Aug. 3, 2026

Cybersecurity Best Practices for Individuals (Encore)

Cybersecurity Best Practices for Individuals (Encore)

Cybersecurity best practices for individuals aren't complicated — they're just often ignored, and that's exactly what this encore episode digs into. This is a rerun of one of our most-engaged episodes, brought back not just because of how many people downloaded it, but because of how much of it people actually stuck around for. Curtis and Prasanna sat down with Mark Shriner, host of the SecureTalk podcast, for a wide-ranging conversation about what it actually takes to protect yourself online — no jargon, no scare tactics, just the stuff that works.

Mark's path into cybersecurity started with a career pivot in 2017, and what he found was a field that goes a mile wide and a mile deep — everything from pen testing to encryption to endpoint protection. But the through-line of this conversation is that security isn't just an IT department problem anymore. It's everybody's problem, whether you're an executive with sensitive data or a parent trying to explain phishing to your kids.

The conversation opens with a genuinely shocking data point: in a University of Michigan study, researchers dropped USB drives around campus, and 48% of them got plugged into a computer, some within minutes. That's the kind of thing that makes MFA (multi-factor authentication) feel less optional. Curtis shares his own MFA journey — from skeptic to evangelist — and the group breaks down why SMS-based authentication is riskier than people think, especially with SIM swapping attacks on the rise.

From there, the conversation covers a lot of ground: the gift card scam that almost caught Mark's son on his third day of an internship, why "didn't expect it, don't click it" is one of the best pieces of advice you'll hear, and how phone-based social engineering is just as dangerous as email-based phishing. On the business side, Mark and Prasanna talk through device management, BYOD policies, and tools for spotting anomalous network behavior.

And of course, backups get their due. Mark's advice for individuals is refreshingly simple: use a cloud-based backup service if you can, but if you can't or won't, at least use whatever's already available to you — Time Machine, an external drive, anything. The point isn't the perfect solution. It's action. Which is exactly how the episode got its name: by the end, everyone agreed the real takeaway was just do something. Don't do nothing.

If you've been meaning to turn on MFA, start backing up your laptop, or just get a better handle on the basics, this is the episode to catch up on.

Chapter markers:

00:00 Cold open

00:03 Meet Mark Shriner

00:10 How Mark got into cybersecurity

00:15 The University of Michigan USB drive study

00:16 Turning on MFA: Curtis's personal journey

00:19 SIM swapping and SMS authentication risks

00:23 Top security concerns for individuals

00:24 Backups, ransomware emails, and phishing basics

00:25 Being aware and pausing before you click

00:26 The gift card scam story

00:28 Phone-based scams and social engineering

00:31 Careful what you post online

00:31 Company-level MFA and security best practices

00:34 Device management and BYOD

00:35 DDI tools and data leak detection

00:43 Cybersecurity best practices for individuals: backup edition

00:45 Just do something — the summary that named the episode

Speaker:

Half of a group of Michigan college students plugged in a random USB

Speaker:

drive that they found lying around, some of them within minutes.

Speaker:

If you're shocked as I was by that story, then you're

Speaker:

listening to the right episode.

Speaker:

It's the fifth in our Encore series, where we're bringing back an episode that

Speaker:

listeners really seem to engage with.

Speaker:

My co-host, Prasanna Malaiyandi, and I, uh, sat down with Mark

Speaker:

Schreiner, host of the SecureTalk podcast, to talk cybersecurity

Speaker:

best practices for individuals.

Speaker:

Not the enterprise SOC stuff that we normally talk about.

Speaker:

Real, practical things that you and your family should be doing.

Speaker:

Things like multi-factor authentication, phishing prevention, SIM swapping

Speaker:

protection, password managers, and of course, my favorite topic, backups.

Speaker:

We landed on a phrase by the end of this episode that summed up the whole thing,

Speaker:

and that is, "Just do something." Don't let perfect be the enemy of protected.

Speaker:

By the way, if this is your first time watching or listening to me, I'm

Speaker:

W. Curtis Preston, AKA Mr. Backup.

Speaker:

I've been obsessing over backup, recovery, and now cyber recovery for over 30 years.

Speaker:

If that's your bag, then I'm your guy and you should probably subscribe.

Speaker:

You're not gonna find anybody that cares about that topic more than me.

Speaker:

Ever since 1993 when I had to tell my boss that there were no backups of

Speaker:

the database that we had just lost.

Speaker:

Now I've written five books, a blog, and a podcast.

Speaker:

Here we turn unappreciated admins into cyber recovery heroes.

Speaker:

This is the Backup Wrap-Up.

Speaker:

hi and welcome to backup.

Speaker:

Central's podcast.

Speaker:

I'm your host, W Curtis Preston AKA Mr. Backup and have with me, my close personal

Speaker:

friend, but a guy who's impossible to get an actual date with Prasanna

Speaker:

Malaiyandi How's it going Prasanna

Speaker:

oh, Curtis, I'm good.

Speaker:

I'm talking about?

Speaker:

Don't you.

Speaker:

I know the fact that you came all the way up to Santa Clara to visit the

Speaker:

office and we didn't get a chance.

Speaker:

to meet

Speaker:

And how many times has that happened?

Speaker:

Just saying,

Speaker:

We didn't.

Speaker:

no.

Speaker:

I think last time you came up, we did meet because remember we did the photo shoot.

Speaker:

okay.

Speaker:

All right.

Speaker:

That

Speaker:

Yes,

Speaker:

The photo shoot doesn't count.

Speaker:

it does.

Speaker:

I think so.

Speaker:

Okay.

Speaker:

before we met twice, so

Speaker:

I

Speaker:

I get to carry over one of those, but you were also busy.

Speaker:

You were also,

Speaker:

feeling a little butt hurt

Speaker:

but you were also busy with your dinners and.

Speaker:

friend, by the way, my friend whose wife isn't even in town, like who, who

Speaker:

took priority over hanging out with me?

Speaker:

What entity I want you to say publicly, what entity took

Speaker:

priority over, hanging out with me.

Speaker:

The dog.

Speaker:

The dog.

Speaker:

Yeah.

Speaker:

Yeah.

Speaker:

The dog, you had something to do with the dog.

Speaker:

And so that was more important than hanging out with me, but whatever,

Speaker:

I love you.

Speaker:

I'm clearly

Speaker:

I love you, Curtis.

Speaker:

I love you.

Speaker:

whatever.

Speaker:

All right.

Speaker:

So our guest is like, what have I wandered into,

Speaker:

Exactly.

Speaker:

Yeah.

Speaker:

we actually have a, this is one of the few times where I was on our guest's

Speaker:

podcast and now he's on my podcast.

Speaker:

Mark Shriner is the strategic sales director for me, by the

Speaker:

way, is it memo Q is that.

Speaker:

perfect.

Speaker:

Okay.

Speaker:

Okay.

Speaker:

Mark Shriner is the strategic sales director for a memo Q a leading

Speaker:

translation management system, a provider, and the founder of host of the secure talk

Speaker:

podcast, which is how we came to meet.

Speaker:

I got to go over and talk about backups on his podcast, and then he got to come here.

Speaker:

He's now on my podcast to talk about security.

Speaker:

He graduated from Penn state university with a bachelor's degree

Speaker:

in liberal arts and sciences.

Speaker:

2022, he completed Harvard cyber security, managing risk in the

Speaker:

information age, diploma program.

Speaker:

So I'm fascinated.

Speaker:

and by the way, welcome to the podcast Mark Shriner

Speaker:

Thank you, Curtis.

Speaker:

And thank you persona.

Speaker:

It's a actually, I've had fun watching you guys with the intro there.

Speaker:

You seem like an old married couple or something too,

Speaker:

We're an old, married couple that never sees each other.

Speaker:

I'm

Speaker:

Yeah.

Speaker:

cause Prasanna lives in and you know what it is.

Speaker:

It's a Santa Clara

Speaker:

Prasanna

Speaker:

Yeah.

Speaker:

He lives in Santa Clara.

Speaker:

I live in San Diego and you live a little bit farther north,

Speaker:

as I recall up in Seattle.

Speaker:

Yes.

Speaker:

Yes.

Speaker:

And I'm envious of both of your weather.

Speaker:

I actually, to be honest with you, I just spent the last three months traveling

Speaker:

between Arizona, St. George, Utah, Las Vegas, and San Diego and Los Angeles

Speaker:

all in that area for three months for business and for some personal business.

Speaker:

in three months we had five cloudy, rainy days.

Speaker:

And I got back here at the beginning of may thinking like, Hey, it's

Speaker:

safe to come back to Seattle wrong.

Speaker:

Yeah, it's funny to see.

Speaker:

Seattle is one of those places where, when it is sunny, it is just one of

Speaker:

the most beautiful places on earth.

Speaker:

I remember.

Speaker:

And I think I told you on when I was on your podcast, that I did some

Speaker:

work for Amazon back in 1998, I put in for the record, I put it in their

Speaker:

first enterprise wide backup system.

Speaker:

I was there in the summer.

Speaker:

And not a single cloudy day for three months.

Speaker:

And it was like I said to them,

Speaker:

Yeah.

Speaker:

going up to Mount Rainier and going out on the sound and them

Speaker:

throw the fish there it's a pike

Speaker:

Yeah.

Speaker:

market, of course, hanging out at the bubble gum wall.

Speaker:

I'm just saying, I like Seattle,

Speaker:

Yeah.

Speaker:

I went for a trip.

Speaker:

Yeah.

Speaker:

I went up for a trip, I think four years ago around this time in may.

Speaker:

And the weather was gorgeous, like perfectly sunny And I was

Speaker:

asking everyone, I was like, what are you guys complaining about?

Speaker:

The weather is gorgeous.

Speaker:

They're like, you just ended up being here on the perfect week.

Speaker:

Yeah, in contrast right now in Seattle or in San Diego, we are in

Speaker:

the middle of what we call may gray.

Speaker:

And then next, next month will be June loom.

Speaker:

this is the worst time of the year to actually visit San Diego.

Speaker:

you can get sunny days, but there will be, multiple days in a row where

Speaker:

it's just a hundred percent overcast.

Speaker:

and.

Speaker:

the fog that comes in or is it just overcast and gray?

Speaker:

It's overcast and gray.

Speaker:

it's not.

Speaker:

So the fog we call that the Marine layer, the Marine layer generally

Speaker:

burns off after around nine or 10.

Speaker:

if you have a strong Marine layer and it's just weird because there's no rain

Speaker:

connected with it, it's just gloomy, and, it just is what it is and, and I

Speaker:

Seattle weather.

Speaker:

They're like, yeah.

Speaker:

and it just.

Speaker:

people will come here.

Speaker:

So I thought you guys were sunny I'm like, to tell you it's may gray man.

Speaker:

Welcome to San Diego.

Speaker:

I've been in San Diego, it's always been sunny and I come down

Speaker:

there three or four times a year.

Speaker:

I'll be there twice, this summer for soccer, for my son's soccer tournaments.

Speaker:

but I love it.

Speaker:

I'm interesting, interested to know, do you think that people.

Speaker:

act and say, what were our personalities different based upon the area and

Speaker:

what I'm getting at is, so for example, in San Diego, do you find

Speaker:

that people are more or less outgoing or Seattle or in Silicon valley?

Speaker:

do you notice that.

Speaker:

I think people are attracted to areas based on, this is our great people

Speaker:

made or they, born or whatever.

Speaker:

same, I think that people are certain types of people are

Speaker:

attracted to certain types of areas.

Speaker:

and I think people that are.

Speaker:

That liked to be outside or attracted to places where that's the case.

Speaker:

Yeah.

Speaker:

but people come here and they, they actually, many people reject

Speaker:

or they react quite negatively to the intense brown that we have.

Speaker:

It's guys, this is a desert.

Speaker:

the only reason that.

Speaker:

That we can occupy this world is thanks to the Colorado river.

Speaker:

You know what that right?

Speaker:

The Colorado river and the LA aqueduct.

Speaker:

that brings water over from, those mountains.

Speaker:

and, and now we finally have our first, desalination plant in Carlsbad.

Speaker:

It's applying 10% of San Diego water, it's a desert, which means everything's brown.

Speaker:

And anything that you see that's green is either some type of cactus

Speaker:

or it is being watered by someone,

Speaker:

It's artificial.

Speaker:

Or where it's artificial, it's a cell phone tree.

Speaker:

but yeah, I don't know.

Speaker:

Yeah.

Speaker:

I don't know.

Speaker:

It's if you're a person who hates a lot of songs, this would

Speaker:

not be the place to be, right?

Speaker:

are people that I've heard of people that hate the sun.

Speaker:

I think they're generally called vampires, but no, sorry.

Speaker:

No,

Speaker:

This is not a time for vampires.

Speaker:

it is very green up here.

Speaker:

It's very nice.

Speaker:

and it's interesting, you mentioned the desalination plant because it's not just

Speaker:

California that, has issues with water.

Speaker:

It's the whole Southwest right now.

Speaker:

And at some point, the Colorado river is dwindling lake Powell, lake Mead.

Speaker:

They're, their levels are going down

Speaker:

It looks horrible yet.

Speaker:

this is a kind of a borderline national security issue.

Speaker:

and then you think about the wildfires because it's the dry dryness.

Speaker:

Desalination plants probably can't help with that, but they can help

Speaker:

with some of the, lack of water.

Speaker:

What are you, what are your, how is it working?

Speaker:

is it solar based?

Speaker:

Is it what's how's it powered?

Speaker:

and is it, is this

Speaker:

Yeah, I think I don't know a lot about it, about like how it works.

Speaker:

I know it took 15 years to make it happen.

Speaker:

And I know that generally speaking, the environmentalist's aren't

Speaker:

huge fans, and the current, the next thing that is finally.

Speaker:

Happening and, it's one of the, where you just have to mentally get past it.

Speaker:

It's a, unofficially referred to as toilet to tap.

Speaker:

that is what's happening.

Speaker:

Finally in California.

Speaker:

It's guys, we're not getting any more water and it's really expensive

Speaker:

to pull it out of the ocean.

Speaker:

why don't we filter what we already have, and that's starting

Speaker:

to happen in these areas.

Speaker:

So we'll see.

Speaker:

in Singapore for four years in, in Singapore is a big, they have no, none

Speaker:

of their own water supplies there.

Speaker:

They're

Speaker:

Right.

Speaker:

dependent upon, a pipeline from Malaysia they have the.

Speaker:

Toilet to tap plants.

Speaker:

And,

Speaker:

Yeah.

Speaker:

you had the prime minister of Singapore go over there and pour himself a glass of

Speaker:

water and just drink it there on the spot.

Speaker:

And I said, if it's good enough for him,

Speaker:

Yep.

Speaker:

Yeah.

Speaker:

yeah, you don't want to think about it.

Speaker:

Like you said, though.

Speaker:

You don't want to think about it, but, try not to, try not to,

Speaker:

but, so I'm curious.

Speaker:

So your, how did you, drew you to cybersecurity?

Speaker:

Well, a couple of different things.

Speaker:

I think.

Speaker:

in 2017 we were moving back from a nine year stint in Asia, moving back to the

Speaker:

states and a good friend of mine, had.

Speaker:

A company that would be with becoming a Microsoft

Speaker:

cybersecurity compliance partner.

Speaker:

he was looking for some help on the business development side.

Speaker:

And, and I started taking a look.

Speaker:

The more I researched, the more interested I became because, cybersecurity is

Speaker:

something that can go a mile wide.

Speaker:

and then also a mile deep

Speaker:

Yeah.

Speaker:

one of those things.

Speaker:

If you want to talk about, pen testing, backups, encryption, different, compliance

Speaker:

organizations, you can just go in so many, data loss prevention, endpoint protection.

Speaker:

you can go so many different directions and then each one of those, you can

Speaker:

go down these super deep rabbit holes.

Speaker:

And I like learning.

Speaker:

The other thing I, that I find interesting about cybersecurity back then, and now is.

Speaker:

Before, I think we thought that this is the cybersecurity.

Speaker:

There was a couple of people in the back, in the corner of the it department

Speaker:

that their job is cybersecurity, but everybody in an organization needs

Speaker:

to have some type of awareness and responsibility for security, but beyond.

Speaker:

that as individuals and consumers, we need to be aware

Speaker:

of some security best practices.

Speaker:

And so it affects everybody's life.

Speaker:

And it's something that, 30 years ago, nobody was talking about

Speaker:

because there was no internet.

Speaker:

And now it's

Speaker:

Yeah.

Speaker:

important with the internet, social media, everything.

Speaker:

I have three children.

Speaker:

And they need to know some best practices about, what does a phishing campaign

Speaker:

look like or a phishing attack look like?

Speaker:

What w how do they protect their passwords?

Speaker:

What should they shouldn't do with their mobile devices, et cetera.

Speaker:

So it affects everybody.

Speaker:

And it's this like new field that was created partially based upon the

Speaker:

explosion of the internet in IOT.

Speaker:

I think we're just getting started in both in terms of understanding

Speaker:

the threat landscape, but also the, the best practices for prevention.

Speaker:

Does that make sense?

Speaker:

Do you see that a lot of this, I know it's an interesting point.

Speaker:

You made that it's rolling into consumers.

Speaker:

Like everyone has to start caring about this.

Speaker:

Like every day.

Speaker:

Do you start to find that's actually happening or.

Speaker:

Or are people yeah, that's just something that a company has to

Speaker:

worry about or a business has to worry about, or like this large CEO

Speaker:

has to worry about not necessarily.

Speaker:

yeah, let me answer that by backing up even farther.

Speaker:

I think in companies right now, where it used to be the perception of the.

Speaker:

of the it teams or the, the CISO's job there, is an a growing or

Speaker:

increasing awareness that it's everybody's responsibilities.

Speaker:

And so you'll have not only do you have structured educational, programs,

Speaker:

but you'll have simulated phishing campaigns and things like that.

Speaker:

So go enterprise wide.

Speaker:

And if you get the CEO and he clicks on the wrong thing and boom, guess

Speaker:

what you got to go to training you're in a you're doing timeout.

Speaker:

and companies try to make that.

Speaker:

So in companies it's becoming, I guess increasingly common for people to accept

Speaker:

that everybody has a responsibility.

Speaker:

If you find a thumb drive in the parking lot, don't just walk in and

Speaker:

stick it in your company's device.

Speaker:

and sharing those stories, I remember growing up and listening to my

Speaker:

grandparents, tell stories about this accident, that accident, this person who

Speaker:

did something good, did something bad.

Speaker:

And we learn from those stories.

Speaker:

And I think when we share these stories about hacks or, the famous

Speaker:

story about somebody finding a thumb drive and then putting it in their

Speaker:

device and then, downloading some malware inadvertently, learn from

Speaker:

that and those stories are important.

Speaker:

So that's one method of, or one, data point.

Speaker:

Come people in organizations are becoming increasingly where individuals I think

Speaker:

are also becoming extreme, increasingly aware, let's start off with high net

Speaker:

worth individuals, where they are very much in the sites of, targeted phishing,

Speaker:

spear, phishing campaigns, right?

Speaker:

And so there are certain tools and methods and processes out there to

Speaker:

help these people at least become aware of what's what the threat looks.

Speaker:

like But beyond that, I think, just the general public, if I look at

Speaker:

my kids, are pretty suspicious and cynical and almost jaded, in terms of

Speaker:

look at this, they'll show me stuff.

Speaker:

They're like, look at this, it's just, and because it's obviously it's a scam.

Speaker:

And so I think.

Speaker:

people are becoming increasingly aware at the same time you still hear

Speaker:

of consumers every day, for example, they're transferring money to a title

Speaker:

agency and somebody spoofs the, the address, that w where they're supposed to

Speaker:

they're there, the account information, that kind of stuff is happening in.

Speaker:

yes and no, to answer

Speaker:

Yeah.

Speaker:

I think people are becoming more aware, but there's, we have a long ways to go.

Speaker:

Yeah.

Speaker:

So that there was a study back in 2016, from the university of Michigan

Speaker:

where they left a series of USB drives that had an HTML there that if you

Speaker:

open up an HTML, it had an image tag.

Speaker:

So they were able to identify, how many people actually clicked on the thing.

Speaker:

do you suppose the percentage was of the people that.

Speaker:

university of Michigan, that's a, that's what?

Speaker:

big 10.

Speaker:

those guys probably I'm west coast, so I'm afraid to guess.

Speaker:

W what was it?

Speaker:

It was half,

Speaker:

Wow.

Speaker:

That was in what year?

Speaker:

20

Speaker:

Wow.

Speaker:

USB drives around the Urbana champagne CA these are college kids.

Speaker:

These are,

Speaker:

At the one of the best universities in the

Speaker:

Yup.

Speaker:

They said they found that 48% of the drives are picked up

Speaker:

and plugged into a computer.

Speaker:

Some within minutes of being dropped.

Speaker:

Yeah.

Speaker:

Let's just, yeah.

Speaker:

hopefully the situation or the awareness is getting better.

Speaker:

I look at little things like, turning on MFA's or multi-factor

Speaker:

authentication two factor authentications for just any, obviously any bank

Speaker:

accounts, but any of your online, tools or apps, just turn it on,

Speaker:

Yeah, exactly.

Speaker:

a simple thing.

Speaker:

That's going to stop 99%.

Speaker:

But some people that, it's a hassle.

Speaker:

Yeah.

Speaker:

If you're, if your account gets compromised, then

Speaker:

that's going to be a hassle.

Speaker:

Yeah.

Speaker:

I've mentioned on this podcast a few times that I went from being an MFA newb,

Speaker:

I don't know, four or five years ago to.

Speaker:

Slowly.

Speaker:

and then it sorta, it was a snowball situation.

Speaker:

I ended up rolling MFA anywhere it mattered.

Speaker:

and the cause I have, oh Lord, I have 800 accounts.

Speaker:

Yeah.

Speaker:

At, I'm not kidding.

Speaker:

I have a password manager, so I, I can pull it up and see it.

Speaker:

And I have, just hundreds and hundreds of accounts at random

Speaker:

places where I don't ever.

Speaker:

man?

Speaker:

Hey,

Speaker:

I just, it's just stuff.

Speaker:

Anyway.

Speaker:

Anyway, my point is.

Speaker:

to tell me Curtis's into some shady stuff, man.

Speaker:

If he's got 800 accounts

Speaker:

I just hope he talks about his experience with MFA.

Speaker:

Yeah.

Speaker:

Yeah.

Speaker:

The story.

Speaker:

so I, don't my point of mentioning how many accounts I have.

Speaker:

I don't have on most of those.

Speaker:

Because they're just stuff where I don't, there's no information I'm just

Speaker:

anyway, I did roll out MFA, everywhere.

Speaker:

And I use Google authenticator and wherever I could, because of what I knew

Speaker:

about that using Google authenticator.

Speaker:

text-based MFA and by the way, I dunno, I'd like to come back to

Speaker:

that idea, but here's what happened.

Speaker:

I got a new phone locked out of all my accounts.

Speaker:

because I didn't know.

Speaker:

I didn't know what I didn't know.

Speaker:

And so I, I, when I re when I rolled that out again, I switched to authy

Speaker:

as an app, which allows you to back up the stuff and try, anyway.

Speaker:

Yeah.

Speaker:

I'm a huge fan of MFA.

Speaker:

and I've mentioned before that, I went from being a newb to being very angry.

Speaker:

If there's a, if there's a company that I'm interacting with where

Speaker:

things matter and they don't have.

Speaker:

the authenticator style of, MFA.

Speaker:

I do want to ask you this, and, how much you know about why the

Speaker:

text-based method of authentication is bad, like sending an SMS message.

Speaker:

I'm just going to take a shot of the dark.

Speaker:

I'm just going to say that it can be somehow intercepted and

Speaker:

somebody could actually just use it or somebody or you could, yeah.

Speaker:

something, a derivative of that.

Speaker:

But tell

Speaker:

Yeah.

Speaker:

Yeah.

Speaker:

know what I, I was hoping, what you knew more than I did,

Speaker:

Yeah.

Speaker:

because it's

Speaker:

now,

Speaker:

and Prasanna you're, you're up on this stuff.

Speaker:

So here's the thing I'm wondering there's a company that offers

Speaker:

multiple methods of authentication.

Speaker:

my, my, my credit union, they have my phone and, they, they use a, they have

Speaker:

an authenticator method where you get, you get the little six digit code.

Speaker:

If you, pull up their app on your phone.

Speaker:

I prefer that method.

Speaker:

I use that method whenever I can, but should I be bothered by the

Speaker:

fact that they also support SMS?

Speaker:

there's no way to disable the fact that they have

Speaker:

I would be a little worried just because the number of SIM swap attacks

Speaker:

that are happening these days, like you hear it all the time when it comes

Speaker:

to crypto, With all these acts where someone SIM swaps with someone else

Speaker:

gets the authenticator code, cleans out their wallet, They're a Bitcoin wallet.

Speaker:

So I think it is common.

Speaker:

And even T-Mobile right.

Speaker:

Was accused of allowing a porting out of numbers as well.

Speaker:

That's another thing that can.

Speaker:

right.

Speaker:

Yes.

Speaker:

so you think I should be worried?

Speaker:

I don't know what I could do.

Speaker:

Yeah.

Speaker:

And it also depends to what extent, like some random person going after

Speaker:

you specifically Curtis, right.

Speaker:

I'm

Speaker:

a

Speaker:

big deal.

Speaker:

exactly.

Speaker:

But I think there are cases like if you're a high net worth user or even

Speaker:

you have sensitive data or things like that, that you care about.

Speaker:

That I think, yeah, you should be worried about even email,

Speaker:

Multi-factor authentication.

Speaker:

Sometimes it's worrisome as well.

Speaker:

It's things which you can't completely secure on a.

Speaker:

Yeah.

Speaker:

I know.

Speaker:

that most of the organizations that I'm F MFA with, offer an option could be,

Speaker:

for example, a token that you have, it could be the authenticator app could be

Speaker:

a text, could be an email and they offer the consumer the choice at this point.

Speaker:

probably just trying to make it easy for somebody to opt in with something.

Speaker:

But there are obviously some that are more secure than others.

Speaker:

And I spoke earlier about the awareness of some consumers, especially high net worth

Speaker:

individuals, becoming more cyber aware.

Speaker:

And the specific attack that I was thinking about is SIM swapping.

Speaker:

And it's be, I, I know a gentleman that's been, SIM swapped three times.

Speaker:

and it's, he described it as he was on an airplane.

Speaker:

He got out the airplane, his phone wouldn't work.

Speaker:

And it is took him days to get back online.

Speaker:

It was maddening, scary, and primarily done through social

Speaker:

engineering where they contact the

Speaker:

Provider.

Speaker:

Yeah.

Speaker:

and convince them that are you and that you need a new SIM.

Speaker:

And it's just that.

Speaker:

Yeah.

Speaker:

They made it so easy to port numbers as well.

Speaker:

that's also another common vector.

Speaker:

What does that mean to port a number?

Speaker:

Does that mean to change carriers?

Speaker:

To change carriers

Speaker:

Okay.

Speaker:

And so basically instead of just doing a SIM swap, they just pretend to be you and

Speaker:

Yup.

Speaker:

your number to another

Speaker:

Yup.

Speaker:

Wow.

Speaker:

Yeah.

Speaker:

That's not good.

Speaker:

These bad guys are really bad mint.

Speaker:

I think that's something we can all agree

Speaker:

Yeah.

Speaker:

yeah, so like I have multiple accounts where, so goo like Gmail.

Speaker:

Okay.

Speaker:

Gmail.

Speaker:

It's very specific on what authentication.

Speaker:

Systems that you use and you can disable ones that you

Speaker:

don't want to use specifically.

Speaker:

You can disable SMS authentication, but my credit union, it supports all of them.

Speaker:

And I suppose the only way to disable SMS based authentication is to delete

Speaker:

my cell phone from the account.

Speaker:

But that's just weird,

Speaker:

But change it to like a mobile number or, sorry, to the home number,

Speaker:

Yeah.

Speaker:

allows you to say, is this a cell phone or.

Speaker:

Or a mo or a home number.

Speaker:

I'm sure if you select a home number, it won't send you SMS, but

Speaker:

a ho what's a home number.

Speaker:

a

Speaker:

landline

Speaker:

a landline and old school.

Speaker:

I know I've seen places where it's is this a home number or is this a cell phone?

Speaker:

Interesting.

Speaker:

so I'm curious, mark, what do you, if you're, so I know, as a dedicated to

Speaker:

backup, there's, I have my top five of these are things and by the way, on your

Speaker:

podcast, the first, like my biggest one, you and I talked about was the idea that

Speaker:

cloud stuff is automatically backed up.

Speaker:

Which it isn't if somebody were to say, what are the top five things

Speaker:

that I need to be concerned about, as a, either personally or it sounds

Speaker:

like personally you're thinking MFA,

Speaker:

Yeah.

Speaker:

I would say that's just a best practice personally or for companies and companies

Speaker:

have a little bit more sophisticated tools at their disposal, so they can push

Speaker:

an MFA depending on, the user behavior.

Speaker:

Are they logging in from.

Speaker:

A new location.

Speaker:

Are they logging in from another country?

Speaker:

Is there some kind of anomalous behavior, mark never

Speaker:

Yes.

Speaker:

these files now he's downloading gigs, downloading gigabytes of finance records.

Speaker:

I think we're gonna force an MFA on that.

Speaker:

so I think MFA is a foundational thing, for individuals or organizations.

Speaker:

I think some other best practices for individuals again, would be backup to

Speaker:

ensure that your information is backed up.

Speaker:

I don't know if you guys have seen these, Mr. Backup gives me a

Speaker:

Yeah.

Speaker:

I'm very excited about that.

Speaker:

from Mr.

Speaker:

Very excited

Speaker:

Backup

Speaker:

that.

Speaker:

the, you have, you guys get these emails that say, Hey, I'm sorry to

Speaker:

tell you, but I've been spying on you for the last couple of months.

Speaker:

And, and if you don't send this money to whatever, I'm going to release this

Speaker:

stuff, this, this thing of you going into these inappropriate websites

Speaker:

and they send these emails out to.

Speaker:

Thousands of people and some people, cause they know that some people will

Speaker:

be like, oh my God, I should pay this.

Speaker:

Yeah.

Speaker:

you should.

Speaker:

For one, if you get that email.

Speaker:

Delete it, care what

Speaker:

Right.

Speaker:

through.

Speaker:

It's just a, they're just phishing and too, if you've got your stuff

Speaker:

backed up, you don't have to worry about anybody encrypting anything.

Speaker:

Now, if they're going to release stuff, that is another thing from

Speaker:

malware is if they take your records, even though you've backed them up.

Speaker:

they're going to release something that you don't want released to the public,

Speaker:

that's a whole nother discussion, but definitely you should back up, antivirus,

Speaker:

running an antivirus is, super important.

Speaker:

what else?

Speaker:

as a consumer.

Speaker:

being aware and pausing.

Speaker:

When you see something that looks a little off any time somebody says, Hey,

Speaker:

there's a problem with your account.

Speaker:

We need you to log in and can now just stop or, oh, your order for $15,000 from

Speaker:

Amazon is on its way, And you're like

Speaker:

Yeah.

Speaker:

out, dude, just,

Speaker:

Yeah.

Speaker:

if you didn't expect it don't click it

Speaker:

Exactly.

Speaker:

that's a perfect way to say it.

Speaker:

I like that.

Speaker:

Didn't expect it.

Speaker:

Don't click it.

Speaker:

And obviously you can, cause you can look at the, the sender's real address

Speaker:

and see, is this something real read?

Speaker:

It is a lot of this stuff, they've got shoddy grammar, fuzzy

Speaker:

images, but people get worked up.

Speaker:

yes, but I'm sure you've seen the ones where you get an email from the CEO.

Speaker:

Hey mark.

Speaker:

I need you to run out and buy 50 gift cards for target and send, it's happened

Speaker:

to one of my boys, who was working as an internship for the cybersecurity

Speaker:

committee that I was working with before, which the is Adaquest the CEO

Speaker:

of Adaquest, his name is Hiram Machado.

Speaker:

it was like my son's third day into his internship.

Speaker:

And he got an email saying, Hey, Makai I need you to run out and buy,

Speaker:

$500 worth of gift cards from target.

Speaker:

And I need you to, once you have that, just let me know, and I'll

Speaker:

tell you what we're going to do with them, but I need this for this

Speaker:

event we're doing this afternoon.

Speaker:

so Makai again, telling you the kids are getting smarter these days.

Speaker:

Hopefully not the ones in university of Michigan, I guess that was 2016.

Speaker:

he emailed me and he goes, what should I do with that?

Speaker:

And I said, send it.

Speaker:

I said, we're going to use this as a case study in a learning

Speaker:

example, don't do anything with it.

Speaker:

but yeah, I don't.

Speaker:

what advice would you guys give.

Speaker:

I mean stuff's all good.

Speaker:

I think, the, you talked about hovering over the site to see the site.

Speaker:

What I generally say is if you.

Speaker:

get an unexpected communication from somebody you actually do business with.

Speaker:

Because I get stuff like that.

Speaker:

My Citibank card has been compromised.

Speaker:

I'm like I haven't had a Citibank card in 20 years.

Speaker:

So I think I'm pretty good, but I get, I've gotten phished from like PayPal,

Speaker:

stuff like that or not from PayPal.

Speaker:

as a PayPal based positioning,

Speaker:

PayPal.

Speaker:

bending, pretending to be PayPal, is if you are actually concerned,

Speaker:

if it sounds like something that, that might be real, to paypal.com.

Speaker:

interact in any way with that email, go to PayPal.com or contact PayPal's phone

Speaker:

number, not anything listed in that email.

Speaker:

would, it's interesting though.

Speaker:

There are times when I, in fact, just a couple of days ago.

Speaker:

I got contacted by a company that I do business with.

Speaker:

there was a credit card company and they were like, we're such and such

Speaker:

from such and such credit card company.

Speaker:

And we want to call to verify charges.

Speaker:

how about I freaking verify you?

Speaker:

you're

Speaker:

Yeah.

Speaker:

nude

Speaker:

Show me your

Speaker:

me show, they will, we want to authenticate.

Speaker:

We want to authenticate you.

Speaker:

before we talk to you about account, I'm like, how do I authenticate you?

Speaker:

Like, why do you people still think this is like Lee?

Speaker:

I will call.

Speaker:

Thank you.

Speaker:

Thank you for calling.

Speaker:

I will call the 800 number on and by the way, it was a real thing.

Speaker:

I will call the 800 number on my credit card and I will ask for the fraud

Speaker:

department and it was real thing.

Speaker:

Th that's annoying that happens, because that is a phishing

Speaker:

No.

Speaker:

right?

Speaker:

Absolutely.

Speaker:

in people think that, all cyber attacks are through email or somehow

Speaker:

somebody is getting into your network.

Speaker:

Some of them are just a phone

Speaker:

Yeah.

Speaker:

I've been called by.

Speaker:

The IRS, the texts, whatever.

Speaker:

And yeah, this Mr. Shriner.

Speaker:

Yes.

Speaker:

We have an urgent matter that we need to talk to you about.

Speaker:

really, and I, sometimes I just where's this gonna go?

Speaker:

Cause I know at one point they're going to ask me for social

Speaker:

security date of birth, blah, blah,

Speaker:

Yeah.

Speaker:

I'm like, okay.

Speaker:

yeah.

Speaker:

What's going on?

Speaker:

They're like, before we can go any further, we need to get some information.

Speaker:

typically the smart ones, they won't go right to social security.

Speaker:

But just say they'll say, I just want to confirm that

Speaker:

your name is blah, blah, blah.

Speaker:

They got your name.

Speaker:

I'm

Speaker:

Yeah.

Speaker:

that's me and that you're living at.

Speaker:

yeah.

Speaker:

Yeah.

Speaker:

And so now I'm starting to respond to them.

Speaker:

And then as sooner or later they're like, okay.

Speaker:

And then, can we give us the year of your date of birth, and you're

Speaker:

like, and they just start to

Speaker:

Yeah.

Speaker:

good ones, start to tease it out of you because they're not gonna, if

Speaker:

they come in first, first thing to ask you is social security people like.

Speaker:

But you down there and then, they build a rapport and that's

Speaker:

what they're all looking for.

Speaker:

Yeah, it feels like they have that information already.

Speaker:

So it's okay, what's this one more piece of information.

Speaker:

fine.

Speaker:

it.

Speaker:

Just to verify that we're talking to the right person, right?

Speaker:

and it's funny.

Speaker:

Cause I remember when my dad retired, like he'd always get all these calls from.

Speaker:

Scammers or salespeople.

Speaker:

And I'd be like, you guys should just chat with them.

Speaker:

It's what do you have to lose?

Speaker:

Just don't give them any information.

Speaker:

But at least you're saying, yeah,

Speaker:

to talk

Speaker:

exactly.

Speaker:

And at least you're saving someone else from having to get a call.

Speaker:

right?

Speaker:

There's a, there's an English dude that I've seen.

Speaker:

He does videos where he interacts with these folks and he like, he does talks

Speaker:

where he talks about his interactions.

Speaker:

Have you seen.

Speaker:

I've seen stuff like that.

Speaker:

yeah.

Speaker:

I don't know if I've seen that specific one, but yeah, where they just go and

Speaker:

after a while the scammers, they were getting really frustrated after a while.

Speaker:

Cause they start to realize that they're the ones getting scammed,

Speaker:

yeah.

Speaker:

Yeah.

Speaker:

There's this one guy and he's just really funny.

Speaker:

And he does he doesn't like a talk

Speaker:

Yeah.

Speaker:

he does it on stage where he talks about his interactions with these

Speaker:

folks and it's just, he does it in a

Speaker:

Yeah.

Speaker:

way.

Speaker:

So the phone calls, Phone calls and emails.

Speaker:

Don't click on the emails.

Speaker:

Like just again, if you think it's actually from PayPal,

Speaker:

then go to paypal.com.

Speaker:

Not anything with that.

Speaker:

Go

Speaker:

and one of the points mark made earlier around social engineering,

Speaker:

I think people also just, it should just be careful what they post online.

Speaker:

If you're like putting Facebook messages or tweets,

Speaker:

Hey,

Speaker:

careful.

Speaker:

Yeah.

Speaker:

for a three week vacation to The Bahamas, Yeah.

Speaker:

Sorry.

Speaker:

Yeah.

Speaker:

Yeah, no.

Speaker:

That's totally the case.

Speaker:

Or it's oh yeah.

Speaker:

Or you start inadvertently being like, Hey, it's my birthday.

Speaker:

Or it's oh, my mother is so and so right.

Speaker:

And, or a favorite dog's name.

Speaker:

And all the rest of this and people can take that information and they

Speaker:

could use it for social engineering to extract other information from you.

Speaker:

I know what your favorite dog's

Speaker:

Yeah.

Speaker:

I, because he was more important than me.

Speaker:

I'm sorry, I'm

Speaker:

Are you a little bit?

Speaker:

Are you a

Speaker:

I think he's really hurt, man.

Speaker:

oh, it's okay.

Speaker:

man.

Speaker:

I went to il fornaio without you.

Speaker:

That's

Speaker:

some really good food.

Speaker:

yeah.

Speaker:

So what about companies?

Speaker:

So we talked about, we talking about have MFA, so there's two ways to about MFA.

Speaker:

You should, as a company, be offering MFA when people are

Speaker:

interacting with your service online,

Speaker:

Yeah.

Speaker:

and then you should, as a company, I like what you were talking about earlier.

Speaker:

cause obviously, by the way, I haven't thrown out our disclaimer, so Prasanna

Speaker:

and I work for different companies.

Speaker:

I work for Druva, he works for zoom and this is not a podcast of either company

Speaker:

and the opinions here are all ours.

Speaker:

And, be sure to rate us by the way, at a ratethispodcast.com/restore

Speaker:

And then, if you want to come on.

Speaker:

listen to me, complain to Prasanna yourself life.

Speaker:

you could

Speaker:

do

Speaker:

that

Speaker:

We

Speaker:

love guests.

Speaker:

it just it on Twitter or wcurtispreston@gmail with Druva for

Speaker:

example, we've supported, third-party MFA for awhile, and now we support native MFA.

Speaker:

if you're a company.

Speaker:

If you're a cloud company, or if you're a company that has information

Speaker:

that is important like that, and people are logging into your system

Speaker:

without MFA Then bad company.

Speaker:

and it should also not be SMS based authentication you should offer,

Speaker:

authenticator method and, and I'm gonna throw out, going to throw out, Don't be.

Speaker:

a website that is hard to use a password manager with, Don't be complaining

Speaker:

about one or two of the character.

Speaker:

The special characters that my password manager came up with, or I

Speaker:

had one this week that complained.

Speaker:

They're like, Hey man, your password's too long.

Speaker:

It was

Speaker:

Yes,

Speaker:

characters.

Speaker:

they said, you can use a maximum 17 characters and I'm like,

Speaker:

17.

Speaker:

Yeah, 17.

Speaker:

That is so weird,

Speaker:

and, the, So based on that, I no longer interact with the IRS.

Speaker:

I'm not.

Speaker:

But I also want to go back to a point mark made earlier, which was that MFA.

Speaker:

I don't think solves everything.

Speaker:

You still need those, especially as a business, you still need those other

Speaker:

things to look for anomalies, right?

Speaker:

For look, to look at the behavior of the user because MFA will protect

Speaker:

you to a certain extent, but it's not the only line of defense.

Speaker:

Oh, yeah.

Speaker:

at the corporate level again, The complexity of the problem and the P the

Speaker:

complexity of the solutions available are much greater, at the corporate level.

Speaker:

you have things like, device management, for example, and these

Speaker:

days everybody wants to BYOD but you also have corporate devices.

Speaker:

And, but on my B my own device, I'm going to have access to company apps and data.

Speaker:

How does the company manage that?

Speaker:

there's mobile device management tools out there that can, if I lose my phone, I can

Speaker:

tell the company, Hey, I lost my phone.

Speaker:

They can remote wipe their data.

Speaker:

they can do remote backups, all of that stuff.

Speaker:

they can check for anamolous behavior on a phone.

Speaker:

Mark just logged in from Bellevue, but he's also logging in.

Speaker:

from Romania.

Speaker:

Something's wrong here.

Speaker:

Yup.

Speaker:

yeah, that stuff and it's, depending on the size and the shape of the

Speaker:

organization, it can be, you have SEIMs to monitor all types of

Speaker:

activity to collect your logs.

Speaker:

that's, again, it comes back to that original point of why cybersecurity,

Speaker:

cause it's such a broad field and there's so many different.

Speaker:

It's constantly evolving.

Speaker:

it's pretty cool.

Speaker:

Yeah.

Speaker:

I'm curious what you think about, so one of the things I'm pushing outside

Speaker:

of the backup space, one of the things that I'm pushing people to do

Speaker:

or companies to do is to look into a couple of different types of tools.

Speaker:

One is we've had, we had somebody on here from a company that does a DDI, right?

Speaker:

So what did we decide that was DNS

Speaker:

DHCP and IPAM.

Speaker:

And IPAM Yeah.

Speaker:

and so th that, those one group of tools, which is they can do things of like,

Speaker:

why is somebody going to this really?

Speaker:

why is something looking at a DNS address that is a. a DNS name

Speaker:

that is like characters long, and it doesn't make any sense.

Speaker:

That, that is a,

Speaker:

Sure

Speaker:

ransomware thing, reaching out for command and control.

Speaker:

that's number one and number two, the type of software or system or

Speaker:

whatever that can identify data leaks.

Speaker:

so that you it's there's a general level of outgoing.

Speaker:

traffic and then suddenly there's this giant spike from Fred's desktop.

Speaker:

that never happened before.

Speaker:

And the

Speaker:

Vacation.

Speaker:

Fred's on vacation.

Speaker:

Cause he posted on Facebook that he's in Maui this week.

Speaker:

and his laptops doing that.

Speaker:

What do you think about those two types of tools?

Speaker:

I think, on the situation, it's, every tool has its usage.

Speaker:

And I think for most companies, both of those make sense.

Speaker:

for both those tools make sense for a lot of companies and organizations out there.

Speaker:

and guess the question, I, again, I'm.

Speaker:

not Technical more at the kind of higher level understanding

Speaker:

what the, to understand, what the problems are putting together.

Speaker:

Some solutions.

Speaker:

One of the challenges is that you have so many different vendors

Speaker:

of so many different tools.

Speaker:

And so do you look for these custom bespoke kind of solutions

Speaker:

and tools, or do you work with.

Speaker:

a Platform provider, for example, Microsoft 365 has

Speaker:

a lot of DLP tools in there.

Speaker:

They have, advanced threat protection.

Speaker:

they have antivirus, anomaly detection, all of that's built in there.

Speaker:

so do you, and then device management as well.

Speaker:

Or do you say no, we don't want to put all of our eggs in the Microsoft basket

Speaker:

and we want to go for best in breed.

Speaker:

And I don't know.

Speaker:

Prasanna like at, I don't know how much you can talk about at Zoom but like, how

Speaker:

do you guys decide, what kind of a tool are you going to go with a, an integrated

Speaker:

approach or do you look for best in breed?

Speaker:

So I can't talk specifically about Zoom but in general, right?

Speaker:

I think it's going to come down to.

Speaker:

The need for a tool, as well as the expertise.

Speaker:

If I'm looking at sort of small, medium businesses where maybe they

Speaker:

don't have specialized it admins, we face the same thing in backup as well.

Speaker:

There is no one who could go learn everything and

Speaker:

anything about security tools.

Speaker:

And so you're going to probably want a single tool that allows

Speaker:

you to solve everything.

Speaker:

Just like in backup.

Speaker:

You have those issues as well, but once you get to larger companies,

Speaker:

or if you have specialized problems, you might start to.

Speaker:

rollout into, okay.

Speaker:

I now need a specialized tool, a best of breed tool because I have this special

Speaker:

need, or I now have the skillsets to be able to address some of these issues.

Speaker:

And therefore I'm going to pick different tools based on my needs.

Speaker:

And I think it's hard to say one is better than another.

Speaker:

I think it depends on where you are and what your needs are.

Speaker:

Yeah, I would agree.

Speaker:

and not just because I work for a SaaS company, but I would agree that where

Speaker:

there's a big business need, that you have such as email, clearly a business

Speaker:

need a need that every business has, that if a SaaS solution is available

Speaker:

and it's a well-known respected cetera solution that you can vet out then.

Speaker:

from a security basis, I would prefer that over something that you're going

Speaker:

to, let's say I would prefer Microsoft 365 over exchange on prem a heartbeat

Speaker:

exchange on prem is harder to secure.

Speaker:

It's harder to manage.

Speaker:

So you've got to manage the system.

Speaker:

You've got to manage the storage and then you got to manage the backup of that.

Speaker:

And then you gotta make sure that backup gets off site.

Speaker:

of that is easier.

Speaker:

If you have Microsoft 365 now you should be backing it up, right?

Speaker:

Microsoft is not backing it up for you.

Speaker:

That was what you and I talked on your podcast, but there are services,

Speaker:

that will back up, obviously Druva offers one, but there are many

Speaker:

companies that backup Microsoft 365.

Speaker:

And so I think from a security basis, as long as you vet the security vendor,

Speaker:

look at, look for things like MFA, look for things like, what their NDA situation

Speaker:

is to cut the type of data that they have, whether or not they share personal

Speaker:

information, cause some, so many of these SaaS vendors, that's actually

Speaker:

their, their business model is they're either cheap or free, and they make.

Speaker:

You know their money with using your personal data?

Speaker:

that's, that's not what I'm

Speaker:

Yep.

Speaker:

No.

Speaker:

it's interesting.

Speaker:

when you talk about, tool selection, I think another factor should be,

Speaker:

do you have the in-house expertise?

Speaker:

and if you don't, how accessible is it on the market?

Speaker:

Because right now, depending on what tool you're trying to deploy,

Speaker:

it could be very challenging.

Speaker:

you can get a great deal and that's interesting, cause it would be what

Speaker:

people will start talking about.

Speaker:

how much is this per seat or per license One of the things that

Speaker:

you have to look at is what are your deployment costs going to be?

Speaker:

And then what are your ongoing maintenance costs going to be in

Speaker:

terms of the expertise to manage that?

Speaker:

And that's something that often come into play until after the,

Speaker:

Yeah.

Speaker:

they focus on the technology, or the vendor, but not on the

Speaker:

total cost of the deployment.

Speaker:

And, I would encourage everybody.

Speaker:

to do that

Speaker:

Yeah

Speaker:

And also along with the deployment, it's how flexible is it to change

Speaker:

as your environment changes as well?

Speaker:

I think some in some tools are very static.

Speaker:

It's easy to deploy the first time, but anytime you add a new app or a new

Speaker:

environment or something else, it becomes very difficult Or it's time consuming

Speaker:

to get it, to expand to now cover that new workload, versus maybe it's

Speaker:

better to get something that might be a little bit more complex for the initial

Speaker:

deployment, but like you said, ongoing maintenance, ongoing monitoring, All

Speaker:

the rest of that becomes a lot easier.

Speaker:

Yeah,

Speaker:

lots of sense.

Speaker:

I think that's why from a security basis, I'm a big fan of SaaS apps because

Speaker:

you look at again in the backup space.

Speaker:

if you're using an on-prem backup software, you must be up to date.

Speaker:

on what, you have both box, maybe multiple boxes that are, you might have

Speaker:

a server, you might have a storage array and a. that you must be up to date on

Speaker:

that operating system and protecting that operation, securing it, doing

Speaker:

all of those things, hope you have MFA on that backup server, by the way.

Speaker:

and then you've got the software, the backup software that you have to stay

Speaker:

up on and people are notoriously very bad at upgrading their backup software

Speaker:

that, the, we, we brought a guy over from Veritas and he told us that their best.

Speaker:

guess was that the average time that customers took to upgrade

Speaker:

their backup software was 18 months.

Speaker:

If it works, don't touch it.

Speaker:

what's that

Speaker:

If it works, don't touch it.

Speaker:

People are terrified of upgrading their backup server.

Speaker:

Cause it's the last line of defense, but the problem is back up.

Speaker:

The problem is that ransomware folks, specifically the Conti group are

Speaker:

specifically targeting backup servers.

Speaker:

so not only is it, something that, that needs to be protected.

Speaker:

It is a, it is a direct attack point,

Speaker:

I'm curious because we touched on consumers before.

Speaker:

what are your recommendations or suggestions for just individuals, to, in

Speaker:

terms of backing up their personal data.

Speaker:

I'm going to sound like a broken record, but SaaS backup, man,

Speaker:

Okay.

Speaker:

there are SaaS backup Druva's not one of them.

Speaker:

There are SaaS backup companies that target consumers and you're,

Speaker:

you're looking at 50 bucks a year, that sort of thing.

Speaker:

I, pay more than I would like to back up my iPhone, like I pay for paid for iCloud.

Speaker:

So that's, there's that, but there are a number of services that will back up.

Speaker:

What's important to you.

Speaker:

and specifically if you've got a, if you've got a laptop, and

Speaker:

let's be honest, you got a laptop.

Speaker:

it's.

Speaker:

It's not that hard to get that laptop backed up.

Speaker:

I am not a fan of using.

Speaker:

USB devices to backup the laptop.

Speaker:

know it works.

Speaker:

The problem is that USB devices generally sitting right next to, or in the same

Speaker:

bag that the laptop itself is you get a theft, there goes your backup,

Speaker:

you get a fire that goes your backup.

Speaker:

So I much prefer for the same reasons for the companies.

Speaker:

I prefer a cloud-based system that will backup the most important stuff for you.

Speaker:

Right.

Speaker:

I'll Disagree with Curtis here

Speaker:

Okay,

Speaker:

I am.

Speaker:

here we go.

Speaker:

I agree that to some extent, yes.

Speaker:

SaaS based is good.

Speaker:

I just muted your microphone Prasanna

Speaker:

Thanks, Curtis.

Speaker:

I've never done that.

Speaker:

That was fun.

Speaker:

So I agree that there are certain things that you do, you will, you

Speaker:

want to use a SaaS based service.

Speaker:

for But if you're not willing to shell out, or if you don't think you

Speaker:

really need it, take at least what's there with your existing, laptop, for

Speaker:

instance, if you have time machine, I know Curtis, we've had the discussion

Speaker:

about time machine in the past.

Speaker:

You're not as thrilled about it, but if you do have a mechanism,

Speaker:

use that mechanism rather than.

Speaker:

have nothing Right.

Speaker:

I'd rather have someone

Speaker:

Yeah.

Speaker:

something rather than being like, oh, do I want to pay $50 a year or whatever it is?

Speaker:

Yes.

Speaker:

Those are better solutions, but take what you have and just do.

Speaker:

something

Speaker:

Yeah, I'm not going to disagree with that.

Speaker:

the only thing I will say is that hard drive that you, if you have the hard

Speaker:

drive already, I'm not saying it's bad.

Speaker:

I'm just saying you just need to think about the fact that, that hard drive

Speaker:

is, it's so do things like rotate,

Speaker:

Yeah.

Speaker:

problem is you go buy You go buy a modern hard drive.

Speaker:

to, to back up your system.

Speaker:

that's going to be a hundred bucks plus, That's a couple of years of

Speaker:

the service that I'm talking about.

Speaker:

Yeah,

Speaker:

just saying,

Speaker:

I got it.

Speaker:

I got it.

Speaker:

Yeah.

Speaker:

I thought, I think the big thing is just do something.

Speaker:

Don't do nothing.

Speaker:

Yeah,

Speaker:

I think we're saying that for, I think that's our summary statement.

Speaker:

Maybe we'll make that the pilot title of the podcast just do something.

Speaker:

the Nike thing, but just put, just change it to something.

Speaker:

do something.

Speaker:

it's not as inspiring as it, but something,

Speaker:

I like it.

Speaker:

Hey, I

Speaker:

yeah.

Speaker:

something.

Speaker:

cause you asked me earlier.

Speaker:

how did your, the idea to do a podcast come about and and your

Speaker:

friendship and how did that work?

Speaker:

I dunno, I got the idea of doing a podcast after being.

Speaker:

After going from not believing in podcasts.

Speaker:

Like I didn't get it.

Speaker:

I didn't understand why anybody would do a podcast.

Speaker:

and then I started listening to podcasts.

Speaker:

I got in a situation where they were valuable to me as a person.

Speaker:

Then I was like, I talk a lot.

Speaker:

Maybe this would be something to do.

Speaker:

And and then I encountered Prasanna in the office, he used to work at Druva,

Speaker:

that's how, that's where I met him.

Speaker:

And, I went up to him.

Speaker:

And, I proposed the idea of us doing a podcast together because I thought

Speaker:

that we had a, a decent interaction and Prasanna just jumped at the chance.

Speaker:

Didn't you Prasanna

Speaker:

I was like, what are we going to talk about for 20 minutes?

Speaker:

I have nothing to talk about at all.

Speaker:

I don't know what you're talking about.

Speaker:

yeah.

Speaker:

It very quickly evolved into kind of a forty-five minutes About three years ago.

Speaker:

3 years ago?

Speaker:

Yeah.

Speaker:

I remember first couple of episodes and being okay, we got to plan this out.

Speaker:

What are we going to talk about?

Speaker:

What are the questions?

Speaker:

And for me, it just evolved into, I just like to have a conversation,

Speaker:

this is, let's just see where it goes.

Speaker:

Most of the time it works, sometimes it flops, but.

Speaker:

Most of the time it works.

Speaker:

Yeah.

Speaker:

And sometimes we get, really just a really banter going and, you can sometimes

Speaker:

uncover some really interesting stuff.

Speaker:

I got to say that I feel, extremely I'm looking at Curtis's background and he's

Speaker:

got diplomas or certificates or something.

Speaker:

At least he's got books there.

Speaker:

yeah.

Speaker:

That's my book right there.

Speaker:

Oh,

Speaker:

Yeah.

Speaker:

little

Speaker:

Behind me.

Speaker:

there on the shoulder.

Speaker:

Yeah.

Speaker:

A little, just a little bit.

Speaker:

Yeah.

Speaker:

it's a very small, so it's not that good of a product placement, but, yeah.

Speaker:

Anyway.

Speaker:

Subliminal.

Speaker:

Yeah.

Speaker:

yeah.

Speaker:

all thanks a lot, mark, for coming on the podcast

Speaker:

this has been awesome.

Speaker:

I don't get a chance to be on too many other podcasts other than my own.

Speaker:

And, I've really enjoyed this.

Speaker:

You guys are awesome and funny and obviously very, deep subject

Speaker:

matter experts in this area.

Speaker:

So I've enjoyed it.

Speaker:

I, and unlike being on your podcast, you can now just leave

Speaker:

and then I have to edit it.

Speaker:

I'm out of here.

Speaker:

What are you going to get this edited?

Speaker:

Yeah.

Speaker:

is he gonna go online,

Speaker:

Yeah.

Speaker:

come

Speaker:

Yeah, exactly.

Speaker:

Thursday.

Speaker:

Exactly.

Speaker:

All right.

Speaker:

right, guys.

Speaker:

Hey,

Speaker:

and thanks.

Speaker:

and have a great 20, 22.

Speaker:

Okay.

Speaker:

Cheers.

Speaker:

thanks Prasanna it's, even though you ditched

Speaker:

me

Speaker:

I'm sorry.

Speaker:

Curtis curtis know

Speaker:

and,

Speaker:

I'm sorry, I disagreed with you about SaaS but yeah, do something.

Speaker:

whatever.

Speaker:

All right.

Speaker:

And

Speaker:

Thanks mark.

Speaker:

make sure to subscribe so that you can restore it all.