00:00:06.160
I guess it is welcome back.
00:00:06.320 --> 00:00:08.240
I mean, we've done we've done bonus content.
00:00:08.320 --> 00:00:09.919
You know, that's been cool to release that.
00:00:10.000 --> 00:00:11.679
And we've put that on our socials a bit.
00:00:11.839 --> 00:00:13.359
Got some decent feedback from that.
00:00:13.439 --> 00:00:20.719
But I guess, yeah, this is welcome back, but first inaugural, like we're going to eat our own dog food, do the show and the proper structure kind of thing.
00:00:20.879 --> 00:00:21.120
Yeah.
00:00:21.199 --> 00:00:22.719
I mean, we have to mess it up first, right?
00:00:22.800 --> 00:00:25.440
So, you know what?
00:00:25.519 --> 00:00:29.359
I feel like this entire thing is going to be a train wreck, but we're going to have fun doing it, right?
00:00:29.440 --> 00:00:35.679
It's going to be a good opportunity, build some community, talk with some folks, meet some people from outside industries we've never met before.
00:00:35.759 --> 00:00:37.840
So yeah, man, I'm I'm looking forward to this thing.
00:00:37.920 --> 00:00:39.039
I'm really psyched about it.
00:00:39.280 --> 00:00:40.000
110%.
00:00:40.399 --> 00:00:42.960
Um definitely looking forward to trying to give it a go this first one.
00:00:43.200 --> 00:00:43.520
Absolutely.
00:00:44.479 --> 00:00:46.079
Any so any wild stuff this week?
00:00:46.240 --> 00:00:50.320
Anything crazy happening to you this week or anything that you kind of read about or saw in the news?
00:00:50.640 --> 00:00:56.240
Um, not necessarily particularly that trying to get caught back up on the real world um coming off of Black Hat and Vacation.
00:00:56.320 --> 00:00:59.359
It really stifles kind of uh daily output, if you will.
00:00:59.600 --> 00:01:01.520
Dude, I was compressed for two weeks.
00:01:01.679 --> 00:01:04.719
Like meetings were backed up, like work had to get done.
00:01:04.879 --> 00:01:05.599
But it's important.
00:01:05.680 --> 00:01:08.560
It's important to get out there and see what's in the industry and see what's happening.
00:01:08.879 --> 00:01:09.439
110%.
00:01:09.840 --> 00:01:10.239
Yeah, man.
00:01:10.400 --> 00:01:12.719
So I did see this wild article this week.
00:01:12.879 --> 00:01:18.319
And apparently Anthropic is going to start like watermarking content that they're producing, right?
00:01:18.400 --> 00:01:22.319
So like people can understand now like what's being produced by AI and what's not.
00:01:22.480 --> 00:01:24.159
Uh what do you think about that?
00:01:24.719 --> 00:01:32.159
Um I think it's what the industry's been asking for, at least the common user, to say, how do I know things are driven via AI or not?
00:01:32.400 --> 00:01:35.519
Um I think this is the world of copyright, right?
00:01:35.599 --> 00:01:36.719
It's nothing that new.
00:01:36.959 --> 00:01:41.519
Um I'm appreciative that some of the AI content is moving towards this.
00:01:41.680 --> 00:01:46.159
Um, but again, I I think it's also a band aid on a larger issue or a problem, right?
00:01:46.319 --> 00:01:49.359
And that's just uh the fidelity on how this has been done, right?
00:01:49.439 --> 00:01:52.799
Or how often will happen, how what's the quality of it, right?
00:01:52.879 --> 00:02:01.439
Um, so again, I think it's a new bells and whistles in the industry, but I mean, like, I I'll I'll definitely like I'll admit to you and the audience, it caught me off guard.
00:02:01.599 --> 00:02:02.799
Like, I knew this was coming.
00:02:02.879 --> 00:02:11.360
I knew in my art of hearts, like generative AI had gotten so good that it's getting really, really hard to figure out like what is actually real, what is not.
00:02:11.520 --> 00:02:19.039
And then of course we see article after article, this this big accounting firm use AI, this big consulting firm used AI, and the reports were wrong.
00:02:19.199 --> 00:02:25.120
We're starting to see things where people are using them in litigation and like it's producing like, you know, poor citations for case law.
00:02:25.280 --> 00:02:27.280
So like I knew that this stuff was coming.
00:02:27.439 --> 00:02:31.520
Um, but it's kind of interesting to like have it be real now, you know?
00:02:31.759 --> 00:02:32.479
Yeah, I don't know.
00:02:32.560 --> 00:02:34.879
I mean, I think it's the application of how people use it, right?
00:02:35.039 --> 00:02:42.560
Um, I know internally with us, um, we use it as a tool, just like Microsoft Excel or Word or anything else that's out there, right?
00:02:42.639 --> 00:02:42.800
Yeah.
00:02:42.960 --> 00:02:49.759
Um, some people already think are using this too much and they're looking to have final output of a product to be solely AI driven.
00:02:49.919 --> 00:02:53.280
Um again, I think from a service-based perspective, right?
00:02:53.680 --> 00:02:59.520
Um CPA firms or law firms that use that to do end-to-end, I think they're making a mistake on that.
00:02:59.680 --> 00:03:06.560
Um, but I'm not as concerned with a watermark or use of AI within helping to be more efficient to get to my end product, right?
00:03:07.120 --> 00:03:09.919
And if I need citation for that, fine, I guess.
00:03:10.080 --> 00:03:16.879
Um, but again, I'm not seeing other places say that, hey, I use SPSS when I was there to crunch out numbers, right?
00:03:16.960 --> 00:03:18.319
They don't advertise that internally.
00:03:18.560 --> 00:03:18.719
Right.
00:03:18.879 --> 00:03:21.039
So it's like, what are we advertising here for, right?
00:03:21.120 --> 00:03:25.680
If we can't trust our product or cite our product properly, I don't know what watermark's gonna do for it.
00:03:26.800 --> 00:03:28.159
Yeah, definitely interesting.
00:03:28.240 --> 00:03:32.960
And and definitely interesting to see like how it's actually applied, who leans into it, who doesn't lean into it.
00:03:33.120 --> 00:03:37.280
Like it's definitely gonna be, and the thing I still don't understand is like how they're gonna do it from a text perspective.
00:03:37.360 --> 00:03:39.199
I gotta do some more research from that perspective.
00:03:39.439 --> 00:03:40.800
I get the I get the image stuff.
00:03:40.879 --> 00:03:44.719
They'll be able to lay the the watermark within the image, within the image pixels itself.
00:03:44.879 --> 00:03:46.159
But like the text, I don't know.
00:03:46.319 --> 00:03:47.599
Is it gonna be a sequence thing?
00:03:47.759 --> 00:03:48.080
Whatever.
00:03:48.240 --> 00:03:49.439
We'll let them solve those problems.
00:03:49.520 --> 00:03:51.520
I'll also be curious to see who follows suit, right?
00:03:51.599 --> 00:03:54.240
If anthropic is the first one out of the gate, who's next?
00:03:54.400 --> 00:03:54.879
Is it Gemini?
00:03:55.039 --> 00:03:56.240
Is it Chappy GPT?
00:03:56.639 --> 00:03:57.759
Have they already been doing these things?
00:03:57.840 --> 00:03:58.639
We just don't know.
00:03:58.800 --> 00:03:59.759
Uh we'll see.
00:03:59.840 --> 00:04:00.639
We'll kind of see how it goes.
00:04:00.800 --> 00:04:04.080
Yeah, it'll be interesting too to see how you it works from a licensing perspective as well, right?
00:04:04.159 --> 00:04:06.400
If I'm a paid client, do I actually have to have that watermark?
00:04:06.560 --> 00:04:06.960
Do I not?
00:04:08.319 --> 00:04:08.560
Good point.
00:04:08.719 --> 00:04:09.520
Um again, right?
00:04:09.599 --> 00:04:12.639
A lot of this is for mass public consumption.
00:04:12.800 --> 00:04:15.680
Um, and that's I think a fair opportunity to use that, right?
00:04:15.759 --> 00:04:16.560
Teachers are gonna love this.
00:04:16.639 --> 00:04:16.959
I'll try.
00:04:17.199 --> 00:04:20.240
Okay, now I get to see where this has been used or generated by AI.
00:04:20.399 --> 00:04:21.920
Um, so yeah, we'll we'll see.
00:04:22.079 --> 00:04:26.480
But again, for I think the the heavy power users of this, um, not much has changed.
00:04:26.560 --> 00:04:32.319
Um, potentially reputation play with your clients, but that's the same thing as anything else that you do uh an output of product, right?
00:04:32.560 --> 00:04:34.000
Yeah, pretty interesting.
00:04:34.319 --> 00:04:34.639
All right.
00:04:34.800 --> 00:04:36.079
I think it's time to get into it.
00:04:36.240 --> 00:04:40.879
I think it's time to lean into to how we've designed, you know, kind of this podcast.
00:04:41.040 --> 00:04:43.519
In fact, Owen, like this is one of the things that you had brought up.
00:04:43.600 --> 00:04:48.560
You this format that we're gonna lean into here, this comes from a different podcast we're borrowing it from, correct?
00:04:48.720 --> 00:05:00.560
Yeah, I definitely have to give shout-outs um in recognition, right, from a psychation perspective, that Wildcard uh hosted on the NPR um podcast network is where this really sparked the idea from.
00:05:00.800 --> 00:05:04.319
Um and so having the kind of the three-card layout, right?
00:05:04.480 --> 00:05:12.160
And again, order of we're using A, B, and C to distribute those three piles, um, and then just make a choice at random, right?
00:05:12.319 --> 00:05:17.600
Um doesn't have to be in order, and it kind of flips a card and allows for a talking point, right?
00:05:17.680 --> 00:05:30.879
Whether it's statistic, uh a quilt, um a theme within uh cybersecurity or adjacent industries to really just help to spark conversation and open up how people think about things um that are vastly different from ourselves.
00:05:31.040 --> 00:05:32.639
So that's kind of the gist of it.
00:05:32.720 --> 00:05:34.800
Um and we're gonna kind of see how this plays out.
00:05:35.040 --> 00:05:35.680
I know, I know.
00:05:35.759 --> 00:05:41.040
And and look, I gotta say, I love this because for me, this is about shared vulnerability, right?
00:05:41.279 --> 00:05:46.240
You, me, we don't know what the what the actual statistic is gonna be.
00:05:46.319 --> 00:05:48.160
The guest isn't gonna know when they join.
00:05:48.240 --> 00:05:51.600
We're truly coming at this from a shared vulnerable space.
00:05:51.759 --> 00:05:55.279
And the guest is gonna be allowed to pick whichever card they want to pick.
00:05:55.439 --> 00:05:58.959
They'll we'll hit them with that statistic, and then we get to talk about what does that mean for you?
00:05:59.040 --> 00:06:00.079
What does that mean for your business?
00:06:00.240 --> 00:06:01.920
What does that mean for your industry?
00:06:02.079 --> 00:06:14.079
And like to get these different perspectives from people across like the different industries that we don't typically interact with, with companies we don't typically interact with, like it's kind of exciting to get out of our bubble, right?
00:06:14.160 --> 00:06:20.079
To be to get away from kind of the enterprise financial services network that we've we've built up and used forever, right?
00:06:20.160 --> 00:06:27.040
But like to be able to see like what does this mean for someone in a different, uh, in a different county or a different state or a different part of the world.
00:06:27.279 --> 00:06:33.839
Um, so in honor of this, Owen, because this was your idea, I would like you to pick the very first card.
00:06:34.079 --> 00:06:35.600
So we have three cards laid out.
00:06:35.759 --> 00:06:38.160
We have card A, card B, card C.
00:06:38.399 --> 00:06:44.160
Don't necessarily know what's going to be on these cards, but why don't you go ahead and select and uh and let's let's go for it.
00:06:44.319 --> 00:06:46.079
Just like my default in the SAT exam.
00:06:46.240 --> 00:06:46.480
See.
00:06:46.720 --> 00:06:47.040
C.
00:06:47.199 --> 00:06:47.759
All right.
00:06:47.920 --> 00:06:49.279
We're going for the last one.
00:06:49.439 --> 00:06:49.680
Interesting.
00:06:49.920 --> 00:06:52.000
You know, before we pick, I was a little worried about that.
00:06:52.160 --> 00:06:54.000
I was a little worried about using ABC.
00:06:54.160 --> 00:07:00.240
Because like, I don't know, like, is there a psychological thing where people will typically pick A or or or like the first card?
00:07:00.399 --> 00:07:03.360
I was wondering if we need to change this to like circle square triangle.
00:07:04.240 --> 00:07:12.879
I think there's always gonna be an inherent move towards something, and it's always gonna trigger someone's mind in some fashion when you use any form of icon or order system.
00:07:13.120 --> 00:07:15.439
Um, so I would say irrelevant.
00:07:15.680 --> 00:07:16.319
Irrelevant.
00:07:16.480 --> 00:07:16.959
Awesome.
00:07:17.199 --> 00:07:17.519
All right.
00:07:17.600 --> 00:07:18.800
Well, let's go ahead and go for it.
00:07:18.959 --> 00:07:20.959
We're gonna go ahead and pick card C.
00:07:21.120 --> 00:07:25.839
And the card that you chose on is a statistic that comes from 2025.
00:07:26.240 --> 00:07:35.519
So in 2025, the vulnerability data came out that there were roughly 130 vulnerabilities discovered per day and disclosed.
00:07:35.680 --> 00:07:37.519
So now we're talking about things like volume.
00:07:37.680 --> 00:07:52.480
We're talking about things like, you know, uh, you know, the actual speed at which things were being disclosed and what that meant for people's attack surface in 2025 as they're trying to keep up with all of this information coming at them and keeping their and keeping their organization safe.
00:07:52.720 --> 00:07:53.920
So let's start with it.
00:07:54.000 --> 00:07:56.639
Well, you read this card initially, what does that mean to you?
00:07:57.040 --> 00:08:04.319
Yeah, again, um, I think 130 attacks per day um reported, right?
00:08:04.399 --> 00:08:06.319
So there's a couple of different things that are interesting there.
00:08:06.399 --> 00:08:12.480
One is the reported nature that doesn't speak to all the other ones that are out there that aren't actually being recorded, right?
00:08:12.560 --> 00:08:13.920
So it's a disability play.
00:08:14.160 --> 00:08:21.759
Um, the other element for me is just the unsurmountable tasks that vulnerability teams kind of are faced with, right?
00:08:21.920 --> 00:08:34.080
Um, and how to basically I don't want to say it's easy to identify vulnerabilities, but that's always the biggest problem is it's one thing to identify, but then how do we actually ingest that and actually prioritize and remediate that?
00:08:34.240 --> 00:08:38.639
Every single vulnerability isn't gonna have the exact same impact for every single organization.
00:08:38.960 --> 00:08:47.759
Um, so it's the notion of kind of slowing down with some of these things and really understanding what is the impact um for your organization specifically.
00:08:47.840 --> 00:08:50.080
Um, but yeah, these numbers are daunting, right?
00:08:50.159 --> 00:09:00.320
If you look at the global numbers versus just your individual organization, this is where that notion of feeling overwhelmed and drained and not really having an opportunity for a solution.
00:09:00.480 --> 00:09:07.279
Um but these are one of the numbers too, as I got more in developed with cybersecurity, is it's less of a scare when you start to see these things.
00:09:07.440 --> 00:09:15.440
Um, but it is honestly really important to understand, like you're saying before, how does this cover across our entire environment, right?
00:09:15.600 --> 00:09:19.440
Um, because they're usually going to be or never located in just one specific spot, right?
00:09:19.519 --> 00:09:20.639
It's gonna be throughout your network.
00:09:20.879 --> 00:09:21.600
You're spot on.
00:09:21.679 --> 00:09:24.320
Like this is one of those things where it's definitely shock and awe.
00:09:24.480 --> 00:09:28.159
Like you see that, and immediately your brain goes to like, oh my God, what's the math?
00:09:28.240 --> 00:09:28.320
Right.
00:09:28.480 --> 00:09:30.399
So like while you were talking, I did some math.
00:09:30.559 --> 00:09:34.559
This works out to a total number of vulnerabilities disclosed, right?
00:09:34.639 --> 00:09:47.360
Actually released in via, you know, the the you know, the the CVS scores, via vendor releases, whatever they were, to 47,450 in 2025 based on this average.
00:09:47.600 --> 00:09:49.200
Might be a little higher, might be a little less, right?
00:09:49.279 --> 00:09:51.039
But this was the statistic we came across.
00:09:51.279 --> 00:09:55.840
Now, what's interesting is like, yes, immediately that's terrifying, but I think you're actually right, right?
00:09:55.919 --> 00:09:59.039
Like the thing is, not all vulnerabilities one are created equal.
00:09:59.200 --> 00:09:59.840
That's number one.
00:10:00.080 --> 00:10:03.360
Two, not all vulnerabilities are gonna apply to every organization, right?
00:10:03.519 --> 00:10:09.279
Depends on your tech stack, depends on your exposures, depends on what applications people are using.
00:10:09.440 --> 00:10:13.840
So, like the example I love to give is, you know, where we use Microsoft, right?
00:10:13.919 --> 00:10:16.879
So that means email is gonna fall to the Microsoft product exchange.
00:10:17.039 --> 00:10:22.000
So if there's a disclosure for something like IBM Lotus Notes, well, all right, so what?
00:10:22.240 --> 00:10:22.960
Doesn't matter, right?
00:10:23.120 --> 00:10:24.720
They can be the worst vulnerability on the planet.
00:10:24.799 --> 00:10:26.159
It doesn't apply to us.
00:10:26.399 --> 00:10:33.519
The other thing that comes to mind here is like a couple of years ago, there was a very, very cool project that came out where it wasn't just C VSS.
00:10:33.840 --> 00:10:46.559
And C VSS talked about like how bad the app, the vulnerability was, like what it allowed an attacker to do and how that attacker could utilize that for whatever the end game was gain access, bypass, you know, cross-stage scripting, whatever.
00:10:46.639 --> 00:10:51.039
Like the the number of attacks that could be tied to these vulnerabilities is almost limitless.
00:10:51.279 --> 00:10:57.200
But what's cool is a couple of years ago, this new project came out that was basically ties to EPSS, right?
00:10:57.360 --> 00:11:08.799
So where C VSS talks about criticality, EPSS talks about how easy or hard it is to use a vulnerability in order to actually enact the exploit.
00:11:08.960 --> 00:11:09.600
Is it trivial?
00:11:09.759 --> 00:11:17.200
Is the exploit as simple as like pushing a button and running a single line command that automatically gives you remote code execution?
00:11:17.440 --> 00:11:27.039
Or does it require multiple steps, including capturing packets on the wire, modifying the packet, sending it to the target, and then you know taking 17 or 18 different steps after that?
00:11:27.279 --> 00:11:41.039
So I think I think what I'm thinking here is like you think about this statistic, 130 a day, 47,000 over the course of the year in 2025, immediately it's shock and awe, immediately it's fear, immediately it's like how do we keep up with these things?
00:11:41.200 --> 00:11:44.639
But then as we start to break it down to your point, what applies to us?
00:11:44.799 --> 00:11:49.519
And then for the ones that actually apply, how easy or hard is it for them to actually exploit us?
00:11:49.759 --> 00:11:57.120
I mean, I feel like that's really what makes this a little bit more manageable, as long as we can gain that visibility for our organizations individually.
00:11:57.360 --> 00:12:03.360
Yeah, I think that's the hardest, it's easy to say here to do, um, but I think that's the hardest thing to establish through your organizational teams.
00:12:03.519 --> 00:12:17.519
Um, to getting the knowledge of having the span of all vulnerabilities, but then getting someone that actually knows not only your network from a systems perspective, but can actually dive down deep into the actual coding languages that your systems require.
00:12:17.679 --> 00:12:17.919
Right.
00:12:18.000 --> 00:12:27.039
So to your point, is if it requires an insider threat that actually has credentials that has to be on-prem, it makes it vastly more difficult for someone to exploit that, right?
00:12:27.200 --> 00:12:35.519
Um, but being able to get these this information and having internal knowledge of how likely things are, and then what's the expectation of that to occur.
00:12:35.679 --> 00:12:39.360
Like we're talking about multiple teams within a cybersecurity organization that have to do that, right?
00:12:39.759 --> 00:12:48.480
Your threat team, your volume team, your remediation team, probably your technology team from the perspective of if you really need to dive into that code to understand how that actually function works, right?
00:12:48.639 --> 00:12:51.519
So this is cutting across multiple organizations.
00:12:51.840 --> 00:12:57.120
And that's why I think it becomes extremely difficult for organizations to manage this at scale.
00:12:57.200 --> 00:12:57.840
Um, right.
00:12:58.000 --> 00:13:03.759
Different application owners are going to say that they're the most important thing in the world and their vulnerabilities need to be addressed.
00:13:03.840 --> 00:13:06.720
But then they say you can't do code changes and patches and updates.
00:13:06.879 --> 00:13:07.200
Right.
00:13:07.440 --> 00:13:22.799
So that's why I'm saying that this space is one of the, I think, most difficult spaces to execute at a high level to decrease what are quote unquote just volume numbers because that's what management looks at, rather than, hey, this is the highest risk in our environment.
00:13:22.879 --> 00:13:25.840
And we're really addressing those for our most critical applications.
00:13:26.000 --> 00:13:26.240
Right.
00:13:26.320 --> 00:13:30.559
That's where the conversation doesn't really flow back and forth between the business and cyber.
00:13:30.639 --> 00:13:43.120
Um, but the more that those two organizations can kind of come together to understand and prioritize how do we really focus on how it needs the focal, then again, you're going to be ahead of the game, not chasing the numbers, but truly reducing the risk where it's needed.
00:13:43.360 --> 00:13:50.559
Oh, it's, you know what, you know, that reminds me of it, reminds me of like the nomenclature, like the cut, the phrases we used to use in enterprise, right?
00:13:50.639 --> 00:13:52.000
Those enterprisesms, right?
00:13:52.159 --> 00:13:53.360
And then what would everyone say?
00:13:53.600 --> 00:13:56.399
We take a risk-based approach on X, Y, or Z.
00:13:56.480 --> 00:13:59.679
And in this case, that does make a ton of sense for vulnerability management, right?
00:13:59.759 --> 00:14:12.559
And again, look, nothing we're saying here is like groundbreaking, but like again, it's interesting to look at the statistic and then like try to put this into context because like I remember I was working with an organization and we're trying to get vulnerabilities under control.
00:14:12.720 --> 00:14:21.759
And when I first stepped into the org and tried to get an understanding of like what we're looking at, their vulnerability count was at something like 2.4 million.
00:14:22.000 --> 00:14:26.080
2.4 million open vulnerabilities across the entire organization.
00:14:26.320 --> 00:14:28.399
They had great visibility, right?
00:14:28.480 --> 00:14:38.879
So from a technology perspective, they had the system fiber scanning, they were doing authenticated scans, they were doing unauthenticated scans, they were scanning regularly, daily, weekly, differentials, like they had everything right.
00:14:38.960 --> 00:14:42.240
So they knew what was there, but they were lacking process, right?
00:14:42.399 --> 00:14:54.799
They didn't have process to be able to say, all right, here's that, here's how we're gonna go through and identify what needs to be done and how we're gonna do it, and what change windows we're gonna use, and when we're gonna do our patching, and how we're gonna test those patches.
00:14:54.960 --> 00:14:56.159
None of that existed.
00:14:56.320 --> 00:15:02.399
So even though they solved the technology problem from a visibility perspective, I can see all the vulnerabilities I have.
00:15:02.559 --> 00:15:04.960
They didn't solve the problem from a process perspective.
00:15:05.120 --> 00:15:07.919
And more importantly, it didn't solve the problem from a people perspective.
00:15:08.080 --> 00:15:16.159
Because what they didn't have is they didn't have assigned accountability back to the various platforms to say, you're responsible for this platform, you're responsible for its health.
00:15:16.320 --> 00:15:16.480
Right.
00:15:16.639 --> 00:15:18.960
So if we're breaking this down across control elements, right?
00:15:19.039 --> 00:15:23.519
If we're looking at things like the Taus Control Stack, like this is how we would dissect that issue.
00:15:23.679 --> 00:15:35.360
And one of the most amazing things that happened is once we sorted accountability and process, like we were able to patch, I think it was something like 12 or 14 applications, and it knocked off a million vulnerabilities.
00:15:35.440 --> 00:15:36.879
It cut them in half, right?
00:15:36.960 --> 00:15:40.720
Because the other issue with vulnerabilities, you know, we we're talking about like size and scale.
00:15:40.879 --> 00:15:48.000
I feel like volume becomes a really big conversation when we talk about vulnerabilities, is that you have these vulnerabilities that come out, right?
00:15:48.080 --> 00:16:07.679
But one vulnerability that's released might result in a thousand vulnerabilities on your network if you have that application installed across a thousand endpoints, or you know, 500 people are using it, or 250 individuals have that app, whatever the whatever the actual volume and sprawl is, like this is where the numbers start to get out of control.
00:16:07.919 --> 00:16:09.519
But the inverse is also true.
00:16:09.679 --> 00:16:20.240
So if you can solve for process, if you can solve for people on an accountability perspective, then you can come back and you can say, look, these are our highest levels, going back to our risk-based approach.
00:16:20.399 --> 00:16:24.559
These are the ones that are most critical, they're forward-facing, they're accessible externally.
00:16:24.720 --> 00:16:36.320
Whatever the criteria is, if we patch these, we can start to take out entire swaths of vulnerability, data of vulnerability count to actually get this to a manageable level where you truly are mitigating risk.
00:16:38.639 --> 00:16:39.200
Is that it?
00:16:39.279 --> 00:16:41.120
Did we kill vulnerability?
00:16:41.600 --> 00:16:44.399
Is that the stat going underground being buried?
00:16:45.679 --> 00:16:46.559
I guess so.
00:16:46.799 --> 00:16:47.120
All right.
00:16:47.279 --> 00:16:49.039
Well, I think I think we're good at vulnerability.
00:16:49.120 --> 00:16:50.080
Any more comments on that one?
00:16:50.159 --> 00:16:51.279
Or do we want to pick another truck?
00:16:51.600 --> 00:16:56.000
No, again, I think, you know, again coming out of Black Hat, um, this problem isn't going anywhere.
00:16:56.080 --> 00:16:58.240
It's going to again be expedited, right?
00:16:58.320 --> 00:17:02.159
Um, with the capability of AI to uh unleash and identify.
00:17:02.320 --> 00:17:07.680
Um and this also goes back to we certainly understand that there's a lot of legacy systems out there, right?
00:17:07.759 --> 00:17:08.960
Um I didn't even think of that.
00:17:09.119 --> 00:17:12.400
And those are the things that are not going to be coming out of the picture of the purview, right?
00:17:12.480 --> 00:17:16.559
You can't hide any longer by being a 2008 shop or anything like that.
00:17:16.799 --> 00:17:27.279
Um so again, it's just as you talked about and highlighted, it's it's not to be overwhelmed or scared by the numbers, but to understand that this is a legitimate tactic that would be taken advantage of.
00:17:27.440 --> 00:17:30.400
And organizations need to build a strategy around for defending it, right?
00:17:30.559 --> 00:17:33.680
So no, you're you're absolutely you're absolutely spot on.
00:17:33.759 --> 00:17:35.279
I actually didn't I didn't even think about that, right?
00:17:35.440 --> 00:17:43.200
So like we we we started this by thinking about the 130 vulnerabilities that existed that were, that were disclosed per day on average in 2025.
00:17:43.519 --> 00:17:45.200
But those are new, right?
00:17:45.359 --> 00:17:56.319
Like let's not forget that these things are compounding over the last 15 years or however long CBSS has been like recording, you know, recording these these vulnerabilities.
00:17:56.559 --> 00:18:01.119
So like the thing that's interesting is you talk about out-of-support software.
00:18:01.200 --> 00:18:08.079
And I've actually I've actually interacted with a couple clients who have had this issue where like they have software where the company may have gone out of business.
00:18:08.240 --> 00:18:09.039
This is a real thing.
00:18:09.200 --> 00:18:12.319
Like they were using something and the company just went belly up.
00:18:12.400 --> 00:18:14.400
They still had this dependency on this application.
00:18:14.559 --> 00:18:15.279
Well, guess what?
00:18:15.440 --> 00:18:17.920
There's no more patching, there's no more support.
00:18:18.079 --> 00:18:20.400
Like, what do you do in that scenario?
00:18:21.279 --> 00:18:22.799
I think roll the dice, right?
00:18:22.960 --> 00:18:26.079
At that point, like security by obscurity.
00:18:26.160 --> 00:18:26.960
I love it, right?
00:18:27.039 --> 00:18:28.000
Just don't tell anybody.
00:18:28.160 --> 00:18:31.279
Take it off of your inventory, just you know, leave it under the desk.
00:18:31.440 --> 00:18:32.559
Don't like, don't bring it up.
00:18:32.640 --> 00:18:34.400
That is definitely one way to address it.
00:18:34.559 --> 00:18:34.799
Yeah.
00:18:34.960 --> 00:18:37.680
No, I mean, look, there's there's a couple of interesting things people have done.
00:18:37.759 --> 00:18:42.160
And again, nothing crazy novel, but like some of the things that they've done have been like, all right, well, you know what?
00:18:42.240 --> 00:18:44.079
We're gonna surround it with additional controls.
00:18:44.240 --> 00:18:47.359
We're gonna compartmentalize the system because we can't patch it.
00:18:47.440 --> 00:18:48.000
We can't fit it.
00:18:48.079 --> 00:18:48.799
It's out of support.
00:18:48.880 --> 00:18:51.039
There's no more new patching that's coming out.
00:18:51.200 --> 00:18:57.599
Like this thing is just now not only vulnerable to certain things, but what's worse is over time those vulnerabilities have become commoditized.
00:18:57.680 --> 00:19:01.359
They're added to all of the different scanners, all the different exploit kits.
00:19:01.519 --> 00:19:03.119
Like they just are automatic, right?
00:19:03.279 --> 00:19:07.359
Attackers are just kidding you immediately and like automatically deploying these vulnerabilities.
00:19:07.519 --> 00:19:14.640
So you have to take this concept of like, all right, I have 130 a day I'm worried about, but I also have the million that's behind that.
00:19:14.799 --> 00:19:19.039
And now I have to deal with software that's actually added out of, you know, out of support.
00:19:19.440 --> 00:19:21.119
All right, I'm back on the scared bubble.
00:19:21.359 --> 00:19:23.920
This is this whole conversation has been an emotional roller coaster.
00:19:24.000 --> 00:19:25.039
It's like really scary.
00:19:25.119 --> 00:19:27.039
We're under control, kind of scary.
00:19:27.200 --> 00:19:28.000
Uh, there's a way out.
00:19:28.079 --> 00:19:29.200
Oh my God, I'm scared again.
00:19:29.359 --> 00:19:32.319
Like, I I'm not sure I can deal with many more of these episodes again.
00:19:34.640 --> 00:19:36.000
I guess the next card, huh?
00:19:36.240 --> 00:19:36.480
I guess.
00:19:36.799 --> 00:19:37.359
Oh, all right.
00:19:37.440 --> 00:19:39.039
Well, you have two cards left to choose from.
00:19:39.119 --> 00:19:40.240
You have A and you have B.
00:19:40.480 --> 00:19:41.759
Well, I can't choose C again.
00:19:42.000 --> 00:19:45.359
I mean, you could, but we'll probably just have to put the episode on repeat.
00:19:45.440 --> 00:19:46.319
It'll save us a bunch of time.
00:19:46.640 --> 00:19:47.119
That'll be good.
00:19:47.440 --> 00:19:49.200
Well, I guess I gotta go the other extreme, right?
00:19:49.279 --> 00:19:49.839
Let's do A.
00:19:50.000 --> 00:19:50.319
A.
00:19:50.480 --> 00:19:52.000
All the way to the left.
00:19:52.079 --> 00:19:52.400
All right.
00:19:52.480 --> 00:19:53.519
Let's go to A.
00:19:53.759 --> 00:19:54.079
Okay.
00:19:54.240 --> 00:19:58.400
So this actually comes from CrowdStrike's 2026 Global Threat Report.
00:19:58.640 --> 00:20:16.480
And what they've reported in that, uh, in that report they released publicly was that the average eat crime breakout in 2025 was down from 40, 48 minutes in 2020, uh, in 2024 to 29 minutes in 2025.
00:20:18.000 --> 00:20:19.759
So can you restate that, please?
00:20:20.480 --> 00:20:21.440
Yeah, I can.
00:20:21.680 --> 00:20:22.240
All right.
00:20:22.480 --> 00:20:23.839
We're I folks, I promise.
00:20:23.920 --> 00:20:24.720
We'll get better at this.
00:20:24.880 --> 00:20:25.920
It's our third episode.
00:20:26.000 --> 00:20:27.200
Like, let us work through this, all right?
00:20:27.359 --> 00:20:28.160
We can't hello.
00:20:28.559 --> 00:20:28.799
We can't.
00:20:28.960 --> 00:20:31.920
We also can't see because I got the I got the years wrong also.
00:20:32.000 --> 00:20:33.759
So I'm gonna restate this completely.
00:20:34.000 --> 00:20:35.200
Thank you for calling this out.
00:20:35.359 --> 00:20:35.599
Okay.
00:20:35.759 --> 00:20:36.559
Here's what we're talking about.
00:20:36.640 --> 00:20:38.319
This is CrowdStrike's global threat report.
00:20:38.400 --> 00:20:40.079
And what they're reporting on here is e-crime.
00:20:40.319 --> 00:20:42.720
And specifically, what they're reporting out is breakout time.
00:20:42.880 --> 00:20:43.920
So let's start with that.
00:20:44.160 --> 00:20:52.160
Breakout time is the time it takes from an attacker to gain access to the very first system and how long it takes them to break out to the next system.
00:20:52.559 --> 00:20:56.400
In 2025, the average breakout time was 48 minutes.
00:20:56.559 --> 00:21:01.200
So an attacker was able to gain a foothold on a very first system, laterally, right?
00:21:01.279 --> 00:21:06.720
And then the time it took them to move laterally from that first entry point was 48 minutes.
00:21:06.960 --> 00:21:12.480
In 2026, their report brought that down to 29 minutes.
00:21:13.039 --> 00:21:19.759
So sub 30 minutes, the ability to break out on average from the first system into the next system.
00:21:20.240 --> 00:21:22.000
What does that feel like for you?
00:21:22.319 --> 00:21:23.200
It's interesting, right?
00:21:23.279 --> 00:21:28.720
I think there's a lot of things that kind of come to mind in the sense of quickness for sure, right?
00:21:28.799 --> 00:21:34.960
I mean, that's the first thing that comes to me is that the attackers are able to move laterally quicker.
00:21:35.200 --> 00:21:39.440
Um the secondary thing is kind of coming to mind is why, right?
00:21:39.519 --> 00:21:39.680
Yeah.
00:21:39.839 --> 00:21:42.799
What why are someone able to move quicker through our environment?
00:21:42.960 --> 00:21:44.240
And again, a couple of things come to mind.
00:21:44.319 --> 00:21:48.319
Again, what a novel here, right, is potentially more living off the land tools.
00:21:48.559 --> 00:21:48.720
Right.
00:21:48.799 --> 00:21:54.640
So as we know that detections are coming through, attackers know actually how to make amass themselves to go through good traffic.
00:21:55.039 --> 00:21:55.440
Um, right.
00:21:55.599 --> 00:21:59.759
And I think a lot of this also brings up to the fact that the breakout time isn't talking about.
00:22:00.079 --> 00:22:01.359
out the dwell time, right?
00:22:01.519 --> 00:22:02.960
How long is someone on the network?
00:22:03.359 --> 00:22:07.119
It would be a really awesome data point to understand this a little bit more.
00:22:07.279 --> 00:22:07.440
Right.
00:22:07.599 --> 00:22:17.359
The reason why I bring that up is because my assumption is that are we having better, more sophisticated attackers to say, get an understanding of the network first and sick.
00:22:17.680 --> 00:22:18.240
Learned.
00:22:18.400 --> 00:22:21.359
Don't try to go in there and get your objective immediately.
00:22:21.920 --> 00:22:29.839
And then the other element of that for me is that they're getting really good at trying to understand the network in a quiet area.
00:22:30.079 --> 00:22:34.400
They may not be hopping somewhere that is the highest level of admin credentials immediately.
00:22:34.559 --> 00:22:34.799
Sure.
00:22:34.880 --> 00:22:43.039
They may be trying to hop to different areas of the network, slowly working their way towards again, admin credentials or elevated privileges.
00:22:44.000 --> 00:22:52.640
And so again, just a couple of those things that are sparking to me from that perspective of, you know, why, what's the importance, um, how are they doing it?
00:22:53.039 --> 00:22:54.799
But then from the defensive perspective, right?
00:22:54.880 --> 00:23:03.039
That that's definitely scary in the sense that you do want to start to reduce how they are going in your network, right?
00:23:03.200 --> 00:23:05.920
If they're in, it's always about containment, right?
00:23:06.079 --> 00:23:08.079
How quickly can we stop them from moving?
00:23:08.559 --> 00:23:12.240
And this is basically saying it's not happened quick enough, right?
00:23:12.480 --> 00:23:12.880
Sure.
00:23:13.119 --> 00:23:16.000
You break you actually bring up something I never thought about before, right?
00:23:16.160 --> 00:23:24.000
So like immediately when I read this card, the things that came to mind are this concept of, okay, clearly AI is playing into this.
00:23:24.160 --> 00:23:27.039
Clearly they're they're playing you know kind of those red team bots.
00:23:27.119 --> 00:23:34.240
Like, and we can talk a little bit about the difference between red teaming and blue teaming and like how AI agents are are changing those worlds and what they're doing.
00:23:34.400 --> 00:23:44.400
And I have, I have a personal opinion that red teaming and like the exploitation side of these bots is way further ahead than blue teaming because of the nuance that comes with defense.
00:23:44.559 --> 00:23:45.680
We can talk about that later.
00:23:45.839 --> 00:23:47.680
But you bring up something I never thought about before.
00:23:47.759 --> 00:23:55.519
Like so I never thought about this concept of living off the land and utilizing those tools in terms of speed, right?
00:23:55.680 --> 00:23:58.079
But I think it actually makes a tremendous amount of sense.
00:23:58.319 --> 00:24:09.039
So for those of you listening, those of you new in your career, we talk about living off the land, what that means is that means that the attackers are using built-in tools that are that are a part of the operating system.
00:24:09.119 --> 00:24:12.160
They're a part of the the actual network that exists.
00:24:12.319 --> 00:24:15.519
They didn't have to drop in new tooling they didn't have to download malware.
00:24:15.680 --> 00:24:19.119
They didn't have to utilize the tools that they built off of offline.
00:24:19.359 --> 00:24:22.720
They focused on like utilizing the things that were already on the system.
00:24:22.880 --> 00:24:27.920
And the reason why this attack is so effective and so useful is because they're hard to detect.
00:24:28.000 --> 00:24:39.119
These are built in, they're trusted, they're signed by Microsoft or whoever, whatever the operating system is so when they're utilized, it's not like we have we have a signature for them, we do, but they're used all over the world, right?
00:24:39.200 --> 00:24:41.359
So it's kind of buried and that's what Owen was alluding to.
00:24:41.519 --> 00:24:48.319
So like if I think about this, which is a new perspective for me from the perspective of speed, I think that makes a tremendous amount of sense.
00:24:48.480 --> 00:24:50.960
The tool is always consistent across the board, right?
00:24:51.119 --> 00:24:54.000
They've gotten good at looking for those specific tools, what to use.
00:24:54.160 --> 00:24:57.279
The commands are probably you know copied and pasted, right?
00:24:57.359 --> 00:25:01.759
If they're not automated, bringing it back to the AI agent stuff we were talking about a second ago.
00:25:01.920 --> 00:25:04.079
So I actually think that makes a ton of sense, right?
00:25:04.160 --> 00:25:05.839
Because like there is no stopping it.
00:25:06.000 --> 00:25:12.640
Like we have to now rely on behavioral analysis because the actual signatures of the software themselves don't matter.
00:25:12.799 --> 00:25:13.839
Everyone has them.
00:25:14.000 --> 00:25:17.359
They're approved they're used for day-to-day administration.
00:25:17.759 --> 00:25:42.640
I think that definitely part of this though is absolutely AI and like this concept of these unconstrained models, the agents that have been built that are basically being fed with every piece of information that any pen test has ever uncovered, any tactic built into things like Cali Linux, any any tooling that's been built over time, like all of these things are being produced and provided at machine speed.
00:25:42.799 --> 00:25:46.960
And that's what I think is starting to get this breakout time down do you think?
00:25:47.440 --> 00:25:53.359
Yeah, no, agreed um my math's horrible right um but that's what 19 minutes difference?
00:25:53.759 --> 00:26:01.759
Yeah so so on average back in your SOC days, how long was a very capable tier one analyst able to dispose of an alert?
00:26:02.160 --> 00:26:03.839
Wow, great question man.
00:26:04.000 --> 00:26:09.680
Like so this is so this is back in the day before we had like AI analysis tools, right?
00:26:09.759 --> 00:26:23.119
Which is which has sped things up amazingly so like if we're not if we're talking about true human look at alert, find the logs, triage, like triage alone would take anywhere from 15 to 25 minutes depending on complexity.
00:26:23.279 --> 00:26:28.240
And that's only the first look and that's only like tier one before we got into levels of escalation.
00:26:28.319 --> 00:26:31.839
And that's assuming the queue didn't have them hold those alerts for two to three hours.
00:26:32.240 --> 00:26:37.599
No totally and so that's where my head is going on this perspective is like it's one thing to understand how quickly the attackers are moving.
00:26:37.759 --> 00:26:44.480
But that's exactly where I think on the best average back in the corporate days when I was about in the sock area, I think was 15 minutes.
00:26:44.640 --> 00:26:46.880
And that's someone that knew their shit excuse me.
00:26:47.039 --> 00:26:50.880
They knew where to go, what to look for, what signatures are bad, what are good.
00:26:51.039 --> 00:26:52.720
And so that's 15 minutes.
00:26:52.880 --> 00:26:56.799
We're saying though that this hot took about 19, right?
00:26:56.960 --> 00:26:57.680
Give or take.
00:26:57.839 --> 00:26:58.160
Yeah.
00:26:58.400 --> 00:27:03.119
On average I would assume that a normal human is about 20 to 30 especially a tier one junior level.
00:27:03.279 --> 00:27:03.519
Sure.
00:27:03.680 --> 00:27:03.839
Right?
00:27:04.000 --> 00:27:14.640
AI is helping along the way but again that's where the notion of if you have AI that's doing an end to end without human intervention, can you trust that how often is the testing being done, right?
00:27:14.720 --> 00:27:16.240
How likely are these to pick that up?
00:27:16.480 --> 00:27:24.640
Even if you have a human that's overlooking AI triage response, again, are they capable enough to see sift through that to be able to pivot?
00:27:24.799 --> 00:27:27.759
So in this example, we've got one hit, right?
00:27:29.119 --> 00:27:33.279
19 minutes quicker, they're already in the next spot of your actual network.
00:27:33.680 --> 00:27:38.160
So is an analyst able to keep up with these speeds and identify as your certain aha right.
00:27:38.240 --> 00:27:44.319
So this just again compounds of definitely want AI automation to be able to know how to take proper action.
00:27:44.559 --> 00:27:52.799
But again going to practice that's extremely difficult because you don't usually want to block certain things on sensitive systems unless you fully know it on 100%.
00:27:53.279 --> 00:28:06.640
And you know what's interesting is like again I'm also terrible in math but like if if if I'm thinking over this if we're going from 48 minutes and reducing by 19 minutes, like we're close to like 35 to 40% reduction in one year.
00:28:06.880 --> 00:28:11.359
I I I can't even imagine what the 2027 number is going to be.
00:28:11.680 --> 00:28:11.920
Right.
00:28:12.079 --> 00:28:15.680
Like we're we're gonna get into like sub 15 from in terms of breakout.
00:28:16.000 --> 00:28:40.319
And the thing is like folks the thing that's scary about this is that it's not necessarily just like oh that's the breakout that's the average right so there are plenty of organizations that have invested in cyber they've they've hardened their systems they've built the right tooling and those breakouts are going to be in the you know whatever hour range but think about all the other organizations where we've seen like we've seen the quickest breakout has been something like 54 seconds.
00:28:40.559 --> 00:28:40.720
Right.
00:28:40.799 --> 00:28:49.680
So like if we're if we're bringing this back down to averages like this doesn't mean you have, you know, whatever it is 29 minutes to get your act together.
00:28:49.839 --> 00:28:54.559
It really depends on your organization, depends on your controls, depends on the staffing you have uh assigned to it.
00:28:54.640 --> 00:28:58.559
Uh, you know, and like these are the things that really start to break out that nuance.
00:28:58.880 --> 00:28:59.039
Yeah.
00:28:59.200 --> 00:29:10.960
And I'm not again I'm not a an AI um evangelist, but I think to your point, right, we've been seeing that over about the last one to three years are that the defenders are understanding that they have to invest in AI.
00:29:11.119 --> 00:29:14.160
So it's now becoming AI is fighting AI is defending AI.
00:29:14.240 --> 00:29:14.319
Right.
00:29:14.480 --> 00:29:15.279
It's AI against AI.
00:29:15.519 --> 00:29:26.160
Yeah it's by vs spy I'm dating myself but the old mad magazine spy versus spy right like and that's where it's again the attackers inherently are going to be ahead of the game because they're able to learn quicker.
00:29:26.240 --> 00:29:29.119
They're able to implement without having to have approvals, right?
00:29:29.359 --> 00:29:32.079
Compliance oversight, governance, none of that stuff.
00:29:32.240 --> 00:29:39.200
But we can't stop to to incorporate the AI capabilities again, as we talked about before defense and depth, right?
00:29:39.279 --> 00:29:44.079
Where are the other controls that we actually can manage to helpfully thwart against that, right?
00:29:44.799 --> 00:29:51.599
I think it was at Black Hat where someone was doing a presentation on the economy of the economics of the economics of malware.
00:29:51.680 --> 00:29:51.839
Yeah.
00:29:51.920 --> 00:29:52.480
That was amazing.
00:29:52.799 --> 00:29:59.839
And kind of shifting from what our big opportunity here is not to fight dollars with dollars, but to kind of rethink how we're implementing our controls.
00:29:59.920 --> 00:30:02.640
And I think what he said is redo the physics of it.
00:30:02.720 --> 00:30:02.880
Yeah.
00:30:03.039 --> 00:30:03.200
Right.
00:30:03.279 --> 00:30:16.880
So I started to think about how do we use tool sets appropriately to keep up with or go past how basically attackers are just leveraging money at the NMS AI tools and capabilities to do things quicker.
00:30:16.960 --> 00:30:17.119
Yeah.
00:30:17.200 --> 00:30:17.359
Right.
00:30:17.440 --> 00:30:19.440
Because we're not going to be able to keep with speed.
00:30:19.759 --> 00:30:24.640
So again moving this to a different area of thought right is sports for me.
00:30:24.799 --> 00:30:27.039
If you're bigger and stronger, I'm gonna be smaller and quicker.
00:30:27.200 --> 00:30:29.440
If you're smaller and quicker, I'm gonna be bigger and stronger.
00:30:29.519 --> 00:30:29.680
Right.
00:30:29.839 --> 00:30:30.000
Right.
00:30:30.079 --> 00:30:38.319
So it's those those notions of how do we stay creative to meet someone at that point of conflict rather than trying to say I'm gonna match you dollar for dollar.
00:30:38.799 --> 00:30:40.640
That is an amazing perspective.
00:30:40.880 --> 00:30:42.799
And that's what this podcast is about.
00:30:43.039 --> 00:30:46.400
So look we're at 30 minutes on this is the fastest 30 minutes this week.
00:30:46.480 --> 00:30:48.799
I'll tell you right now, this conversation just flowed for me.
00:30:48.960 --> 00:30:51.279
Super amazing to take a beat and talk about these things.
00:30:51.440 --> 00:30:52.319
Really appreciate it.
00:30:52.480 --> 00:30:54.960
What are your last thoughts you want the audience to leave with on this one?
00:30:55.200 --> 00:30:59.839
I'm just looking forward to to getting participants, building the community right love Paul.
00:31:00.319 --> 00:31:07.519
No I think we're both you know somewhat intelligent, fun people to talk with, but um we definitely need others, right?
00:31:08.960 --> 00:31:13.440
We definitely want some different perspectives or we're gonna start saying the same thing over and over again.
00:31:13.680 --> 00:31:14.000
Agreed.
00:31:14.079 --> 00:31:20.079
And and look we definitely have a bunch of guests lined up super excited to circum some folks on on the uh on the show here.
00:31:20.720 --> 00:31:27.759
You know what I want to be audio to leave with on this one is for me, like a lot of the theme here is fear today.
00:31:27.920 --> 00:31:28.720
And I hate that.
00:31:28.960 --> 00:31:35.920
I hate that our industry that cybersecurity just drives this concept of fear all the time and it it's very frustrating.
00:31:36.079 --> 00:31:41.440
But like I think what we talked about today are exactly how you get past that fear, right?
00:31:41.599 --> 00:31:45.039
Like the numbers are scary, but you're in control of your network.
00:31:45.200 --> 00:31:53.519
You can pull the levers you need to in order to start to reduce these numbers, reduce your attack surface and make it harder for the attackers to do what they need to do.
00:31:53.680 --> 00:31:54.880
But that's on you, right?
00:31:54.960 --> 00:32:01.680
Like one of the things I love to tell clients when I'm talking them is remember you have home court advantage to bring this back to a sports analogy, right?
00:32:01.839 --> 00:32:03.039
You have control over all the tech.
00:32:03.599 --> 00:32:06.720
You can fix the things in order to make sure things like this don't happen.
00:32:06.960 --> 00:32:19.039
Or when they do happen, because that unfortunately is a reality in our space, you minimize the blast radius, you keep things nice and small and you make them easy to just kind of fix and move on from I think that's it, man.
00:32:19.200 --> 00:32:22.799
That's uh the first full episode in the books and uh it's been a pleasure.
00:32:22.880 --> 00:32:24.160
I can't wait to get it going again.
00:32:24.400 --> 00:32:25.039
Gaveled.
00:32:25.200 --> 00:32:25.680
Gavled.
00:32:25.839 --> 00:32:26.559
Also take care.