Cybercrime Is a Human Problem: What MSPs Need to Know
with Sean Walsh, CEO of Encore
Cyrus Walker joins Encore CEO Sean Walsh on Profit Grow Exit to explain why cybercrime is a human problem, what MSPs get wrong in the first hours after an attack, and why the MSP model has to move from alerts to operations.
On this episode of Profit Grow Exit, a podcast for managed service provider (MSP) owners, Cyrus Walker and Encore CEO Sean Walsh — a former police detective and computer forensics investigator — trace their paths into cybercrime investigation and make the case that cybercrime is a human problem, not a technology one. They walk through the mistakes MSPs make in the first hours after an attack, from wiping the drives that hold the evidence to restoring backups that bring the vulnerabilities back, and discuss how AI is lowering the bar for attackers while helping defenders cut through the noise. Cyrus closes on why MSPs need to move from a monitor-and-alert model to a co-managed, operations-driven one.
Hello, and welcome back to another episode of Profit Grow Exit, the podcast where we help MSP owners build stronger, more profitable, and more valuable businesses. Today, we're diving into a topic that every MSP talks about, but very few truly understand: cybercrime and what actually happens after an attack.
Joining me today are two people who have spent decades on the front lines of this issue, Sean Walsh, our CEO here at Encore, a former police detective, computer forensics investigator, MSP founder, and educator, and Cyrus Walker, who is the founder and CEO of Data Defenders. Cyrus has been working in the cybersecurity since the mid-1990s and has trained law enforcement through the Department of Homeland Security. He's helped build cybersecurity programs for colleges and universities and has led countless incident response investigations. So thank you so much for both of you for joining me today. Thank you for having me.
Absolutely. Thank you, Abby. This is gonna be a fun one. I feel like I'm getting back to my roots.
Yes, I think this is gonna be super interesting for our listeners, and I'm looking forward to learning something new too. So let's jump into it. Cyrus, you have been involved in cybersecurity before most people even knew the term existed. Tell us- Mm-hmm ... how you found yourself building a career investigating cybercrime and how you kinda got to that point. So yeah, I started out, uh, in the early '90s, uh, building high-speed wide area networks.
And, uh, as things became more complicated, uh, for the organizations that I was working for, uh, we also saw a need for this new trend that we were hearing about, um, hacking. Um, and so I began to transition into cybersecurity in the mid '90s, um, working with, uh, uh, what I would call prehistoric cybersecurity equipment like the Raptor firewall, which was a software-based firewall that you had to install on a Sun Microsystems, uh, computer, uh, with multiple network mix to connect between your, your, your Cisco, uh, 21X routers.
Uh, it was very rudimentary at the time. Um, and, uh, as, as my work continued there, I, I continued to find myself specializing more and more in cybersecurity. Uh, in the, uh, early, uh, late, uh, uh, uh, as my kids call it, the late 1900s. Uh, and they're like- Um- Right, right. They said I was born in the late 1900s.
I said, "You're grounded for the next 20 years."Um, but in, in like '98, '99, um, I, uh, uh, uh, uh, found myself becoming more specialized, uh, in that and, um, began to work for a company, uh, that was completely dot-com focused. Uh, and they had brought me on board to build out their cyber practice, cybersecurity practice. And, uh, of course, we all know what happened in 2000 with the, uh, dot-com bubble bursting, and I was let go and, uh, decided that, uh, since I knew what I was doing, I would go and do this on my own.
So I started my own cybersecurity company focused on providing advisory services, professional services, and then found myself in teaching, um, where I wound up teaching for the Department of Homeland Security and the s- city colleges of Chicago, uh, training law enforcement and other professionals looking to make a transition into cybersecurity and, and, uh, incident response and investigating cybercrime, uh, and so forth and so on.
And so, um, that was my progression from a technology networking background to, uh, cybersecurity and focusing on incident response and cybercrime. Well, I'm excited to learn more about your expertise some through this podcast. Now, Sean, just for everybody who's listening, your journey started in law enforcement rather than IT.
So how did a police detective end up running an MSP? You know, um, so after I made detective, I realized that if I wanted to continue in my career path, I should probably go back to school and complete my bachelor's degree. And, uh, ironically enough They signed my second class, they signed me up for a computer class. And I said, "I don't wanna learn anything about computers. I hate computers.
Find another class for me." And they said, "You know, sorry, this is the only thing that fits your schedule. It's required. Just suck it up and take it." And I wound up going into this class, and I just, I was like, "Wow, this is, this just clicks for me."
And I wound up changing my major to, uh, to computer science and business. And by the end of that class, I had maxed out three credit cards, got my first 286SX and had the whole thing stripped down, taken apart, and put back together and, and, uh, found I really liked this. And at the time, the police department was starting to go computerized, and we had a part-time police officer who was a full-time software engineer at Digital Equipment, and, and I learned on the MicroVAX system.
And, and he started developing a records management system for police departments, so he kind of coached me along and he said, "Hey, you know, do you wanna, do you wanna help me and learn some of this stuff?" And so I jumped on board. So I'm learning all this stuff in a police context of, of records management, different types of systems, PCs, MicroVAX, and then all of a sudden we're starting to see a new kind of crime come in, and it's computer crime.
And all of a sudden there are computers involved in these investigations, and everybody else is looking at each other and I'm going, "Hey, I know how that thing works." And so I became the de facto expert on it. And, and now again, going, going back, and I'll age myself a little bit differently than Cyrus did, but you know, I started doing computer forensics when I could analyze an entire hard drive manually using Norton DiskEdit, which means you're actually looking at the zeros and ones yourself.
You don't have a system going through it. Um, and that's where I started on that, and I really found that I had a love for it and, and, uh, I had a couple of early wins in cases where we found evidence on hard drives that, uh, the person thought they had disposed of. It got me really excited. But I also saw that there's a need for training and understanding on how to memorialize this evidence in the future so that we don't lose it. And other police officers had no idea how to do or that, that even there might be evidence on these devices.
And so that's where I really did a deep dive in forensic. I started using tools like EnCase. Um, it's now owned by a different company, but it's an analysis software, and it allowed us to, to make, uh, copies of the drives that were forensically correct, so which means we're getting all the deleted data and, and data that most users don't see. Uh, and then I started teaching computer crime investigation at the New Hampshire Police Academy. We did one of the very first, um, computer, uh, uh, computer crime scene response courses, uh, in the country there.
Uh, myself and a, a friend of mine who's a retired FBI agent, uh, taught that class together and developed the curriculum.
And then I found that I was kind of making more money on my days off than I was as a week of, uh, being a d- uh, a detective sergeant at the, at the, who was heading the d- uh, division. Um, and then it came to a point where I had to make a decision, which career am I gonna pick? And, uh, my wife basically told me, "I don't care which career you pick, but pick one."
So I decided we, we... I started up my company, uh, um, and, uh, we created, uh, what became an MSP, but our focus was on, uh, medical, legal, and, and banking, and financial services because those people all had a compliance obligation, and they needed to have an awareness of, of, um, of computer crime and regulatory components before anybody else did i- in, in, in IT.
So that was kind of, uh, how I got my start, and that was, that was the path from, you know... I, I get the question all the time, "How the heck did you go from, from being a police detective to this?" And I'm like, it, it actually was more logical than, than most people would think, so. Um, but that was it, and, and here we are today.
But I, I still have a love for, uh, you know, for the, the, the, the, the crime scene aspect of it and, uh, and, and what we can do combining those two passions in my life. Now, we often hear that cybersecurity is a technology problem, but you both mentioned in our last conversation that you tend to disagree with that.
So can you tell me or discuss amongst the two of you why you think that cybercrime is really a human problem? Well, um, w-we look at it as a human problem because if you take the human being out of the equation, then you no longer have any cybercrime. I guess. Uh, well, no, that was before AI came online, and who knows how sophisticated that's gonna be in, in, in, uh, wreaking havoc, uh, in our lives, but that remains to be seen.
But, um, uh, you know, when you look at, uh, the, the, the whole, um, framework of the environment of technology, w- um, you know, and software really is where it stems from. You know, hardware is not the issue at all. You know, we're talking strictly about software. Who designs software? Well, the human being does.
You know, who, uh, uh, looks to ex- identify and exploit vulnerabilities?
It's the human being. You know, who is managing and misconfiguring, you know, devices and that run, that run a technology infrastructure for a business? It's the, the, the human being. Um, you know, who's impacted by, uh, you know, cybercrime and, you know, the nefarious activities that go along with that? It's the human being.
So this is really a, a, a human problem, and there are ve- there are a number of ways to, uh, address it. And obviously from our perspective, we do look at the technology as particularly the software, because that's typically where the main target is. But now y- y- you know, you have things like social engineering, where the human has become the target.
Uh, but again, there's that, that word, the human being. Um, so we, we, we, we approach it from that perspective, um, because that is prevalent throughout the entire landscape of cybers- cybercrime, cybersecurity, technology management, so forth and so on. That's the common denominator. Yeah, absolutely. You know, when, when you, when you look to, um, break into something or, or do a compromise, what you're looking for is the weak link in the system.
And historically, the weakest link is always the human link. And one of the first kind of celebrity hackers out there was a guy by the name of Kevin Mitnick, and, and he was a very early, um, um, uh, hacker the way he wound up doing federal prison time. And like, like all federal, uh, hackers, like all hackers who do time in prison, they become a consultant when they get out, and Kevin has written several books, and they're very good. But the majority of what he talks about is social engineering, which Cyrus mentioned, which means he wouldn't do a brute force attack to maybe get a password where you're using... He wasn't using the technology.
He was actually picking up the phone and going, "Hey, this is Kevin at the help desk. I, I'm fixing something.
Can you give me the password for this system?" And people would just give it to him. Or he would show up dressed in a, uh, you know, a uniform of the person who fixes the internet, and he would just walk right into a place. And, but it, but he was very, very good at exploiting the human weaknesses to get into the systems that he wanted to get into.
And I think, I think most people, um, who are not in technology and not in computer crime greatly underestimate this because they perceive it as a technical crime, and it is not. It is very, very much a human crime, like, like every other crime. And, you know, we joke around about, we joke around about the spam emails, you know, the, the Niger- it's called the Nigerian prince, where, "Hey, I'm a Nigerian prince and I inherited this money and I need to get it out of the country."And people look at that nowadays as a technical crime. But back when I became a police detective, we used to get those letters on paper. That was, that was not done with technology.
That c- that whole crime, these things that are done with spam and links were actually done with physical paper and physical bank accounts before it became a technological crime.
So it's always been a human thing. Right. It's interesting. I think, uh, myself born in the very late 1900s as, as a millennial has a unique ex- uh, experience with technology because while I wasn't completely raised with it, I've been ingrained in it since high school and college and beyond. And I think that, you know, we tend to see, like the Nigerian prince emails, I think people in my age demographic were like, "Uh, yeah, that's a scam, Mom and Dad and Grandma, don't do that."
But they've gotten so good now that there's some that working in technology I can spot certain things, but I, I say, "Man, I think I could have fallen for that if I didn't know better." Uh- Yeah ... that being said, Cyrus, you've worked hundreds of these incidents over the years. Do you see the same patterns, different patterns?
Are they changing? Well, uh, the one pattern that I see emerging, uh, quite, uh, significantly is a, a pattern of focus on the human element and not on the technology. You know, the technology has gotten pretty sophisticated and pretty complex, but, uh, I think hackers have, have wised up and realized that they, they wanna maximize their, their time and their profit, and the best way to do that is to focus on the human element. Um, and I'll give you an example. We had a, w- a, a previous customer of ours, um, uh, we were, uh, we provided full-scale cybersecurity operations for them for six years.
Uh, it was a municipality. Um, they, uh, uh, we, we got them to zero breach over that s- six-year period. Um, they end up, uh, the political winds of change in Chic- in Chicago, if you will, you know, as they say, you know, blew very hard, and as a result, the change of administration, administration decided to change our vendors.
So, you know, we were, we found ourselves on the outs. Four months later, they wind up with a cyber incident. Cost them $1.2 million. Wow. The cyber incident targeted their contro- that controller through a phone call to get this person to give up their credentials so that they could log into the system.
They weren't spending a whole lot of time trying to brute force passwords or, you know, uh, uh, do enumeration on systems to find out code versions or operating system versions to then do vulnerability research and so forth and so on. They simply picked up the phone and called a person who was unsuspecting and got them to give up the credentials, and voila, they were in and were able to siphon off, what, you know, $1.2 million. I have always said that you can spend a billion dollars on a cybersecurity system, and it just takes one person to give away the password to render that system completely useless, and that's exactly what happened. Um, so that's the trend that we're seeing. We're, we're seeing a trend focusing on the, the, the human being because as, as Sean mentioned, they're the weakest link.
And so why, why attack a, uh, you know, a firewall that sits on a, uh, you know, a device that's able to process, you know, a billion packets a second or something like that, you know, that can detect that threat in the payload? Focus on the human being who is unsuspecting. They're probably busy in their day, not paying attention. You know, you catch them on a good day, you're gonna get exactly what you need in a matter of minutes in order to do what you, what, what you're planning to do, which is to get into the system and then, uh, you know, deliver your payload, whatever that is. So that's the trend that we're seeing.
And I know we're gonna talk about AI a little bit, but, you know, as we see AI, you know, come online and become more sophisticated, we see those attack vectors becoming more robust as well, those attack vectors foc- focused on, uh, the, the human element. And so those are the trend...
Well, that's the, the one major trend we see, uh, today. Well, and to stay on that topic a little bit, I think that's where a lot of MSPs may have a blind spot because w- I don't wanna say everybody, but a lot of, a lot of MSP know how to prevent attacks. They know what to do to, to, with the technology side.
But what happens if and when one actually happens? So can you walk us through what you should do in those first hours? Uh, what, what happens after the attack happens? Yeah. So, um, y-you know, a basic framework, uh, and Sean mentioned this word, um, forensically correct earlier.
Mm-hmm. Um, what, what, what typically happens is there's a mad scramble to regain control over the, uh, or reestablish operations.
You know, systems are down, business is stopped. You know, now everyone is running around like a chicken with their head cut off to get everything back up and going because you got management breathing down your neck. You know, no one, no one wants to be looked at as responsible. You know, people are trying to do what's necessary to restore operations.
And so what you have happening is people tripping over each other. You know, you have ta-taking systems offline, re-imaging systems, so you're losing evidence. Um, and, and, uh, and you're making the problem worse because in, in, in today's advanced, uh, threat vector environment with ransomware, for instance, if you have a sophisticated ransomware variant, uh, attacking your system and you are shutting down systems or unplugging networks or, or, or doing those kinds of things, if that ransomware variant is sophisticated enough, it's gonna be calling out to a command and control center to, uh, change itself so that your virus or your malware detection or eradication system, uh, can't detect it so that it can cont-continue to do what it's doing.
We saw that in a, a, a very huge, uh, ransomware attack on a, a, a, a, a, on a local, uh, police agency here in Chicago about, um... This happened maybe, maybe about 10 years ago, where someone got a link from Amazon. They clicked on it. It was a ransomware link. It started, uh, replicating itself across the environment.
First thing they started to do was to take these systems offline to run their, um, uh, a malware eradication software. I believe it was McAfee at the time. Um, but McAfee just could not keep up. It was, it was, uh, duplicating itself, uh, across the network. It was changing itself 'cause it kept calling out, uh, to a command and control, uh, center, uh, or, or, or, or server, uh, to download new variants.
And for three weeks, they were chasing themselves trying to get this thing under control. Um- The first mistake that they made was that they didn't call the professionals. They, they tried to approach this from an IT perspective, and they didn't call, uh, uh, the professionals in until three weeks later when they realized they just couldn't get their arms around it. Three weeks. Wow.
Three weeks, yes. And when we came in, we immediately determined that this was an advanced ransomware variant that, uh, was calling out. And so the first thing to do was to shut down those ports so that it couldn't call out anymore to give McAfee an opportunity to catch up in its eradication process to get these systems clean.
Uh, so go back to your original question. That's the first mistake people make is they, they go into a restoration mode instead of into a triage mode. And I, and I get that, you know. You, you, you see what's happening, you know, your systems... And, and this is really a, a, um, it's a, it's, it's a judgment call, you know, to some degree, uh, depending on the data that's being impacted, you know, by the ransomware variant.
But, um, I, I think that the very first thing they should be doing is calling their, uh, professionals if they have a relationship with a, uh, with a, with a, uh, uh, incident response, uh, company that can deliver incident response services, uh, a computer forensics examiner, you know, that can come in and help them, uh, start the triage process to really understand what's going on, what's been impacted, uh, and then develop a strategy of, of approach to attack this, this thing, uh, in order to get their arms around it.
So those are some of the things I think that, uh, people make mistakes in. And, and, and, and to go back to the, um, beginning part of all of this is most of, most companies don't have a tested incident response plan. They may have a template that they've downloaded from somewhere and they filled in, you know, the, the, the fill in the blanks.
Uh, it's not tested. They don't know if they can actually execute it. They're really just meeting some compliance checkbox that, uh, their insurance company might have required them to do or, you know, some compliance, uh, regulatory compliance, uh, has, uh, stipulated that they, that they needed to meet. So they don't have that plan in place that helps them to really understand their own capability in responding to an incident and doing so in a preplanned and, and tested way. It's like a fire drill with your kids.
Everybody knows where they need to go. Right. Right. Absolutely. Absolutely.
Yeah. Just to reiterate, I can't stress that enough. And, um, to exactly what Cyrus was saying, you know, an MSP's mindset is, "Let's get the customer back up and running." And what I... And, and, you know, uh, you know, you seem shocked about the three weeks to get to the experts, and, and the shocking part is how common that is because they are just, they just wanna get the client back up and running 'cause that's what the client pays them to do.
And, and they're not, they're not law enforcement people, they're not, they're not, um, incident response people. So I, I understand the mindset and why that comes first. But what, what MSPs should really be doing in this day and age is when you, when you sit down with a client, part of your onboarding should be to find out who their insurance provider is.
Call the insurance provider, say, "If this client was to have an attack, who would you be sending out? How would you want us to respond? Can you, can we work with you to build an incident response?" So when that alarm goes off and that client calls up and says, "Oh my gosh, one of our employees clicked on this link, I think we've been hacked," you can take steps immediately to do things in the right order so that you can get the client up and running, but you can also keep the integrity of the evidence intact.
A-and, and so an example of that is when you start erasing hard drives, you go, "Oh my God, we've been hacked. Let's just wipe out the hard drive and, and go, you know, let's restore from backup." You are wiping out and overwriting critical evidence, because the evidence that we're gonna be looking for in that investigation is on that hard drive.
Even if files have been deleted, there's remnants of, of the, the files that are still there. But when you format the drive, in most cases, you're going to get rid of all that. So it, it's almost, it's like you walked into a murder scene with a gallon of bleach and just started spreading it around. That was...
I-I-I-Imagine if a police department did that as their first response to a murder scene. You'd, you'd go, "Oh my God, are these people crazy?" But that's what we're doing when... That's what a lot of MSPs are doing when we have a cybercrime incident. And you know, I, I used to tell them, "Look, if, if you feel like you have to do something, just pull the plug."Pull... Don't try to shut down gracefully, just pull the plug out of the wall.
Cut the power, leave it because you're at least you're, you're freezing it in a state of time. Take the hard drive out, 'cause that's where the evidence is. Plug in a new... Go to the store, buy a new one. Hard drives are cheap in the grand scheme of things.
Restore from that, and then put that hard drive aside, label it, date it, put it in a box, put it in a safe, maintain control of it so we maintain the chain of custody and the evidence. But at least that is better than what, how most people are responding, and that will at least memorialize the evidence on that hard drive in that point in time.
Yep. One of the things I wanna add to what Sean is saying is in, in the restoration process, most often when you're restoring from a backup or an image, you're more than likely restoring the vulnerabilities back onto that system as well. Um- Great point, Cyrus. Yeah. Great point.
Yeah. And, uh, so what... So, so one of the things you wanna do is you wanna run that image through some kind of assessment to identify any vulnerabilities on it, uh, or c- configuration issues on it that might have led to that, uh, issue in the first place.
And that's why the triage piece is so important, because it, it can lead you to understanding, uh, what the, uh, cause, the root cause of that issue was in the first place so that you're not reintroducing that back into your environment. 'Cause one of the things that attackers are gonna wanna do is establish prevalence over your environment.
So when you get rid of one thing, you know, there might be another thing there that they've already gained control over and, and are going to use that, you know, once you've closed that door, that first door on them, that that second door is still open. Mm-hmm. And so you wanna make sure that the, that if you're restoring from backups or images, that you're not reintroducing the same vulnerabilities in that got you in the, in that situation in the first place. Yeah, and to, to build on that point, the, um, not only by the time you realize you've been hacked, there's a good chance you've done a couple of backups and the, and now- Right ... the virus is on- Right ... the backup. Right.
But some of the more advanced attacks now will, will, once they're on your system, they will seek out your backup drives- Mm-hmm
and they will infect the backup drive. So it's not even just that you're copying it. The, the virus or the attack will actually seek to corrupt the backups or wipe- Right ... them out, which is one of the reasons why in your backup strategy, you have to have air-gapped backups, where you're- Mm-hmm ... actually physically detaching them every- Right
so often from the network, so you know that there's not a path from the main system, which has been breached now, to the backups. Right. Absolutely. That's absolutely correct. That's all really good information for everyone to hear, but our MSP listeners for sure.
I do, I wanna shift gears just a little bit here because you did mention AI, Cyrus, and that is something that we are all hearing about every single day, and it's moving incredibly fast. Should MSPs be excited, nervous, or maybe a little bit of both? Yeah, you know, it should be a little bit of both. Um, you know, AI is a definitely a benefit and a challenge for everyone involved, uh, particularly MSPs, and here's the reason why. Um, just like, uh, uh, the, the, the customer, you know, and particularly when it comes to cybersecurity, there's a lot of telemetry being generated these days, uh, from these devices that, um, is overwhelming to the human component of a, of an, uh, of an infrastructure, of an operations.
And because it's overwhelming, you are more than likely going to miss what we call that needle in the haystack, uh, that identifies the presence of that threat in your environment. Um, it's, it's, uh, you know, there's been some data and some statistics given out that says that, um, you know, by the time a-an attack is discovered, that attacker has been in your environment for up to eight months doing footprinting and enumeration to figure out, you know, how to maneuver through the, uh, architecture.
And, um, and the reason why they're able to do that is because of all the telemetry that's being generated, not just from cybersecurity, but also from the technology devices, the routers, the switches, the, the servers, the computers, everything generating data on a daily basis, and that, that, the presence gets drowned out by that, what we call noise, uh, from a cybersecurity perspective. And so what AI will help you do is to, to, to do what's called aggregation, correlation, and analysis of all that data to get some context around what's going on, um, to identify that needle in the, the needle in the haystack in a much more faster way. So that's the benefit to MSPs, being able to automate a lot of the processes that are traditionally done manually in a, in a, uh, in, in a SOC or a NOC, uh, being able to process data in a, uh, much more faster way, uh, to get down to what you're actually looking for, uh, and, and, and, and, and being able to automate some of those processes that, that, uh, you know, allow you to quickly, uh, manage, um, identify vulnerabilities and issues, uh, and in some cases rectify those vulnerabilities and issues, um, through the automated process.
Now, of course, on the bad guy side, you know, that's allowing them to process data much faster. That's allowing them to get to what we call the little fish in the big pond in a much more, much more cohesive and collective way. So, you know, we say that, you know, you're no longer a little fish in a big pond, you're just a fish in the pond, uh, that will eventually be discovered. Uh, and with AI and quantum computing coming on at some point in time, you know, that's just gonna make it even worse. So, um, you know, with s- with, with, uh, w- targeted attacks like what we talked about, you know, with social engineering, you know, you see those attacks getting much more sophisticated, you know, with deep fakes and voice fakes and all those things that are, that are now, um, prevalent and prevalently used these days, uh, that, uh, makes the, the, the, uh, the human element that much more vulnerable.
Um, so it's, it's a, it's both a win and a challenge for MSPs and for everyone involved for that matter. But, um, I'll take the win because that allows me to deal with the challenges in a much more cohesive way. Mm-hmm. Anything to add to that, Sean? Yeah.
Uh, um I-I, from the bad guy perspective, AI is gonna lower the bar to entry.
You don't have to be a brilliant, smart bad guy like Kevin Mitnick. You can be a not so bright bad guy who just knows how to ask the right question on a computer terminal now, and it's gonna give you the smart guy answer. Um, so that's where we have to be careful, because I don't have to know, I don't even have to know how to code anymore.
Now I can just go into, into Claude or some AI tool. I think Claude has some barriers if it thinks you're doing something bad, but, but there's lots of other AI tools out there. You could even, you know, buy a, a Mac Mini with enough horsepower and run your own LLM and just say, um, "Hey, write me a script to, to break, to, to take, uh, to, to exploit this vulnerability on this piece of software," and there it is.
Yep. I didn't have to write a line of code, I just had to ask for it. So, so we have on the bad guy side, the bar being lowered so... And even, even on the social engineering, "Hey, write me a script so that I can call up and convince this person to, to, um, uh, give me their password." So you don't even have to be a brilliant social person anymore.
And, and on the flip side, as Cyrus said, for those of us responding to these things, we can act faster, hopefully use AI tools to identify the vulnerabilities faster, um, identify the attack vectors faster, and then come up with a response plan faster. So it's, it's a double-edged sword. Um, but, uh, you know, we'll take the win, and you can't put the genie back in the bottle.
It's- Right ... it's out there, and so we have to, we have to work the positive side because I can assure you the bad guys are gonna be working their side of it too. Yeah. It's, it's making bad guys very lazy. Uh- ... they don't have to work, they don't have to work hard anymore, you know? Right.
They literally don't have to make that phone call that you mentioned, Sean.
I know. You know, they can, they can clone their voice or, you know, th-there's a, there's a threat vector out where, you know, you get a phone call, you know, someone on the other line, they ask you a question, they get you to respond in a certain way. Uh, they take that, and they're recording you. They take that recording, they create a duplicate voice, uh, uh, of you, and then they can use that, you know, for whatever nefarious deeds, you know, that they, that they are, uh, uh, seeking to execute.
Um, I mean, we use it for good, you know, on, on our side, uh, to streamline a lot of our content development and so forth and so on, but the bad guys are using it on their side in order to fake and impersonate. Uh, and it's working like a charm. Uh, people are falling for it left and right. Uh, and it's, it's making our jobs much, uh, busier because, you know, these attacks are becoming more prevalent. Yeah You know, back, back years ago, there was a term we used to use called script kiddies.
Right. And this is where, this is where being the guy with all the gray, I'll be the, the- Mm-hmm ... I'll give you the get off my lawn speech on this- ... is that, you know, when we were going up against the original hackers, it was smart guys against smart guys.
And then- Mm-hmm ... we became very indignant because smart guys started posting their scripts up on the web, and people would download them and just use what other people wrote. We called them- Mm-hmm ... script kiddies because- Mm-hmm ... they, they didn't really understand the technology, but they knew enough to figure out what they needed to download and use it.
And we, you know, and we used to make fun of them. "Oh, they're just lazy. They don't even know how, they don't even know how to code." Mm-hmm. And now, I mean, the AI makes the script kiddies look like they were actually- Yeah ... working for it. Right.
So it's that next generation like, "Oh, you kids don't know what it was to have to hack."
Right. Yep. It, uh, we, we, we're becoming lazy and sophisticated at the same time. Exactly. I mean, and, and you don't, you don't, you don't have to...
The bad guys don't have to spend as much time doing all that research and groundwork. They can just jump right to the higher level- Right. Right ... um, just by asking the right questions.
Yep. Absolutely. So we're truly looking at cybersecurity becoming more operational rather than reactive. So all of this kind of added together, Cyrus, what does the future look like for MSPs that want to protect their clients or for clients that maybe get hacked? So MSPs, they need to move away from this, what I call the 20-year-old model of delivering MSP services, and that's what w- what I describe as an asymmetrical model, uh, heavily reliant on the customer, uh, as part of the delivery of the, the services, particularly when it comes to incident response, uh, and providing what I, what I call a, a, a static delivery of services, meaning that they're just alert, th- they are monitoring and alerting the customer, but the customer still has to participate directly in that response effort.
I think that's a mistake primarily because businesses aren't set up to deal with cybersecurity related issues. They're set up to deliver products, services, you know, what have you, to their targeted marketplaces. But, uh, for them to build, uh, the, uh, capability in-house to be able to participate actively in that relationship requires an ex- a major expenditure of resources that are, uh, impacted by what we call seven challenges, uh, of, of, uh, managing cybersecurity, and one of those being the expense of it, uh, you know, two being the, the lack of, um, skilled resources in this country.
You know, there's a major shortage around the world. Um, and we're, we're pumping out cybersecurity professionals every day, but we just can't do it fast enough in order to keep up with the, with the, uh, threat landscape. Um, and then there are five other challenges. Uh, some of I talked about like relying on the human element for, um, you know, dealing with the data and so forth and so on. I think MSPs need to move away from that static 20-year-old asymmetrical model and move more to a, to a symmetrical model, or what Gartner calls a co-managed model- Mm-hmm ... in that both parties in that relationship are appropriately positioned in their strengths.
And so what that means is obviously the MSP has the skill set and capability from a technical perspective to deliver a service, uh, and the customer is best positioned in the governance, uh, uh, uh, place of that, uh, relationship, focused on strategy, focused on compliance, focused on policy, focused on risk identification and management, but also supported by the MSP because they understand the impacts of governance and strategy and risk and, and policy. Um, and, and so when you put the, the two parties to that relationship in their right place, they operate from a place of strength. Now you have a much more robust relationship between the MSP and the, um, customer that allows for a stronger operational framework to develop. So you have the, the, the, the vendor that's focused on, uh, um, threat detection and response, um, you know, the process procedure of it all, the, the vulnerability management, incident response, um, staffing, uh, which, which is a major problem on the, um, business side of the house.
Um, and, uh, and so when you have the vendor that's focused on delivering those components of the operation and delivering the service on a 24 by seven by 365 basis, now you allow the customer to focus on what they do best, but also to contribute to that relationship in dealing with governance and compliance and strategy and risk and policy and all those things.
Um, so you have a, y- you have w- what's called a, uh, a, an even seesaw, if you will. Um- Yeah There's a, there's a, a framework in that, that I think if a, a, a MSP adopted the framework of, uh, what we call the lifecycle, the cybersecurity lifecycle, um, I think you'll see the relationship get even stronger, and that is the lifecycle focused on governance, technical infrastructure management, and process and procedure.
And we call it a lifecycle because it's always evolving. Technology's always changing. Business operations are always changing. The threat landscape is always changing. And so that lifecycle needs to continue to evolve with governance feeding technical infrastructure management, technical infrastructure management feeding process procedure, and so forth and so on.
So if there's a change in governance, that change gets properly reflected in technical infrastructure management and process and procedure, and so forth and so on. When you change the, um, uh, when, when you, when you change the, the, the operational, um, or the focus from that perspective, you have what we call a very strong operations and, and not a program.
It used to be that cybersecurity was called a program. Let's go develop our cybersecurity program, which consisted of all these static things. Now it's an operations because an operations is consistent, it's ongoing, it's evolving, um, and, and, and it's all driven by the environmental landscape as it, as it changes.
So that's where I think the MSP market should, should go. And we, we coined that, um, not a managed cybersec- or managed security service provider, but we now coin it a managed cybersecurity operations provider because they're delivering everything that's necessary for the organization to, uh, adequately protect their environment on an ongoing and consistent basis, um, while maintaining a very strong relationship between the business and the vendor That's great.
That's really good advice. Now, I'm gonna wrap up with a question that I'm going to ask each of you, and that is, if you could leave every MSP owner listening with one piece of advice when it comes to protecting their customers, what would it be? And Sean, I will let you jump in first. Well, Cyrus teed this up great for me with a few of his comments.
So, you know, he used the term, um, MSSP, which we're seeing out there. And since that term came out, I, I, I've always, uh, when I first heard it, I said, "This is gonna be a transitional term." And what do I mean by that? I mean that in technology, I used to joke around to people that I, I, I went into a career path where I have to reinvent myself every three to four years.
And if you look at the history of being a technology service provider, you know, at one point we were selling hardware at tremendous margins and we gave away services. And then margin-- Then hardware got commoditized, we had to learn to be service providers, and we had to kind of make the turn. Some people couldn't make that turn, and I, I call it going off the cliff.
They went off the cliff. And then we went from being a reactive service provider to being an MSP, being proactive, and some people couldn't make the turn and become MSPs, and they went off the cliff. I think three to five years from now, every MSP has got to be an MSSP, and there will not be two different acronyms because if you're not providing security services, you will go off the cliff next.
That's the next cliff you're gonna be looking at. So you better get this down and, and incorporate it into your practice. Um, we use a term when we talk about business planning with our clients called start with the end in mind, which means when you're starting a business, you should be thinking about the exit plan on day one.
And same thing with response incidents. We wait to come up with a response plan when there's an incident. When you are onboarding a new client as an MSP, you should be setting up the response plan for that client on day one, like I talked about reaching out to the insurance company. Who are the other providers?
Have that plan. And then Abby, you used the term fire drill. You need to be running regular fire drills with your clients just like you do test backups, okay? Just like you check your patches. You need to be saying, "Hey, let's, let's pretend there was a breach.
Let's go through the motions. This is h- what we're gonna do when I get that call at 2:00 in the morning that says, 'I think we've been breached.'"
And then finally, um, Cyrus had a great point that this, this is a partnership. And so many MSPs still struggle when they're doing their, their, their scheduled business reviews with their clients, and they talk about how the clients don't wanna take them. Because we in the MSP industry, most of us came from the technical side, and we like talking tech.
It's where we're comfortable, and we like talking in our comfort zone. And most technicians and engineers have a hard time talking about business goals and objectives, but that's the conversation we nee- need to be having. We need to sit down with that client during those QBRs and say, "Okay, if you had a breach tomorrow, what's that...
how is that gonna impact your business goals and your objectives?" And you need to be adjusting for that, and I, I refer to this as we need to stop having server room conversations, and we have to start having boardroom conversations. But this i-- I think that's, this is even more important when it comes to the cybersecurity element and the response element.
So make sure you are asking the right questions ahead of time and then listening to what the client says and working in partnership to make sure that, that everybody can respond appropriately when that alarm is sounded. And Cyrus, I know you've shared so much good advice with us today, but if there was one piece that they're really gonna take away, what do you think that would be?
Yeah. So I'm gonna go over to the technical side a, a little bit and talk about these, these three minor components of the life cycle, and that is visibility, agility, and control. Um, what, one of the things, and, and, uh, I think Sean, uh, hit on this, uh, uh, in his comments, um, uh, rigidity is not your friend in cybersecurity. Um, you have to be agile, um, you have to have complete visibility and complete control in order to be able to move forward. And if you don't have those things, you are going to be rigid and static and, and out of touch with, uh, the current threat landscape and, and unable to be able to, um, effectively mitigate that landscape.
So those three minor components, visibility, agility, and control, I think are extremely important to any MSP operation. Great. Well, I just wanna say a huge thank you to you, Cyrus, for being here today and sharing all of your experience with cybercrime investigations and how we can better protect our clients.
And Sean, of course, thank you for jumping in and sharing your perspective. And to everybody listening, if today's conversation gave you a new perspective on what it really means to protect your clients, please be sure to subscribe to Profit, Grow, Exit and share this episode with another MSP owner. We'll see you next time
Key takeaways
- Attackers target people because it is cheaper than beating the technology. A former municipal client of Data Defenders had zero breaches in six years; four months after switching vendors, one phone call that talked a controller out of their credentials cost it $1.2 million.
- The biggest mistake after an attack is going straight into restoration instead of triage. Wiping and re-imaging destroys evidence, and a sophisticated ransomware variant keeps changing while you chase it — one Chicago police agency spent three weeks before calling in professionals.
- If you feel you have to act, pull the plug rather than shutting down, remove the hard drive, and label, date and lock it away to keep the chain of custody. Restore onto a new drive.
- Restoring from a backup or image can put the original vulnerability straight back, and advanced attacks hunt down and corrupt backups. Keep backups air-gapped and check images before they go back into production.
- MSPs should build each client’s incident response plan at onboarding — including who the insurer would send — and run regular breach “fire drills,” the same way they test backups.