Building a Cybersecurity Culture in Your Company (Encore)
Building a cybersecurity culture in your company doesn't take a bigger budget — it takes a weekly habit. In this final episode of our encore series, returning guest snorkel42, a longtime Reddit voice in InfoSec, breaks down how he turned a company with zero dedicated security staff into one with a real security culture, just by committing to one small improvement every week instead of waiting on the next six-figure product.
We picked this one to bring back because of how it performed with you — not just downloads, but how much of the episode people actually stuck around for. That combination told us this conversation landed, and a lot of you came back to it more than once.
snorkel42 walks through where the term "security cadence" came from: a network engineering team, no InfoSec department, and a room full of unused tools nobody had the bandwidth to run. Instead of asking for more products, the team set a rule — one security change a week, no new vendor purchases allowed — for six months straight. What happened next is the real story: leadership noticed, and the team went from begging for resources to being handed them.
From there we get into what it actually took to build that cybersecurity culture day to day — the early challenges, how the team picked what to tackle first, and how a scrappy internal habit turned into something leadership actively championed. We also cover MFA, including why not all MFA is created equal, the SIM jacking risk that undercuts SMS-based codes, and the push-notification fatigue tactics attackers use to wear users down until they hit "yes" out of exhaustion. snorkel42 closes with a piece of advice worth sitting with: stop chasing the latest zero-day and start building your cybersecurity culture around how attacks actually function, start to finish. Do that, and ransomware protection comes along for free.
If you're the person in your company quietly carrying the security load, or you're trying to convince leadership that culture matters more than another line-item purchase, this one's for you.
00:00:00 — Cold open: you already own the tools you need
00:01:36 — Show intro and disclaimers
00:04:05 — Guest introduction: snorkel42's Reddit history and security cadence series
00:05:53 — Where the term "security cadence" came from
00:08:40 — Early challenges building the habit
00:44:57 — MFA, password security, and why not all MFA is equal
00:47:46 — SIM jacking and push-notification fatigue attacks
00:51:45 — Patching, WannaCry, and why chasing zero-days misses the point
You probably already own the cybersecurity tools that you need.
Speaker:That's not the issue.
Speaker:The issue is that nobody's using them, or certainly not using them correctly.
Speaker:Today's guest built an entire cybersecurity culture out of that
Speaker:one realization, one week at a time.
Speaker:This is the final episode in our Encore series, where we picked the
Speaker:episodes over the last few years that our listeners really engaged with.
Speaker:We found this guest schooling people on Reddit with a series of posts, uh,
Speaker:on what he called a security cadence.
Speaker:His pitch was to skip the new six-figure product and instead commit
Speaker:to one small, deliberate security change, uh, and improvement per week.
Speaker:We get into how that habit turned into a real culture shift at his company.
Speaker:Plus, of course, we talk about things like MFA, SIM hijacking,
Speaker:and why he thinks that chasing the latest zero day misses the point.
Speaker:He goes by his Reddit username of Snorkel42, and he clearly knows his stuff.
Speaker:If this is your first time watching or listening to me, hi, I'm W.
Speaker:Curtis Preston, AKA Mr. Backup.
Speaker:I've been obsessing about backup, recovery, and now cyber
Speaker:recovery for over 30 years.
Speaker:If that's your bag, then I'm your guy.
Speaker:You're not gonna find anyone that cares about that topic more than me.
Speaker:Ever since 1993 when I had to tell my boss that there were no backups of
Speaker:the database that we had just lost.
Speaker:Now I've written five O'Reilly books, a blog, and a podcast.
Speaker:Here we turn unappreciated admins into cyber recovery heroes.
Speaker:This is the Backup Wrap Up
Speaker:Hi, and welcome to Backup Central's podcast.
Speaker:I'm your host, W. Curtis Preston, AKA Mr. Backup.
Speaker:I have with me, my ghee deployment consultant, Prasanna Malaiyandi.
Speaker:uh, Curtis, how's your ghee going?
Speaker:You know, you may recall it a month or so ago.
Speaker:I got ghee for the first time.
Speaker:And, you know, for those that don't know what ghee is, it's
Speaker:clarified butter specifically.
Speaker:It's apparently an Indian thing, right?
Speaker:we did learn that ghee is from Sanskrit.
Speaker:That means sprinkled, which is interesting.
Speaker:But the, um, and the thing about it is that it can sit on the counter.
Speaker:Um, like it's shelf stable so it can sit on the counter and
Speaker:you made a comment by the way.
Speaker:I know this because I'm literally editing this episode right now.
Speaker:And you made a comment that, you know, it can sit there probably for a
Speaker:couple of months or until you run out.
Speaker:So I'll just say this, the, uh, the jar, I thought that I was going to
Speaker:be the only weirdo using the ghee.
Speaker:Yeah, I am not the only weirdo using ghee.
Speaker:In fact, if anything, the rest of the house is used the
Speaker:ghee much more than I have.
Speaker:And that jar that we bought is close to gone.
Speaker:So
Speaker:it's convenient.
Speaker:It's super easy.
Speaker:You just keep it out.
Speaker:You warm it up a little.
Speaker:It becomes really liquidy.
Speaker:You put it on warm bread.
Speaker:You toast that.
Speaker:super good.
Speaker:You can also put it in rice.
Speaker:Warm rice.
Speaker:It's really good.
Speaker:Yeah, well, I mean, it's like it's butter, right?
Speaker:you know, all the places you can put butter, you can put ghee.
Speaker:Um, it's just, it, it, it is interesting for those that have never had it.
Speaker:It has a slightly different flavor than butter, but it, you know, so there
Speaker:is a, there is a, I didn't know what my mouth was going, what was going
Speaker:to happen when I put it in there,
Speaker:That's funny because I never think about that.
Speaker:Like to me, like butter and ghee it's like, ah, yeah.
Speaker:Yeah.
Speaker:The first time I had, I had ghee, I remember going, huh,
Speaker:this tastes different, you know?
Speaker:Um, but what it was, but it was, but it was yummy, you know, so we continue to,
Speaker:but yeah, I think that jar is almost gone.
Speaker:So we're going to have to, we're going to have to find the ghee at Costco, which is
Speaker:like 64 ounce.
Speaker:like one pound.
Speaker:Yeah, one pound jars or something.
Speaker:Well we have a, a back by popular demand guest here.
Speaker:Uh, he was on the podcast before and.
Speaker:Is the author of the security cadence series on Reddit, been in IT for about
Speaker:25 years and in InfoSec about 20 years.
Speaker:And he is quite the celebrity over there on Reddit because I, you know,
Speaker:his posts have been incredibly popular with, uh, uh, he's got a, uh, a, uh,
Speaker:what a, what do they call it over there?
Speaker:The karma of 35,000, which, you know, if you don't know anything
Speaker:about Reddit, that's a, BFD, I'll just say that right now.
Speaker:And we had him previously on the podcast so if you haven't heard that podcast,
Speaker:you should totally listen to that.
Speaker:Welcome back to the podcast.
Speaker:snorkel42.
Speaker:Good to be back.
Speaker:And I tell you, so last time I learned what karma meant on reddit.
Speaker:time I learned what ghee is so good for me.
Speaker:So, um,
Speaker:I want to hear about this thing.
Speaker:You mentioned about security cadence.
Speaker:What, what started, because that was, that was the, um, that was
Speaker:the, what, what do you call that?
Speaker:Uh, the thing before the thing, the, the precursor, the preamble,
Speaker:the, in the title, um, uh, to the post that we saw that.
Speaker:So where did that term come from?
Speaker:So the term came from a previous employer.
Speaker:I worked at where I was a network engineer, um, and it was a large company
Speaker:that did not have an InfoSec presence.
Speaker:There was no InfoSec team.
Speaker:It was just kind of considered, Hey, all engineers are responsible for security.
Speaker:Um, and you know, we would, we'd have our occasional shots off the bow in terms of
Speaker:security, you know, problems or issues.
Speaker:You know, I, I hesitate to say breaches, but, you know, incidents and when
Speaker:they would occur and we would all pile into a conference room and we would
Speaker:talk about what happened and what we should have done to prevent it.
Speaker:And it would always come down to, well, if we just bought six figure dollar
Speaker:product X, this would not have occurred.
Speaker:Meanwhile, in the data center, there were piles of six-figure products
Speaker:that were completely ignored because those products never run themselves.
Speaker:And if you're complaining of not having resources to run those products, what
Speaker:makes you think you're going to have resources to buy and run new products?
Speaker:So I finally got fed up one day and just challenged the team to, you know what?
Speaker:We've got plenty of tooling.
Speaker:That's not the issue.
Speaker:We just don't have the oomph.
Speaker:We don't have the motivation to actually use it.
Speaker:So why don't we set ourselves a goal for six months, we're going to
Speaker:implement a security change every week.
Speaker:It could be a big change, could be a really minor change, but
Speaker:there's going to be something.
Speaker:Move the ball forward.
Speaker:And also during that six months, we are going to just put the
Speaker:kibosh on talking to any vendors.
Speaker:So no products are allowed, no solutions are allowed that we don't already own.
Speaker:Um, and you know, it took some, took some talking and wrangling
Speaker:people, but eventually folks fell in line and we sat down.
Speaker:We'd wrote out a list of, you know, here's some things just off the top of our head
Speaker:that we know we could implement with, you know, very little roadblocks, no impact.
Speaker:And we just started and we called it our security cadence.
Speaker:Once a week, we have a security cadence of releasing a security update and
Speaker:it, you know, it ended around six months in our CIO came to us and said,
Speaker:listen to what you guys are doing is fantastic, but please don't restrict
Speaker:yourself to only free solutions.
Speaker:Like we have money.
Speaker:If there's stuff you need to keep this ball moving, please ask.
Speaker:Um, so, you know, it kind of turned the whole thing on its head of,
Speaker:you know, securing the company.
Speaker:But also we were no longer begging for resources.
Speaker:The, you know, the executive leadership was asking us, was begging us to start
Speaker:spending resources because they saw what we were doing and saw the value.
Speaker:So, could you talk a little bit, I'm sure at the very beginning
Speaker:as you're starting this right.
Speaker:With any new process or new, any new endeavor, it's a little difficult, right.
Speaker:Sort of getting into what does it mean?
Speaker:And trying to figure things out.
Speaker:So what were some of the challenges you guys went through and how did you address.
Speaker:Yeah.
Speaker:So I would say the biggest challenge with any sort of security changes,
Speaker:especially in a large company is just the unknown of what will this break.
Speaker:Um, because quite often, especially in those early days, what you're changing
Speaker:are out of the box configurations.
Speaker:So there's this kind of mentality of, well, it's probably an out of the box
Speaker:configuration for some reason, or, you know, we don't know what legacy, I
Speaker:mean, this company that I was working at at the time was started in the 1930s.
Speaker:Now we don't know what kind of legacy applications are
Speaker:relying on this technology.
Speaker:Um, so I would say the first, the biggest thing was to just start
Speaker:easy, take the really easy ones to get as much buy-in as you can, you
Speaker:know, sit down to the engineers.
Speaker:Can anyone think of anything that would break by doing this?
Speaker:And you will get some feedback.
Speaker:Yeah.
Speaker:But who cares?
Speaker:It's not going to fix anything.
Speaker:Okay.
Speaker:That's fine.
Speaker:Let's just do it anyways.
Speaker:Um, and then start, you know, slowly ramping it up and
Speaker:taking little bite-size chunks.
Speaker:And if you look at the security CA cadence, Reddit posts, that's exactly
Speaker:how I've been approaching them.
Speaker:You know, I've started off with just really easy things to do and things
Speaker:I would not expect, um, to break many enterprises, you know, I tried to
Speaker:make it very clear in those posts of, you know, everyone's environment is
Speaker:different and be careful, but you know, I've called out certain items of this.
Speaker:Isn't going to break anything, just do it, you know, please just, just do it.
Speaker:I do remember in your, the trio of posts that you did that were around
Speaker:ransomware, you, you had a, there was a phrase that came up a lot.
Speaker:It's escaping me at the moment, but it was like, turn this on
Speaker:and then customize as necessary.
Speaker:Right.
Speaker:That, that, that, you know, that you can't, that no one solution does, uh, you,
Speaker:you can make a general rule for example, and then you're going to find somebody
Speaker:that needs, that thing turned on the thing you just turned off, you're going
Speaker:to find somebody that needs, that turned on and then you can turn it on for them.
Speaker:Right.
Speaker:Um, and, and that's okay.
Speaker:Yeah.
Speaker:So one of the catchphrases are one of my guiding lights in InfoSec is to never
Speaker:let perfect get in the way of being good.
Speaker:I call it out a lot.
Speaker:And part of the reason why I lean on it so heavily is it's often a. Uh, voice of
Speaker:dissension that you get from folks when you're trying to talk them into things
Speaker:like, oh, well that won't solve this one edge case, so let's not do it at all.
Speaker:Um, and you know, when it comes to security, security, it's all about
Speaker:layers and it's all about catching the attacker and yeah, there, this may
Speaker:not solve all of your problems, but it might be the alert that gets generated
Speaker:that tells you that they're there.
Speaker:Um, you know, and so it is definitely a strong, um, demand I make a people of,
Speaker:you know, if you can only do this for one system, great, it's better than none.
Speaker:Um, and yeah, so there there's something to be said about going
Speaker:slow and implementing slowly, but there's also something that I said
Speaker:about implementing broad and then backing off where you need to.
Speaker:Hmm.
Speaker:Yeah.
Speaker:Yeah, exactly.
Speaker:I would say that.
Speaker:When you, when you try the latter, when it, when I was thinking about your,
Speaker:your initial, this, the six months program that you had, the farther
Speaker:you got into that six months, and the more complicated things that you were
Speaker:doing that were potentially riskier, if you will, to the environment that
Speaker:you could potentially impact someone's ability to do their job, the more
Speaker:you're going to need support from above.
Speaker:Right?
Speaker:Like, I, I, I told, you know, I told them to do this.
Speaker:We're sorry that it broke, you know, we'll
Speaker:Yeah.
Speaker:we turned it off for now.
Speaker:We didn't realize that by pushing this one button was going to make everyone in
Speaker:the company not be able to log in ever.
Speaker:Uh, we've turned it off until we figured that out.
Speaker:Right.
Speaker:Don't don't go, don't go beat, snorkel out.
Speaker:And maybe that's also where you get some of those early
Speaker:wins before you take on those.
Speaker:So you get sort of the buy-in from upper management that, Hey,
Speaker:they are doing the right things.
Speaker:They are making improvements.
Speaker:Yeah, absolutely.
Speaker:Yeah,
Speaker:One of the, the biggest allies of InfoSec people that they forget about is the CFO.
Speaker:The CFO is the person when you're doing these sorts of things that you
Speaker:want to have in your back pocket to be able to go have that conversation of,
Speaker:Hey, where is our money actually made?
Speaker:Because I want to know, Hey, what, what divisions of this company aren't really
Speaker:contributing that much to the bottom line.
Speaker:Cause those just became my test case the things that I'm really
Speaker:not sure about.
Speaker:Let's take them down because that's not going to, you know, that's not going
Speaker:to ruin our end of quarter numbers.
Speaker:So they're going to start this off as a retailer.
Speaker:So that was obvious.
Speaker:Don't take down the stores under no circumstances do you take down the stores.
Speaker:Right.
Speaker:Right.
Speaker:but legal?
Speaker:Go for for it,
Speaker:Yep.
Speaker:I don't know how legal would feel about that.
Speaker:But yeah, no, I understand what you're saying basically.
Speaker:So w every change that you made, you don't have to roll it out.
Speaker:Company-wide you, you put it into places where you felt that it would do, you know,
Speaker:hopefully the change would have a minimal impact, but if it did have an impact,
Speaker:it would have a minimal impact to the company, because it only made legal, not
Speaker:be able to do something for a day or two,
Speaker:Absolutely.
Speaker:which is a very different thing than no one can log into the
Speaker:cash registers for a day or two.
Speaker:Absolutely.
Speaker:In retail, taking down the chain is the worst thing you could possibly do.
Speaker:Yeah, exactly.
Speaker:So for the record, I actually started in retail.
Speaker:I, I worked a hundred years ago.
Speaker:I was a shoe salesman at a, a chain called Kenny shoes, which no one.
Speaker:Under 25 even know exists, but you know, it used to, it was the parent
Speaker:company that created Footlocker.
Speaker:So Footlocker is still around, but Kenny shoes was its own store.
Speaker:And I worked in, uh, retail.
Speaker:So I know I also worked at some, some what we now call big box stores.
Speaker:So I know what it's like to be at the receiving end of that.
Speaker:And when, uh, when corporate, when corporation changes things
Speaker:and then poof, you know, you, you suddenly can't do your job.
Speaker:That's unacceptable.
Speaker:So you went through this exercise, you had this process of, um,
Speaker:going for six months, doing a security update or roll out a week.
Speaker:And then you started writing about this small things that people can do
Speaker:to improve their security posture.
Speaker:And where did you go from there?
Speaker:Like, did you think you would keep writing this long because
Speaker:how long have you been posting on Reddit for your security cadence?
Speaker:So I, I only started it in January.
Speaker:I did it as a new year's resolution.
Speaker:Um, and it, the idea came to me.
Speaker:I was on a, on a different podcast.
Speaker:Um, and we were talking about InfoSec and we were talking about a term that I
Speaker:believe Wendy Nader from duo security, uh, coined, which is InfoSec poverty.
Speaker:Um, and it's basically in reference to companies that just don't have the
Speaker:resources to have dedicated InfoSec people or InfoSec tooling, and how,
Speaker:you know, it's not really fair to expect these companies that just
Speaker:don't have those resources to really be able to stand up against you know,
Speaker:the modern era of security threats.
Speaker:Um, so on this podcast we were discussing, you know, what do, what can we as InfoSec
Speaker:professionals do to help those companies?
Speaker:Um, and it's been kind of living rent free in the back of my brain
Speaker:since I was on that podcast.
Speaker:Um, so as I was approaching the new year, I was like, you know what, I'm just going
Speaker:to hop on Reddit, starting in January and make that weekly post and see if
Speaker:I cant' help um, you know, some of the folks in the sysadmin sub Reddit, which,
Speaker:you know, the sysadmin subreddit, they have the, um, the flares for everyone.
Speaker:And there's a lot of them that list themselves as Jack of all trades.
Speaker:And those are those sysadmins that are working in smaller companies.
Speaker:And they're, you know, if it plugs into the wall, that's their job.
Speaker:Um, and you know, those companies are exactly what InfoSec
Speaker:poverty is calling out of.
Speaker:You know, you have these brilliant sysadmins who are heavily
Speaker:overburdened, and they just don't have the time to focus on this.
Speaker:Um, and they just kind of need someone to say, Hey, you know, this week, why don't
Speaker:you disable this one thing that comes out of the box in windows and you do not need,
Speaker:and it creates a massive security risk.
Speaker:Um, yeah, so I started in January and I have a nice long list,
Speaker:uh, in one note of post to make.
Speaker:And you know, every every week around Wednesday night, I just pull one
Speaker:up and I write a quick blog post.
Speaker:Yeah.
Speaker:Cause you can't, you can't schedule Reddit posts, Right.
Speaker:I don't
Speaker:Right.
Speaker:You can, uh, you can put them in drafts.
Speaker:So I write them
Speaker:Wednesday night and Monday morning I remove it from draft,
Speaker:got it.
Speaker:Yeah.
Speaker:that was Paul's InfoSec weekly, I believe.
Speaker:Was it the podcast where you were, right, right.
Speaker:Yeah, Shout out to them.
Speaker:Um, so, uh, so you said you started in January, So, you're what, uh,
Speaker:like eight or nine posts in on that.
Speaker:And did this, this, uh, this, what do you call it?
Speaker:Um, or maybe like 10.
Speaker:I don't know.
Speaker:I can't do math.
Speaker:Anyway.
Speaker:This is, um, the ransomware posts were, where did that fall into that?
Speaker:You know, the
Speaker:yeah, it's a fun question because literally, since I started this since
Speaker:post one, I've had people messaging me on Reddit saying, Hey, could
Speaker:you do something about ransomware?
Speaker:Um, cause it's you know, it's a top of mind topic, especially for the
Speaker:smaller orgs, that's the big boogeyman.
Speaker:Um, and I've been honestly kind of Mr. Miyagi'ing it in terms
Speaker:of, well, everything I'm posting really has to do with ransomware.
Speaker:You just don't realize it.
Speaker:Um, but when.
Speaker:reference by the way not sure if everybody listening will understand that
Speaker:reference, But, very nice reference.
Speaker:But, yeah, so my expectation was I haven't, you know, a list of posts that
Speaker:eventually I was going to say, Hey, you know, if you've been messaging me
Speaker:about ransomware, go read these posts.
Speaker:This is what I was driving at.
Speaker:Um, but then, uh, when Russia invaded Ukraine and the Conti ransomware
Speaker:groups, uh, came out and said that anyone that takes up arms or,
Speaker:you know, it goes against Russia.
Speaker:We're going to come after I got flooded with people saying, no, really, please.
Speaker:We need something.
Speaker:So hence the title, the, okay, fine.
Speaker:Let's talk about
Speaker:Yeah,
Speaker:Um, so I decided, yeah, it was time to just at least take
Speaker:a truncated approach to it.
Speaker:How did you approach because ransomware is such a huge topic, right?
Speaker:I know Curtis, you and I, we talked about it, but just sort of your
Speaker:thought process behind like the series that you wrote and how do you
Speaker:get such a dense topic out there?
Speaker:Because there are so many different ways that ransomware can attack you
Speaker:and so many different, uh, crews out there with different methods.
Speaker:So how do you sort of generalize it, especially, like you said,
Speaker:for those people who don't have the time to research and follow up
Speaker:everything related to InfoSec, right?
Speaker:So I giggle when you say dense.
Speaker:Cause one of the other pieces of feedback I get quite frequently
Speaker:is that my posts are too long.
Speaker:Um, but yeah, so my take on ransomware is that companies tend
Speaker:to focus on the exact wrong spot.
Speaker:Um, and I apologize for coming on to a backup, um, related podcast
Speaker:and say that most companies focus on backup and that's, that's
Speaker:No, no.
Speaker:effort.
Speaker:That's the, that's the thing that
Speaker:hopefully saves the company when everything else has
Speaker:just gone poorly for you.
Speaker:And don't Don't worry, snorkel.
Speaker:We have the same opinion as well, or at least I do, right.
Speaker:That
Speaker:it's just a last resort, but you should really be protecting yourself upfront.
Speaker:Um, and so the thing that comes, that happens every time, there's a major
Speaker:ransomware breach, um, is, you know, it hits the media and everyone starts talking
Speaker:about the indicators of compromise.
Speaker:It loves talking about indicators of compromise because it's easy to deal
Speaker:with, you know, how did they get in?
Speaker:I was an email.
Speaker:Well, where did the email come from?
Speaker:What was the subject?
Speaker:Did it link to something, where did the link go to?
Speaker:What did it download?
Speaker:What was the hash of that downloaded and on and on and on and on.
Speaker:And because it's easy then to go into your controls and, oh, we're going to put in
Speaker:our spam filters to block that address.
Speaker:We're going to block that domain.
Speaker:We're going to put in our, uh, endpoint security tools to block that
Speaker:hash, but it's all pointless, right?
Speaker:Because that breach is done.
Speaker:That entire infrastructure has been burned.
Speaker:There was nothing left of it.
Speaker:So, you know, you're, you're reacting to something that's no longer exist.
Speaker:But when no one ever asks is, wait a minute, how did you know Susie
Speaker:in accounting downloading this attachment lead to their entire VMware
Speaker:infrastructure getting encrypted.
Speaker:And that's, that's the real takeaway from every single ransomware breach of, you
Speaker:know, it's one thing to come in and, you know, the accounting system, one person
Speaker:in the accounting system is encrypted.
Speaker:It's another thing entirely to come in.
Speaker:And yeah, the entire network has gone now and we don't have any data.
Speaker:Um, and that's really where the security cadence posts come in.
Speaker:And w what I try to focus on, especially in the first post of this
Speaker:is what I would be doing right now.
Speaker:If you are waking up to a world where Russia has invaded Ukraine, and you're
Speaker:all of a sudden, greatly concerned that ransomware group's going to
Speaker:come after you, these are the things to start off with, and it isn't
Speaker:necessarily preventing ransomware.
Speaker:It's preventing ransomware from being able to do anything significant.
Speaker:Um, and the nice thing about those controls is it translates
Speaker:to way more than just ransomware.
Speaker:Which is another issue that I think smaller companies particularly have
Speaker:when they're dealing with InfoSec, as they put their blinders on and
Speaker:very specific attack types, like how do we protect against ransomware?
Speaker:Oh, we get good backups.
Speaker:Well, how about, how do we protect against any sort of extortion attempt?
Speaker:You know, we, we had the lupus group or excuse me, Lapsis
Speaker:Yeah, I think it was locked system.
Speaker:Yep.
Speaker:I had been talking about all week and I just blanked on there anyways, you
Speaker:know, going after Nvidia and Okta and Microsoft and LG, really their playbook
Speaker:is the exact same as a ransomware group.
Speaker:You know, ransomware only exists, not because they care
Speaker:about encrypting your data.
Speaker:They've went to extort you for money.
Speaker:Ransomware shifted, shifted recently to exfiltrating data because people had
Speaker:good backups or had restoration methods.
Speaker:We'll find let's steal the data.
Speaker:Cause we never really cared about encrypting the data.
Speaker:We just needed that incentive to get you to pay.
Speaker:Um, so when you take a step back and look at how attacks function
Speaker:from the ground up and started going at the common denominators.
Speaker:You, you really don't care about what the actual end objective is any longer
Speaker:because the controls are there to make sure that they never made it past sending
Speaker:that initial email, um, or, you know, tacking this particular vulnerability you
Speaker:had exposed to the perimeter for a week.
Speaker:Because those vulnerabilities will constantly be evolving.
Speaker:Right.
Speaker:And so you kind of need a generic.
Speaker:Protection scheme, if you will, rather than something tailored for a particular
Speaker:ransom group, but that comes after you.
Speaker:Yeah, the rent
Speaker:A ransomware attack is it's the conclusion of, you know, what, like you
Speaker:got infected, but the ranch, I don't know if I'm saying, I'm not saying this
Speaker:right, but It's I want to say it's the symptom, but it is actually the infection.
Speaker:Right.
Speaker:But that
Speaker:not the cause.
Speaker:The problem is what allowed them to get there in the first place.
Speaker:You're absolutely right.
Speaker:And it's, it's interesting that it is a multi-tiered product at this point.
Speaker:There are, there are groups out there that sell you the initial breach.
Speaker:Um, so if you and Conti is one of the groups that are suspected of doing this,
Speaker:that they don't do the initial breach, they buy the breach, they buy someone
Speaker:who already has the foothold and then use that foothold to do the actual encryption.
Speaker:Hmm.
Speaker:And so you have this entire life cycle of, you know, third-party vendors
Speaker:that lead up to the final breach.
Speaker:Right.
Speaker:Um, you know, you know, Conti may be purchasing someone else's exploit kits,
Speaker:um, someone else's encryption kits.
Speaker:So you're exactly right.
Speaker:That there's the initial breach.
Speaker:That's really your first opportunity.
Speaker:And when you get to the point where things are encrypting, so many other
Speaker:things have been missed by that.
Speaker:That at least if you get to that point, you know, you have
Speaker:a lot of great opportunities to prevent it from happening again.
Speaker:Cause you should have learned so much up to that point of, oh my gosh, they
Speaker:got the phishing email through my end user is able to download this thing.
Speaker:They were able to click this link to this weird domain that was stood up yesterday.
Speaker:Um, they're able to execute a program after they downloaded it off the internet.
Speaker:I mean all these different controls that had to go poorly just to
Speaker:get to that point of encryption.
Speaker:Uh, speaking of phishing, I did see something like this is just a couple
Speaker:of days ago and they were, and, and again, I, I don't remember exactly
Speaker:where I saw it, but it was like, it was saying that phishing had surpassed,
Speaker:uh,, that it now become the number one method of attacking companies versus
Speaker:I guess, uh, a standard exploit, I guess, would be number two, right?
Speaker:A standard sort of direct hacking attempt the phishing had become the number one.
Speaker:I don't know if you,
Speaker:No,
Speaker:sounds like you saw that as the number one.
Speaker:Yeah.
Speaker:Actually someone that, one of the things I really liked with the
Speaker:security cadence post is when people get in and correct me, or, you know,
Speaker:point out other things, because I'm certainly not an expert in all things.
Speaker:Uh, but in the first ransomware post, I made a person who works
Speaker:for a cyber insurance policy holder actually called me out and said, yo,
Speaker:phishing is the number one for sure.
Speaker:But right close on its heels is the proxy shell exchange vulnerability, uh, which
Speaker:is a vulnerability from last year and, you know, impacting on-prem Exchange,
Speaker:uh, deployments and, you know, still plenty of unpatched boxes out there.
Speaker:But yeah, you know, you get these massive blips, right.
Speaker:You know, a log4j S sort of thing.
Speaker:That is a crazy large vulnerability.
Speaker:That attackers jump on quickly.
Speaker:But the internal one is always fishing.
Speaker:There's always social engineering is the quickest path to get past your perimeter.
Speaker:Yeah.
Speaker:And especially with some of these large spikes, you also
Speaker:have the long tails, right.
Speaker:In terms of how long it takes to get every single system out there patched.
Speaker:And you'll always have systems out there which don't go patched for so long and
Speaker:still continues to be an attack vector.
Speaker:Right?
Speaker:Right.
Speaker:And it's that InfoSec debt that, that again, of, you know, a company that
Speaker:hired someone else that comes stand up their IT infrastructure one time
Speaker:and it's been neglected ever since.
Speaker:And there's no one patching those systems that are running
Speaker:their exchange 2003 deployments.
Speaker:I mean, they're out there.
Speaker:the way.
Speaker:Here's what I want to say.
Speaker:Who the hell is still running on prem Exchange.
Speaker:That's all I want to say about that.
Speaker:And why aren't you using 365?
Speaker:That's all I'm saying Microsoft.
Speaker:You're welcome.
Speaker:I'm just saying I don't, it's just, it's just
Speaker:Wait, wait, you forgot to add one thing to that, Curtis,
Speaker:what's that?
Speaker:What's that.
Speaker:if you are using Microsoft 365, make sure to back it up.
Speaker:Yeah, absolutely.
Speaker:Yes.
Speaker:Thank you.
Speaker:Because Microsoft isn't doing it for you.
Speaker:Yeah.
Speaker:Yeah.
Speaker:It's a standard thing.
Speaker:We have to mention here on, on the podcast,
Speaker:So a dropper is typically the initial thing that gets downloaded.
Speaker:So if you look through a normal, any sort of malware campaign, we'll keep
Speaker:it as ransomware that, you know, I sent an email, uh, as a, as an
Speaker:attacker, that's a phishing email.
Speaker:And then the whole point is to try to trick someone into clicking a
Speaker:link and downloading the program.
Speaker:Um, or maybe it's attached, uh, maybe it's a word document or
Speaker:something like that it's attached, but it's something small and.
Speaker:Typically, you're going to see it as a document macro.
Speaker:Um, and the whole point of it is that's the simple, easy thing that's going
Speaker:to slip through, you know, your, your various defenses, because it's just
Speaker:a word document, but you enable the macro in the macros, what reaches out
Speaker:and downloads the current malware.
Speaker:And there there's a few reasons for that.
Speaker:A big one is that malware could potentially being, be being generated
Speaker:on the fly, meaning that the definition that's behind that, the hash for it, or,
Speaker:you know, the, the detection mechanisms that more traditional antivirus is
Speaker:looking at won't have those definitions.
Speaker:Cause it was generated at the moment of downloads.
Speaker:Um, you know, we've just minor changes, but just to throw off that hash, um,
Speaker:but then that's the thing that actually gets downloaded and executed and, um,
Speaker:you know, causes you all your problems.
Speaker:And, you know, from there it could be any number of things.
Speaker:So as we were saying that there are people who would just tell
Speaker:you that footprint, right.
Speaker:Or that foothold.
Speaker:Right.
Speaker:That dropper could download just seed, too.
Speaker:Just something that's calling back saying.
Speaker:Yep.
Speaker:I got something running on this computer and that's it.
Speaker:Hmm.
Speaker:All it could literally.
Speaker:Oh, okay.
Speaker:So he could just literally sit there and wait for the second group.
Speaker:That's going to purchase that.
Speaker:And then they download the malware that they want to download.
Speaker:Right.
Speaker:So.
Speaker:That's what you were referring to earlier.
Speaker:And so it looked like the, and again, this is common sense to you,
Speaker:but not necessarily to everybody, it looked like, you know, your
Speaker:best advice was to, to stop.
Speaker:Ransomware is to just think about how ransomware works when it gets
Speaker:in, when that dropper gets in.
Speaker:You're not going to, I mean, yes, you should do user training and
Speaker:yes, you should do, you know, you should do all those things.
Speaker:And, but you should just assume that at least one of
Speaker:them is going to get it wrong.
Speaker:I mean, I remember back when I was, uh, you know, 25 years ago when I
Speaker:was at a bank, we did regular InfoSec training with every new employee.
Speaker:And one of the things we constantly said, well, Uh, no one in it
Speaker:will ever call and ask you for your password ever, ever, ever.
Speaker:And then we would, and then immediately after the training, we would call them
Speaker:and ask them for their password and still a percentage of them would give it to us.
Speaker:Right.
Speaker:Um, So.
Speaker:you, you do the training, but then you just sort of assume that that's going to,
Speaker:um, you know, um, that th that somebody is going to click on the wrong link.
Speaker:And so then you just think about stopping that malware at that point,
Speaker:you know, stopping them from accessing a command and control server, looking
Speaker:for, you know, this, this weird, you know, domains that stood up yesterday,
Speaker:domains that were stood up a long time ago, but just suddenly when active,
Speaker:um, you know, the limiting lateral movement inside the company, all of
Speaker:these things, uh, what, what did I miss.
Speaker:A big thing that a lot of ransomware particularly will do.
Speaker:First thing is start deleting, shadow copies as a quick restoration point.
Speaker:So that is a pretty dead giveaway of, you know, you get the event ID
Speaker:that shadow copy was just deleted.
Speaker:That's
Speaker:And you're referring to VSS there, right?
Speaker:The windows shadow copy.
Speaker:Yeah.
Speaker:So I had a question for you snorkel about that one.
Speaker:Is, does that prevent backup apps from actually running that might
Speaker:leverage VSS and shadow copies?
Speaker:Maybe it is the short answer, but depending how you attack this,
Speaker:if you're, if you're attacked for this is just, I want an alert on
Speaker:anything that delete shadow copies.
Speaker:Well, you know, if you have a backup solution that makes use of shadow copies
Speaker:and deletes shadow copies, then you know, that's something that you tune out, right?
Speaker:So you need to know the source of what deleted then that should be your event
Speaker:ID and you just tune that one out.
Speaker:Gotcha.
Speaker:So then you should only look for anomalous events that happen.
Speaker:Typically backup apps are going to, um, create a, create a shadow copy just
Speaker:to have a stable frame of reference and then delete it when they're done.
Speaker:Your backup app is probably running as a service.
Speaker:So that's going to run a system or whatever your backup, um, username
Speaker:is, or a user account is, whereas your ransomware is likely going
Speaker:to be running as that end user.
Speaker:Hm.
Speaker:So when you ask yourself, does an accountant have reason to
Speaker:be deleting, shadow copies?
Speaker:Probably not.
Speaker:So you can look for all these patterns and determine what's real versus
Speaker:what's not because I guess that's the other hard part in InfoSec is like
Speaker:tuning out the noise or the normal behavior versus what's anomalous.
Speaker:Right.
Speaker:Um, and you know, it all starts with really, really good logs.
Speaker:you need to have that log information and then what's going on in your systems.
Speaker:But honestly, going back to deleting shadow copies, of the other call-outs
Speaker:I made from a higher level, it's just looking at what would, you
Speaker:would expect an end user to run, especially from the command prompt.
Speaker:Right.
Speaker:You know, do you expect someone in legal to ever open a command
Speaker:prompt, let alone, you know, run whoami or run nets, you know, and
Speaker:start looking around your network.
Speaker:Probably not.
Speaker:So if someone in legal opens up a command prompt, that right there, it might be
Speaker:enough for you to go well, that's weird.
Speaker:Start running, you know, typical attack commands, or, you know,
Speaker:living off the land commands.
Speaker:Now it's real weird.
Speaker:And what would you use to watch for.
Speaker:Th there was a tool.
Speaker:I forgot its name that you mentioned about that.
Speaker:Uh, so the tool I mentioned in one of my blog posts was raccine,
Speaker:which is so vaccine with an R, um, which is a tool that just monitors
Speaker:for shadow copy deletion, and just kills any process that does it.
Speaker:Um, the problem is it doesn't discriminate.
Speaker:So again, if you do have a backup tool that does make use
Speaker:of deleting shadow copies, it's going to kill that process for you.
Speaker:Um, but if you don't have that limitation, it's a really handy,
Speaker:little quick, simple solution.
Speaker:but can you tune that or do you need another tool that's tuneable.
Speaker:Uh, well, it's, it's open source, so you can certainly modify the code, but no,
Speaker:uh, the current version that exists does not have any sort of options for that.
Speaker:It is, uh, a one and done sort of thing.
Speaker:Gotcha.
Speaker:Okay.
Speaker:yeah.
Speaker:So that would be, that'd be a perfect example of, like you said, when we
Speaker:were talking earlier, let's try this.
Speaker:Right.
Speaker:Hopefully it doesn't kill the backups, but if it does kill the backups, it
Speaker:would be pretty obvious because all the backups will fail because they're
Speaker:unable to create, uh, the shadow copies.
Speaker:I think one of the ones, and I don't know which article number was from that I
Speaker:thought was very unique that you brought up was a different way to sort of trick
Speaker:the ransomware, um, into sort of not destroying your entire infrastructure.
Speaker:I think one of the examples you brought up is sort of creating
Speaker:hidden drives and book-ending normal drives available on that system.
Speaker:So ransomware kind of get stuck, or you can monitor for that.
Speaker:Yeah.
Speaker:So, I mean, it's part two, in case you're wondering, um, so the, the actions
Speaker:on objectives posts, so, you know, we have the, the initial infection,
Speaker:you know, they mapped your network.
Speaker:They're starting to spread out.
Speaker:Now they're actually going to start trying to attack, you know, at this point.
Speaker:1, you you have to call out that in 2022, one hopes that your endpoint
Speaker:security software, you know, whatever anti-virus, anti-malware, you're
Speaker:running sees process X is encrypting word document Y. I'm going to kill it.
Speaker:If it doesn't, you really need to have a come to Jesus moment with your
Speaker:endpoint protection vendor at this point.
Speaker:But you know, if you have something that's running, that's actively doing that.
Speaker:Um, at that point, I think one of the best controls you can possibly have.
Speaker:Is feeding it data that you don't care about and putting alerts on it.
Speaker:So, you know, as you were saying, Prasanna.
Speaker:One of the things I do is I create, um, deceptive file shares on my network.
Speaker:So just file servers that, you know, on their own separate windows box, doesn't
Speaker:don't have any useful data on them.
Speaker:I actually just clone my actual production file names and structures
Speaker:and just put random data in them.
Speaker:Uh, but then I make drive mappings to my end points.
Speaker:Um, hidden drive mapping said, you know, from the windows GUI,
Speaker:you can't see them, but, you know, from command prompt, you can.
Speaker:Um, and I just book in my valid drives.
Speaker:So, you know, you have a home drive at H. So put something before
Speaker:that and put something after that.
Speaker:And, you know, hopefully the ransomware will go after those first.
Speaker:Um, and then I put just, you know, files on those servers that I monitor.
Speaker:If anything gets changed for them, no reason for anyone
Speaker:to ever touch these servers.
Speaker:No reason for anyone to touch these files.
Speaker:So, if anything gets modified, then it sets off alerts and I
Speaker:know something weird is going on.
Speaker:Um, and hopefully it buys you enough time to, you know, to remote in at three in
Speaker:the morning and down whatever's going on.
Speaker:Um, and yeah, the other thing I, I offered up in that it was what
Speaker:I coined as a ransomware tar pit of an actual service that's just
Speaker:running or monitoring that server.
Speaker:And it just starts seeing files getting modified.
Speaker:It starts generating more.
Speaker:Um, so, you know, Hey, the ransomware, it hit my fake file share.
Speaker:It file one.
Speaker:Well, here's four more files for you and it'll just keep going and just keep going.
Speaker:And you know, it may not be foolproof, but it might just depending on
Speaker:how the ransomware is written, it might just put it in the loop
Speaker:that it will never escape from.
Speaker:Yeah.
Speaker:I mean, uh, the concept of honeypots is not new, but I like to sort
Speaker:of modifying it to, you know, the world of, of, uh, ransomware.
Speaker:I agree with everything you said about stopping it in the first place.
Speaker:What about, um, detecting data exfiltration?
Speaker:What, what do you think, um, companies can do there?
Speaker:Yeah, so it's a definitely a trickier process.
Speaker:Um, mainly from a tooling standpoint, at this point, you're probably
Speaker:going to have to open up the wallet.
Speaker:Um, but you know, there there's one, there's just a basic security controls
Speaker:of content filtering and making sure that your end users don't have a path out to
Speaker:the internet for mass file transfers.
Speaker:So for most enterprises, you probably don't need more than HTTP
Speaker:and HTTPS from your workstations.
Speaker:Um, so you know, a lot of those transfers are trying to transfer out via FTP
Speaker:or, you know, a more traditional file transfer method that shouldn't be allowed.
Speaker:Um, but going further, you need to look at, you know, what sites are out there
Speaker:for allowing mass transfers, you know, to, to keep it simple, to do all your users
Speaker:need to be able to reach Dropbox, um, or box or Google drive or any of that stuff.
Speaker:If the answer's no, prevent it because that's an exfiltration method.
Speaker:Um,
Speaker:Let me ask you about that.
Speaker:I guess I had this, this apparently misconception that they would be sending
Speaker:these exfiltrated files to something that they owned and controlled.
Speaker:Right.
Speaker:So, and that's, so I'm trying to build this out from, what's easier to, harder
Speaker:to implement, um, going to that point.
Speaker:Yes.
Speaker:So when you get to the point of we're going to just
Speaker:transfer to something we own.
Speaker:And honestly, at that point you're probably hitting up AWS
Speaker:or Azure or something like that.
Speaker:And that's where it gets really messy.
Speaker:Unfortunately, in the cloud world, we live in, you can't exactly block Azure.
Speaker:Right.
Speaker:Um, but that's where I started looking at DNS security.
Speaker:Um, and one of my absolute favorite controls is just blocking newly
Speaker:registered domains or domains that have been parked for years that
Speaker:have all of a sudden gone live.
Speaker:Um, cause a lot of the attack infrastructure, and this is honestly a
Speaker:great way of also stopping the initial drop or download because there's a
Speaker:good chance that that's going to go somewhere that was just newly stood up.
Speaker:Um, but yeah, so that, that is another control where you might be able to
Speaker:just stop them from being able to get to whatever destination there
Speaker:they stood up to accept these files.
Speaker:Another point is always just a basic security, um, control of proper ACL's.
Speaker:Um, you know, when it gets to data exfiltration again, you know, keep
Speaker:picking on poor Susie in accounting, but Susie and in accounting shouldn't
Speaker:be able to get to your HR documents.
Speaker:She shouldn't be able to get to your operations documents.
Speaker:Yeah.
Speaker:They might be able to export out your payroll, which that's terrible, but
Speaker:you know, your payroll showing up on pay spend tomorrow is a bad day.
Speaker:It's not an end of the company sort of day though.
Speaker:Right?
Speaker:Like that's not trade secrets going out.
Speaker:Um, you know, so, so that's another control.
Speaker:Another thing that I would absolutely call out though is still honey documents.
Speaker:You know, having documents for them to interact and transfer out that as soon
Speaker:as you see somebody interact with that, you're, you're figuring out what process
Speaker:it was and figuring out where system that came from, just stopping that information.
Speaker:Um, and then going into the, probably the more logical solution, but
Speaker:definitely at a cost it's just the behavioral controls because in that
Speaker:exfiltration attempt, there's going to be an end point that's all of a sudden
Speaker:transferring a lot of data out to a new source that has never been seen before.
Speaker:And if you really know what normal looks like in your network, that should
Speaker:stick out like a big, big red flag.
Speaker:Um, and it's a very hard thing to do with free solutions, but there
Speaker:are plenty of security products out there that are all about mapping,
Speaker:how your end points interact with each other on the network and what
Speaker:looks like normal, what isn't normal.
Speaker:Um, I think it's money well spent for those types of controls.
Speaker:Can I ask a question about an earlier topic you brought up around EDR.
Speaker:So if most, or if EDRs are useful for detecting when encryption is happening and
Speaker:killing processes, et cetera, if that's the case, would a lot of these ransomware
Speaker:attacks be prevented to start with.
Speaker:Or, and is it that companies who've been hit with ransomware have not deployed
Speaker:EDR solutions in their environments?
Speaker:If EDRs can detect when encryption is happening on endpoint devices, if a
Speaker:company has deployed EDRs, does that mean they'd be able to stop ransomware?
Speaker:And so a lot of companies who got hit with ransomware.
Speaker:Didn't have EDRs deployed.
Speaker:Endpoint detection response is what we're talking about here.
Speaker:So first information security is all about layered defenses, and
Speaker:you never rely on a single defense.
Speaker:Um, in my mind when your antivirus, your EDR, WM, whatever your endpoint security
Speaker:tool is, if that's the thing that stops the malware, thank God it was there,
Speaker:but that's still a, oh my goodness.
Speaker:How many different things failed before it got to the point
Speaker:where that had to step up?
Speaker:Like, I never want to see anything out of that system.
Speaker:Um, that's not false positives.
Speaker:Cause that's the fun with EDR is they are a pile of false positive.
Speaker:Um, you know, to your question, did they not have it maybe, um, you know, EDRs
Speaker:are expensive, they are expensive tools.
Speaker:They are great tools, but they're expensive.
Speaker:And like so many other expensive security tools that are rarely
Speaker:set it and forget it tools.
Speaker:They are tools that require a lot of tuning and a lot of
Speaker:the finding of what's right.
Speaker:Excuse me, within your enterprise.
Speaker:Um, but you certainly have a lot of companies out there that are still,
Speaker:you know, with prop with old definition based antivirus, that's just scanning
Speaker:files and doing your nightly full scans.
Speaker:You know, like we did back in the nineties, um, and companies that have
Speaker:been very happy to embrace Microsoft defender as their only antivirus.
Speaker:And, you know, there there's some logic to it.
Speaker:It's a great solution and it's free depending on what your
Speaker:office 365 licensing looks like.
Speaker:Um, but I think the number of customers out there that have these large EDR
Speaker:solutions are few and far between.
Speaker:Uh, definitely the companies I'm targeting with my security cadence
Speaker:posts are the companies that probably don't have that kind of assessment.
Speaker:Yeah.
Speaker:Or even if they did sort of managing it on a daily basis, becomes
Speaker:difficult, especially with everything else they have to do, because it's
Speaker:not a one and done sort of a deal.
Speaker:Right.
Speaker:And you know, honestly, if you think about it as a, the evolution of antivirus,
Speaker:antivirus was a one and done for the most part, you know, you deployed Symantec
Speaker:back in the day, next next finish.
Speaker:And you never touched it again.
Speaker:Right.
Speaker:EDRs aren't that.
Speaker:EDR is, are constant tuning and definitions and breaking
Speaker:things in your environment and having to tune them back out.
Speaker:And I think that's also in the recall that I know of a number of
Speaker:companies have thrown their EDRs out because, oh, it just broke everything.
Speaker:That product was terrible.
Speaker:It wasn't, you just needed the resources to handle it properly.
Speaker:Yeah.
Speaker:I want to sort of round out things here.
Speaker:There's some things that we haven't talked about that were obvious ones that were.
Speaker:You mentioned in your first post that, you know, you talked about, you know, you
Speaker:password security, you talked about MFA.
Speaker:Um, these are things that just everybody should be doing.
Speaker:Uh, my, my personal opinion at this point, you know, th th you know,
Speaker:if you're not doing MFA on anything that matters, uh, you know, you're
Speaker:not doing your job and, uh, and you know, that's my opinion for what it's
Speaker:worth, but MFA stops so many things.
Speaker:Yeah, I If you were waiting for me to disagree.
Speaker:I wasn't going to.
Speaker:I have a question for you though.
Speaker:So I dunno if we're going to talk about it now or later, but I've read
Speaker:recently with a lot of the Lapsis attacks as well as other gangs, right.
Speaker:There is a notion of SIM swapping attacks, right.
Speaker:Which sort of hurt some of the MFA approaches taken.
Speaker:So Prasanna, don't let perfect get in the way being good,
Speaker:I I was gonna I was going to say that that goes right to that, right?
Speaker:Yeah.
Speaker:Just because it won't fix everything doesn't mean you shouldn't do it, right.
Speaker:but no.
Speaker:not, there is no silver bullet.
Speaker:Right.
Speaker:Um, and you know, a good backup person would never say don't do InfoSec and
Speaker:a good InfoSec person would never say, do backup or not do backup.
Speaker:Um, but I think that MFA is just so, and by the way, I, I finally
Speaker:ate my own dog food maybe about two years ago where I just realized that
Speaker:there were a lot of vendors that I personally interacted with, banks and
Speaker:things, that offered MFA as an option.
Speaker:And I finally said, look, I know it's going to make it harder for me to access
Speaker:my bank account and my, you know, my PayPal and, you know, I, there, there's
Speaker:only like, I dunno, there's only like 20 accounts that I felt had that level
Speaker:of information that I needed MFA on.
Speaker:Um, and then, and then, and then I became like this like MFA Nazi, where I was like,
Speaker:I'm mad at them if they don't offer MFA.
Speaker:I remember what happened when you traded in your phone and
Speaker:you lost access to your MFA.
Speaker:Yeah.
Speaker:So I was using a Google authenticator, not realizing that when I traded in my
Speaker:phone that I lost all of my MFA tokens.
Speaker:And so I switched actually to authy, so that I can, I don't have that problem.
Speaker:But, um, and now, and now I'm actually looking at a password manager.
Speaker:I think it's one password that manages both your passwords and your MFA stuff.
Speaker:That sounds nice.
Speaker:So I'm already a big password manager, uh, fan, I just, um,
Speaker:didn't, you know, I currently have to use two solutions, but Yeah.
Speaker:Yeah.
Speaker:And to your point, Prasanna, about, you know, SIM jacking you know, and not being
Speaker:the silver bullet, the one thing I'd say is not all MFA's are created equal.
Speaker:Any MFA is better than no MFA, um, but you know, it doesn't have to be a
Speaker:roadblock in your organization, you know, Fido keys, Titan keys, things like that,
Speaker:that are literally you get the prompt and you tap a, the thing hanging out of
Speaker:your USB port or taps onto your phone is a really, really nice MFA solution.
Speaker:That's really easy for your users.
Speaker:And they require something that you have that's truly physical.
Speaker:Um, and rather than, you know, replying to a text message, you know, there's,
Speaker:uh, one of the big debates going on in the InfoSec world right now is the, the
Speaker:push notifications of yes, that was me.
Speaker:Um, and it's right out of, uh, the playbook of lapsis of just that they
Speaker:actually had a picture on Twitter, um, yesterday of one of their chat things.
Speaker:Yeah.
Speaker:Just spam them a hundred times.
Speaker:Eventually they'll get mad and hit yes.
Speaker:Yeah, absolutely.
Speaker:And it's funny, cause I actually had, um, our MFA at work today went a little
Speaker:bit sideways and they started pinging me repeatedly for something I had just
Speaker:tried to sign into it had in the back of my mind, like, Hmm, check the logs to
Speaker:make sure like, this is kind of weird.
Speaker:Um, but still it's, it's better than nothing and yeah.
Speaker:Your end user may fail you and hit.
Speaker:Yes, that was me.
Speaker:Cause I got tired of getting this prompt a hundred times.
Speaker:at three in the morning, but still, um, but as InfoSec practitioners,
Speaker:that's where we need to step in and go don't we think it was abnormal that
Speaker:they got a hundred prompts, like did that not set off an alarm right there?
Speaker:Why is it if we're getting pinged over and over and over and over again?
Speaker:Um, cause I guarantee you that created a log somewhere.
Speaker:Yeah.
Speaker:All right.
Speaker:All right.
Speaker:Well, the summary statement of your, of your blog series or your post series,
Speaker:whatever you going to call this, and by the way, your posts are long.
Speaker:I, uh, after you made the comment I went and while you were talking,
Speaker:I copied and pasted the three posts into a, uh, Google docs.
Speaker:Uh, one of them is 4,500 words long my friend.
Speaker:I mean, that's long, even for me, I'm just saying
Speaker:I got to tell you someone the other day commented about how
Speaker:much they liked my writing style.
Speaker:And it was the first time ever in my 42 years of life that
Speaker:anyone has ever said such a thing
Speaker:I actually liked your writing style.
Speaker:I thought it was good
Speaker:This is a reason, this is a reason you're here is you.
Speaker:Well, it's a complicated issue.
Speaker:So, you know, I, I jab, but you know, 4,500 words is not that much
Speaker:for, for an issue of this magnitude.
Speaker:Right.
Speaker:But, uh, the first was 2,500.
Speaker:The second one was 2000, but the last one was 4,500.
Speaker:I was like, yeah, the boy could talk.
Speaker:Um, I would just reiterate what I said of so many companies
Speaker:focus on the recovery side.
Speaker:Um, and that focus comes from focusing on what the actual objective was of
Speaker:the ransomware group to begin with.
Speaker:What was it?
Speaker:They were trying to do, whether they were going to encrypt your stuff.
Speaker:So you start there and it's the wrong place to start.
Speaker:Start at the beginning, start with how they're going to
Speaker:compromise your first endpoint.
Speaker:And if you start looking at InfoSec from that perspective, what you'll end up
Speaker:finding, and it's a really gratifying feeling is you would turn on the news one
Speaker:day and there will be the latest, massive vulnerability or exploit being discussed.
Speaker:And you'll look at it and go, oh, my controls account for that.
Speaker:Not because I built controls around that particular exploit or vulnerability,
Speaker:but because I just built my controls around, how do I walk an attacker through
Speaker:initial foothold, moving laterally throughout my environment, and then acting
Speaker:on their objectives and then how do I stop them at each one of those steps?
Speaker:Um, so I guess the, the, the too long, didn't read it to use Reddit terminology.
Speaker:Don't focus on ransomware, just focus on how attacks function and you'll get
Speaker:ransomware taken care of by default.
Speaker:Right in the, the only major one that we didn't discuss, which we really
Speaker:should have is the whole patching thing.
Speaker:Right.
Speaker:I go back to, I'm pretty sure if my, if my memory serves correctly, Wannacry.
Speaker:Was, you know, it was one of the.
Speaker:first big ones that really went, you know, it went haywire and everywhere.
Speaker:If I recall correctly, it was an exploit that had been patched
Speaker:a year prior in a windows.
Speaker:And if you had just been anywhere near up to date, then you'd have been fine.
Speaker:Yeah.
Speaker:And Microsoft is, they are both great in how they maintain with a
Speaker:lion's grip to a, or with an iron grip to backwards compatibility.
Speaker:And they are also just ridiculous.
Speaker:in they're lions grip, iron grip on backwards compatibility,
Speaker:but I mean, Wannacry.
Speaker:The other side of Wannacry is exposure to the internet, um, which, and this kind
Speaker:of goes back to the proxy shell thing.
Speaker:You know, Wannacry has went gangbusters because of all the companies that
Speaker:have Samba, SMB exposed to the internet, which again is you take
Speaker:a step back and go good god, why?
Speaker:But then you go jump on something like showdown and you look
Speaker:like, oh yeah, there's tons.
Speaker:There's tons of vCenters exposed to the internet and you go good god, why?
Speaker:Um, and again, it just kind of comes down to, well, I had this one sysadmin who
Speaker:was overworked and doing what they could, and we had this use case and he stood
Speaker:it up, but he wasn't InfoSec focused.
Speaker:He didn't know what he was doing.
Speaker:And from that regards and didn't see the problem with it.
Speaker:Um, so yeah, I mean, to your point of patching.
Speaker:Absolutely.
Speaker:Uh, but I guess my takeaway is focusing on the big things.
Speaker:And don't worry about the latest zero day, quite as much.
Speaker:Um, cause I tell you attackers rarely are focused on that.
Speaker:Cause there's so much low-hanging fruit of the stuff that has
Speaker:been patched since 2018.
Speaker:Anyways.
Speaker:Yeah.
Speaker:you, you mentioned SMB.
Speaker:My other big one is RDP RDP to the internet is just, I just want to slap you.
Speaker:Well, listen, we could talk all day.
Speaker:Uh, I just, I want to say thank you again, and, you know, for
Speaker:coming on the podcast and talking to these really important things,
Speaker:No, it was a pleasure to be here.
Speaker:I really, I have to say when I got, when I got your message,
Speaker:like, wait, is that Mr. Backup?
Speaker:That is Mr. Backup!
Speaker:I was really excited.
Speaker:this is me.
Speaker:I, well, and I'm honored that you, that you knew who I was, so, Hey,
Speaker:you know, we're, we're members of the mutual admiration society, Prasanna?
Speaker:Yeah, no, it's been great snorkel having you on and yeah, great
Speaker:articles I'm will continue to read.
Speaker:I hope you keep doing your weekly posts on security cadence, because I'm sure a lot
Speaker:of people learn a lot of things from that.
Speaker:So
Speaker:I'll try to make a cliff notes version.
Speaker:yeah, I keep it long.
Speaker:I
Speaker:Yeah.
Speaker:Good, good luck with that.
Speaker:Uh, yeah, he's easy to find on Reddit is snorkel 42, make sure to check them.
Speaker:out and make sure to subscribe.
Speaker:The Backup Wrap Up is written, recorded, and produced by me, W. Curtis Preston.
Speaker:If you need backup or DR consulting, content generation, or expert witness
Speaker:work, check out backupcentral.com.
Speaker:You can also find links for my O'Reilly books on the same website.
Speaker:Remember, this is an independent podcast, and any opinions that
Speaker:you hear are those of the speaker and not necessarily an employer.
Speaker:Thanks for listening