Video: How Small & Medium-Sized Businesses Can Navigate Soaring Cyber Risk with Confidence | Duration: 2796s | Summary: How Small & Medium-Sized Businesses Can Navigate Soaring Cyber Risk with Confidence
Transcript for "How Small & Medium-Sized Businesses Can Navigate Soaring Cyber Risk with Confidence": Paul Nagelich and Pete Bernhard. Paul, thanks a lot for being here. You wanna kick things off and introduce yourself? Yeah. Thanks a lot, Robert. Appreciate you having us, and, welcome to everyone. Paul Nagelich. I run our our fractional CSO program here, our vCSO side. Been in IT for now 35 years. All the areas from, from network to application development, infrastructure, Cloud, and cybersecurity. That's my focus now over the last 5 years and helping people through this journey. Excellent. Thanks a lot for being here, Paul. Pete, you want to introduce yourselves? Sure. Robert, thank you very much, and, hello to everybody out there. I'm thrilled to be here. My name is Pete Bernhard, and, I head up the managed services business unit here at CEI. With over 20 years of experience in the space, not only managed services, but also cybersecurity. Today, I hope to give you a little insight into the conversations I've had over the last 2 decades with, IT thought leaders and in the small to midsize and, small enterprise space. So, again, thrilled to be here. Thanks, Robert. Fantastic. And, Pete, before we jump in, you wanna just tell us a little bit more about CEI, what you guys do, who who you serve? Sure. Absolutely. So CEI is a global company. We've been in business for over 30 years, and, our core competencies, center around managed services, both cloud infrastructure and cybersecurity. We also have a strategy and advisory group, which, focuses on ERP implementation. We have an IT staffing arm as well as an application development unit as far and as well as, managing those applications. So we're based in Pittsburgh, but, we do have footprint in Europe, India, and South America. Fantastic. Thanks for that introduction. Yep. Alright. So, we're going to go probably about 45 minutes today, and we'll be filling questions as we go if they're appropriate for the conversation and kinda in the in the flow of things. If you have a question, you can either just chat us or hit us in the questions box that you see on the right side of your screen. And again, we'll try to address them in the course of the conversation. If we don't get to them, we'll save some time at the end to get through as many as we can. So let's kick the discussion off by giving some insight high level into the risk and regulatory landscape, particularly facing smaller organizations. And Paul, I'll start with you. If you're running a company today, then again this is a very kind of big picture question, but what should be kind of top of mind for you with respect to security? Sure. That's a great question. So so as as we know, the the landscape is getting more and more complex. You're you're seeing a lot of news stories today, of of people that have been either breached, or have, some sort of ransomware attack or or whatnot. The the thing that I would really suggest from a small midsize is is what's your posture management right now? And in taking a look at the different, specific controls that are out there and and really doing a baseline based on on your business. So if you're in the medical field, you know, obviously HIPAA and PHI, but how does that map into some of the other regulatory compliance related controls? And, we'll talk a little bit more about that as we go along. But really getting a good sense of your current posture and your baseline, so you can you can then make business decisions on what those next steps are. And and, Paul, just, to kinda level set for everybody, when you talk about security posture, what are kind of the the components that you think about that that kinda go into that? Oh, absolutely. So, so various areas that that hit in that is your security awareness training. Looking at that first and foremost, that's the the single entry point into your company is the human firewall that that we call it. So what are you doing on a regular basis to train your employees? Make them part of of your cyber posture. And that gives you a good sense of the population of your your company, who is being, you know, who is is taking the bait for phishing, who's responding to password changes, you know, and it could be even down to the the, the physical side of checking people in and making sure, folks are who they say they are. So pulling all that together gives you you know, that's that's one area. The other side, you know, there's there's several different, but, awareness training by far, you know, is number 1. But then having, you know, specific tasks or specific, duties that are done on a regular basis from vulnerability patching, to data protection. How are you protecting your data? And, you know, some of the sensitive data, specifically PII, you know, personal information, whether that's driver's license, social social, to, you know, company specific data. And having, having a good posture keeps those in mind as you, as you navigate through those waters. Yeah. Well put. And, Pete, we'll bring you here, bring you in here in a second. But, Paul, just sticking with you for for now. Sure. You you mentioned you mentioned ransomware among other things. PII and kind of the the additional privacy regulations around that. But when you think about kind of how the risk landscape has has evolved and the and the regulatory landscape, like, what what are kind of the the big emerging risk that you're seeing especially as you're you're talking with, you know, some of your prospects and and customers? Yeah. And it it really comes around to having the best practices in place and asking just some of the rudimentary questions. But doing, you know, more importantly is is performing a risk assessment. And and in doing that in a in a very objective way. So, more or less having the controls in place, making sure they map into your company specifically into the vertical space that you're in, whether that's retail, manufacturing, finance, or so on because there there's specific things that do map into that. And and looking, you know, specific on health care, obviously, HIPAA, PHI, and and those come into play. But then, if you have specific privacy, that's ramping up and and whether that's GDPR, MIST 2, CCPA, and others, making sure that those controls are identified and you have a policy and and you're mapping your procedures in on a on a on a on a regular basis. Yeah. Will put. And and, Pete, I imagine when you're having some conversations, especially with the smaller organizations, they they might think of security, almost as like a like an insurance policy. Yep. But but it's it's really important to kinda help people understand how security really maps to business outcomes. So what are kind of the primary business factors that you see influencing cybersecurity practices? Yeah. So, again, like I said in the beginning, I've I've had the pleasure in the last 20 years of talking to IT thought leaders. Right? And, there there are 3 or 4 things that they point to. One is the protection of their sensitive data. Right? And each company differs, in what they consider to be their sensitive data. It doesn't matter what vertical. Everybody has sense of sensitive data. So first and foremost, it's are we protecting that the best we can? The other piece and as it applies to the SMB space is reputation management. Right? If, for instance, I'm a consumer of a company's product, and I hear that maybe there is a breach, right, in their system. As a consumer, I'm gonna be concerned because all of my data that they may house may have gone out into, you know, into the ether, and who knows what those folks that the bad actors are gonna do with that. The other piece is in that same vein is, a competitive advantage for companies in each vertical. Right? If if you can maintain that level of security and avoid those major costly breaches, it's going to give you a competitive advantage in the market. Does that answer your your question, Robert? Yeah. Absolutely. And and you I think you hit on a key point which is it's not just risk reduction and avoiding the the bad things that might happen, but there's also, you know, there are, business gains that can come out of this as well. So I think as such as a competitive advantage, being able to to service new markets for instance, accelerating sales cycles because you have all of your certifications ready to go. I mean, we we see that all the time in our our business. Absolutely. Yeah. And if I can if I can just add on to that, Robert, we're doing several of these, engagements today. Coming out of an assessment, a lot of our customers are are seeing and and really getting proactive. Or today, we were in a in a in a readout executive summary and, the CEO was like, hey, how can I get I wanna get away from being on defense? I wanna be on offense. And that's I mean, that was a great point. Is how do we get to the point where I know I can see exactly where we're at? And when I talk to my potential customers, I can instill confidence that we do have the right controls in place. So I thought that was that was very good, analogy, now that we're in the football season of, getting off a defense and getting into the the offensive side of the house. And and did you get a sense of, like, when talking to that CEO, what being on the offensive would mean for for him in the business? Absolutely. So when when new contracts or when new relationships start, this is a manufacturing and services company, A lot of new regulation and new compliance is coming into place. So if you want our contract requirements are coming down that you need to be, NIST compliant or ISO 27, k compliant, so that we have the, the ability to know that our risk is much lower, that you're, that you're taking care of our data, that you're taking care of our, you know, services in a, in a in a security thoughtful way. Yeah. Yeah. Well played. Pete, going back to you, when you're talking to, some of the leaders of these businesses, like, what would you say are their biggest misconceptions around not just kind of security in general, but but where like, feelings where they think they might be better off than they actually are? Yeah. So real really good question there. And I I like to kinda paint the landscape of, these bad actors. There is honor among thieves. Right? So, in that vein, there are a lot of companies that I talk to that that simply say, you know what? We're too small to be a viable target for these people. And, actually, if if you read and you can find it anywhere, that there are certain groups of these these hacking organizations, and some of them and not as many are focused on the larger enterprise clients, but we are finding daily that more of these kind of offshoots of these larger larger organizations are going after the small to midsize market for the simple reason that they're assuming because you're a small organization and you may not have a robust internal ID to IT department, your security is not going to be as mature as maybe, let's say, an enterprise account. That's the biggest one that I come across all the time. You know? And and it's just it it really is a true misconception. You you can read it. The other piece I'll I'll add is when we watch the news, they're not reporting on the $500,000,000,000,000 company that was hacked. They're talking about Target. They're talking about Microsoft. Right? And all these things, right, if it's not front of mind, if you're not seeing or reading about it, people are assuming it's not happening, but that's just not the case. Yeah. Good point. And, I mean, to your point, like, you'll see the statistics and the Verizon reports and and everything else. But, when you look at actual data breaches and and attacks, more than 50% are, I think it's under businesses under 500 employees. And to your point, it's because at least there's a sense that those are, you know, from a security posture perspective, you know, they're they're less rigorous than their their larger counterparts. Right? Well and I would add the the other piece, the other common misconception that cybersecurity outsourcing any piece of that is too expensive. And and we have found, I have found, if you look at all the things you may outsource, as far as IT in in your environment, cyber cybersecurity is the least expensive piece. It's less expensive than a help desk or traditional cloud infrastructure managed services. It actually to get your initial posture in shape, it is the least expensive out outsourcing service you can provide to your company. Well, we're gonna talk about this later on in the presentation, but especially less expensive and especially when you start to think about the returns on the investment. Right. It it refers to stack up. Right? Right. Absolutely. Well, let me ask you, and maybe this is kind of more of a, you know, getting to the technical side now. But based on the initial assessments you perform with some of these organizations, like, where would you say, that that a lot of these clients or prospective clients are most often kind of gapped when it comes to their security posture? Yeah. It's, it's it's a great question. And, I think there's definitely, when when security over the years has has been, hey, let's just lock it down with a password or, make sure it's in the DMZ. And, you know, we feel, you know, nothing's happened, so we feel pretty good. But when you go through a CIS framework, which is the Center For Internet Security, we can break it down into into 3 implementation groups. So it's just having the basic hygiene in the implementation group 1 to additional controls that come with IG2 and IG3. But typically when we go into a company that's a 100, 200 people, companies usually land in the upper 40% to the mid 50%, just running through the controls that, are outlined by the CIS advisory group. And and when you think about kind of the the remaining 50%, like, where are, you know, where where are the most impactful things do you that that can kind of be checked off? Or or or maybe another way to ask it is, like, where often do you see that that 50% not being met? Oh, no. Absolutely. So mentioned, awareness training, upfront early on. That's normally a big area that's not not being covered. So bringing in a provider that that has that capability. Obviously, you know, specifics out there we can we can go through from a know before to Microsoft and there's over a dozen different companies that provide an LMS type of solution. But some of the other things that a lot of people don't realize is they're not, they're not implementing multi factor authentication, especially in the small, midsize, businesses and, helping them through whether it's Microsoft or or Cisco or others is identifying a recommendation to get that multifactor in place. Data protection is another big area. So whether that's, having immutable backups, which, you know, takes your backups, puts them at another site and encrypts them, to data loss prevention and and making sure that your critical data is being is being secure and, being managed. So those are those are a lot of big things, that we see. And then lastly, I encourage people to make sure they're doing an annual penetration test. And that looks outside of your company and that looks inside your company. You know, and and making sure that ports are being, you know, locked down to making sure your strong passwords are in place to, you know, how can how easy is it to crack your wireless, you know, landing zones and networks and so forth. So those are those are the the big things that really come up, more often than not. I'm curious, are are there do you all see, like, certain types of organizations that you think are are more vulnerable, for instance, to attack just due to the kind of the either the business they're in or the kind of information that they hold. I'm I'm thinking, for instance, about, like, law firms, for instance, or or health care. I mean, we we mentioned that where they're deal dealing with a lot of PII. Pete, you're nodding your head. Yep. Go ahead. Well and and, again, it speaks a little bit to the misconception, but I will tell you when somebody thinks of cyberattacks, they're thinking about financial institutions. Right? When I think about it, and I talk to people that that really aren't involved on a day to day basis talking about security, they're like, well, I I mean, of course, a bank is going to get you know, be the target before anything else. But but, honestly, that's just not true. And, yes, there may be more cases, but it doesn't matter what vertical, honestly, you're in. We see it a lot in health care. I don't know. It's, again, you can't it seems like you can't go a week without seeing, you know, or hearing about some big health care system that that was compromised. So it's across the board wherever there is user data available, you're a target, unfortunately. Yep. Yeah. And I just to add on to that, I I see a lot in the services side of the business where, people are out and about, you know, they just, you know, at the end of the day, until something happens, you know, they push it, you know, kinda lower on the the priority level. And again, it's going from defense to offense, being a little more proactive. And there's there's things that we can we can help, on the front end that aren't crazy investment. It might just be some resource and, policies that need to be identified and implemented to to raise your posture up. So So So that I mean, that's a really good transition into our next session, which is kinda what this process looks like. If you've, you know, if you're an organization, maybe you've you've talked to a CEI and you've made the decision that, like, yes. I got a problem here and I need to do something. Paul, let's go back to you. Where does this whole process start? Like, if you wanna evaluate kinda where you are from a risk perspective, or or maybe you have to align to a a compliance framework, like, where where does this even start? Yeah. Straight away is is from a risk assessment And partnering with a with a good, GRC platform like like Abtega, really helps us navigate through that. You know, just picking on a specific framework, again, going to the CIS, side of the house, we can then, engage, run through this assessment. We've got technical people that can actually not only facilitate some of the questions, but gathering the evidence, looking at, you know, specific technical pieces like your logs, down to the technical layers to validate what you have in place, is where we start. And then, Robert, if you if you could share, I believe it's slide number 2. Yep. And and that process usually takes, depending on the size of the company, that usually takes 2 to 3 weeks. Sometimes a little bit more if we get into some of the other controls like visiting physical locations or whatnot. But as you can see, on this, CIS has, 18 different controls. And where we like to start again is IG one, but, we also have the ability to look at the different other areas as well. So when we complete the the assessment, we will give an executive summary of each of these controls. And as you can see, over the 200 sub controls that are within CIS, this gives you a good reference of where the baseline sits. So with this company, which is most recently, they came in around just north of 50%. And then comparatively, the question is always asked, okay. For the company of my size and my industry, how does that compare? And that's where our partnership with Abtega is really strong in the sense that, they've got well over 3,000 customers, through their partner ecosystem. So we can take a look and say, okay. In this industry, once the controls are in place, that compares, to a 77% side of the house. So that just gives you a good reference of where I'm at, and then you can take a snapshot below or take a look. And and there's 3 or 4 areas that if we, remediate, fairly quickly, that number will then go up to what the what the the median range is or or higher. And and Paul, I'm curious to know kinda and as we're we're looking at what this, you know, what this looks like, and considering, you know, some organizations are juggling multiple frameworks or they're they're wanting to, you know, fill compliance obligation and up level their security posture, like, when you're seeing these gaps, what's the work that that you all are doing to start to prioritize where, like, the most impactful work is and make sure that you're doing that first and budgeting for it? Because there there might be, you know, I I imagine you you step into some situations where it's like, we got a lot of work to do, and the organization might not know kinda where to start and what's gonna be most impactful for their their business or, you know, earlier on. Right. No. And and that's great great segue into the next slide is is your risk posture management or your risk, where you're currently at. And again, the the the Aptega tool is, you know, I've been a partner now over 3 years. And this gives a great visual of where those, where those areas are in this heat map. The current left side of the diagram shows, where those specific areas are. And then when when you're within the platform, you can then you can then navigate around. So you can click on that top right risk, and it can share exactly what what is tied to that, the different controls. So that's what we use to work with customers to say this is our recommendation to start, and we'll lay out a road map, a 3 month, a 6 month, into the next 12 plus months to say this is where we should start, higher risk, you know, lower investment, if you will, some of the low hanging fruit, and then, put together that plan, collaboratively with our customers. But then when we get those remediations done, you can see on the right side, what the residual is, And and you can then see, how that, how that progress is mapping, you know, in real time. Sure. I mean, here here's what a a road map might might look like as you as you are laying it out. Correct. And and thanks for bringing that. So remediation to next steps over the next 6, 12, 24 months. Awesome. And then on the bottom, you can see, you know, where your current score is and where that's going, once those are remediated. Yep. Fantastic. And and, Pete, when you think about kind of resource allocation for something like this, and and budgeting in particular, like, how how are you kinda counseling some of your clients to think about, you know, what what what the initial spend is gonna be, but maybe more importantly, like, how to actually think about the return on the investment? Sure. Sure. The first piece, you know, I'm never going to pretend to know more about my client's business than they do. Right? So the first step is they need to identify what their key assets are to begin with. Right? And and those key assets then become part of that initial assessment. And, when you talk about budgeting, these assessments that we do at CEI to get to get a baseline on your security posture, depending on the complexity of the environment, we can come in and do those assessments at no cost, honestly. So we come in, do that initial assessment, and then give you that road map that will, align with your current budget and then also look at allocations for future spend. Right? To to Paul's point, we do not expect, and it's actually not even best practice, to try and attack the entire environment as a whole from the very beginning. Right? You you have to start small and again, that goes back to the cost of actually securing this is not nearly what people think it is. So a lot of times those budgets are in place without without these companies actually having to move money around into operational and and capital buckets. Yeah. Well well said. And and and Pete, kinda thinking about this from the the client's perspective, and I asked this question, you know, knowing that you've been doing this for 20 years. Yeah. What, like, what should clients be asking to, like, validate that you all know what you're doing? Especially, and and we talk about this all the time at Aptica, but there there's there's been this proliferation of service providers out there that, you know, that say at least that they can do all of the stuff that everybody else can do. Right. So so what are the things to look forward to know that, like, yes. This is a, you know, this is a solid provider, and they're gonna be able to execute on the things that they say they can. Yeah. And and, there's a real easy first question to this. When you talk about security and cybersecurity, the first question is, tell me about your SOC. What does your security operation center look like? A lot of people assume it's 24 by 7, but sometimes that's not the case. So tell me about your SOC. Tell me, is it 24 by 7? Tell me about your staff qualifications. Talk to me about the people that are actually going to be watching my environment. Right? This is not these are not positions for junior IT folks. Right? These have to be folks that have been in this world, have seen some of the threats, have actually responded to some of these threats. Right? And, the the other critical piece for that is ask your provider. Explain to me what your incident response plan is. Right? Just because I'm an MSSP, I should have that in place, but you'd be surprised that that some of these these newer companies say they can do all these things, but then they're not actually eating their own own dog food, so to speak. Right? So just real simply, the first question is tell me about your sock. And you should expect full transparency from any company you're gonna potentially work with. Yeah. Yeah. And I can I can add just a little bit more color to that is not only what's going on today, but then, you know, we're we're very passionate about doing what we call tabletop exercises and looking at the the specifics that are in place? So show me your last, incident response, to Pete's point and and walk me through what what happened. What, you know, give me the timelines. You know, what what how did it affect the business? Let me take a look at what forensics were done. So coming to the table and really talking about not only some of the controls you have in place today, but making sure, you know, it's not if, it's when. And when it does happen to your organization, you wanna be on offense again. You wanna have a plan. You wanna know how to to manage that incident. You wanna know if you do need to get, your cyber insurance engaged, when to do that, what client privilege there is, how to navigate through PR, and those those types of topics. And and that's what we try to do upfront is really give you a a good picture of of been there, done that, and, help you, you know, through that side. Yeah. Fantastic. And and, Paul, when you're having those initial conversations, maybe even before you get into, like, a a risk assessment, what are the things that you look for, maybe in terms of of kind of buy in, culture? I mean, obviously, there there's budget that needs to be committed to that, but that indicates that this is, a a client that that you're gonna be able to work with well and and achieve the results that ultimately they wanna they wanna achieve that are gonna be impactful for their business. Yeah. Absolutely. It's we we we need to to know that at the at the top layer, the senior side is they recognize that cyber is an organizational challenge. This is an organizational, need. This isn't just an IT check the box. That's what I wanna hear is that, this cup this touches all of our our organization from HR to marketing to our our operations, and people need to be in alignment. So we've got to we've got to have that, that type of those those are the types of answers that I'm looking for. Yeah. Awesome. Let's talk briefly here about kind of the relationship between compliance and security, and we I I I'm kinda guilty of using these 2 interchangeably, but often the compliance frameworks can inform, the the the security practices and actually validate them as well. Paul, going back to you, I'm curious kind of how you explain the relationship between the two and how organizations should be thinking about this. Yeah. And really from a compliance side that usually hits, the regulated areas. Whether it's government, healthcare, finance, public companies. You know, they gotta have that compliance, in place. But there are, you know, several other small medium sized businesses that that need the cyber in the security side. So there's there's 2 ways to look at that. 1, you've gotta to maintain your your compliance with the regulations. But, on the other side, you gotta know where you are from that posture from a security side. And keeping those 2 aligned, is is really important as we as we, continue on this journey. Yeah. Sure. And and Pete, I'm curious to know from you. I mean, it's it's one thing if you're, you know, a publicly traded company or you're doing international business or you're a big health care provider or whatever and there are, like, clear regulatory obligations. I imagine a lot of the companies that that we're talking about that are smaller might not have as rigorous obligations or at least are under the impression that they don't. How do you how do you kinda get that message across and and and let them know that, yeah, this is this is important for you too? Yeah. Compliance can be a scary word. Right? Especially for for those in verticals that that aren't financial or health care. But using these compliance frameworks simply helps mitigate risk. It doesn't matter what vertical you're in. So these compliance network or or these these compliance frameworks, yes, some of them were designed specific to verticals, but overarching, the biggest piece that any company is worried about is mitigating risk. And that's the thing that we talk about. It doesn't have that that's why compliance, like I said, can can be a scary word, but all it is is we've developed ways to help you mitigate risk and it doesn't matter what regulatory bodies you're answering to. Mhmm. Yep. Fantastic. And and Paul, can you can you speak to this? You know, we we've talked about, you know, security is not and compliance is not checking off boxes and then kinda setting it aside and say, hey. Hey. I I did this. We're good. It's a continuous thing that that you all are are delivering and working with these clients with over time. How do you how do you all kind of show that progress and and how should the the client be thinking about kind of increasing their posture over over time and and the value that that brings to their their business? Yeah. Absolutely. And and having a having a solid partnership with, with Aptega is is really a great way to show transparency of where you're at and, what the road map and recommendations are. As we shared earlier, that heat map, you know, you can see progress on a regular basis. We really encourage on a quarterly basis to, to have that plan and how how we are performing to that plan. And and in that that risk side is, you know, there are budgetary, you know, pieces that we need to keep in mind, not only if if there's a capital investment, but a resource investment and how it's gonna impact the overall company. You know, being with a couple of companies, locally here this week, it's, the CEOs or or the the top side says, yeah, just turn on, you know, take away admin rights to to the to the laptops. Just do it now. And it's like, no. No. No. No. No. We gotta we gotta communicate and plan and and and put those in motion. But that is, you know, where we need to go. So, but having a tool and a and a platform to to show the progress is, you know, 9 times out of 10 that that really just, you know, indicates where we're at, where we're going, showing the trend lines, and at the end maintaining that, that level, throughout the year. Yeah. Fantastic. So let's spend the next few minutes here before we end just talking about kinda how to how to kinda quantify if you're the business the the value of security and compliance. And and, Pete, I'll go back to you. I mean, you're, you know, you're you're on the business development side. Yeah. I I I imagine you get frequent pushback on, even though, you know, this is this is a lower cost thing relative to other initiatives. You're probably getting a lot of pushback on kind of budget and price and all that kind of stuff. Tell us about those conversations and and kinda how you get across the the value of of of these services. Yeah. So, a couple things can happen immediately if if you are breached. Right? There is immediate financial cost. Right? Immediate. The other thing that that I like to talk to the the, the clients about is tell me if your data was, you know, if somebody came in and hacked your environment and and held your data ransom, what does 1 minute cost to your business? What is 30 minutes? What is 1 hour? What is 1 week? I can't quantify that for you. Tell me what that tell me what would happen to your business. Right? And that's not even to mention, or to to to to bring up customer trust. Right? We talked about that earlier. So all those things, I help clients that haven't maybe thought about it in terms, of that to to kinda define and quantify those things. Right? And then they can sit back and say, oh, okay. Tell me again, where do we start? What's the initial cost going to be? And then they can start to to justify, you know, that cost associated with building a strong, security environment. And and there there are, like, hard costs that can be saved as well. I mean, I think about, like, insurance premiums for instance. Yes. There there are a lot of providers out there that are giving discounts, you know, if you can show not just alignment with a, you know, a security or compliance framework, but but you're actually following it. Right? And you're and you're more likely to get coverage in the event that something goes wrong. Correct. And and and just real quickly on this because I'm I'm sure, talking about insurance is not the most thrilling topic. But but what happened yeah. Yeah. What what what happened years ago were the companies that provided the cyber insurance didn't really have a baseline. So a lot of these premiums were very paying out more than they were bringing in with these premiums. So what happens then? 10 x. Right? And we're even finding that some companies can't get coverage because they don't have the first you know, Paul talked about MFA. If you don't have MFA, that is, like, step 1 in cyber in the cybersecurity world. We're finding that a lot of companies are being turned down to get coverage. Right? So, yes, if if we can decrease your premiums by adding security layers into your environment, you talk about ROI, that can pay for a lot of these services when you just talk about premiums on insurance. Yeah. Well well said. Paul, let me ask you, and we probably got a couple more questions and then we'll we'll wrap up. But it's it's increasingly important and you think about, like, the s the new SEC guidelines, FTC guidelines, from a an investor and a c level perspective to to be able to kind of attest to the things that you're doing on the on the security side, to make sure that your, you know, your your investors, if if, you know, if you have shareholders, that that you share this stuff with them. When you think about the conversations that you're having with leadership and and being able to help them actually report on this stuff in a in an articulate way, tell us about the importance of that and and how you're actually doing that. Yeah. 2 different ways that come to my mind. Obviously, if you're publicly traded, you you obviously are answering to the board and your shareholders. So, increasing more and more pressure, to make sure that we have, the maturity and the posture there, that we can we can clearly communicate. This is where we're at. This is our plan. That's what most investors and the board is looking for is 1, what's your baseline and what's your plan to bring this along? So having having that in, you know, readily available at any point is, is, you know, immeasurable or, you know, very, very finite. The other side that I would go to is we're engaging a lot with PE firms. Mhmm. Not only from from an acquisition perspective is who are they acquiring? What's their posture? Can we get into a quick, you know, quick template to just give me, you know, a feel for where they're at? Because typically, if if they're down in that 20 to 30% range, there's gonna be a lot of remediation and there's gonna there's gonna be some investment there. On the other side, from a divestiture perspective, if you have your controls and your posture up, so is the value of your company or your assets. So those are the things that when I when I talk to folks, especially when they're they're having to to answer to a board, to their investors, to shareholder communities, this is, you know, this is an area that gets them a lot of attention. And, every board meeting that I'm at or a shareholder meeting, the the top 2 or 3 things on the CEO mind is what's my risk position right now, or what is your risk position. And whether that's cyber or financial or whatnot, cyber keeps bubbling up to the top. So having having a plan of where you're at the baseline and moving forward really helps take a lot of the pressure off. Robert, if you don't mind, if I could add, that's a lot. Right? Like, how how am I going to get all this information to these key stakeholders, these board members? How much time is that going to take and what's that going to cost? Using tools like Aptaga, right, we can generate automated reporting so that it can be scheduled on on what whatever that cadence needs to be internally. We can make that as seamless as possible for you. So you're saving time and you're not having to spend days on end putting together all the this reporting about, you know, where you are as far as risk is concerned. Fantastic. So let's end with this. I'll each give you, let's say, 30 seconds. Just best piece of advice for an organization that's considering kind of going through this process and and really taking their security posture seriously and and wanting to improve it. Paul, go back to you. Yeah. So right away, I would I would do that risk assessment. Trust but verify. If you have an MSP or an MSSP, you know, it's okay to do a risk assessment and provide an outside, lens into where you're at. And, again, it's, you know, it's 0 to low cost, whether you're how you're doing your assessment. Well put. Pete, how about you? Yeah. And and with that assessment comes, let's implement basic security measures. Right? And in conjunction with that is user training. Right? 90% of breaches start at the user level. Right? So those two things. And again, it is not something that's cost prohibitive when you look at what potentially you're staving off as an organization when it comes to, to risk. Yeah. Fantastic and and well said. We're gonna leave it there. Pete, thanks a lot for being here. Paul, it was a pleasure, as usual. Thank you to our audience as well. We have the next Aptigo webinar coming up in a couple weeks. We'll email you about the schedule. We're also gonna send a survey out right after this. If you would like more information about CEI, if you'd like us to connect you with Pete or Paul, please just check the box and and we'll make sure that happens. And we'll see you all next time. Have a great rest of your afternoon. Thanks a lot. Thank you. Thanks.