Transcript
Give us a fighting chance. Give yourself a fighting chance. If you have multi-factor authentication, if you have endpoints, a VPN to encrypt your connections, you're backing up, you're patching, well, it might not stop it, but what it does, it's like another hurdle or another lock they gotta pick. And when you combine those, you get that opportunity to go, hang on a second, I've seen a few things occur, maybe there's something, and then you can dive in. But if you don't have those, there are no alarm bells, there are no tripwires. Unfortunately, it's like the big bang happens, right? That's when you wake up one day and all your data's gone, or your money's been emptied out of an account, and it's too late. Welcome to Now That's It, Stories of MSP Success, where we dive into the journeys of some of the trailblazers in our industry to find out how they used their passion for technology to help turn managed services into the thriving sector it is today. Mark Sangster, cybersecurity author, expert, evangelist, and industry security strategist. Currently the chief of strategy at AdLumen. Mark, welcome to the Now That's It podcast. Oh, this is fabulous. Thanks for having me on the show. So it's always an honor to have industry leaders join the podcast. You have a ton of stories. We'll talk a little bit about your book, and I'm really looking forward to some of the stories today. This is gonna be a lot of fun, and just the conversations we've had beforehand, planning, yeah, I'm looking forward to it. So you've had an extensive career, probably more extensive than most of my guests, and we'll talk about some of those honorable things that you've been part of. But has security always been a North Star for you, Mark? You know, it has. I don't think I'd have actually recognized that, but as you say it, you're absolutely right. So, you know, back in the day, I worked for a company called BlackBerry. Do you remember those, those mobile devices that were keypads? And I worked on the first encrypted device, which at the time was for the Congress and for the DOD, but, you know, the tech wasn't there, right? So like you would, you know, send a message and encrypt it, and you could go for a coffee and maybe it had gone. And then when you got the response, you went for lunch to wait till it decrypted so you could actually read the thing, right? But that's, you know, that's the early kind of heady days in this. And of course it's changed so dramatically now, but yeah, and then working with Intel and Cisco, and then of course AdLumen, you know, that's it, right? And it's become, I think in the last decade, it's now a household kind of term, right? And it's a whole new category. You know, we look at it in investment, we look at it from a risk strategy perspective, and that's made a difference. So it's in the forefront now. So before your time at AdLumen, you were a principal evangelist and vice president of industry security strategies at East Sentire. Right. While you were there, you did a number of pretty cool things, and I wanted to talk about a couple of them. Alrighty. The first, you wrote a book called No Safe Harbor. Yep, that's right. The inside truth about cyber crime and how to protect your business. Bought it online, fantastic. You did that back in 2020, right? That's right, right in the pandemic, yep. Perfect timing. You tell some stories about some of these breaches and some of the things that filled sort of the headlines. And there were several takeaways from the book that I got, but one that really struck me was that, as you mentioned a little bit ago, organizations really need to ship those security discussions away from the technology, right? Like we're here, we're talking about a technology stack and what should be in there, but focus on leadership. Right. Why is that so important? Because at the end of the day, they have to set the objectives, right? So I'll give you a good example here of a manufacturing firm that we did some work with. And that firm about three, four years ago was hit by Conti at the time, was a very active ransomware gang and pretty prolific at the time. And they were doing things like when they were shut down, the CFO was working with tech people, sort of saying, look, you need to get these people up and running first. If you can get our design engineers up and running and their systems are working, well, then they can sort of be doing the design work. And then those plans go down to the floor and then you can get the factory guys going. So they really set the objectives for the organization and that's sort of post-attack, but pre-attack, how do you figure out where to spend your resources, right? How do you prioritize? And that is gonna be down to the leadership to be able to say, here's the critical things, right? Whether it might not be data, but it could be systems. This matters to our business, this is our lifeblood. So for every $1 you spend on protecting something else, I want $9 to go to protecting that because if this gets affected, we're gone. So, you know, helping sort of set that and then also understanding and listening to the IT people. The one thing I talk about with the executives and I learned this from a good friend of mine, he's actually, he flew Marine One for three presidents. He was in the White House during the attacks on 9-11. He ended up in the president's bunker because he was kind of the highest ranking military officer at the time who was there. And he talks all the time about the what, not the how. An executive or a leader's role is to say, here's what I want to see or, you know, what my objective should be. You're the expert, you do the how. And I think that is a critical difference because a lot of time in leadership, right? You have to be strong, you're supposed to know everything. You always have to have an answer and that's not true. You got to surround yourself with smart people who they have the answers, you just have to guide them. So what is it about the security industry that excites you the most and conversely terrifies you the most? Well, so I think the first thing is like a joke that about a year in cybersecurity is like working for a decade. So it's constantly changing. There's always something going on. You go to vacation, you can't really vacation. You come back and things have radically changed, right? Every day you roll out of bed, you walk in the office and somebody says, did you hear about such and such event? So it is both terrifying and exciting. I love the excitement of it because it is constantly changing. It is dynamic and you're kind of playing chess with these guys, right? And when I say that, I don't mean to make it a game because it's not, right? The victims, that's significant. That's people's jobs, that's businesses going under, that's hospitals that can't treat patients. And of course we know where that sort of thing leads. On the terror side, that's exactly it. There's a lot at stake here. I recognize that some of the decisions and recommendations we're making are kind of on that nice edge, right? And if something goes well, it's great. But there's a lot of times I often use analogies and visuals in my presentations around things like mountain climbing and that's it, right? And showing the guy hanging off the edge of the cliff because that's what it feels like a lot of the time. And I certainly sympathize with the companies that end up in this position, particularly where they've had a big incident and they're making some tough decisions against the clock, right? And trying to get that to whatever, get that field goal with the last second or two left on the clock. It's a tough, it's a good analogy. You've had the opportunity to speak with businesses of all shapes and sizes, sometimes giving them advice, but oftentimes just listening to their stories. Sometimes they're not pretty stories. What were some of those common themes that you've uncovered with some of this conversation? Yeah, it's great that you lead in with that because it's right. Sometimes people want you to help solve the problem and other times they just want you to listen. But when it comes to these stories, first, I think there's this kind of undertone of misconceptions. So people think, we're too small, we have nothing worth stealing. If big bad guys like Nation States or a ransomware gang come a-calling, how are we possibly going to defend ourselves? And then ultimately there's also this kind of cavalier attitude where it's like, well, even if something happens, we have insurance and backups and we'll be fine. And the problem is, I think it's like a get out of jail free card, right? They think that there's some kind of magic button they can press or whatever it is, an UNO, like a reverse card, that's gonna fix it. And the reality is, there isn't. It is far more complicated than that. So a lot of it is down to executive leadership. Seeing this is, as I talk about all the time, cybersecurity is not an IT problem to solve. It's a business risk to manage, just like any other risk that they might face, whether that's economic headwinds or a natural disaster or something along those lines. And so it's shifting the narrative until they see that, then you can start to have meaningful conversations about, all right, now that we understand it, what are we gonna do to solve this problem? Excellent. You don't have to name names, but I'm just curious. Have you ever heard a story that is maybe just so gut-wrenching or horrible that maybe provoked some deep thought about maybe the state of the industry and where some of these businesses were at? Yeah, for sure. I mean, we've certainly seen this in hospitals, for example, when healthcare facilities, community healthcare centers are taken down. And when you look at that sort of industry, right, there's a lot of consolidation. And that sounds like a lovely sort of corporate term. And really, frankly, it's a euphemism for a bunch of them shutting down. And so you may have areas where there's one center for 100-mile radius and everybody's gotta come in there. And there are cases, I hate to say this, but there are fatalities associated with ransomware attacks, right? And this is simple delays in things like medical records now being transferred as paper and pen, people writing down the wrong thing or misreading it. Or we also see that often the med tech gets taken down and so doctors don't trust it. So they look at the results and they go, no, that can't be right. And so they miss things. So in those situations where it's life and death, right, where time matters like strokes and heart attacks or trauma with car accidents, unfortunately we see fatalities go up after ransomware. And that to me is, I feel like we could have avoided that, right? That's it's unnecessary. In other cases, it's businesses, people that those companies go under. And the executives, one case where an executive took his own life because the company went under and that's tragic. There's definitely been a shift to more sophisticated attacks. Agreed. Is this a wake up call or should it be a wake up call for businesses to treat security really as a foundational policy rather than sort of a nice to have insurance policy? I don't think this is gonna happen. Yeah, you know what? I love the term that sort of foundational policy is exactly what it needs to be. So like you said, just like any other form of risk, whether it's economic, it's legal strife or whatever it might be, they have to look at it like that. And those assets, whether it's bad deals or whether it's a cyber criminal stealing that money, they have to, it has to be primary. And we're seeing that as well as evidenced in things like investment banking, mergers and acquisition, where this is an area where they're really focusing on making sure there isn't gonna be a loss of value. And then insurance is the other one where insurers are saying, if you're not doing these things effectively, if you don't drive the speed limit, wear your seatbelt, all that kind of thing, then we're gonna invalidate your coverage if something does happen. And I think that's the real lesson here is if we were to use that auto insurance analogy, we've got companies driving around with blindfolds on, their seatbelts off and their airbags disabled, running red lights and thinking like, whatever, my car is too small, no one's gonna hit my car, all that kind of, like I said, those misconceptions. And of course, when it happens, then it's the reality check because they realize it isn't like, well, it won't happen to me, it happens to somebody else. As I mentioned earlier, your current role is the Chief of Strategy at AdLumen, a cloud native managed detection and response platform. I come from the MSP industry, I used to try to sell security. We're doing our best as MSPs and our customers really to sell security and sell the value and the importance of security. They run assessments to identify gaps, they perform training, they're doing a number of different things. But in the end, it's always trying to sell security as a must-have versus a nice-to-have. What advice do you give to some of the MSPs and service providers that are out there on pitching the security narrative to make security that baseline instead of an add-on? Yeah, so there's a term in the security industry called FUD, fear, uncertainty, and doubt. And everybody kind of sells the scary, right? The big and scary. And I did a little bit earlier when I told you those hospital stories. But I think the other thing that a lot of people, when they go to market, when they're working with these types of companies, is we live in a world of corporate statistics and metrics. And so the problem is we throw out all these crime kind of statistics. The problem with crime statistics is that they're abstract. But if I tell you that your neighbor got robbed at gunpoint, now it's a different story. Now you get an alarm system, right? You get a bigger dog, better locks, or you move. Because it's personal and it's relevant. And I think that's what you gotta do. So less of, I think, the stats and kind of the overarching things. Because when you say, well, the average cost of ransomware is four and a half million dollars and so on, they just kind of gloss over. It's something that's not tangible and they can't really understand it. But when you tell a story and you talk about how the spouse of one of the executives, their account got hacked and they were able to see what she was doing and they were able to defraud the company of like a million dollars, suddenly that matters to them. And so when they understand those things, as I joke about it, there is no ROI as in return on investment in cybersecurity, but I kind of kid around that there's ROI, which is risk of incarceration, which is that little bit of, you know, in larger companies is that there is a liability here, right? There's a fiduciary obligation and you're getting held to it, whether it's courts, class action suits, your clients or regulators. So let's talk tech for a few minutes here. So as MSPs are building their security stack, most have endpoint protection as a priority, right? They might EDR or next gen AV or something like that. They might be patching, backing up. Is that enough, Mark? Those are fundamentals, right? In some way I talk about it, it's like, you know, brushing and flossing, you know, you gotta do it. Is it gonna stop all the cavities? No, but it's, you still have to do it, right? And I think that's important and I don't wanna diminish those. Things like endpoint has become critical because we see a lot of activity on the endpoint. And so it's moved the front line from the firewall to there. That's important. Things like backing up and patching. Unfortunately, when we look at even sophisticated attacks, the sort of the basic tools and techniques they use aren't necessarily that sophisticated. They're still phishing, right? They're still getting you to click on a link. And so that's not new, that's very low tech. The problem is when you can combine all these things, that's when you can see it happen. So that's what I always say is, give us a fighting chance, give yourself a fighting chance. If you have multi-factor authentication, if you have endpoints, you know, a VPN to encrypt your connections, you're backing up, you're patching, well, it might not stop it, but what it does, it's like another hurdle or another lock they gotta pick. And when you combine those, you get that opportunity to go, hang on a second, I've seen a few things occur. Maybe there's something, you know, there's suspicious activity here, and then you can dive in. But if you don't have those, there are no alarm bells, there are no tripwires. Unfortunately, it's like the big bang happens, right? That's when you wake up one day and all your data's gone, or your money's been emptied out of an account, and it's too late. Those, I think, give you the, I call them the, they're precursors, right? That's a better opportunity to figure out when something's happened, and it's like, the earlier you catch it, the less it's gonna cost you. It's cleaning up spilled milk. I would rather clean up spilled milk all day long than I would let it metastasize in an organization, and now you have, you know, a crippling event that's gonna cost this business millions of dollars. It's all about reducing that attack surface. 100%. Your book was obviously very successful, so much so that it inspired you to write a second. You wanna share with everybody about the second book? Yeah, so I'm working on a second book right now, and again, it's gonna be cybersecurity, you know, shocking. And I am gonna focus on the sort of right of boom, right? So more of the incident response sort of stuff and what's happened. And I've been interviewing about 30, 40 people now. So it's executives and leaders from companies that have been affected, right? In healthcare, manufacturing, and others. I'm also talking to industry leaders. So, you know, security veterans. I've talked to people in the government. And most interesting, actually, I've been talking to a handful of people who have been with various agencies. You can decide. They call them civilians attached to the military. I'll let you pick a few letters that you can slap in, you know, in parentheses behind their name. And so they've been doing things like working in Afghanistan. Right now, there's a group of them working in the Ukraine. And the reason I wanted to talk to them was like, you know, to really understand what's the ideology behind these criminals, right? Why is it we see so many attacks come from Russia? And there's lots of interesting political, ideological issues. And of course, you know, at the end of the day, it's a lot of economic ones. And so it's just to sort of understand, because I think, you know, there's a whole lot of, you know, know your enemy, right? If you understand their motivations and what they're trying to achieve and think like them, that helps you figure out how to defeat them, right? Sort of Sun Tzu or whatever. So that's the idea anyway. So we're going to put that together and come up with a very light framework because that's the other issue we see is there's, you know, all these big security frameworks with hundreds of controls in them and everybody looks at it and goes, I don't even know where to start. So I just want to go, if there's five things you could do today, you know, do this this week, do this the next thing the next week and so on, that's just going to improve the resiliency of their business. Anyway, I can help. That's why I want to, you know, sort of broaden the message. And that's book two. I'm looking forward to it, Mark. I am definitely going to pick it up and I'm sure some of our listeners will as well. The second thing that I thought was pretty cool is that CNN asks for your input on the rise of ransomware attacks against the U.S. critical infrastructure. That's right. And this was at a time during, I remember this, right during the GBS meat supplier, that's right. That's right. Pipeline attacks. First off, what was that experience like? Okay, so probably the most terrifying thing I've had and it happens quick. So I had one of the people I worked with, she called on like a Friday around lunch and said, hey, CNN wants to interview you. Are you willing to do this? We had to, you know, send a bunch of stuff like other videos we'd recorded, you know, like public speaking. And they wanted to make sure you weren't going to, you know, fall over or freeze on camera, right? When the red light goes on. And then it was sort of like, I don't know, is this going to happen? Is this not going to happen? And the next thing I know, it's like, it's going to happen, you know, 10 a.m. the next day. I get myself all prepped up. And the way it works when you're remote is they, you know, they Skype you in or WebEx you in, right? So you're on a, you know, a remote tool. You're staring at a black screen. You can't see anything. And every so often the director would come on just on audio and say, okay, so we're going to do, we're going to run a story about this topic. Then we're going to go to commercial and then they're going to come back and you're going to have the lead in. And you know, the reporter will start talking and then they'll introduce you. And I'm like, okay. And that just got dragged and dragged. So I'm sitting there for like an hour. Of course, my neighbors, they start doing construction on their deck. So I walked over there with a case of beer and said, hey guys, can you take a break? You know, do that, give me, you know, I'm on CNN. And they're like, come on. I'm like, no, I really actually am on CNN. So we dealt with that. And then, you know, and then when it started, it's just like, it's adrenaline. And I will tell you, I think the big thing I was afraid of was, you know, are they going to ask some kind of political type of question, right? And I'm like, I'm not here to answer those kinds of questions, I'm here to talk about security. But, you know, big, big takeaway for me is, is this sort of scary and as challenging it is, as it is speaking into a black screen. I will say that, you know, the fact that it was household, that people were watching, you know, news hour, you know, at 10 a.m. on a Saturday tells you the state of cybersecurity and the fact that it is, you know, like I said, you know, ransomware is a household term now. Everybody knows what it means. Yeah, it was a big deal. I remember those two sort of infrastructure attacks and anytime pipelines are shut down and meat centers and things like that, that's incredibly scary. Oh, there's another one. What's here at Fort Worth? Just a couple of the utilities just got shut down. They were announcing today. All right, so over the past year, Enable has announced a partnership with AdLumen to bring MDR to the masses, the MSP masses, if you will. What excites you so much about that, Mark? You know, it's a bit like writing the book, right? So, you know, I used to say, if you read the, you know, in the preface, I talked about how I'm standing in boardroom after boardroom saying the same things over and over and I don't feel like I'm getting anywhere. I'm on a hamster wheel. And, you know, you know, AdLumen has done such a great job. You know, I think we have like 1,500 customers, you know, several hundred thousand devices being managed and it's great, right? But coming in with Enable, I think you have such a large access to market. You also have a trust brand with the customers. In cybersecurity, the biggest, you know, currency is trust. So having them say, you know what, we want you to talk to AdLumen because we've done the vetting and we believe they're the right solution for you, that just accelerates what we can do. So the more work we can do, I love doing the roadshows that you have, getting in front of those people, telling stories, but most importantly, it's like hearing their stories. And that just helps us refine what we can do, do a better job again of, you know, keep sharpening the knives as we go to market. And, you know, and I think that's where, you know, you do this at an economy of scale that, you know, effective, like I said, it just accelerates what we're doing. And I think together you have a visibility into the technology that they're using. You understand their world, you understand their business. And, you know, we're the specific player when it comes to how to secure that. And so it's a really, it's a great, you know, marriage. Yeah, we're definitely proud of that trust that we built, that partnership we built with our partners. And it's great to be able to partner with a brand like AdLumen that has an amazing product and to be able to share that with the customers and see what they can do with it. We saw one of those on the main stage today, talk about the value. So I want to ask you, what are some of the ways you hope that the Enable partners develop their managed security offering on top of AdLumen technology? So one of the things I think is there's again, a notion out there that, you know, even if they realize they have the risks, they don't know where to start or they can't afford it. You know, it's like, well, this is way too complicated. And so when I say afford, I don't just mean sort of a financial perspective. I mean, you know, can they manage it? Do they have the expertise? And I think that's what we can do together, right? So we can move into those markets and really bring security, the kind of security that larger, you know, big banks, government, defense have. We're doing the same thing. We're just together. I think we can do this at an economy of scale that allows us to get it down to that market. And you know, when you look at it, right, it's a pyramid, you know, you've only got a handful of those small Fortune 500s in government, but you've got a plethora of all these little businesses and those are the guys that bear the brunt of these attacks. So the more we can do to help them, the better. So you mentioned the roadshows and obviously you're here this week at our big conference, the Empower Conference. Talk about some of the interactions you've had with some of the partners and what those conversations have been like. Yeah, I can tell you after the keynote this morning, fabulous, right? We had lineups at the booth. I, in fact, you know, at one point I was like, I need to go, you know, I need to go sit outside here and like, you know, come up for air for a minute. I mean, it felt like I was donating blood, right? You're sort of, you know, you're doing so much. But yeah, we've had really good conversations where people, I think they got the message, right? They realized, okay, we had these, you know, basic security things in play. You're right, we really didn't know how to aggregate that, pull that together and start doing that other kind of defense that I was talking about earlier. And so that's the, you know, very quickly those conversations went from a, so what do you do? How does this work? To, you know, the next thing I know, I felt like I was being interrogated on speeds and feeds and it was like, okay, so you guys are already doing due diligence effectively, right? And I had one conversation with a partner who the CIO walked out of our meeting room. I was with one of their head technical people and he just walked up and said, yeah, we're doing this. So, you know, work with Mark and figure out, you know, what it is, you know, get all the info you need to like check your boxes and feel good, but this is happening. So, you know, that's, again, this is back to that acceleration and getting to market quicker. I go to a lot of conferences, I do a lot of speaking, but this one, this one, you know, I set it apart because I think it's not only having really good meaningful conversations, but you can see the traction. That's great. Thanks, Mark, really appreciate that. So let me ask you, what are some goals going forward? Obviously you've got a book on the horizon here. You're really excited about this partnership with Enable and what you can bring. What are some other things on the horizon for you? Yeah, I think with security and focusing on the executive layer, right, as I've talked about, you know, one of the things I'd love to do with Enable is kind of brandish what we call like tabletops, right? Tabletop exercises. The idea is, you know, we get the people, we get the leaders, we get the technical people in the room and we simulate these scenarios and it's the best way for them to learn. It's the best way for them to suddenly understand it's not a security issue. Good example I have, there's a few firms now have fallen for this where when they're attacked, you know, some clever person in IT will put up a sign that says, you know, don't connect to the network, don't connect your laptop, all that kind of stuff. Well, the next thing you know, some irate customer takes a picture, sticks it on social media and then you got the news. And so I like to kind of, you know, talk about that and show them, well, that was your call. Or, you know, you don't want the IT person to say, well, I'm gonna take down the service because there's something bad going on and that's gonna knock out a critic, you know, maybe that's online banking, right? Or that's medical imaging in a hospital and now you can't treat patients and that's where they understand that. So, you know, I think there's lots we can do there. Continue with your conferences. I gotta tell you, I would love to be up on that stage. I love the big keynote. You know, I don't know what it is. It's somehow, you know, the bigger the stage, the more fun and interesting it gets, right? And you can kind of do a much different talk, which is, you know, a little less in the weeds, but it's more inspirational and that's where, so I think there's plenty of opportunity for us in the future. You definitely bring a ton of energy, a ton of passion to the security space. You've built an incredible career over the last, you know, 20 plus years. So I have to ask you, when did you know now that's it? In terms of like being in cybersecurity? You know, I would probably say, you know, it was probably five years ago and it's when you're sitting in a room, you know, you're in a boardroom, you're with people and you're talking and you're kind of like, am I even getting through to you? Like, I don't really know. And then all of a sudden you have somebody come up and they say, okay, I'm going to get you in with the CEO. I'm going to get you in front of our board. Can you do this? And then it just sort of, it goes from there. And I realized, you know what? I finally, you know, it took me a long time, but I finally found the right vocabulary, right? I'm pushing the right buttons and people are responding. And it's not that your knowledge changed. I think it's just, it's kind of the way you go to market, right? Speak their language, right? And as soon as you sort of figure that out, it all clicks and it just gets easy. And then you see the demand go up. And so, yeah, it was probably, you know, it's like they said, it was at least a few years ago. And I had that moment of like, this is where I'm supposed to be. You know, you're sitting on a stage somewhere, giving a talk and you're watching people and they're taking pictures of your slides and they're kind of eating it all up. And you're like, yeah, I, you know, I know I'm getting to these people and, you know, and ultimately hope you're helping them. I love that, Mark. Mark, thank you so much for being with us today. You are an incredible evangelist. I am looking forward to the partners, the continued partnership with AdLumen. And I wish you the absolute best in the future. Oh, thanks so much for having us here. And yeah, I'm looking forward to the next one. When's the next one? It's next year in Berlin, is it? Ooh, some secrets, yeah. Uh-oh, sorry. Letting the secrets out of the bag. All right. That's right. By the time we get this out, it'll be news. So it won't matter. That's right. Well, there you go. Yeah, I broke confidentiality and security. Love to have you there. We'll hopefully join you. Yeah, sounds great. Thank you. Thanks, Mark.