Transcript
It's great that you're all here. Today, we're going to talk about security awareness as a business field for managed services with Darius Ansari, Managing Director at Networkbox Germany GmbH. Darius, it's great that you're here. I'm Hanna Lüdicke, Marketing Manager at Ninja One. I'd say we'll wait until one or two people have joined in. In the meantime, I'll tell you a little bit about the technical setup. We're really looking forward to a lot of participation. Please select the chat function for this. Please make sure that you set the box for discussion participation and viewers. Otherwise, you'll only get your answers in a small circle. It would be great if everyone could read your comments. And, of course, the Q&A section. We're really looking forward to your questions and interactions. We'll make sure that we answer them either during the session or at the end. Actually, that's all from me. Now, I'll hand it over to you, Darius. Thank you, Hanna, for the introduction. I can't see how many participants are in the presentation. Can you give me a number? Yes, at the moment, it's just under 25. Yes, nice. We can also wait another minute. Or you can tell me when to start. Well, I'd say we only have a minute left. I'd like to know where all the participants are coming from. So, please give me some information about what kind of roof area you're coming from. I'll send you the chat function right away. Ah, Bavu. Where exactly? Bavu is a bit of Dortmund. That's really cool. It really represents the entire roof region. I'm really happy about that. Oh, and Koblenz, my home town. That's really nice. And not so far from you, Darius Koblenz. Very good. It's not far. From Cologne to Koblenz. Just a few minutes. If you're fast. Exactly. No, but that's really cool. It's great that you're all here. Let's start with the topic. Yes, I'd love to. Thank you to all the participants for coming. I brought a presentation on the topic of awareness as a business model. A topic that is very close to our hearts as a company. Maybe briefly about myself. My name is Darius Ansari. I am the managing director of Networkbox Germany GmbH. I'm 81 years old. Nationality Cologne, even if that doesn't quite give the name. Persian roots. And we as a company are developers, manufacturers and managed service providers. Our own IT security solutions. That means everything we use here, except for the endpoint protection, which comes from F-Secure, is self-developed. And two years ago, we included the topic of awareness and, in conjunction with it, the topic of consulting into the portfolio. In the field of consulting, we have expanded a bit. And here we are also in the field of ISO 27001 Lead Auditor. Yes, like every lecture, mine also starts with a few numbers, data and facts. Numbers, data and facts that might underline the argument for this business model. These are data from the latest BSI situation report. So reflect the year 2021. We are talking about 144 million new chart program variants that we have noticed. That's on average around 400,000 new chart program variants per day. The whole thing has increased by 20% compared to 2020. As you can imagine, the area of phishing, i.e. the one-off gate via email, is still a big problem. We have seen another big problem within the framework of the big security gaps. Puffneum, PrintNightmare, Kaseya and, last but not least, at the end of the year, Lock4J, all of us who are in the security industry, have been kept on edge and ensured that we don't get tired, or get particularly tired, because we had to work a lot. As I just said, the area of phishing is a big problem. More than 80% of the incidents we have seen were traced back to emails, where the employee clicked on the link or the link, which then triggered a chart program, regardless of the size, i.e. the encryption size or other. We also see the resurgence of SMS in this area. Today, we call it smishing. We get tailor-made SMS, where, for example, package announcements are made. DHL is a very popular name in such SMS. Often, these flu bots also have the property to take over the phone book of an attacker and thus tailor-made contacts from the phone book, in order to gain more seriousness and trust. Very, very mean. I think the pandemic, the age of time, you can almost say that we are now in the third year. You might not believe how fast everything is going and how time is running, but I think if this whole situation has taught us one thing, it was that we are really very connected as humans. Now you can talk about an IT security world that has been talking about a pandemic for a long time. If we look at 194 million chart program variants, you could somehow compare that to virus mutations. Especially in 2020, when it all started, we were sent to the home office. And that was a completely new situation for many people, a situation that caused a lot of stress, because many people do not have a home office-capable home and at the same time had to cope with their partner, children, parents, grandparents, in the same quality, with the additional task of caring for them. Of course, this has ensured that attackers have used this situation harmlessly and, in relation to the corona pandemic, has sent well-fabricated emails to people to simply spread the chart programs even more broadly. And what the situation report also clearly shows is that, especially smaller companies, i.e. companies somewhere smaller than 50 employees, were particularly affected by it. And as far as an accident has been successful, there were even some difficult existential consequences. There are some companies that unfortunately had to go into insolvency because of such stories. What is the reason for this? This can probably be explained by the fact that, more often than not, smaller companies have not implemented these security standards as much, such as ISO 27001. It is then regularly checked, i.e. re-audited, to ensure that the IT security concepts and processes are then really continued. Often, such small companies, and if you are from the system, you know this, often have such a small patchwork, where things are implemented but not really strictly implemented. 223 billion in economic damage alone in Germany. I gave a lecture in 2016, where this number was 50 billion euros. That means we are talking about economic growth here, i.e. damage, growth of almost 350 percent. That's wild, that's really a lot. And that shows us very, very clearly that we have to be careful about what we do there. And that also shows very clearly that the employee in such a security concept is probably even the most important puzzle piece. And how can we now generate a business out of it? I think each of us has said it before, the biggest security gap is in front of the computer, or the biggest security gap is the human being. And we've been saying that for years. But I believe that the topic of awareness, also as an idea for a business, is relatively new. And many still don't know what you can do with it, or how to generate a business out of it, and how to create a win-win-win situation, from which everyone benefits. We have, to start with, tried to define the term awareness. Because awareness is not a solution that you can just buy off the shelf, but awareness is a very soft, very flexible term. Actually, it's a goal that we're trying to achieve. When this goal is achieved, and how this goal is achieved, is just very difficult to measure. But there are many different ways to do it, and I'd like to show you a few of them today. But I also want to emphasize at this point that what I'm showing here today, and that's basically what we do, when we want to implement awareness for customers of our partners. Not that it's a stone-cold recipe, but actually just a recipe. You can really do a lot right with awareness, and a little wrong. You just have to somehow make sure that the topic remains exciting. We've divided awareness into six terms, the terms awareness, attention, attention, sensitivity, awareness, and awareness. Now we all know that in our companies we also have a certain rule for the use of IT. What can I do on the Internet? What can't I do? Can I use my mobile devices provided by the company privately? Can't I? These are the rules that were created and that you have to stick to. Now let's assume that every employee knows these rules and also has them in his head and sticks to them. But there are also situations that happen outside of this rule. And now awareness is actually always achieved when a person manages to react correctly to a new situation outside of this rule, which he recognizes. Let's take the example of an incoming e-mail. If an e-mail lands in our mailbox, we decide within milliseconds whether this e-mail is valid, i.e. can continue to be tracked and processed, or whether it is rather fake. We recognize bad e-mails immediately. With good e-mails, we may have to look a little longer. Just like the person who comes through the door for the first time and within milliseconds develops sympathy or antipathy for this person, this is also the case in the field of e-mails. This is the situation that is new, because we are confronted with something new. And here we have to distinguish between right and wrong. The way there is new, I don't want to say now, but I think it can be derived a lot from human logic. First of all, you have to understand that security is not a project, as I just said. You can't just buy security in the field of OANs, but it is a process that has to start at some point and then simply develops further. First of all, you have to understand that information security is not a pure IT topic, i.e. not a 100% technological topic. Information security is a concern for existence. We want to prevent an accident so that we can continue to work. An accident can lead to us being shut down for days, if we are unlucky, for weeks, and not be able to continue working, even if we are unlucky and want to close down. We have to be aware that information security is permanently threatened. 194 million Schadprogram variants per year. That's quite a lot that could happen to us in theory. And that, above all, attack scenarios, we remember the term smishing, simply develop further. This is a very, very good business model for attackers, here with simple means, very, very much, and also to earn money in the hidden. For them, this is a relatively risk-free business. And now we have to look at which measures we use to minimize our risks. And that's where humans play a very, very special role. I always like to compare this to environmental protection. We all remember a few years ago, we threw all the garbage, whether it was paper, organic or plastic, into the black bin and didn't separate it. But when we saw that icebergs were melting somewhere and that it is very good for the environment to separate the garbage, if you can recycle it in parts, we introduced behavioral changes and started separating garbage. This is very, very similar here in the field of awareness. We have to get the employee to adapt his behavior to the situation, and to adapt to these different situations again and again. Now let's start with an awareness training. And now, again in theory, a learning curve begins. We know this from the time we were still in school or at university. We start with fabric, beat it into the brain, and the learning curve goes up steeply. But if we don't continue, this learning remains in the short term, and the learning curve falls just as quickly as it has gone down again. And what we have done there is lost. So we have to make sure that we somehow manage to keep tension on the subject, that there is a presence in the subject, and that the employees learn to behave properly in these situations through repetition. So how can we build a business model out of this? First of all, we have to understand why we are doing this. What advantages does this have for us as a provider when we do awareness? It has many advantages. First of all, it is a new business field, through which you can limit yourself a little in the competition. We start from this pure, I sell you a telephone system now, so let's say the classic IT distribution, to grow into this consulting track, which simply creates the increase in sensitization with the efficient use of tools. This also generates a very strong cross-selling effect. Why? Because, for example, we start after an evaluation, let's say we have now carried out a phishing simulation with a customer, and in the evaluation it turns out that 30% of the employees clicked on the link in this email. Then we talk about treatment recommendations that are derived from this. For example, the customer only had a Fritzbox in his company and always assumed that he had a firewall in use, and he was totally consultative. Now we have facts on which we argue and tell him, look, the Fritzbox didn't manage to filter out this email, because that's just not possible. But a real firewall, a real UTM with a spam proxy, would have increased the probability of filtering out this email many times. So we then argue on the basis of facts that we have created. We increase trust. We also increase customer ties because we immerse ourselves in new areas, because we come into much closer contact with the management when it comes to these areas, because it is an organizational area and an organizational process that intervenes in many areas of the company. We can, if we implement it this way, also generate regular income, which helps us, or the term managed service, to create plannability and security for us as a provider. And, I have to have a quick drink of water. We also create, and this is the last win in this win-win-win, we also create the verificability for the end customer. He is obliged to provide proof in certain areas. Since the state data protection authorities are currently conducting tests, especially in small companies, to check how far the specifications of the DSGVO have been implemented. Now we are always talking about this state of the art, which has never really been defined. But you can assume that at least once an UTM or a firewall, endpoint and backup, are provided. More and more this topic of awareness is also emerging. We ourselves had a small security incident that was noteworthy. Our sales manager put all our partners, and that's a little over 350 partners, instead of putting them in BCC, in CC. According to the data protection authorities, this was a security incident. And I was very happy that we were able to go through it once, on such a low-level risk factor. And we got a questionnaire that we had to fill out. And there was the question, what did you do to prevent something like this from happening again? And the standard answer, which our data protection officer wrote in there, is that we have fired an employee. So now the data protection authority comes up with the idea and says, please prove it to me. And if you then get the proof out of your pocket from 2018, where you and your data protection officer did the DSGVO certifications together, then that is probably a bit outdated from the point of view of the state data protection authority. And there is a risk of a small fine. ISO 27001, ISMS, VDS 10.000 and Co. have defined the employees' sensitization as an absolute requirement in their standards. A very important topic. And with this training, we get this proof for the company. What advantages does this still have for the customer? So first of all, it reduces the risk of attack. Because the biggest security gap in his system is trained accordingly. He generates the proof, we just had that, thus also his liability. And we experience this more and more often, that even cyber insurers go and say, we can only extend the cyber insurance if you give us certain proof. Or first, we can only give you a cyber policy if you also provide certain proof. And we are also working closely with various cyber insurers and we also know the questions there. And in each of these questions it says, do you sensitize your employees, if so, how? And do you let us know? What we have also experienced, especially with a larger customer here from Cologne, namely the ZDG, i.e. the two-wheeled shopping community, which is a world market leader in the bicycle sector. Brands like Bulls, Pegasus, Hercules, Kettler, for example, are part of it. They have a turnover of 2 billion euros. They also have the Eurorad Leasing on board, which offers this employee bicycle leasing. And a large chemical company had asked them, what is it like? They would like to become customers. And of course an Eurorad Leasing is happy about that, because if you can equip several thousand employees with bicycles, that's a good business. However, the customer had certain conditions for the cooperation. These conditions were provided in the form of an audit. So there was a big question mark in the questions like, what do you do for IT security? And please let us know what you do for your employees, because we want our data to be protected by our supplier. That means, the topic is getting broader, the topic is becoming more and more important, also for many others, because we all want the data we work with, which belongs to us, in the hands of those we trust, to be protected with appropriate security. In addition, we also have the advantage that we can use this topic very well in the outside influence, i.e. in communication, PR, marketing, in order to increase trust in the direction of the end customer. We take the topic of awareness or IT security so seriously, that we regularly sensitize our employees. I would like that as a customer. What are the tools with which you can use awareness, or implement it, or create the way towards the end goal? For us, we use artificial simulation, we use face-to-face training, we do webinars, we have our own e-learning platform where you can book training, we send newsletters, we have a dark web monitoring, and we are also very happy to use visual and haptic newsletters. So a combination of different tools that open up different possibilities for us, especially when it comes to doing cross-sourcing, or, above all, when it comes to getting things into the subconscious of the employees. I just have two examples here today, very profane and totally underestimated. A door hanger sign. On one side it says, don't be an idiot, private is private, work is work, IT security starts with you. On the other side it says, be smart, watch what you click on. And on this mouse pad here, it says, be sure, fake mails look fake, also here, IT security starts with you. This is underestimated, because if I compare it to my daily routine, when I get to the office in the morning, I go to my workplace and drive my computer up. Then I go straight to the kitchen, heat up the coffee machine, grab a cup from the cupboard, fill the cup with coffee, greet one or the other employee on the way, and then walk back to my office and have a cup of coffee. If there are nice sayings in any way in all the places I have touched and seen so far, they don't have to be as provocative as being an idiot or something, it can always be a bit out of business. Then at some point it burns into the subconscious, and I just pay attention to it. You can also play with such warning colors here. We decided on this yellow, which you can also see on the foils, simply because we wanted it to be a bit fresh, and because we really wanted to play with these warning colors. A totally effective tool, these visual and haptic media. And above all, cheap, because we also buy our PR products and our PR department, our marketing department, thinks about a few good sayings and we just publish them. Now we have already, especially if we remember this coordinate system with the learning curve, that this learning through repetition is totally important. So ongoing campaigns that don't just stop when you've taken a step, but really ensure that there is tension on this topic. We want to establish a learning rhythm. We want to use our tools, our tools on a regular basis, so that we can confront the employees over a certain period of time, preferably over the years, with the topic and ensure that they are brought into situations where they have to distinguish between right and wrong. The whole thing has to be measured, of course, so that we can see the progress. And you can do that really well if you do, for example, two, three or four phishing simulations per year. You can measure that really well if you see how much interest there is in e-learning training. So how high is the participant rate, how many employees have, how much time is needed to do these e-learnings. And you can also react accordingly to the events or to the results that happen. Of course, this is always totally individual. So there is an introduction phase, a knowledge transmission phase and a sustainability phase. That's a framework that you can stick to if you want to start with something like this. What is the introduction phase? The introduction phase is first of all to make the topic known. We want to show the employees a sympathy for this topic. We want the employees to enjoy the action. Because if we have employees who just roll their eyes and say, oh, some new shit again, then we have already taken the first step in the wrong direction. What is important about this topic is that you announce something like this, that you warn the employees that we do not want to specifically control employees here, but that we are here anonymously evaluating, because it is about bringing this level of anonymity up here in the team in order to, as was seen on the fourth slide, ensure the provision of existence. We just have to inform the employees about it. Advantage if you announce the whole thing, we have already taken the first step in the right direction, we have made the target. As soon as this management statement comes from the management or from above, people read the next emails that they receive with a little more caution. Guaranteed. That means we announce, we take the employees by surprise, everything is analyzed and evaluated here, we build sympathy for the topic and then start the knowledge transfer phase, where we, with phishing simulations, e-learnings, the listing of tools, which I have already done, then ensure that the people are brought to a new level here. The whole thing is repeated regularly over a certain period of time. Establish a learning rhythm. I would, for example, if you have access to an e-learning platform, never turn off all courses at once for an employee, but do so at regular intervals, so that the employee, on the day he gets his access data and has a lot of time, does not rock through all the courses and then the learning curve goes up, but there is nothing left that he can do later and the learning curve falls down again. It is better to turn off one course once a month, every three months, let the employee absorb this one course and ensure that the learning topics really arrive and stay in the head over a certain period of time. So create a cycle, generate a process. Maybe also think about how to incorporate awareness into the adjustment process of new employees. This is probably something that a managing director has not yet thought about, but it also helps him to do this cross-selling again. Every new employee should, before he starts working, perhaps first take an e-learning course so that he understands that the company puts a lot of value on security and, above all, on the topic of employees and security. And we take advantage of this situation that employees who are just starting to work are nervous at first, are insecure, orient themselves, get to know colleagues first, don't want to do anything wrong. This is a totally good moment when an employee is very receptive to any information and we can implement this very well. And you sell an e-learning course for a new employee. And if the fluctuation is high, you can simply sell more access permanently here. What are the payment options? Can this only be derived from our portfolio? We calculate on a basis per employee per month. A small amount of money. The most expensive amount you can pay per employee is 2.20 euros. And that's for the smallest company. Companies pay up to 10 employees per employee per month. 2.20 euros. And here we have any awareness measures that we have in our portfolio, i.e. phishing simulations, e-learnings and browser plug-ins, which we also have to recognize fake online pages, which are already included. Then there is an installation package. These are the prices with which our partners go out. Our partners also get a purchase price discount and we basically do the work for them in the background. But of course such a model can also be integrated into a maintenance contract that you may already have with your customer. Something like, I don't know, the small, medium, large contract. And in the large contract, this is simply included. For example, maybe a good idea. Yes, that was my presentation for the area of awareness as a business model. As I said at the beginning, a recipe that, of course, everyone can adapt to the way they want to use it. There are no rigid rules for it. Awareness is a very broad, very flexible area. You can do a lot here to achieve a lot. These were the areas that we considered important for us. And that's how we implement things. Exactly. Maybe again as the last slide. Hanna gave me the permission to do a bit of self-promotion again. We are a service provider. That means we operate a security operation center here in Cologne. We operate a security operation center so that we, as our own employees, who are positioned within the partnership, take care of the topics of firewall, UTM, endpoint protection, awareness training, dark web monitoring and also consultancy topics. In principle, we are only a step away from the telephone for our partners in the home office. We are located in Cologne and are happy to answer questions, suggestions, and impulses. That was the lecture. I hope that now one or two questions will come up and we can discuss them again. Thank you very much for the exciting topic. I also think that it is incredibly present and up-to-date and, as you showed at the beginning, also in terms of the billions of damage that have increased rapidly in recent years. Simply incredibly important. Of course, I would be interested if you have now really come across an interest. How can you work together with you? How does that work? Maybe you can report on that again. Yes, there is actually no hurdle. There are no pressure screens. The only prerequisite to go into a partnership with us is to want it. That means there are no minimum costs, there are no certification fees, there are basically, as I said, no pressure screens. If you want to work with us, everyone is warmly invited to do so. We understand each other as relief. We understand each other as specialists. We are specialists in these areas. And we take over these areas very closely and always at eye level for our partner, with our partner. Of course, we don't work past them, but also stick to the communication chains that the partner wants. For example, we only contact the customer directly when the partner wants it. Otherwise, we like to stay in the background and help with such innovative topics into the portfolio without really having to make our own investment and effort so that you can offer something like that. Especially for smaller systems as a partner, maybe not uninteresting if you get another employee who, as I said, only has access to the phone while watching TV in Cologne. Yes, in any case, I think this is a great opportunity to further expand your own IT services. What I would be interested in in general from your experience, from everyday life, you already showed at the beginning what the biggest dangers are besides phishing. But what are really your experiences and what do employees fall into the most? In terms of experience or what you know from practice. The CEO fraud is of course an area where people fall into quickly. An email that looks like it's coming from a trusted person or a well-known person, but not from this person. Especially when it comes to topical topics. For example, we sent a lot of emails about new corona hygiene rules. They came from the management. You could already see that the click rates were mostly above 80%. Almost everyone fell for it. Despite the introduction of errors, of course. Because here, too, you have to make sure that when you do something, you don't fake a perfect email. The employee must already have the chance to recognize this email as fake. So somehow you have to introduce errors. And despite the introduction of certain errors, the click rate is very high. Of course, this has to do with people being afraid of getting infected with colleagues who were recently in the immediate vicinity. Definitely. But also in the future, I think this CEO fraud will remain a big problem. In the hectic, in the stress, in the hurry, he will overlook certain things that you have to be careful about. That's exactly the point. To be honest, when I fly over my emails in everyday life, I actually only fly over them. And as you already said, sometimes a spelling mistake or something else, that you may not look carefully at the sender's email, can really slip through. But then again, you may click on a certain link or a document. I also think that this security awareness is not so important at all. How often would you recommend such regularity in the company? How often would you recommend such regularity in the company? There is no set concept for this. In my opinion, this is very individual. There are moments in a company's everyday life when something doesn't fit at all and absolutely bothers. Let's take the end-of-year business from a retailer, for example. Of course, it is totally important but in order to do such a training, there is a need for a certain coordination. As I said in the introduction, we want to make it measurable. Now, of course, if you have done two phishing simulations and want to compare them, you have to make sure that the emails are comparable. I can't compare the CEO fraud with an ad email. The click rates on both topics have to be comparable. But if I want to do a CEO fraud, the topic in the email has to be related to a current situation in a certain way. Let's say Corona or the company is considering to lease bicycles for the employees. Then you could also build an email on this topic. But then we also need an email. Then the email has to be released in order to attack someone. That means the client has to at least one of the clients, the CEO in the best case, should have seen the email that we use and release it. So he has to take time for the evaluation and talk to us. I mean the partner and us if we should be there. That's a lot of work. We recommend an onboarding, a kick-off conversation with the client to ask how the communication is. Are there areas that can be used? Are there communication tools that can be used to get awareness? For example, the canteen plan on the internet is a good place. Everyone looks at it at 12 o'clock before going downstairs to see what there is to eat. There shouldn't be an endless amount of phishing simulations. It has to fit what the company is doing. It's a measure. But two phishing simulations to get a bit of the answer. Two phishing simulations per year is good. And e-learnings a maximum of one per month, depending on how it goes. I find that very interesting. I think to keep it in the employees' mind, it has to be a cycle with measures. I found it interesting that Eric asked a very interesting question about the design of phishing e-mails. You mentioned that it should be a current topic or a topic that is currently present in the company. Now he asks the question of copyright errors or sender addresses. How conspicuous are these points designed by you? Or is it dependent on the customer? We don't send e-mails via the domain of the end customer, but via other domains. That's one error that should be noticed. It's not ansari.network-box.eu, but ansari.email-digital.de, to give an example. That should be noticed by all of my employees. The design of e-mails. There is everything. We have already sent a notification via e-mail. That's nonsense, because you have never received a notification via e-mail. Where should the road traffic office or Flensburg get our e-mail address that matches the license plate? There is no correlation at all. Not in real life. Still, people click on it, because they are confronted with streets. They are afraid, because you get flashed more often. That works well. You can actually let your creativity run free here. What I still recommend is that when you have to deal with larger companies or departments, build different phishing e-mails for each department, in order to evaluate them across departments. For example, the marketing department is more susceptible to phishing e-mails than the sales department, accounting, management, human resource department, etc. That could lead to taking certain departments and having tailor-made training courses for a marketing department to confront them with the corresponding dangers and make sure that it improves. Of course, you can also work in different languages. If the company is multilingual and operates in different locations around the world, you can work in different languages at different times. You can send different e-mails at the same time in order to have the same effect on all levels. CEO fraud and advertising e-mails. You can send out a whole bunch of e-mails. You should also discuss this with the customer. Do you already offer templates or suggestions? Or is it further defined in the collaboration? How does the process work? We have a catalog with phishing e-mails that we have already built that you can choose from. We also have a lot of CEO fraud templates with topics that we know work well at different times of the year. At Christmas, people are more sentimental and want to do something good for society. You can call them and say instead of a Christmas card we would like to ask you to donate a euro for the Deutsche Kloppenmarkt. We have built countless templates that you can use quickly. But quite often there is a lot of individual work in the area of the customer. Great. Tim is asking if you can get a demo access to take a look at all of this. All of your features. Maybe you can give us some information about the setup or how it works for you. Of course. You can visit us. We are transparent and show what we have. At the end of the day the partner doesn't have to put in the effort. We do it. We have a so-called getting started document where you can see the process. What do we need from the partner and customer side We talk and onboard our partner in a conversation where we discuss all possible topics and very individually look at the system and see if he is looking after a specific industry. Let's say doctors. We have prepared a lot for doctors. Does he look after tax advisors? Then we know with tax advisors you can do this and that very well. We do the onboarding and show how it works. We also help with the better understanding of the argumentation for the customer. We do sales coaching. All of this is free and belongs to us. We all want to do a good business and live a good partnership. You don't have to worry about the costs. We also evaluate the customer and we do that at any cost. Cool. I would say that was a very nice conclusion for our webinar. There will definitely be a follow-up with the recording and the presentation and a link to Darius. If you have any questions you can send them to me or to Darius. Darius, do you have any final words? Yes, maybe one last sentence. I find it absolutely fascinating and impressive that we have the opportunity to use IT the way we use it right now. We are spread across Germany and Europe and can listen to anyone in Cologne or talk to someone from any other city without having to get on a plane, a car or a train. We were able to do that before the pandemic but we didn't live like that. I think that this new type of digitization, this new type of networking and the possibilities that it gives us is worth protecting. I think that is also something that the customer understands. It is no longer a matter of course that we look back at the end of a month and say, nothing happened. That is something special if we can say that. That is why it is so important that we look at IT security as a whole and choose a 360-degree approach where we look at the concept from all sides. Nice conclusion. Thank you for joining us. Have a nice day. Take care. Bye.