Bitcoin, Cryptocurrencies, Ransomware Security Risk Assessments, Craig Petronella & Lisa Shasteen
Recorded March 2021. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.
What this episode covers
In this March 2021 episode, Craig Petronella of Petronella Technology Group welcomes attorney Lisa Shastine to discuss Bitcoin, ransomware, and security risk assessments. Lisa explains that, at the time of recording, the financial regulator had opened financial institutions to serving as stewards of cryptocurrency under new guidance, and she questions whether protections like Secret Service involvement would extend to Bitcoin.
Craig, who has mined cryptocurrency, argues that coins held by others are not truly yours and warns that safely storing private keys requires technical skill most individuals lack. They discuss the Hafnium attacks targeting Microsoft Exchange servers reported just before recording, and Craig recommends encrypted email on top of Exchange. The conversation covers identity theft monitoring, free credit freezes, and weakened trust in vendors after SolarWinds. Craig advocates security risk assessments, ransomware fire drills, tested offsite backups, and redundancy, while Lisa urges everyone to have a trusted technologist. They finish with cyber insurance questionnaires, PCI self-assessments, cloud shared responsibility, and CMMC, which Lisa says required companies serving federal contractors, at the time of recording, to prove compliance through trained assessors rather than self-certification.
Worth rememberingKey takeaways
- Craig argues that cryptocurrency held by someone else is not really yours, so controlling your own private keys matters.
“Ultimately, if you don't control your private keys, you don't really have your Bitcoin or your crypto.”
- The guest recommends placing free credit freezes with Equifax, Experian, and TransUnion so nobody can open credit without the PIN.
“And they will, for free, put a credit freeze on your account. And you should just do it because that way nobody's getting in unless they have your PIN number.”
- Craig says an independent security risk assessment works as a checks and balance even when a company trusts its existing IT provider.
“It's not going to hurt you to have a security risk assessment done in working with that vendor, if you choose, and do a checks and balance.”
- Craig urges companies to run ransomware fire drills to learn how fast they can recover and how much downtime they can tolerate.
“Your company should be doing fire drills around ransomware and pretend that you just got ransomware today.”
- Craig says that with strong data backup, disaster recovery, and business continuity, a company does not have to pay the ransom.
“if you have strong data backup, disaster recovery, and business continuity, if you have strong systems in place to protect your organization, you do not have to pay the ransom.”
- The guest warns that a backup connected to the production system is likely to be encrypted by ransomware too, so keep backups separate.
“But if you have your backup connected to your production system, it's likely going to be ransomware too.”
- Craig stresses that outsourcing to providers like Amazon AWS does not remove an organization's responsibility to secure its own systems.
“Just because you're outsourcing or paying a monthly fee to them, does not take that responsibility away from you.”
The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.
From the show notesAbout this episode
Craig Petronella and Attorney Lisa Shasteen talk about the latest news on Bitcoin, Cryptocurrencies, Ransomware, the importance of Security Risk Assessments now more than ever. Cybersecurity insurance requirements, vendor security questionnaires. Visit to purchase DIY products to help you proactively protect your organization from cybersecurity threats like Ransomware and malware. Practice proactive fire drills on your data backup, Disaster Recovery and Business Continuity to score your organization and fill your gaps.
Episode transcript
Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.
This is Encrypted Ambition, a podcast about the builders rewriting the rules. Join Petronella Technology Group as we decode the ideas, challenges, and momentum behind tomorrow's business, technology, and leadership breakthroughs. You're listening to Cybersecurity and Compliance with Craig Petronella. Visit us online at petronellatech.com.
Hello and welcome to another podcast episode. It's March third already, 2021, and we have our guest attorney Lisa Shastine. Please introduce yourself. Hi, good morning. I'm Lisa Shastine with Shastine and Percy Law Firm. Awesome! So exciting times today. We're going to talk a little bit about maybe some Bitcoin and maybe the.
The security risk assessment, the needs of why companies should be doing assessments, and kind of get into also know your customer, know your vendors. You know, obviously the SolarWinds Orion hack, putting too much trust, and how to vet the the folks that you work with. You probably have an IT person or an IT provider that you work with.
But how do you know that they're doing everything they should be to protect your organization from something like ransomware? You want to talk about that a little bit, if you don't mind. Sure, I got a lot of stuff I want to talk about. I'm just full of information today and questions, so yeah. Absolutely. So, what's your take on Bitcoin? Bitcoin is, I think, it's over fifty thousand dollars again.
This is so crazy, and I'm so sorry. I'm not a Bitcoin investor. I'm just I could just kill myself for that, right? But but the thing is, so one thing is that the the financial regulator has opened opened up Bitcoin. You know, has opened up financial institutions to be stewards of.
Of cryptocurrency, and they've they've put out guidance for what you'd have to do in order to be a steward of cryptocurrency. So, so what does that mean, like for for folks, you know, what does that mean in layman's terms, if you don't mind? Okay, so so what it means, and I'm trying to pull up some information on this.
But what they what they have done is they've created some rules, like what kind of protections do you have to have in place, and what kind of procedures and you know security and everything do you have to have in place in order to take in cryptocurrency? You know, it's basically you're storing the the keys, the critical keys, right, for someone private key, yeah.
So, so that's that's essentially what the bank is storing. Bank security tends to be pretty good, so it's not like it's a you know it's it's necessarily bad thing. So, is this kind of like custodian or services? Well, no, it's it's kind of like it's kind of like banking. Kind of like they they hold.
The keys to your money, right? Well, they they currently hold the keys to your money, right? So they they just do that now. But in order to play in the world of Bitcoin, they're holding something other than, you know, electronic indicators, I guess, of of of you know U.S. currency. And you know, my question, and I'm not an expert on this part.
Is you know okay? Like if you if you have an issue, the U.S. Secret Service is responsible for protecting our U.S. currency, right? So what happens if, like for example, if if you're at a closing, you wire in two hundred and fifty thousand dollars to.
You know, buy a house or whatever, and it goes missing, right? Because the the wiring instructions were were a hoax, and you sent your money to some you know nefarious actor's bank account. Okay, so the U.S. Secret Service will get involved, and they they are a partner with Fincen.
Which no human being can call. You have to be law enforcement or somebody in order to contact FinCEN to trace wires internationally and stuff. And so the U.S. Secret Service can do that for you. Will they do that for Bitcoin? Riddle me this. I don't know because it's not U.S. currency. It's something else. Right. Yeah, I think that there's going to be.
And will be more regulation around something like Bitcoin and other cryptocurrencies. I think that, you know, you reference the the bank and the controller of the keys. You know, I've been doing a lot of research and have done a lot of research around Bitcoin and have done mining and gone through that rabbit hole. And.
Ultimately, if you don't control your private keys, you don't really have your Bitcoin or your crypto. So, if you trust somebody else to have the keys, it's not really yours, technically. So, there's things called cold wallets that exist where you can have your keys and be in control of them. But then that opens the whole door of basic cybersecurity hygiene. You know, if you don't properly store your keys.
And you get hacked, you have no excuse but yourself. I actually have a friend that happened to. He's an electrician. This guy got into cryptocurrency. God bless him. You know, made some money. He's doing great. Got all his cryptocurrency, and then he was hacked. It's all gone. And I'm like, look at what the.
There's that guy. I forget his last name. His first name's Craig, actually, but he claims to be Satoshi Nakamoto, and he has no supporting evidence. The world doesn't believe him, right? You know. But but there was a. I read something. Gosh, I think it was last year around this time that he claims that he got hacked and billions of dollars.
Were stolen in Bitcoin, and you know Bitcoin and cryptocurrencies, as it stands today, my opinion is it's it's new. You know, it's still in its infancy. There, it's the Wild West. There's a lot of technical proficiency that's required to store and properly secure your private keys, and and the most.
You know, typical individuals are not going to have that technical know-how to do that. And you know, we as humans are poor with passwords now. So now you're you're introducing, you know, I think it's like 26 different unique words that you have to have as part of your private key in a certain order, and you can't store them or you should not store them on your computer or anywhere electronically. It's literally written down on a piece of paper, and if you lose that sheet, and and then you lose your
Like your hardware wallet or your cold wallet, you're toast. It's gone forever. There's no no bank to run to. There's nobody that can help you. You're you're you're toast. Right, right. And and there's I mean, so that's that is the issue, and that's and that's what I'm thinking. You know, from a legal standpoint, we're not ready. We're we're just not ready. We don't we don't have.
Well, I mean, let me put it this way: if you can, if you are prepared to lose it all, go right ahead. But if you, you know, if you put actual money into cryptocurrency rather than investing at a dollar and then it becomes like a billion dollars, you know, I mean, if you put your actual money, let's say you buy fifty thousand dollars worth of that stuff, I mean, that's probably a.
A significant transaction to most people in the United States. So, you know, if you were to put U.S. currency into cryptocurrency, and then you don't have good cyber hygiene and you get hacked and it's gone, who are you going to run to? It's like, well, what are you going to call law enforcement? You call, you know, Secret Star. Absolutely valid point, and.
I think that's why you're starting to see companies. I know of some. There's, there's, I think one in Raleigh. It's called Casa, C A S A. I don't know if you ever heard of them. But they're like, okay, they're like a a custody company that you can hire and pay them to help you with this stuff. It's expensive, but if you've got a lot of of crypto and and Bitcoin, you want to make sure that you're spreading yourself around so that.
You know, you're not. You don't become a target, basically. So, I think that there's going to be new companies that sprout up like that that help folks with this. And you know, we have a domain, a website that we launch called BlockchainSecurity.com, and we're actually starting to put a store on that to help people around this. and
You know, give them. We're building some new training around you know basic cybersecurity hygiene for how to protect yourselves. I I think that Bitcoin is here to stay, and I think that it is going to be a big transformation. Do I think it's going to be difficult? Absolutely. Do I think it's going to go up and down? Yeah. You know, in the short term. Fighting, and here is what I would say. You know.
I love technology. You know me. I love technology. I wish I were. I want to be you when I grow up. You know, I really I love technology, right? But I also have to weigh the risks for myself. And I think this is where the individual investor has to has to look at that. And that's something that even you know Charles Schwab or you know whatever E Trade is going to ask you is.
You know what? They're going to ask you to fill out a profile. What is your profile for risk? Just like with stocks, right? Yeah. Right. Exactly. So your investment advisors and everybody is going to assess your ability or willingness to your appetite for risk. Yeah. And so if you can risk the money, go right ahead. But I'm just saying, for me, I really wouldn't want to lose fifty thousand dollars right now.
I mean, I just wouldn't want to do that. I've got a bunch of commitments going out the door, and I just that's not something I'm interested in. So I'm just thinking, you know, can I make money somewhere else where I pretty much know that in one fell swoop I won't lose it all? Yeah, I know, I know places where I can put it where I know it'll be, or at least most of it'll be. You know.
Yeah, I think it. You know, it's different for different people, and you know, it's not for everyone. I think it's the point. I think long term, you know, it will be good. You know, as an investment, but you're absolutely right. I think in the short term, you know, it's going to have fluctuations. So if you can't stomach that, then definitely don't get into it for sure. I mean, I would say if you're going to do that, if you're going to put any significant amount of money into it, unless you're just a cowboy rock star and you can just.
Whatever, then I would suggest getting, you know, like calling, you know, Petronella or or somebody to consult with you, and just make sure that the environment that you're storing your keys in is going to be, you know, at least reasonably sufficient, you know, that you can count on it. Now, counting on things, speaking of which, I want to talk about the hafnium thing.
Okay, this was out yesterday, right? Microsoft is like their hair is on fire, right? Because you know the Exchange servers software is being targeted by a nation state, and it's China. You know, it's Chinese based. Let's put it that way. So, and that's from Microsoft.
You know, these these people are determined, and they're they're trying to exfiltrate information. That's what they're trying to do. So, how many people you know live with an exchange server? I do. You know, so backbone of Office three sixty five. Hello. So, and that's how a lot of people manage things. They manage permissions. They manage all sorts of things. You know.
But you know, this goes back to, in my opinion, encryption. So, if you're using encrypted email on top of Exchange, they can hack Exchange all day long. They're not getting in the encrypted contents. So, okay, see, there there's a good thing, right? Okay, so so see, this is my this is what I wanted to talk about is like how you know what are some steps people can take.
Immediately to sort of protect themselves right now, because I'm interested, right? Yeah, I mean, well, it all starts. You know, it all starts with you know, how do we check the pulse and and get that risk assessment done, right? So it all starts with that security risk assessment and having a vendor that's trusted and vetted and and has a good reputation. Go through all this with you and with a fine tooth comb.
You know, there's been so many breaches that you really can't trust anybody. So, in my opinion, you should really be using encryption everywhere possible. You know, it's become like that, hasn't it? I mean, it really has. It's it's so crazy because, and a lot of people are still thinking, "Oh, I don't have anything to hide." Yes, you do. Trust me on this. I mean, I have.
Of a friend who's a physician, he was, you know, his his identity was was stolen, and it took him five years to prove who he was. He needed to buy a new house for his his wife and his family's got four kids. You know, he's a very successful surgeon. He had to go through absolute.
Heck, to you know, to just establish he was who he was through the IRS, through you know everything, and it's it's just a matter of the willingness to inform yourself and to take. Well, and I think it goes back to you know, if we talk about identity theft for a moment.
It goes back to monitoring. You don't know what you don't know, so everyone listening should have some type of identity theft monitoring service from a trusted vendor. That you know you're keeping eyes on this stuff. You know you're you're made aware of your information leaked on the dark web, and you're made aware if somebody tries to open credit in your name.
You know, there's all these these bad actors, and they're looking to exploit you any way they possibly can. And ID theft is a, you know, it's a big black market game. You know, and if you're a fairly well-to-do person, like a physician, like you mentioned, or a surgeon, you know, that's an identity that hackers are going to want to take and exploit. Yeah, I mean, you're going to be a primary target. You could be a, you know, a spearfishing target.
Right. You know, I to me, you know, it it seems like identity theft monitoring, or identity monitoring and and identity theft protection, has become essential. It's kind of like, well, are you gonna buy, uh, you know, insurance for your car?
Well, of course you are. So, you know, wouldn't you do that for your life and who you are and like all of your accounts? I mean, seems to me like that's even more fundamental, and it's inexpensive. I mean, it's like just freaking do it. And why doesn't everybody just run right out right now, put down the the you know cursor?
And call the identity, or call the credit monitoring agencies. There are three of them: Equifax, Experian, and TransUnion. And they will, for free, put a credit freeze on your account. And you should just do it because that way nobody's getting in unless they have your PIN number. Period. That's right. I mean, there's just it's so. I mean, it's free. Why wouldn't you do it?
Just do it. It's just actually, if you need credit, you give somebody a pen. You lift the you lift the freeze for that particular person, and then you move on and you put the freeze back. Right. Not hard, you know. Do it. Yeah. Well, the the you know, I call those layers. That's a layer. That's a good strong layer. You know, can't obviously rely on that as a silver bullet, but it's it's definitely one good layer to start with, and any anyone can call and do that for free.
And then layering on these other things like the monitoring and other technologies. But you know, going back to the Exchange server, you know, if you use encryption on top of Microsoft Exchange Server, I mean, obviously, you want to patch and make sure that things are are secure, and then test the patches to make sure they're effective. But at the end of the day, if you're using end-to-end encryption, which is what we use.
And they do get breached and hacked. The hackers get scrambled data. Well, let's talk about something else. I want to talk about something else. So, you know, the the issue of trust right now has become really critical. And I mentioned, I think, last time this this book written by Major General Mary Kay Eater. It's American Cyberscape, and it's it's a path to trust.
It's she just in a very short, a very narrow book. It's very little you can read it. It is it just lays it all out. Like why do we not trust? We don't trust anybody anymore except for small businesses. We we we trust nobody. Especially we don't trust the news media. We don't trust anything. And it's warranted.
So, how do we get back to a place where we know what we can trust? We can't even after solar winds. We can't even trust the vendors that we've decided to trust to allow them to update automatically on our systems. How do we deal with that? Well, you know, a company that I'm actually on the board of, so full disclosure, but Threat Warrior is figuring that out, and they've got a situation for that.
But the point is, you know, it's very, very difficult for the normal human being to figure out what to trust, right? Yeah, but if, but if we, you know, go back to the basics and we use a layer. What's that? It's, it's a, it's a layered approach. I, I mean, yeah, that's what you were saying. Is yeah, but if you know, we use an end-to-end encrypted data storage and an end-to-end encrypted email.
If we go back to the the solar winds hack and the patch, again, they get into the system. But as long as I am smart enough to put my sensitive information in the encrypted vault, you are not getting it. And and the system that I use doesn't use passwords. It's it's bound to the device, so you can't fish me for my password. You know, so the you know, but you're but you're you know, okay.
But you are a technology. You're an expert at this, okay? People need your advice. But there are a lot of people running around out there. There's they still try to do it themselves. Can I? I want to talk about something else. So, so I want to talk about the wisdom of of having someone. You know, to to.
To help consult with, or or something. I mean, Craig. People, Craig is a really nice person. You know, he will he will help you out. He will he will tell you stuff. He will help you look at your situation. He'll give you an idea of what you need. He'll help you implement if you want to pay him. But the thing is, you know, you got it. You got to first at least reach out. You know, Craig doesn't bite.
You know, Craig's actually a really good friend, and and you know, so so it's easy to contact someone who's knowledgeable. The the question is, who is knowledgeable? And you know, so again, it's back to that trust issue. Well, I know Craig, so I would trust him. So there you go, and his number's right there on the screen. But.
And and this is not just a it's not just a you know plug or anything it's it's just that you need to have that person in your life just like you have people that fix your car you have people that you know clean your business they you have these people who are service providers to you you have your banker you have your lawyers you have you know these people who are professionals that help serve you and you know them and you trust them you need a technologist in your life you've got to.
But it's just - it's one of those things. They're in your little - they're in your little tribe. You gotta have one, you know. Thank you. I appreciate those kind words. I agree with you. I mean, and even if you have a IT person or an IT provider that you're working with, you know, we're not looking to take their job. You know, if you've got a good relationship, keep that relationship. But what we are saying is.
It's not going to hurt you to have a security risk assessment done in working with that vendor, if you choose, and do a checks and balance. I mean, we have to have it done too, especially with the companies that we are working with around the CMMC or in a regulated space like HIPAA. You know, you want to make sure that you're checking these things at least annually, and then you know that's your maturity level, your scorecard, and.
You know, people are human. You know, maybe your IT provider had all the best intentions, but maybe you didn't have the best protections against ransomware, or maybe the IT provider wasn't aware of some new technology that could benefit and really significantly reduce the risks of your company. And you know, there's gaps that can be found in most companies. Some are bigger gaps than others, but the fact is that you know we can help identify these gaps and then provide solutions to fill the.
Gaps, you know, and and the more gaps you fill, the better protected you are. Well, and what I think, I think one of the things that I'm seeing, like, I got a call this morning of a a gentleman who has a significant business and with several locations, and his business was down for an entire week.
I mean, he sells items, large-ticket items, and he sells them all day long, every day, and they are in high demand. They're actually backordered, et cetera. And he was down for a week, and I was like, "Hey, if I run down to one of your locations with a bunch of cash in my hand, can you sell me one of these things?" And he was like, "No, I can't." That was his employee, actually.
And so I talked to the, you know, the owner, and and they have people who have learned to maintain their network, you know, just to keep things up and running for the business. But they don't have anybody really managing this. And I think in this day and age, it has become. I mean, there's not going to be a neon sign, everybody. So here's my neon sign. I'm like making one right in front of you.
Now is the time. It is happening, right? You have to have somebody looking at this stuff, at least from the outside. Have an outside advisor come in, like Craig was saying. It's called a risk assessment. But you know, just you know, if you if you have a situation like that, you need to do something called hardening.
And and you've got to you've got to go in there and find out the holes in your your security settings and your systems and all that kind of stuff. Figure out where your protected data is. Right, you have to have a data classification idea. Otherwise, everything in your company is should be protected, and that's not that's not realistic.
So you you want to make sure you classify your data, figure out where your data your your your most sensitive data is, your most valuable data that's critical to your business, and you need to figure out where it is exposed. What are you doing with it? Where does it fit in your business processes? Right? And in that business process, is there technology that can help?
Protect that data as you do those processes. This is not technology that's going to slow you down. It's not meant to interfere with anything, but it's just it's there working in the background to keep it secure, and that's what Craig does. So let's say you have this, you know, this um.
You know ransomware hit Craig. What what do you do when I mean? Is there a protocol that you use? What what what do you do when you when you confront a situation like this? Because I think you know this is basic, but it's but it's actually happening so much. It's not. It's important. Sure. So.
You know, ransomware. Just to kind of briefly overview what it is, it's malware that gets into your system, oftentimes through business email compromise or a phishing email or some type of link that somebody's clicked on in the organization, and it drops what's called a payload, and oftentimes encrypts the system with very strong.
2048-bit encryption, and it's extortion. It basically says, "Okay, depending on the strain of ransomware you get, you might have 24 or 48 hours to respond." And they an encryption, by the way, means it locks up your data. You can't right, yeah, you can't get access to any of your files on your system, and it it causes you know disruption, business disruption. So.
You know why your data scrambled? The hackers want to get paid in Bitcoin, typically because it's you know more anonymized. And but the but here's the bottom line: if you have strong data backup, disaster recovery, and business continuity, if you have strong systems in place to protect your organization, you do not have to pay the ransom. And this is something that I say all the time.
Your company should be doing fire drills around ransomware and pretend that you just got ransomware today. How fast can you recover? What happens? Are all your staff unable to work if they're degraded? At what what percentage are they degraded? Well, figure out what the what the acceptable risk is. Right, right. Okay for you to be down for a day, for a week, for a month. I mean, how? What is your tolerance for that? Yeah. So let's say you know.
Let's say you have, you know, you don't have a very large budget. Maybe you're a small business, and you know, you don't have a large budget, but you can afford to be down for a week. You know, most people can't, but let's say you can. You know, the longer you could afford to be down, the cheaper the solution becomes. the The less time you're able to accept, and typically, bigger companies, if you've got a hundred or a thousand or ten thousand employees, you have to multiply this stuff. So.
If you're a big company of a thousand employees and you're down just 15 minutes, that's a whole lot of money that you just spent, you know. So, so there's more advanced systems that have appliances that will do data backup, disaster recovery, and business continuity, and then take that data at a bit level and move it offsite and then encrypt it to make sure that ransomware can't get into that as well, because.
You know, poor backup solutions can also get infected, and the hackers know. I mean, you bring up a good point. So, you know my my thought process because you guys have taught me really well. You know, when when somebody says I've been hit by ransomware, my first question is, "Where's your backups?" You know, so it's like ransomware equals "Where's my backup."
But if you have your backup connected to your production system, it's likely going to be ransomware too. So you can't do that. You got to have backup management also, and that's what you're talking about, right? Because anything connected to that network that's infected could be locked up.
And that's separate backups, and you have to know back to when do you have the information backed up, right? Like, how often do you back up? Can you get everything restored as of yesterday, or, you know, is it going to be like a month ago because you didn't back up since a month ago or something, and take it offsite? So anyway.
And so, we recently launched a new website called compliancearmor.com. And on ComplianceArmor®, there's some - I call them puzzle pieces. They're inexpensive products that you can buy. There's a scorecard on there that you can score the cybersecurity maturity level of your organization. It's like a one-page checklist sheet.
That does a good job of identifying the areas that you should pay attention to, but you know, take take note. Take today, put the you know the mouse down and the pen down, and do a fire drill on your backup systems. You know, pretend that your your stuff crashed. What do you do? What's your process? Do you have a policy, a backup disaster recovery policy? Do you have security control layers in place?
You know, I hope you're not using something like Dropbox or something like that's online only, because those systems sometimes get infected too. You got to make sure that you know there's actually ransomware simulations that we can do, where we can pretend that you're infected and and what you know what does it get into? How does it how does it affect the organization? But doing this proactive drills and exercises are are worth so much in the end because.
If you actually do this stuff, and then God forbid, in the future you get hit, you've gone through it before. It's a drill, so you know what what's what you're up against. But it's the companies that are using, like Lisa said, the USB attached hard drive to the server, and it always sticks. You know, it's always connected, and you might rotate them out. Maybe you have more than one, and and somebody takes one home. The point is that.
If you're doing that type of system and it's still connected, it can also get the ransomware on it as well. And you know what happens? I've seen this time and time again. People use these these what I call dated or legacy backup solutions that are inexpensive and cheap, but they don't have the knowledge and know how to check to actually make sure the proper data is on them.
I can't tell you how many times I've had business owners tell me, "Oh, we're doing these this rotated hard drive thing, where I take this this USB hard drive home every day and we swap it out." Well, that's great, but when was the last time you did a backup fire drill to look on that device and see, number one, did it work, and number two, is it backing up the data that you actually need? Yeah, have you ever have you ever checked?
Whether it will work to restore, right? Yeah, because it, you know, every little tiny piece of that can fail, and and so it really has to be practiced. There has to be a regular schedule. Yeah, I mean, I just, you know, I had, I talk about this all the time: redundancy, multiple systems.
You know, never rely on one system to do all your work because it will fail. It'll fail one day. My own desktop that I built from scratch - I use it for artificial intelligence and research. It died the other week, and what did I do? I have two laptops as my backup, so I work off my laptops. You know, and I - I'm till I get back up and running.
But the fact of the matter is, you know, we we are human. We get comfortable in our our our space and how we have things set up, right? But if you're not if you're not doing these fire drills to anticipate failure in the future, it's going to happen at the worst time possible. You're going to this your computer's going to crash right before your meeting or or your big proposal or your big Zoom meeting or whatever nowadays, and.
What's your plan? What do you do when that happens? You have to have redundancy in place. And if you've got a server and it's a single point of failure, well, you're a sitting duck. You need to have some redundancy there. And and when I talk about redundancy, I'm not talking about an extra hard drive in a RAID array. I'm talking about separate systems, redundancy protocols, you know, policies, procedures. What do you do in these situations? How do you how do you function? How does your business continue to operate?
Think about this. You know, like if you, if let's say, let's say you were you were fished and your your emails compromised, which is extremely common. It's 85% of the of the the data compromise, right? Sure. So I mean, phishing is real. You know, it's a thing. So you know, if you do that, then all of a sudden, people in companies, I've seen them.
They start emailing around. I'm like, your email system is infected. Hello, you know, it's like, no, you don't email me. You have to have a, you have to have a, a separate communication system, a bridge, you know, some chat channel, something that you're using that's outside of your system because you don't yet know what's infected.
You have to have Craig come in with forensics and figure it out. But until then, you gotta have a way to communicate. So how are you gonna do that? You need to have a policy, and everybody needs to know what that is before they get to that incident. Because people will be running around with their hair on fire because they can't do business, and they're gonna just do. They're gonna grab whatever is the most convenient. They're gonna use their emails. They're gonna tell their friends. They're gonna be. You know, I mean, it's a nightmare.
Yeah, I have. You gotta, and that's even worse. Because I'm like, ah, this is a legal event. Please don't tell everybody. I have a policy about, you know, confidentiality. You know, things like that are very important to the company. So, you know, all these all these things work together. It's it's really better to just be prepared.
Before you get there, because it's hard to learn it the the day that it's happening. You just can't learn it. Right, and I and honestly, I think that as companies like cybersecurity and company like cybersecurity insurance providers become more strict on.
Requiring the supporting evidence of the organization to just even get the insurance, you know, with ransomware, a lot of folks don't get an insurance coverage or a payout because they didn't have anything in place. So, you know, the insurance companies have been getting killed with ransomware payouts. So they're getting finally, they're waking up from the slumber. They're getting smarter and they're looking for.
Risk assessment supporting evidence. You know what did what is your organization doing to anticipate and and proactively prepare in the event this happens to you? And if you can show enough supporting evidence that you've done your part, then you'll you'll most likely get that payout. But I I've actually received a lot of calls to our company around folks looking to get cybersecurity coverage, and they can't get it because they get this really long.
What I call a vendor security questionnaire, and it's sometimes three hundred plus questions about your organization and your policies and your procedures. And what do you? When was your last risk assessment done? And how are you training your your staff? And what evidence do you have that you're doing all this stuff? Well, and by the way, it's not just that. Let's talk about PCI. So, so the payment card industry. Anybody out there take credit cards?
I think most people do, right? Yep. So, so basically, you should be doing this anyway because you have to do a self assessment, if nothing else, for the credit card companies every year. And God help you if you lie on those things. But here's the here's the thing that a lot of people don't understand. I I think that.
They use something like Square or QuickBooks to take. Oh yeah, they think. Oh, they they do it. It's not my. Yeah, they think it's they think it's the vendor's problem, and that they're paying the vendor to. And that's not the truth. That's a captain of the ship. You chose the vendor. It's your responsibility. Yeah, that's that's a big one. A lot of people come to me and they're like, "Well, why do I need all this security that you're recommending, Craig? You know, I'm using Amazon AWS. I'm secure, right? Oh."
Okay. Yeah, Amazon will secure its environment, but not yours. You have to. Yeah, that's the. I think that's the ultimate takeaway. The the users or the organizations have their own responsibilities. The you know these providers like Amazon, AWS, or Microsoft or Google, they provide their platform, but it's your responsibility.
To secure and use and leverage the tools that they give you, and provide the evidence that you've configured those systems and security hardened those systems properly, and that you're doing the risk assessments and the pen testing on those systems. Just because you're outsourcing or paying a monthly fee to them, does not take that responsibility away from you. That's true. And also, you know, this whole thing with.
You know, like if you if you are breached, and I was talking to Craig before this podcast, and you know, one of the things he was suggesting is he's like, well, you know, I I go to NIST if somebody has a breach situation, I go to NIST in in trying to you know get them back up and running, and I I look through the security protocols.
I look through the cybersecurity framework. I run them through, maybe even CMMC, which is the cyber cybersecurity maturity model put out by the Department of Defense. Well, sponsored by the Department of Defense, put out by CMMC-AB. But in any event, CMMC builds upon a federal requirement, a security requirement for companies.
Serving the federal contractors, you could be baking chickens, and you still have to be CMMC certified by somebody else. You cannot self-certify anymore. Used to be NIST 80171 would allow you to just self-certify. Oh yeah, I'm doing all that. Yeah, uh-huh. Yeah, I got all that in place.
Okay, now they're like, well, actually, we've had so many problems with people getting hacked and being insecure. That was big, big fat lie. And now we're going to require that these trained assessors come in and take two pieces of evidence for every practice that's required at your level. There's five levels. So Craig was talking about putting that.
You know, just sort of reviewing that, you know, because it is a very strong security model. It's it's a it's a jumping off point. It's not it's it's not necessarily all you need, but it's certainly it's certainly a very good comprehensive review, right? And the thing is, what I would say to you is, it is a maturity model.
So the so the thing is, if if if you're supposed to have this baked into your organization, you can't just call Craig like a week before the assessor is supposed to show up and say, "Hey, man, I need to be level three CMMC, okay? So can you put some stuff in my system and everything?" No, you really can't. Um.
Yeah, you have to show the supporting culture. So you have to show the timeline. So if you well, the practices. You know, they have they have like for level three, which is probably going to be common, is you know, it's got 131 practices. Well, you have to then have procedures underneath those practices that implement what those practices are.
And then the the auditor has to be able to take two objective pieces of evidence that you are adhering to that, and it has to be something that you're used to, and everybody in your organization is used to. They can say, "Hey, I want to talk to Fred over there. I want to see what he knows about this." And you gotta you gotta let them do it. And they can't help you comply up either. They when they when they talk to you can't help you.
All they can do is look at it and say, "Mm-hmm, okay," and they make a note and they're out the door. And it's pass fail, right? It is pass fail. So, so you're going to fail if you do that kind of stuff, and then you're going to pay a lot of money. But the point is, and that's important to anybody working in that chain for you know federal contracting right now, which everybody thinks is going to probably roll out to states and everything else. If you're supplying any of those people, you might want to think about it.
Call Craig. He is he is a what you're an RPO, right? That's right, a registered provider organization, and and I'm a certified registered practitioner. As am I. That's right. So, but Craig made me do that, which was really good for me. So, anyway.
What I would say is, I think it's just you know, takeaway bottom line. It's important to have a technology person that you can call and consult with, just like you would consult with your lawyers and your accountants, no matter what you're doing. If you're making a change and you're reviewing things, maybe annually, at the very least, you know, you need to, you know.
Consult with your technology expert that is not the same person as your regular technology person, because it's hard for somebody to check their own homework. They see as being good, right? So you have to have somebody come in and do an assessment. And yeah, well said. And and one of the things too to point out is with the CMMC, you can't have the IT.
Person be the same role as the cyber person and the compliance. They have to be two separate people or providers that do that. So that's really important. And you should also in your organization, you you need to designate somebody that's going to be the lead on this. You know, and like Lisa said, you have to go through.
Your policies, procedures, your risk assessments, your pen tests - you need to do that at least every year. And the there are some companies that are going after higher levels, like level four and level five CMMC maturity levels, and you're going to have to do them more often. Well, and that requires a really advanced level of of cyber and visibility into data exfiltration and stuff, which something like Threat Warrior can can provide.
But it's, um, but it's, you know, that's a very advanced, um, concept. Exactly. Yeah. Well, this has been fantastic. Thank you, Lisa. I appreciate it. Sorry, it's so random that I just have all these questions today. No, that's fine. That's how. That's how. Honestly, I like these to be because I don't like to have the, you know, a formal fixed agenda. I like to, whatever kind of.
Pops in my head at the time, or questions. You know that that's. I think that's the the fun of it, really. Yeah. Well, that's what I'm thinking about today. So. Well, thank you. I appreciate it very much. Have a good rest of your day. All right, man. Thanks. Bye. Thank you. Thanks for listening to yet another episode of Cybersecurity and Compliance with Craig Petronella. Listen to all of our podcasts on Apple, Google, and Spotify.
Visit us online at petronella.tech.com to book a meeting with Craig about your business. That's a wrap on this episode of Encrypted Ambition. Subscribe wherever you listen, and if today's guest inspired you, leave us a review or share the show with someone in your circle. To learn more about how we support innovators with AI, cybersecurity, and compliance, head to petronella.tech.com. Thanks for listening, and remember, the future favors the bold.
Never miss an episode
New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.