Aug. 10, 2026

Building a Cybersecurity Culture in Your Company (Encore)

Building a Cybersecurity Culture in Your Company (Encore)

Building a cybersecurity culture in your company doesn't take a bigger budget — it takes a weekly habit. In this final episode of our encore series, returning guest snorkel42, a longtime Reddit voice in InfoSec, breaks down how he turned a company with zero dedicated security staff into one with a real security culture, just by committing to one small improvement every week instead of waiting on the next six-figure product.

We picked this one to bring back because of how it performed with you — not just downloads, but how much of the episode people actually stuck around for. That combination told us this conversation landed, and a lot of you came back to it more than once.

snorkel42 walks through where the term "security cadence" came from: a network engineering team, no InfoSec department, and a room full of unused tools nobody had the bandwidth to run. Instead of asking for more products, the team set a rule — one security change a week, no new vendor purchases allowed — for six months straight. What happened next is the real story: leadership noticed, and the team went from begging for resources to being handed them.

From there we get into what it actually took to build that cybersecurity culture day to day — the early challenges, how the team picked what to tackle first, and how a scrappy internal habit turned into something leadership actively championed. We also cover MFA, including why not all MFA is created equal, the SIM jacking risk that undercuts SMS-based codes, and the push-notification fatigue tactics attackers use to wear users down until they hit "yes" out of exhaustion. snorkel42 closes with a piece of advice worth sitting with: stop chasing the latest zero-day and start building your cybersecurity culture around how attacks actually function, start to finish. Do that, and ransomware protection comes along for free.

If you're the person in your company quietly carrying the security load, or you're trying to convince leadership that culture matters more than another line-item purchase, this one's for you.

00:00:00 — Cold open: you already own the tools you need

00:01:36 — Show intro and disclaimers

00:04:05 — Guest introduction: snorkel42's Reddit history and security cadence series

00:05:53 — Where the term "security cadence" came from

00:08:40 — Early challenges building the habit

00:44:57 — MFA, password security, and why not all MFA is equal

00:47:46 — SIM jacking and push-notification fatigue attacks

00:51:45 — Patching, WannaCry, and why chasing zero-days misses the point

Speaker:

You probably already own the cybersecurity tools that you need.

Speaker:

That's not the issue.

Speaker:

The issue is that nobody's using them, or certainly not using them correctly.

Speaker:

Today's guest built an entire cybersecurity culture out of that

Speaker:

one realization, one week at a time.

Speaker:

This is the final episode in our Encore series, where we picked the

Speaker:

episodes over the last few years that our listeners really engaged with.

Speaker:

We found this guest schooling people on Reddit with a series of posts, uh,

Speaker:

on what he called a security cadence.

Speaker:

His pitch was to skip the new six-figure product and instead commit

Speaker:

to one small, deliberate security change, uh, and improvement per week.

Speaker:

We get into how that habit turned into a real culture shift at his company.

Speaker:

Plus, of course, we talk about things like MFA, SIM hijacking,

Speaker:

and why he thinks that chasing the latest zero day misses the point.

Speaker:

He goes by his Reddit username of Snorkel42, and he clearly knows his stuff.

Speaker:

If this is your first time watching or listening to me, hi, I'm W.

Speaker:

Curtis Preston, AKA Mr. Backup.

Speaker:

I've been obsessing about backup, recovery, and now cyber

Speaker:

recovery for over 30 years.

Speaker:

If that's your bag, then I'm your guy.

Speaker:

You're not gonna find anyone that cares about that topic more than me.

Speaker:

Ever since 1993 when I had to tell my boss that there were no backups of

Speaker:

the database that we had just lost.

Speaker:

Now I've written five O'Reilly books, a blog, and a podcast.

Speaker:

Here we turn unappreciated admins into cyber recovery heroes.

Speaker:

This is the Backup Wrap Up

Speaker:

Hi, and welcome to Backup Central's podcast.

Speaker:

I'm your host, W. Curtis Preston, AKA Mr. Backup.

Speaker:

I have with me, my ghee deployment consultant, Prasanna Malaiyandi.

Speaker:

uh, Curtis, how's your ghee going?

Speaker:

You know, you may recall it a month or so ago.

Speaker:

I got ghee for the first time.

Speaker:

And, you know, for those that don't know what ghee is, it's

Speaker:

clarified butter specifically.

Speaker:

It's apparently an Indian thing, right?

Speaker:

we did learn that ghee is from Sanskrit.

Speaker:

That means sprinkled, which is interesting.

Speaker:

But the, um, and the thing about it is that it can sit on the counter.

Speaker:

Um, like it's shelf stable so it can sit on the counter and

Speaker:

you made a comment by the way.

Speaker:

I know this because I'm literally editing this episode right now.

Speaker:

And you made a comment that, you know, it can sit there probably for a

Speaker:

couple of months or until you run out.

Speaker:

So I'll just say this, the, uh, the jar, I thought that I was going to

Speaker:

be the only weirdo using the ghee.

Speaker:

Yeah, I am not the only weirdo using ghee.

Speaker:

In fact, if anything, the rest of the house is used the

Speaker:

ghee much more than I have.

Speaker:

And that jar that we bought is close to gone.

Speaker:

So

Speaker:

it's convenient.

Speaker:

It's super easy.

Speaker:

You just keep it out.

Speaker:

You warm it up a little.

Speaker:

It becomes really liquidy.

Speaker:

You put it on warm bread.

Speaker:

You toast that.

Speaker:

super good.

Speaker:

You can also put it in rice.

Speaker:

Warm rice.

Speaker:

It's really good.

Speaker:

Yeah, well, I mean, it's like it's butter, right?

Speaker:

you know, all the places you can put butter, you can put ghee.

Speaker:

Um, it's just, it, it, it is interesting for those that have never had it.

Speaker:

It has a slightly different flavor than butter, but it, you know, so there

Speaker:

is a, there is a, I didn't know what my mouth was going, what was going

Speaker:

to happen when I put it in there,

Speaker:

That's funny because I never think about that.

Speaker:

Like to me, like butter and ghee it's like, ah, yeah.

Speaker:

Yeah.

Speaker:

The first time I had, I had ghee, I remember going, huh,

Speaker:

this tastes different, you know?

Speaker:

Um, but what it was, but it was, but it was yummy, you know, so we continue to,

Speaker:

but yeah, I think that jar is almost gone.

Speaker:

So we're going to have to, we're going to have to find the ghee at Costco, which is

Speaker:

like 64 ounce.

Speaker:

like one pound.

Speaker:

Yeah, one pound jars or something.

Speaker:

Well we have a, a back by popular demand guest here.

Speaker:

Uh, he was on the podcast before and.

Speaker:

Is the author of the security cadence series on Reddit, been in IT for about

Speaker:

25 years and in InfoSec about 20 years.

Speaker:

And he is quite the celebrity over there on Reddit because I, you know,

Speaker:

his posts have been incredibly popular with, uh, uh, he's got a, uh, a, uh,

Speaker:

what a, what do they call it over there?

Speaker:

The karma of 35,000, which, you know, if you don't know anything

Speaker:

about Reddit, that's a, BFD, I'll just say that right now.

Speaker:

And we had him previously on the podcast so if you haven't heard that podcast,

Speaker:

you should totally listen to that.

Speaker:

Welcome back to the podcast.

Speaker:

snorkel42.

Speaker:

Good to be back.

Speaker:

And I tell you, so last time I learned what karma meant on reddit.

Speaker:

time I learned what ghee is so good for me.

Speaker:

So, um,

Speaker:

I want to hear about this thing.

Speaker:

You mentioned about security cadence.

Speaker:

What, what started, because that was, that was the, um, that was

Speaker:

the, what, what do you call that?

Speaker:

Uh, the thing before the thing, the, the precursor, the preamble,

Speaker:

the, in the title, um, uh, to the post that we saw that.

Speaker:

So where did that term come from?

Speaker:

So the term came from a previous employer.

Speaker:

I worked at where I was a network engineer, um, and it was a large company

Speaker:

that did not have an InfoSec presence.

Speaker:

There was no InfoSec team.

Speaker:

It was just kind of considered, Hey, all engineers are responsible for security.

Speaker:

Um, and you know, we would, we'd have our occasional shots off the bow in terms of

Speaker:

security, you know, problems or issues.

Speaker:

You know, I, I hesitate to say breaches, but, you know, incidents and when

Speaker:

they would occur and we would all pile into a conference room and we would

Speaker:

talk about what happened and what we should have done to prevent it.

Speaker:

And it would always come down to, well, if we just bought six figure dollar

Speaker:

product X, this would not have occurred.

Speaker:

Meanwhile, in the data center, there were piles of six-figure products

Speaker:

that were completely ignored because those products never run themselves.

Speaker:

And if you're complaining of not having resources to run those products, what

Speaker:

makes you think you're going to have resources to buy and run new products?

Speaker:

So I finally got fed up one day and just challenged the team to, you know what?

Speaker:

We've got plenty of tooling.

Speaker:

That's not the issue.

Speaker:

We just don't have the oomph.

Speaker:

We don't have the motivation to actually use it.

Speaker:

So why don't we set ourselves a goal for six months, we're going to

Speaker:

implement a security change every week.

Speaker:

It could be a big change, could be a really minor change, but

Speaker:

there's going to be something.

Speaker:

Move the ball forward.

Speaker:

And also during that six months, we are going to just put the

Speaker:

kibosh on talking to any vendors.

Speaker:

So no products are allowed, no solutions are allowed that we don't already own.

Speaker:

Um, and you know, it took some, took some talking and wrangling

Speaker:

people, but eventually folks fell in line and we sat down.

Speaker:

We'd wrote out a list of, you know, here's some things just off the top of our head

Speaker:

that we know we could implement with, you know, very little roadblocks, no impact.

Speaker:

And we just started and we called it our security cadence.

Speaker:

Once a week, we have a security cadence of releasing a security update and

Speaker:

it, you know, it ended around six months in our CIO came to us and said,

Speaker:

listen to what you guys are doing is fantastic, but please don't restrict

Speaker:

yourself to only free solutions.

Speaker:

Like we have money.

Speaker:

If there's stuff you need to keep this ball moving, please ask.

Speaker:

Um, so, you know, it kind of turned the whole thing on its head of,

Speaker:

you know, securing the company.

Speaker:

But also we were no longer begging for resources.

Speaker:

The, you know, the executive leadership was asking us, was begging us to start

Speaker:

spending resources because they saw what we were doing and saw the value.

Speaker:

So, could you talk a little bit, I'm sure at the very beginning

Speaker:

as you're starting this right.

Speaker:

With any new process or new, any new endeavor, it's a little difficult, right.

Speaker:

Sort of getting into what does it mean?

Speaker:

And trying to figure things out.

Speaker:

So what were some of the challenges you guys went through and how did you address.

Speaker:

Yeah.

Speaker:

So I would say the biggest challenge with any sort of security changes,

Speaker:

especially in a large company is just the unknown of what will this break.

Speaker:

Um, because quite often, especially in those early days, what you're changing

Speaker:

are out of the box configurations.

Speaker:

So there's this kind of mentality of, well, it's probably an out of the box

Speaker:

configuration for some reason, or, you know, we don't know what legacy, I

Speaker:

mean, this company that I was working at at the time was started in the 1930s.

Speaker:

Now we don't know what kind of legacy applications are

Speaker:

relying on this technology.

Speaker:

Um, so I would say the first, the biggest thing was to just start

Speaker:

easy, take the really easy ones to get as much buy-in as you can, you

Speaker:

know, sit down to the engineers.

Speaker:

Can anyone think of anything that would break by doing this?

Speaker:

And you will get some feedback.

Speaker:

Yeah.

Speaker:

But who cares?

Speaker:

It's not going to fix anything.

Speaker:

Okay.

Speaker:

That's fine.

Speaker:

Let's just do it anyways.

Speaker:

Um, and then start, you know, slowly ramping it up and

Speaker:

taking little bite-size chunks.

Speaker:

And if you look at the security CA cadence, Reddit posts, that's exactly

Speaker:

how I've been approaching them.

Speaker:

You know, I've started off with just really easy things to do and things

Speaker:

I would not expect, um, to break many enterprises, you know, I tried to

Speaker:

make it very clear in those posts of, you know, everyone's environment is

Speaker:

different and be careful, but you know, I've called out certain items of this.

Speaker:

Isn't going to break anything, just do it, you know, please just, just do it.

Speaker:

I do remember in your, the trio of posts that you did that were around

Speaker:

ransomware, you, you had a, there was a phrase that came up a lot.

Speaker:

It's escaping me at the moment, but it was like, turn this on

Speaker:

and then customize as necessary.

Speaker:

Right.

Speaker:

That, that, that, you know, that you can't, that no one solution does, uh, you,

Speaker:

you can make a general rule for example, and then you're going to find somebody

Speaker:

that needs, that thing turned on the thing you just turned off, you're going

Speaker:

to find somebody that needs, that turned on and then you can turn it on for them.

Speaker:

Right.

Speaker:

Um, and, and that's okay.

Speaker:

Yeah.

Speaker:

So one of the catchphrases are one of my guiding lights in InfoSec is to never

Speaker:

let perfect get in the way of being good.

Speaker:

I call it out a lot.

Speaker:

And part of the reason why I lean on it so heavily is it's often a. Uh, voice of

Speaker:

dissension that you get from folks when you're trying to talk them into things

Speaker:

like, oh, well that won't solve this one edge case, so let's not do it at all.

Speaker:

Um, and you know, when it comes to security, security, it's all about

Speaker:

layers and it's all about catching the attacker and yeah, there, this may

Speaker:

not solve all of your problems, but it might be the alert that gets generated

Speaker:

that tells you that they're there.

Speaker:

Um, you know, and so it is definitely a strong, um, demand I make a people of,

Speaker:

you know, if you can only do this for one system, great, it's better than none.

Speaker:

Um, and yeah, so there there's something to be said about going

Speaker:

slow and implementing slowly, but there's also something that I said

Speaker:

about implementing broad and then backing off where you need to.

Speaker:

Hmm.

Speaker:

Yeah.

Speaker:

Yeah, exactly.

Speaker:

I would say that.

Speaker:

When you, when you try the latter, when it, when I was thinking about your,

Speaker:

your initial, this, the six months program that you had, the farther

Speaker:

you got into that six months, and the more complicated things that you were

Speaker:

doing that were potentially riskier, if you will, to the environment that

Speaker:

you could potentially impact someone's ability to do their job, the more

Speaker:

you're going to need support from above.

Speaker:

Right?

Speaker:

Like, I, I, I told, you know, I told them to do this.

Speaker:

We're sorry that it broke, you know, we'll

Speaker:

Yeah.

Speaker:

we turned it off for now.

Speaker:

We didn't realize that by pushing this one button was going to make everyone in

Speaker:

the company not be able to log in ever.

Speaker:

Uh, we've turned it off until we figured that out.

Speaker:

Right.

Speaker:

Don't don't go, don't go beat, snorkel out.

Speaker:

And maybe that's also where you get some of those early

Speaker:

wins before you take on those.

Speaker:

So you get sort of the buy-in from upper management that, Hey,

Speaker:

they are doing the right things.

Speaker:

They are making improvements.

Speaker:

Yeah, absolutely.

Speaker:

Yeah,

Speaker:

One of the, the biggest allies of InfoSec people that they forget about is the CFO.

Speaker:

The CFO is the person when you're doing these sorts of things that you

Speaker:

want to have in your back pocket to be able to go have that conversation of,

Speaker:

Hey, where is our money actually made?

Speaker:

Because I want to know, Hey, what, what divisions of this company aren't really

Speaker:

contributing that much to the bottom line.

Speaker:

Cause those just became my test case the things that I'm really

Speaker:

not sure about.

Speaker:

Let's take them down because that's not going to, you know, that's not going

Speaker:

to ruin our end of quarter numbers.

Speaker:

So they're going to start this off as a retailer.

Speaker:

So that was obvious.

Speaker:

Don't take down the stores under no circumstances do you take down the stores.

Speaker:

Right.

Speaker:

Right.

Speaker:

but legal?

Speaker:

Go for for it,

Speaker:

Yep.

Speaker:

I don't know how legal would feel about that.

Speaker:

But yeah, no, I understand what you're saying basically.

Speaker:

So w every change that you made, you don't have to roll it out.

Speaker:

Company-wide you, you put it into places where you felt that it would do, you know,

Speaker:

hopefully the change would have a minimal impact, but if it did have an impact,

Speaker:

it would have a minimal impact to the company, because it only made legal, not

Speaker:

be able to do something for a day or two,

Speaker:

Absolutely.

Speaker:

which is a very different thing than no one can log into the

Speaker:

cash registers for a day or two.

Speaker:

Absolutely.

Speaker:

In retail, taking down the chain is the worst thing you could possibly do.

Speaker:

Yeah, exactly.

Speaker:

So for the record, I actually started in retail.

Speaker:

I, I worked a hundred years ago.

Speaker:

I was a shoe salesman at a, a chain called Kenny shoes, which no one.

Speaker:

Under 25 even know exists, but you know, it used to, it was the parent

Speaker:

company that created Footlocker.

Speaker:

So Footlocker is still around, but Kenny shoes was its own store.

Speaker:

And I worked in, uh, retail.

Speaker:

So I know I also worked at some, some what we now call big box stores.

Speaker:

So I know what it's like to be at the receiving end of that.

Speaker:

And when, uh, when corporate, when corporation changes things

Speaker:

and then poof, you know, you, you suddenly can't do your job.

Speaker:

That's unacceptable.

Speaker:

So you went through this exercise, you had this process of, um,

Speaker:

going for six months, doing a security update or roll out a week.

Speaker:

And then you started writing about this small things that people can do

Speaker:

to improve their security posture.

Speaker:

And where did you go from there?

Speaker:

Like, did you think you would keep writing this long because

Speaker:

how long have you been posting on Reddit for your security cadence?

Speaker:

So I, I only started it in January.

Speaker:

I did it as a new year's resolution.

Speaker:

Um, and it, the idea came to me.

Speaker:

I was on a, on a different podcast.

Speaker:

Um, and we were talking about InfoSec and we were talking about a term that I

Speaker:

believe Wendy Nader from duo security, uh, coined, which is InfoSec poverty.

Speaker:

Um, and it's basically in reference to companies that just don't have the

Speaker:

resources to have dedicated InfoSec people or InfoSec tooling, and how,

Speaker:

you know, it's not really fair to expect these companies that just

Speaker:

don't have those resources to really be able to stand up against you know,

Speaker:

the modern era of security threats.

Speaker:

Um, so on this podcast we were discussing, you know, what do, what can we as InfoSec

Speaker:

professionals do to help those companies?

Speaker:

Um, and it's been kind of living rent free in the back of my brain

Speaker:

since I was on that podcast.

Speaker:

Um, so as I was approaching the new year, I was like, you know what, I'm just going

Speaker:

to hop on Reddit, starting in January and make that weekly post and see if

Speaker:

I cant' help um, you know, some of the folks in the sysadmin sub Reddit, which,

Speaker:

you know, the sysadmin subreddit, they have the, um, the flares for everyone.

Speaker:

And there's a lot of them that list themselves as Jack of all trades.

Speaker:

And those are those sysadmins that are working in smaller companies.

Speaker:

And they're, you know, if it plugs into the wall, that's their job.

Speaker:

Um, and you know, those companies are exactly what InfoSec

Speaker:

poverty is calling out of.

Speaker:

You know, you have these brilliant sysadmins who are heavily

Speaker:

overburdened, and they just don't have the time to focus on this.

Speaker:

Um, and they just kind of need someone to say, Hey, you know, this week, why don't

Speaker:

you disable this one thing that comes out of the box in windows and you do not need,

Speaker:

and it creates a massive security risk.

Speaker:

Um, yeah, so I started in January and I have a nice long list,

Speaker:

uh, in one note of post to make.

Speaker:

And you know, every every week around Wednesday night, I just pull one

Speaker:

up and I write a quick blog post.

Speaker:

Yeah.

Speaker:

Cause you can't, you can't schedule Reddit posts, Right.

Speaker:

I don't

Speaker:

Right.

Speaker:

You can, uh, you can put them in drafts.

Speaker:

So I write them

Speaker:

Wednesday night and Monday morning I remove it from draft,

Speaker:

got it.

Speaker:

Yeah.

Speaker:

that was Paul's InfoSec weekly, I believe.

Speaker:

Was it the podcast where you were, right, right.

Speaker:

Yeah, Shout out to them.

Speaker:

Um, so, uh, so you said you started in January, So, you're what, uh,

Speaker:

like eight or nine posts in on that.

Speaker:

And did this, this, uh, this, what do you call it?

Speaker:

Um, or maybe like 10.

Speaker:

I don't know.

Speaker:

I can't do math.

Speaker:

Anyway.

Speaker:

This is, um, the ransomware posts were, where did that fall into that?

Speaker:

You know, the

Speaker:

yeah, it's a fun question because literally, since I started this since

Speaker:

post one, I've had people messaging me on Reddit saying, Hey, could

Speaker:

you do something about ransomware?

Speaker:

Um, cause it's you know, it's a top of mind topic, especially for the

Speaker:

smaller orgs, that's the big boogeyman.

Speaker:

Um, and I've been honestly kind of Mr. Miyagi'ing it in terms

Speaker:

of, well, everything I'm posting really has to do with ransomware.

Speaker:

You just don't realize it.

Speaker:

Um, but when.

Speaker:

reference by the way not sure if everybody listening will understand that

Speaker:

reference, But, very nice reference.

Speaker:

But, yeah, so my expectation was I haven't, you know, a list of posts that

Speaker:

eventually I was going to say, Hey, you know, if you've been messaging me

Speaker:

about ransomware, go read these posts.

Speaker:

This is what I was driving at.

Speaker:

Um, but then, uh, when Russia invaded Ukraine and the Conti ransomware

Speaker:

groups, uh, came out and said that anyone that takes up arms or,

Speaker:

you know, it goes against Russia.

Speaker:

We're going to come after I got flooded with people saying, no, really, please.

Speaker:

We need something.

Speaker:

So hence the title, the, okay, fine.

Speaker:

Let's talk about

Speaker:

Yeah,

Speaker:

Um, so I decided, yeah, it was time to just at least take

Speaker:

a truncated approach to it.

Speaker:

How did you approach because ransomware is such a huge topic, right?

Speaker:

I know Curtis, you and I, we talked about it, but just sort of your

Speaker:

thought process behind like the series that you wrote and how do you

Speaker:

get such a dense topic out there?

Speaker:

Because there are so many different ways that ransomware can attack you

Speaker:

and so many different, uh, crews out there with different methods.

Speaker:

So how do you sort of generalize it, especially, like you said,

Speaker:

for those people who don't have the time to research and follow up

Speaker:

everything related to InfoSec, right?

Speaker:

So I giggle when you say dense.

Speaker:

Cause one of the other pieces of feedback I get quite frequently

Speaker:

is that my posts are too long.

Speaker:

Um, but yeah, so my take on ransomware is that companies tend

Speaker:

to focus on the exact wrong spot.

Speaker:

Um, and I apologize for coming on to a backup, um, related podcast

Speaker:

and say that most companies focus on backup and that's, that's

Speaker:

No, no.

Speaker:

effort.

Speaker:

That's the, that's the thing that

Speaker:

hopefully saves the company when everything else has

Speaker:

just gone poorly for you.

Speaker:

And don't Don't worry, snorkel.

Speaker:

We have the same opinion as well, or at least I do, right.

Speaker:

That

Speaker:

it's just a last resort, but you should really be protecting yourself upfront.

Speaker:

Um, and so the thing that comes, that happens every time, there's a major

Speaker:

ransomware breach, um, is, you know, it hits the media and everyone starts talking

Speaker:

about the indicators of compromise.

Speaker:

It loves talking about indicators of compromise because it's easy to deal

Speaker:

with, you know, how did they get in?

Speaker:

I was an email.

Speaker:

Well, where did the email come from?

Speaker:

What was the subject?

Speaker:

Did it link to something, where did the link go to?

Speaker:

What did it download?

Speaker:

What was the hash of that downloaded and on and on and on and on.

Speaker:

And because it's easy then to go into your controls and, oh, we're going to put in

Speaker:

our spam filters to block that address.

Speaker:

We're going to block that domain.

Speaker:

We're going to put in our, uh, endpoint security tools to block that

Speaker:

hash, but it's all pointless, right?

Speaker:

Because that breach is done.

Speaker:

That entire infrastructure has been burned.

Speaker:

There was nothing left of it.

Speaker:

So, you know, you're, you're reacting to something that's no longer exist.

Speaker:

But when no one ever asks is, wait a minute, how did you know Susie

Speaker:

in accounting downloading this attachment lead to their entire VMware

Speaker:

infrastructure getting encrypted.

Speaker:

And that's, that's the real takeaway from every single ransomware breach of, you

Speaker:

know, it's one thing to come in and, you know, the accounting system, one person

Speaker:

in the accounting system is encrypted.

Speaker:

It's another thing entirely to come in.

Speaker:

And yeah, the entire network has gone now and we don't have any data.

Speaker:

Um, and that's really where the security cadence posts come in.

Speaker:

And w what I try to focus on, especially in the first post of this

Speaker:

is what I would be doing right now.

Speaker:

If you are waking up to a world where Russia has invaded Ukraine, and you're

Speaker:

all of a sudden, greatly concerned that ransomware group's going to

Speaker:

come after you, these are the things to start off with, and it isn't

Speaker:

necessarily preventing ransomware.

Speaker:

It's preventing ransomware from being able to do anything significant.

Speaker:

Um, and the nice thing about those controls is it translates

Speaker:

to way more than just ransomware.

Speaker:

Which is another issue that I think smaller companies particularly have

Speaker:

when they're dealing with InfoSec, as they put their blinders on and

Speaker:

very specific attack types, like how do we protect against ransomware?

Speaker:

Oh, we get good backups.

Speaker:

Well, how about, how do we protect against any sort of extortion attempt?

Speaker:

You know, we, we had the lupus group or excuse me, Lapsis

Speaker:

Yeah, I think it was locked system.

Speaker:

Yep.

Speaker:

I had been talking about all week and I just blanked on there anyways, you

Speaker:

know, going after Nvidia and Okta and Microsoft and LG, really their playbook

Speaker:

is the exact same as a ransomware group.

Speaker:

You know, ransomware only exists, not because they care

Speaker:

about encrypting your data.

Speaker:

They've went to extort you for money.

Speaker:

Ransomware shifted, shifted recently to exfiltrating data because people had

Speaker:

good backups or had restoration methods.

Speaker:

We'll find let's steal the data.

Speaker:

Cause we never really cared about encrypting the data.

Speaker:

We just needed that incentive to get you to pay.

Speaker:

Um, so when you take a step back and look at how attacks function

Speaker:

from the ground up and started going at the common denominators.

Speaker:

You, you really don't care about what the actual end objective is any longer

Speaker:

because the controls are there to make sure that they never made it past sending

Speaker:

that initial email, um, or, you know, tacking this particular vulnerability you

Speaker:

had exposed to the perimeter for a week.

Speaker:

Because those vulnerabilities will constantly be evolving.

Speaker:

Right.

Speaker:

And so you kind of need a generic.

Speaker:

Protection scheme, if you will, rather than something tailored for a particular

Speaker:

ransom group, but that comes after you.

Speaker:

Yeah, the rent

Speaker:

A ransomware attack is it's the conclusion of, you know, what, like you

Speaker:

got infected, but the ranch, I don't know if I'm saying, I'm not saying this

Speaker:

right, but It's I want to say it's the symptom, but it is actually the infection.

Speaker:

Right.

Speaker:

But that

Speaker:

not the cause.

Speaker:

The problem is what allowed them to get there in the first place.

Speaker:

You're absolutely right.

Speaker:

And it's, it's interesting that it is a multi-tiered product at this point.

Speaker:

There are, there are groups out there that sell you the initial breach.

Speaker:

Um, so if you and Conti is one of the groups that are suspected of doing this,

Speaker:

that they don't do the initial breach, they buy the breach, they buy someone

Speaker:

who already has the foothold and then use that foothold to do the actual encryption.

Speaker:

Hmm.

Speaker:

And so you have this entire life cycle of, you know, third-party vendors

Speaker:

that lead up to the final breach.

Speaker:

Right.

Speaker:

Um, you know, you know, Conti may be purchasing someone else's exploit kits,

Speaker:

um, someone else's encryption kits.

Speaker:

So you're exactly right.

Speaker:

That there's the initial breach.

Speaker:

That's really your first opportunity.

Speaker:

And when you get to the point where things are encrypting, so many other

Speaker:

things have been missed by that.

Speaker:

That at least if you get to that point, you know, you have

Speaker:

a lot of great opportunities to prevent it from happening again.

Speaker:

Cause you should have learned so much up to that point of, oh my gosh, they

Speaker:

got the phishing email through my end user is able to download this thing.

Speaker:

They were able to click this link to this weird domain that was stood up yesterday.

Speaker:

Um, they're able to execute a program after they downloaded it off the internet.

Speaker:

I mean all these different controls that had to go poorly just to

Speaker:

get to that point of encryption.

Speaker:

Uh, speaking of phishing, I did see something like this is just a couple

Speaker:

of days ago and they were, and, and again, I, I don't remember exactly

Speaker:

where I saw it, but it was like, it was saying that phishing had surpassed,

Speaker:

uh,, that it now become the number one method of attacking companies versus

Speaker:

I guess, uh, a standard exploit, I guess, would be number two, right?

Speaker:

A standard sort of direct hacking attempt the phishing had become the number one.

Speaker:

I don't know if you,

Speaker:

No,

Speaker:

sounds like you saw that as the number one.

Speaker:

Yeah.

Speaker:

Actually someone that, one of the things I really liked with the

Speaker:

security cadence post is when people get in and correct me, or, you know,

Speaker:

point out other things, because I'm certainly not an expert in all things.

Speaker:

Uh, but in the first ransomware post, I made a person who works

Speaker:

for a cyber insurance policy holder actually called me out and said, yo,

Speaker:

phishing is the number one for sure.

Speaker:

But right close on its heels is the proxy shell exchange vulnerability, uh, which

Speaker:

is a vulnerability from last year and, you know, impacting on-prem Exchange,

Speaker:

uh, deployments and, you know, still plenty of unpatched boxes out there.

Speaker:

But yeah, you know, you get these massive blips, right.

Speaker:

You know, a log4j S sort of thing.

Speaker:

That is a crazy large vulnerability.

Speaker:

That attackers jump on quickly.

Speaker:

But the internal one is always fishing.

Speaker:

There's always social engineering is the quickest path to get past your perimeter.

Speaker:

Yeah.

Speaker:

And especially with some of these large spikes, you also

Speaker:

have the long tails, right.

Speaker:

In terms of how long it takes to get every single system out there patched.

Speaker:

And you'll always have systems out there which don't go patched for so long and

Speaker:

still continues to be an attack vector.

Speaker:

Right?

Speaker:

Right.

Speaker:

And it's that InfoSec debt that, that again, of, you know, a company that

Speaker:

hired someone else that comes stand up their IT infrastructure one time

Speaker:

and it's been neglected ever since.

Speaker:

And there's no one patching those systems that are running

Speaker:

their exchange 2003 deployments.

Speaker:

I mean, they're out there.

Speaker:

the way.

Speaker:

Here's what I want to say.

Speaker:

Who the hell is still running on prem Exchange.

Speaker:

That's all I want to say about that.

Speaker:

And why aren't you using 365?

Speaker:

That's all I'm saying Microsoft.

Speaker:

You're welcome.

Speaker:

I'm just saying I don't, it's just, it's just

Speaker:

Wait, wait, you forgot to add one thing to that, Curtis,

Speaker:

what's that?

Speaker:

What's that.

Speaker:

if you are using Microsoft 365, make sure to back it up.

Speaker:

Yeah, absolutely.

Speaker:

Yes.

Speaker:

Thank you.

Speaker:

Because Microsoft isn't doing it for you.

Speaker:

Yeah.

Speaker:

Yeah.

Speaker:

It's a standard thing.

Speaker:

We have to mention here on, on the podcast,

Speaker:

So a dropper is typically the initial thing that gets downloaded.

Speaker:

So if you look through a normal, any sort of malware campaign, we'll keep

Speaker:

it as ransomware that, you know, I sent an email, uh, as a, as an

Speaker:

attacker, that's a phishing email.

Speaker:

And then the whole point is to try to trick someone into clicking a

Speaker:

link and downloading the program.

Speaker:

Um, or maybe it's attached, uh, maybe it's a word document or

Speaker:

something like that it's attached, but it's something small and.

Speaker:

Typically, you're going to see it as a document macro.

Speaker:

Um, and the whole point of it is that's the simple, easy thing that's going

Speaker:

to slip through, you know, your, your various defenses, because it's just

Speaker:

a word document, but you enable the macro in the macros, what reaches out

Speaker:

and downloads the current malware.

Speaker:

And there there's a few reasons for that.

Speaker:

A big one is that malware could potentially being, be being generated

Speaker:

on the fly, meaning that the definition that's behind that, the hash for it, or,

Speaker:

you know, the, the detection mechanisms that more traditional antivirus is

Speaker:

looking at won't have those definitions.

Speaker:

Cause it was generated at the moment of downloads.

Speaker:

Um, you know, we've just minor changes, but just to throw off that hash, um,

Speaker:

but then that's the thing that actually gets downloaded and executed and, um,

Speaker:

you know, causes you all your problems.

Speaker:

And, you know, from there it could be any number of things.

Speaker:

So as we were saying that there are people who would just tell

Speaker:

you that footprint, right.

Speaker:

Or that foothold.

Speaker:

Right.

Speaker:

That dropper could download just seed, too.

Speaker:

Just something that's calling back saying.

Speaker:

Yep.

Speaker:

I got something running on this computer and that's it.

Speaker:

Hmm.

Speaker:

All it could literally.

Speaker:

Oh, okay.

Speaker:

So he could just literally sit there and wait for the second group.

Speaker:

That's going to purchase that.

Speaker:

And then they download the malware that they want to download.

Speaker:

Right.

Speaker:

So.

Speaker:

That's what you were referring to earlier.

Speaker:

And so it looked like the, and again, this is common sense to you,

Speaker:

but not necessarily to everybody, it looked like, you know, your

Speaker:

best advice was to, to stop.

Speaker:

Ransomware is to just think about how ransomware works when it gets

Speaker:

in, when that dropper gets in.

Speaker:

You're not going to, I mean, yes, you should do user training and

Speaker:

yes, you should do, you know, you should do all those things.

Speaker:

And, but you should just assume that at least one of

Speaker:

them is going to get it wrong.

Speaker:

I mean, I remember back when I was, uh, you know, 25 years ago when I

Speaker:

was at a bank, we did regular InfoSec training with every new employee.

Speaker:

And one of the things we constantly said, well, Uh, no one in it

Speaker:

will ever call and ask you for your password ever, ever, ever.

Speaker:

And then we would, and then immediately after the training, we would call them

Speaker:

and ask them for their password and still a percentage of them would give it to us.

Speaker:

Right.

Speaker:

Um, So.

Speaker:

you, you do the training, but then you just sort of assume that that's going to,

Speaker:

um, you know, um, that th that somebody is going to click on the wrong link.

Speaker:

And so then you just think about stopping that malware at that point,

Speaker:

you know, stopping them from accessing a command and control server, looking

Speaker:

for, you know, this, this weird, you know, domains that stood up yesterday,

Speaker:

domains that were stood up a long time ago, but just suddenly when active,

Speaker:

um, you know, the limiting lateral movement inside the company, all of

Speaker:

these things, uh, what, what did I miss.

Speaker:

A big thing that a lot of ransomware particularly will do.

Speaker:

First thing is start deleting, shadow copies as a quick restoration point.

Speaker:

So that is a pretty dead giveaway of, you know, you get the event ID

Speaker:

that shadow copy was just deleted.

Speaker:

That's

Speaker:

And you're referring to VSS there, right?

Speaker:

The windows shadow copy.

Speaker:

Yeah.

Speaker:

So I had a question for you snorkel about that one.

Speaker:

Is, does that prevent backup apps from actually running that might

Speaker:

leverage VSS and shadow copies?

Speaker:

Maybe it is the short answer, but depending how you attack this,

Speaker:

if you're, if you're attacked for this is just, I want an alert on

Speaker:

anything that delete shadow copies.

Speaker:

Well, you know, if you have a backup solution that makes use of shadow copies

Speaker:

and deletes shadow copies, then you know, that's something that you tune out, right?

Speaker:

So you need to know the source of what deleted then that should be your event

Speaker:

ID and you just tune that one out.

Speaker:

Gotcha.

Speaker:

So then you should only look for anomalous events that happen.

Speaker:

Typically backup apps are going to, um, create a, create a shadow copy just

Speaker:

to have a stable frame of reference and then delete it when they're done.

Speaker:

Your backup app is probably running as a service.

Speaker:

So that's going to run a system or whatever your backup, um, username

Speaker:

is, or a user account is, whereas your ransomware is likely going

Speaker:

to be running as that end user.

Speaker:

Hm.

Speaker:

So when you ask yourself, does an accountant have reason to

Speaker:

be deleting, shadow copies?

Speaker:

Probably not.

Speaker:

So you can look for all these patterns and determine what's real versus

Speaker:

what's not because I guess that's the other hard part in InfoSec is like

Speaker:

tuning out the noise or the normal behavior versus what's anomalous.

Speaker:

Right.

Speaker:

Um, and you know, it all starts with really, really good logs.

Speaker:

you need to have that log information and then what's going on in your systems.

Speaker:

But honestly, going back to deleting shadow copies, of the other call-outs

Speaker:

I made from a higher level, it's just looking at what would, you

Speaker:

would expect an end user to run, especially from the command prompt.

Speaker:

Right.

Speaker:

You know, do you expect someone in legal to ever open a command

Speaker:

prompt, let alone, you know, run whoami or run nets, you know, and

Speaker:

start looking around your network.

Speaker:

Probably not.

Speaker:

So if someone in legal opens up a command prompt, that right there, it might be

Speaker:

enough for you to go well, that's weird.

Speaker:

Start running, you know, typical attack commands, or, you know,

Speaker:

living off the land commands.

Speaker:

Now it's real weird.

Speaker:

And what would you use to watch for.

Speaker:

Th there was a tool.

Speaker:

I forgot its name that you mentioned about that.

Speaker:

Uh, so the tool I mentioned in one of my blog posts was raccine,

Speaker:

which is so vaccine with an R, um, which is a tool that just monitors

Speaker:

for shadow copy deletion, and just kills any process that does it.

Speaker:

Um, the problem is it doesn't discriminate.

Speaker:

So again, if you do have a backup tool that does make use

Speaker:

of deleting shadow copies, it's going to kill that process for you.

Speaker:

Um, but if you don't have that limitation, it's a really handy,

Speaker:

little quick, simple solution.

Speaker:

but can you tune that or do you need another tool that's tuneable.

Speaker:

Uh, well, it's, it's open source, so you can certainly modify the code, but no,

Speaker:

uh, the current version that exists does not have any sort of options for that.

Speaker:

It is, uh, a one and done sort of thing.

Speaker:

Gotcha.

Speaker:

Okay.

Speaker:

yeah.

Speaker:

So that would be, that'd be a perfect example of, like you said, when we

Speaker:

were talking earlier, let's try this.

Speaker:

Right.

Speaker:

Hopefully it doesn't kill the backups, but if it does kill the backups, it

Speaker:

would be pretty obvious because all the backups will fail because they're

Speaker:

unable to create, uh, the shadow copies.

Speaker:

I think one of the ones, and I don't know which article number was from that I

Speaker:

thought was very unique that you brought up was a different way to sort of trick

Speaker:

the ransomware, um, into sort of not destroying your entire infrastructure.

Speaker:

I think one of the examples you brought up is sort of creating

Speaker:

hidden drives and book-ending normal drives available on that system.

Speaker:

So ransomware kind of get stuck, or you can monitor for that.

Speaker:

Yeah.

Speaker:

So, I mean, it's part two, in case you're wondering, um, so the, the actions

Speaker:

on objectives posts, so, you know, we have the, the initial infection,

Speaker:

you know, they mapped your network.

Speaker:

They're starting to spread out.

Speaker:

Now they're actually going to start trying to attack, you know, at this point.

Speaker:

1, you you have to call out that in 2022, one hopes that your endpoint

Speaker:

security software, you know, whatever anti-virus, anti-malware, you're

Speaker:

running sees process X is encrypting word document Y. I'm going to kill it.

Speaker:

If it doesn't, you really need to have a come to Jesus moment with your

Speaker:

endpoint protection vendor at this point.

Speaker:

But you know, if you have something that's running, that's actively doing that.

Speaker:

Um, at that point, I think one of the best controls you can possibly have.

Speaker:

Is feeding it data that you don't care about and putting alerts on it.

Speaker:

So, you know, as you were saying, Prasanna.

Speaker:

One of the things I do is I create, um, deceptive file shares on my network.

Speaker:

So just file servers that, you know, on their own separate windows box, doesn't

Speaker:

don't have any useful data on them.

Speaker:

I actually just clone my actual production file names and structures

Speaker:

and just put random data in them.

Speaker:

Uh, but then I make drive mappings to my end points.

Speaker:

Um, hidden drive mapping said, you know, from the windows GUI,

Speaker:

you can't see them, but, you know, from command prompt, you can.

Speaker:

Um, and I just book in my valid drives.

Speaker:

So, you know, you have a home drive at H. So put something before

Speaker:

that and put something after that.

Speaker:

And, you know, hopefully the ransomware will go after those first.

Speaker:

Um, and then I put just, you know, files on those servers that I monitor.

Speaker:

If anything gets changed for them, no reason for anyone

Speaker:

to ever touch these servers.

Speaker:

No reason for anyone to touch these files.

Speaker:

So, if anything gets modified, then it sets off alerts and I

Speaker:

know something weird is going on.

Speaker:

Um, and hopefully it buys you enough time to, you know, to remote in at three in

Speaker:

the morning and down whatever's going on.

Speaker:

Um, and yeah, the other thing I, I offered up in that it was what

Speaker:

I coined as a ransomware tar pit of an actual service that's just

Speaker:

running or monitoring that server.

Speaker:

And it just starts seeing files getting modified.

Speaker:

It starts generating more.

Speaker:

Um, so, you know, Hey, the ransomware, it hit my fake file share.

Speaker:

It file one.

Speaker:

Well, here's four more files for you and it'll just keep going and just keep going.

Speaker:

And you know, it may not be foolproof, but it might just depending on

Speaker:

how the ransomware is written, it might just put it in the loop

Speaker:

that it will never escape from.

Speaker:

Yeah.

Speaker:

I mean, uh, the concept of honeypots is not new, but I like to sort

Speaker:

of modifying it to, you know, the world of, of, uh, ransomware.

Speaker:

I agree with everything you said about stopping it in the first place.

Speaker:

What about, um, detecting data exfiltration?

Speaker:

What, what do you think, um, companies can do there?

Speaker:

Yeah, so it's a definitely a trickier process.

Speaker:

Um, mainly from a tooling standpoint, at this point, you're probably

Speaker:

going to have to open up the wallet.

Speaker:

Um, but you know, there there's one, there's just a basic security controls

Speaker:

of content filtering and making sure that your end users don't have a path out to

Speaker:

the internet for mass file transfers.

Speaker:

So for most enterprises, you probably don't need more than HTTP

Speaker:

and HTTPS from your workstations.

Speaker:

Um, so you know, a lot of those transfers are trying to transfer out via FTP

Speaker:

or, you know, a more traditional file transfer method that shouldn't be allowed.

Speaker:

Um, but going further, you need to look at, you know, what sites are out there

Speaker:

for allowing mass transfers, you know, to, to keep it simple, to do all your users

Speaker:

need to be able to reach Dropbox, um, or box or Google drive or any of that stuff.

Speaker:

If the answer's no, prevent it because that's an exfiltration method.

Speaker:

Um,

Speaker:

Let me ask you about that.

Speaker:

I guess I had this, this apparently misconception that they would be sending

Speaker:

these exfiltrated files to something that they owned and controlled.

Speaker:

Right.

Speaker:

So, and that's, so I'm trying to build this out from, what's easier to, harder

Speaker:

to implement, um, going to that point.

Speaker:

Yes.

Speaker:

So when you get to the point of we're going to just

Speaker:

transfer to something we own.

Speaker:

And honestly, at that point you're probably hitting up AWS

Speaker:

or Azure or something like that.

Speaker:

And that's where it gets really messy.

Speaker:

Unfortunately, in the cloud world, we live in, you can't exactly block Azure.

Speaker:

Right.

Speaker:

Um, but that's where I started looking at DNS security.

Speaker:

Um, and one of my absolute favorite controls is just blocking newly

Speaker:

registered domains or domains that have been parked for years that

Speaker:

have all of a sudden gone live.

Speaker:

Um, cause a lot of the attack infrastructure, and this is honestly a

Speaker:

great way of also stopping the initial drop or download because there's a

Speaker:

good chance that that's going to go somewhere that was just newly stood up.

Speaker:

Um, but yeah, so that, that is another control where you might be able to

Speaker:

just stop them from being able to get to whatever destination there

Speaker:

they stood up to accept these files.

Speaker:

Another point is always just a basic security, um, control of proper ACL's.

Speaker:

Um, you know, when it gets to data exfiltration again, you know, keep

Speaker:

picking on poor Susie in accounting, but Susie and in accounting shouldn't

Speaker:

be able to get to your HR documents.

Speaker:

She shouldn't be able to get to your operations documents.

Speaker:

Yeah.

Speaker:

They might be able to export out your payroll, which that's terrible, but

Speaker:

you know, your payroll showing up on pay spend tomorrow is a bad day.

Speaker:

It's not an end of the company sort of day though.

Speaker:

Right?

Speaker:

Like that's not trade secrets going out.

Speaker:

Um, you know, so, so that's another control.

Speaker:

Another thing that I would absolutely call out though is still honey documents.

Speaker:

You know, having documents for them to interact and transfer out that as soon

Speaker:

as you see somebody interact with that, you're, you're figuring out what process

Speaker:

it was and figuring out where system that came from, just stopping that information.

Speaker:

Um, and then going into the, probably the more logical solution, but

Speaker:

definitely at a cost it's just the behavioral controls because in that

Speaker:

exfiltration attempt, there's going to be an end point that's all of a sudden

Speaker:

transferring a lot of data out to a new source that has never been seen before.

Speaker:

And if you really know what normal looks like in your network, that should

Speaker:

stick out like a big, big red flag.

Speaker:

Um, and it's a very hard thing to do with free solutions, but there

Speaker:

are plenty of security products out there that are all about mapping,

Speaker:

how your end points interact with each other on the network and what

Speaker:

looks like normal, what isn't normal.

Speaker:

Um, I think it's money well spent for those types of controls.

Speaker:

Can I ask a question about an earlier topic you brought up around EDR.

Speaker:

So if most, or if EDRs are useful for detecting when encryption is happening and

Speaker:

killing processes, et cetera, if that's the case, would a lot of these ransomware

Speaker:

attacks be prevented to start with.

Speaker:

Or, and is it that companies who've been hit with ransomware have not deployed

Speaker:

EDR solutions in their environments?

Speaker:

If EDRs can detect when encryption is happening on endpoint devices, if a

Speaker:

company has deployed EDRs, does that mean they'd be able to stop ransomware?

Speaker:

And so a lot of companies who got hit with ransomware.

Speaker:

Didn't have EDRs deployed.

Speaker:

Endpoint detection response is what we're talking about here.

Speaker:

So first information security is all about layered defenses, and

Speaker:

you never rely on a single defense.

Speaker:

Um, in my mind when your antivirus, your EDR, WM, whatever your endpoint security

Speaker:

tool is, if that's the thing that stops the malware, thank God it was there,

Speaker:

but that's still a, oh my goodness.

Speaker:

How many different things failed before it got to the point

Speaker:

where that had to step up?

Speaker:

Like, I never want to see anything out of that system.

Speaker:

Um, that's not false positives.

Speaker:

Cause that's the fun with EDR is they are a pile of false positive.

Speaker:

Um, you know, to your question, did they not have it maybe, um, you know, EDRs

Speaker:

are expensive, they are expensive tools.

Speaker:

They are great tools, but they're expensive.

Speaker:

And like so many other expensive security tools that are rarely

Speaker:

set it and forget it tools.

Speaker:

They are tools that require a lot of tuning and a lot of

Speaker:

the finding of what's right.

Speaker:

Excuse me, within your enterprise.

Speaker:

Um, but you certainly have a lot of companies out there that are still,

Speaker:

you know, with prop with old definition based antivirus, that's just scanning

Speaker:

files and doing your nightly full scans.

Speaker:

You know, like we did back in the nineties, um, and companies that have

Speaker:

been very happy to embrace Microsoft defender as their only antivirus.

Speaker:

And, you know, there there's some logic to it.

Speaker:

It's a great solution and it's free depending on what your

Speaker:

office 365 licensing looks like.

Speaker:

Um, but I think the number of customers out there that have these large EDR

Speaker:

solutions are few and far between.

Speaker:

Uh, definitely the companies I'm targeting with my security cadence

Speaker:

posts are the companies that probably don't have that kind of assessment.

Speaker:

Yeah.

Speaker:

Or even if they did sort of managing it on a daily basis, becomes

Speaker:

difficult, especially with everything else they have to do, because it's

Speaker:

not a one and done sort of a deal.

Speaker:

Right.

Speaker:

And you know, honestly, if you think about it as a, the evolution of antivirus,

Speaker:

antivirus was a one and done for the most part, you know, you deployed Symantec

Speaker:

back in the day, next next finish.

Speaker:

And you never touched it again.

Speaker:

Right.

Speaker:

EDRs aren't that.

Speaker:

EDR is, are constant tuning and definitions and breaking

Speaker:

things in your environment and having to tune them back out.

Speaker:

And I think that's also in the recall that I know of a number of

Speaker:

companies have thrown their EDRs out because, oh, it just broke everything.

Speaker:

That product was terrible.

Speaker:

It wasn't, you just needed the resources to handle it properly.

Speaker:

Yeah.

Speaker:

I want to sort of round out things here.

Speaker:

There's some things that we haven't talked about that were obvious ones that were.

Speaker:

You mentioned in your first post that, you know, you talked about, you know, you

Speaker:

password security, you talked about MFA.

Speaker:

Um, these are things that just everybody should be doing.

Speaker:

Uh, my, my personal opinion at this point, you know, th th you know,

Speaker:

if you're not doing MFA on anything that matters, uh, you know, you're

Speaker:

not doing your job and, uh, and you know, that's my opinion for what it's

Speaker:

worth, but MFA stops so many things.

Speaker:

Yeah, I If you were waiting for me to disagree.

Speaker:

I wasn't going to.

Speaker:

I have a question for you though.

Speaker:

So I dunno if we're going to talk about it now or later, but I've read

Speaker:

recently with a lot of the Lapsis attacks as well as other gangs, right.

Speaker:

There is a notion of SIM swapping attacks, right.

Speaker:

Which sort of hurt some of the MFA approaches taken.

Speaker:

So Prasanna, don't let perfect get in the way being good,

Speaker:

I I was gonna I was going to say that that goes right to that, right?

Speaker:

Yeah.

Speaker:

Just because it won't fix everything doesn't mean you shouldn't do it, right.

Speaker:

but no.

Speaker:

not, there is no silver bullet.

Speaker:

Right.

Speaker:

Um, and you know, a good backup person would never say don't do InfoSec and

Speaker:

a good InfoSec person would never say, do backup or not do backup.

Speaker:

Um, but I think that MFA is just so, and by the way, I, I finally

Speaker:

ate my own dog food maybe about two years ago where I just realized that

Speaker:

there were a lot of vendors that I personally interacted with, banks and

Speaker:

things, that offered MFA as an option.

Speaker:

And I finally said, look, I know it's going to make it harder for me to access

Speaker:

my bank account and my, you know, my PayPal and, you know, I, there, there's

Speaker:

only like, I dunno, there's only like 20 accounts that I felt had that level

Speaker:

of information that I needed MFA on.

Speaker:

Um, and then, and then, and then I became like this like MFA Nazi, where I was like,

Speaker:

I'm mad at them if they don't offer MFA.

Speaker:

I remember what happened when you traded in your phone and

Speaker:

you lost access to your MFA.

Speaker:

Yeah.

Speaker:

So I was using a Google authenticator, not realizing that when I traded in my

Speaker:

phone that I lost all of my MFA tokens.

Speaker:

And so I switched actually to authy, so that I can, I don't have that problem.

Speaker:

But, um, and now, and now I'm actually looking at a password manager.

Speaker:

I think it's one password that manages both your passwords and your MFA stuff.

Speaker:

That sounds nice.

Speaker:

So I'm already a big password manager, uh, fan, I just, um,

Speaker:

didn't, you know, I currently have to use two solutions, but Yeah.

Speaker:

Yeah.

Speaker:

And to your point, Prasanna, about, you know, SIM jacking you know, and not being

Speaker:

the silver bullet, the one thing I'd say is not all MFA's are created equal.

Speaker:

Any MFA is better than no MFA, um, but you know, it doesn't have to be a

Speaker:

roadblock in your organization, you know, Fido keys, Titan keys, things like that,

Speaker:

that are literally you get the prompt and you tap a, the thing hanging out of

Speaker:

your USB port or taps onto your phone is a really, really nice MFA solution.

Speaker:

That's really easy for your users.

Speaker:

And they require something that you have that's truly physical.

Speaker:

Um, and rather than, you know, replying to a text message, you know, there's,

Speaker:

uh, one of the big debates going on in the InfoSec world right now is the, the

Speaker:

push notifications of yes, that was me.

Speaker:

Um, and it's right out of, uh, the playbook of lapsis of just that they

Speaker:

actually had a picture on Twitter, um, yesterday of one of their chat things.

Speaker:

Yeah.

Speaker:

Just spam them a hundred times.

Speaker:

Eventually they'll get mad and hit yes.

Speaker:

Yeah, absolutely.

Speaker:

And it's funny, cause I actually had, um, our MFA at work today went a little

Speaker:

bit sideways and they started pinging me repeatedly for something I had just

Speaker:

tried to sign into it had in the back of my mind, like, Hmm, check the logs to

Speaker:

make sure like, this is kind of weird.

Speaker:

Um, but still it's, it's better than nothing and yeah.

Speaker:

Your end user may fail you and hit.

Speaker:

Yes, that was me.

Speaker:

Cause I got tired of getting this prompt a hundred times.

Speaker:

at three in the morning, but still, um, but as InfoSec practitioners,

Speaker:

that's where we need to step in and go don't we think it was abnormal that

Speaker:

they got a hundred prompts, like did that not set off an alarm right there?

Speaker:

Why is it if we're getting pinged over and over and over and over again?

Speaker:

Um, cause I guarantee you that created a log somewhere.

Speaker:

Yeah.

Speaker:

All right.

Speaker:

All right.

Speaker:

Well, the summary statement of your, of your blog series or your post series,

Speaker:

whatever you going to call this, and by the way, your posts are long.

Speaker:

I, uh, after you made the comment I went and while you were talking,

Speaker:

I copied and pasted the three posts into a, uh, Google docs.

Speaker:

Uh, one of them is 4,500 words long my friend.

Speaker:

I mean, that's long, even for me, I'm just saying

Speaker:

I got to tell you someone the other day commented about how

Speaker:

much they liked my writing style.

Speaker:

And it was the first time ever in my 42 years of life that

Speaker:

anyone has ever said such a thing

Speaker:

I actually liked your writing style.

Speaker:

I thought it was good

Speaker:

This is a reason, this is a reason you're here is you.

Speaker:

Well, it's a complicated issue.

Speaker:

So, you know, I, I jab, but you know, 4,500 words is not that much

Speaker:

for, for an issue of this magnitude.

Speaker:

Right.

Speaker:

But, uh, the first was 2,500.

Speaker:

The second one was 2000, but the last one was 4,500.

Speaker:

I was like, yeah, the boy could talk.

Speaker:

Um, I would just reiterate what I said of so many companies

Speaker:

focus on the recovery side.

Speaker:

Um, and that focus comes from focusing on what the actual objective was of

Speaker:

the ransomware group to begin with.

Speaker:

What was it?

Speaker:

They were trying to do, whether they were going to encrypt your stuff.

Speaker:

So you start there and it's the wrong place to start.

Speaker:

Start at the beginning, start with how they're going to

Speaker:

compromise your first endpoint.

Speaker:

And if you start looking at InfoSec from that perspective, what you'll end up

Speaker:

finding, and it's a really gratifying feeling is you would turn on the news one

Speaker:

day and there will be the latest, massive vulnerability or exploit being discussed.

Speaker:

And you'll look at it and go, oh, my controls account for that.

Speaker:

Not because I built controls around that particular exploit or vulnerability,

Speaker:

but because I just built my controls around, how do I walk an attacker through

Speaker:

initial foothold, moving laterally throughout my environment, and then acting

Speaker:

on their objectives and then how do I stop them at each one of those steps?

Speaker:

Um, so I guess the, the, the too long, didn't read it to use Reddit terminology.

Speaker:

Don't focus on ransomware, just focus on how attacks function and you'll get

Speaker:

ransomware taken care of by default.

Speaker:

Right in the, the only major one that we didn't discuss, which we really

Speaker:

should have is the whole patching thing.

Speaker:

Right.

Speaker:

I go back to, I'm pretty sure if my, if my memory serves correctly, Wannacry.

Speaker:

Was, you know, it was one of the.

Speaker:

first big ones that really went, you know, it went haywire and everywhere.

Speaker:

If I recall correctly, it was an exploit that had been patched

Speaker:

a year prior in a windows.

Speaker:

And if you had just been anywhere near up to date, then you'd have been fine.

Speaker:

Yeah.

Speaker:

And Microsoft is, they are both great in how they maintain with a

Speaker:

lion's grip to a, or with an iron grip to backwards compatibility.

Speaker:

And they are also just ridiculous.

Speaker:

in they're lions grip, iron grip on backwards compatibility,

Speaker:

but I mean, Wannacry.

Speaker:

The other side of Wannacry is exposure to the internet, um, which, and this kind

Speaker:

of goes back to the proxy shell thing.

Speaker:

You know, Wannacry has went gangbusters because of all the companies that

Speaker:

have Samba, SMB exposed to the internet, which again is you take

Speaker:

a step back and go good god, why?

Speaker:

But then you go jump on something like showdown and you look

Speaker:

like, oh yeah, there's tons.

Speaker:

There's tons of vCenters exposed to the internet and you go good god, why?

Speaker:

Um, and again, it just kind of comes down to, well, I had this one sysadmin who

Speaker:

was overworked and doing what they could, and we had this use case and he stood

Speaker:

it up, but he wasn't InfoSec focused.

Speaker:

He didn't know what he was doing.

Speaker:

And from that regards and didn't see the problem with it.

Speaker:

Um, so yeah, I mean, to your point of patching.

Speaker:

Absolutely.

Speaker:

Uh, but I guess my takeaway is focusing on the big things.

Speaker:

And don't worry about the latest zero day, quite as much.

Speaker:

Um, cause I tell you attackers rarely are focused on that.

Speaker:

Cause there's so much low-hanging fruit of the stuff that has

Speaker:

been patched since 2018.

Speaker:

Anyways.

Speaker:

Yeah.

Speaker:

you, you mentioned SMB.

Speaker:

My other big one is RDP RDP to the internet is just, I just want to slap you.

Speaker:

Well, listen, we could talk all day.

Speaker:

Uh, I just, I want to say thank you again, and, you know, for

Speaker:

coming on the podcast and talking to these really important things,

Speaker:

No, it was a pleasure to be here.

Speaker:

I really, I have to say when I got, when I got your message,

Speaker:

like, wait, is that Mr. Backup?

Speaker:

That is Mr. Backup!

Speaker:

I was really excited.

Speaker:

this is me.

Speaker:

I, well, and I'm honored that you, that you knew who I was, so, Hey,

Speaker:

you know, we're, we're members of the mutual admiration society, Prasanna?

Speaker:

Yeah, no, it's been great snorkel having you on and yeah, great

Speaker:

articles I'm will continue to read.

Speaker:

I hope you keep doing your weekly posts on security cadence, because I'm sure a lot

Speaker:

of people learn a lot of things from that.

Speaker:

So

Speaker:

I'll try to make a cliff notes version.

Speaker:

yeah, I keep it long.

Speaker:

I

Speaker:

Yeah.

Speaker:

Good, good luck with that.

Speaker:

Uh, yeah, he's easy to find on Reddit is snorkel 42, make sure to check them.

Speaker:

out and make sure to subscribe.

Speaker:

The Backup Wrap Up is written, recorded, and produced by me, W. Curtis Preston.

Speaker:

If you need backup or DR consulting, content generation, or expert witness

Speaker:

work, check out backupcentral.com.

Speaker:

You can also find links for my O'Reilly books on the same website.

Speaker:

Remember, this is an independent podcast, and any opinions that

Speaker:

you hear are those of the speaker and not necessarily an employer.

Speaker:

Thanks for listening