How To Choose A Cybersecurity Provider, Penetration Test Pricing, Zero Trust and The Latest Tips On FTX Crypto Exchange Hack
Recorded December 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.
What this episode covers
In this episode of Encrypted Ambition, the Petronella Technology Group podcast, the host and Blake Rea discuss how to choose a cybersecurity provider. The host argues that IT and cybersecurity are distinct roles, like a general practitioner and a specialist, and says having one company both build and secure a network is a conflict of interest.
He explains that, at the time of recording, the Cybersecurity Maturity Model Certification was the latest regulatory standard and separates these roles, and he welcomes third-party auditing because many breached companies had only self-attested. Together they outline red flags when vetting providers, including reluctance to share references, unfamiliarity with regulations and lingo, and quoting prices without a discovery or assessment. They also explain why penetration testing prices vary, contrasting genuine ethical hacking with automated vulnerability scans, and Blake Rea observes that customers often value tangible products more than intangible services. The host advocates a layered, zero trust approach, promotes the firm's five hundred dollar KAVA vulnerability assessment, and closes with advice on the FTX collapse and cold wallets.
Worth rememberingKey takeaways
- Hire a dedicated cybersecurity specialist rather than the IT provider that built your network, since the host calls combining both roles a conflict of interest.
“You don't want the person building your network to also be the one responsible for securing your network.”
- Vet providers through track record, references, certifications and accolades; the host says a firm hesitant to provide references is a red flag.
“If they're hesitant to give you references or they're kind of hiding behind the curtain, that's a red flag.”
- Ask whether a quoted pen test is a genuine penetration test; the host warns some providers misrepresent automated vulnerability scans as pen tests.
“Well, in the industry, a lot of people would abuse the word, the keyword, pen test, and confuse it with vulnerability assessment.”
- Be wary of any provider that quotes prices without first performing a discovery and assessment; the host calls that approach unethical.
“Pricing cannot be achieved or given without a proper discovery or an assessment process, and that's part of our methodology.”
- The host recommends layering zero trust and trustless technologies so the business relies on the sum of layers, not any one.
“Try to find vendors that embrace zero trust and trustless technologies that are layered.”
- Following the FTX collapse, the host urges anyone dabbling in cryptocurrency to use a cold wallet, control the private keys and never share them.
“If you're dabbling in cryptocurrency, you should be using a cold wallet where only you control the private keys, and no one else never share them with anyone.”
- Buy cold wallets directly from the manufacturer rather than resellers, the host warns, because scammers repackage wallets with pre-configured secret keys.
“never buy a cold wallet on Amazon or any other merchant. You have to buy them direct from the manufacturer of the of the cold wallet.”
The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.
From the show notesAbout this episode
How To Choose A Cybersecurity Provider. Learn tips on what to ask for and what to look for. Penetration Tests vs. Vulnerability Scans, Pricing, Zero Trust Technology and The Latest Takeaways from the recent FTX Crypto Exchange Hack.
Episode transcript
Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.
This is Encrypted Ambition, a podcast about the builders rewriting the rules. Join Petronella Technology Group as we decode the ideas, challenges, and momentum behind tomorrow's business, technology, and leadership breakthroughs. Hello, and welcome to another podcast episode, Petronella Cybersecurity. Got Blake Rea.
Hello, it's been a few weeks. Sorry, guys, it's been a crazy few months. Actually, today we wanted to talk about how to choose a cybersecurity provider. Yeah, I think that's going to be a good topic, especially with the escalating landscape of the cybersecurity vulnerabilities that just seem to never end.
Absolutely. So, Blake, you have a specific question, or what you're thinking as far as to kick it off? I think there's a lot of probably there's a lot of people out there that are curious as to how they can bet or test a cybersecurity provider. Things to look for, things to avoid. I mean, there's a lot of people out there that.
I know we've worked with that. That pose is competent, but don't seem to be. So yeah, maybe things that we can look for, things that that yeah, things that our our listeners should avoid. I think that'd be a pretty cool topic. Yeah, so I I I agree. I think that.
You know, like any hot industry, I think that there were a lot of IT providers or IT guys that maybe saw an opportunity with cybersecurity and wanted to get into it, but may not be the best qualified, because nowadays cybersecurity is a quite a broad topic.
As is IT, but they're really two separate roles, much like a general practitioner versus a specialist. So, my suggestion for folks looking to hire a cybersecurity company would be to look at their track record, their reviews, references, certifications, accolades.
Things like that, and then areas of expertise. You know, we've talked in previous episodes around the Cybersecurity Maturity Model Certification, or the CMMC, which is a mouthful, I know. But that maturity model is really the latest regulatory standard for cybersecurity, and.
T here is been a lot of push to put the CMMC and have it overtake some older regulations, and I think overall that would be a good thing and make things hopefully less confusing for a lot of folks, especially smaller businesses and companies. So you might know this. I am CMMC certified. Blake CMMC certified. We have a lot of others that are certified on our team and partners.
And one of the big things with the CMMC is there's a clear distinction between the roles of cybersecurity and IT, and you can't have the same company playing both sides. It's not ethical, and it's a conflict of interest. So a lot of companies, I don't think, realize that they may be comfortable with the IT guy that they've been using for a while, or maybe the managed service provider.
And you know, obviously, with the latest threat landscape, you know, you might have called your IT guy or your managed service provider about, you know, how do I protect my company from ransomware? Have we done a simulation? You know what what kind of tabletop exercises can we do? So, I think that that conversation would be naturally brought up to the trusted IT.
But the reality is that that vendor may not be best suited to deliver. And, like I said, there's a good reason of why the Department of Defense put out the CMMC process and why they they separated those roles. You know, I think it's it's good to have a checks and balance.
You don't want the person building your network to also be the one responsible for securing your network. So, I think that that's probably a good place to start. What do you think? Oh, I can't hear you, Blake. Are you muted? Yeah, it definitely does seem like a conflict of interest.
You know, obviously, those who are building your network and cybersecurity infrastructure should understand it, and they're going to know the weak points of it. Because, frankly, none of us have unlimited budget. So, so yeah, they may be able to, I guess, know where the the bodies are hidden or the, I guess, skeletons in the closet. Yeah, I don't know that's proper analogy, but.
But yeah, and so having somebody else, you know, check your network and go over your network, the health of your your cybersecurity policies and infrastructures and cybersecurity hygiene makes a lot of sense. Because, I mean, you're not taking the same test twice, you know. It's like a student grading their their own paper or something, you know.
Yeah, I think I think that's a good point. I think that you know, you know, even for our work with the CMMC, you know, we're a registered provider organization or an RPO, and we help a lot of defense industrial-based companies or DIB companies, as well as small businesses, medium business enterprise customers of all shapes and sizes. We help them.
Make sense of a lot of these regulations. You know, CMMC is the newest iteration; that's why it keeps coming up. But even those in healthcare for HIPAA, or now there's the new Federal Trade Commission or FTC regulation for automotive dealerships. You know, we have clients that we help with that. So there's all these new regulations that keep coming out. But even we as a provider.
The work that we do under cyber with the CMMC, they have to. Those companies have to get our work checked by what's called a certified third party organization or a C three P A O, and that their job is only to check and provide the formal audit. So we're not allowed to do the formal audit. We could do what's called a practice audit or or a pre assessment and all the the consultative preparatory work.
To get to the formal audit, but we're not allowed to do the formal audit because it's a conflict of interest. So, I actually think that's a great idea. I welcome it because if you look at the supply chain and you look at all the statistics and the threat landscape of all the previous hacks, most of them, sadly, were self attestation and they weren't third party audited.
So, a lot of these companies that were hacked, they never had a risk assessment from a third party. You know, in the HIPAA world or the medical world, they allow a self-assessment. You don't have to get a third-party assessment. However, a third-party assessment, while most often does cost money and may be viewed as expensive, it's actually one of the cheapest and best things that your company can do.
Because you're getting that specialist to look through everything with a fine tooth comb, and it's not to put anyone down or you know criticize anything. It's really just to catch, like Blake said, the skeletons in the closet, and hopefully catch them proactively before you have an issue or a breach. What would you say? I mean, we've worked with.
A lot of, at least, I I know we have worked with a lot of third party IT firms, and I guess in the day to day operation side of things, like I am sure you've noticed more red flags than I have, but I've certainly noticed some red flags, and you know, maybe I guess our our listeners might be able to to pick up on some of those things if we can call attention to them.
In this podcast, so I guess if you know our customers or our listeners were vetting a cybersecurity firm, you know what advice could you give them to look out for in terms of red flags? Yeah, so some advice would be, like I was saying earlier, looking at track record, looking at references. If they're hesitant to give you references or they're kind of hiding behind the curtain, that's a red flag.
If they don't understand the latest regulations and the standards, that's a red flag. I've this is a little comical to me. Sometimes companies will misspell certain regulations, like HIPAA. A lot of times they'll misspell with two P's: HIPAA, which is incorrect. That is wrong. It is HIPAA.
So different regulations like that, I could see like a office person or an employee misspelling it. But your expert, your specialist, that should know that regulation inside and out. It's just comical and a bit inexcusable to me for them to misspell it. So that's a red flag in my viewpoint. Like with the same with the CMMC.
If they don't know what that stands for, or they don't know the lingo, and there's a lot of lingo. I mean, I'm not saying that that person has that, or that company has to know everything, because we're not that person or that company either. We don't claim to be the know-it-all of every situation. However, it's a red flag when no one in the company or
Connected to the company via partnership, whatever can can shed light on the topic. That's where it gets a little fishy to me. Experience, in my opinion, is very powerful. Testimonials and references are very powerful. Letting their customers tell you about the experience, hopefully a positive one, is powerful.
I know Blake. You know project that comes to mind that we did for a big bank locally here. You know, I feel like we did a great job of showing and shedding light on, or pulling, like you said, skeletons out of the closet on certain things. And you know, I feel like we did a great job pretending to be the hackers because here is the thing. You know, hackers don't care. They want. They're doing their job, and their job.
In this context or this case, is most often stealing intellectual property, causing disruption, whatever malicious act. But the point is that they're not going to wear kids' gloves. You know, they're they're going to do what they can, right? And and when we do a job or we do a project like that, we try to emulate what that experience would look like. So.
You know, just like with the military drills, fire drills, different types of practice exercises, like we talked about, tabletop exercises. Having companies do these things, you know, if you call your cybersecurity prospective company that you're thinking about hiring and you say, "Hey, I'd like to do a tabletop," if they're like, "What's a tabletop?" You know, that's a red flag. You know.
If you feel like you know the lingo better than they do, that's a red flag, you know. So you could check, you know, well-known publications on, you know, ranking. Like UpCity is a good one that ranks different companies on their expertise and their their awards and things like that. Certifications, you know, that's a good measurement. Different types of certifications exist.
Um, but real, I feel like experience and track record and references or customers that talk about their their positive experiences. I feel like that's really the best way to vet, you know, a provider. Something that I think about too that immediately came to mind. I was waiting for you to say it, but I'm surprised you didn't. Is is pricing services?
Or products without without fully understanding, you know your security your security placement, your security layers, what you have implemented, your your current cyber hygiene. You know, I think that to me is the one that I see the most. You know, when I've talked to customers before on the phone, they're like, "Oh yeah, well this person."
Quoted me this this amount this amount. It's like, they know what servers you're running. Do they know like what your fire like what type of firewall you're running? Do you know like how many endpoints you have? Like they they don't seem to to to know any of this, but they're still somehow pricing out you know services or products. Yeah, that's a good point. So.
Pricing is a challenging task. You know, the from a customer lens is, you know, how much does this cost? You know, what is this going to cost me? How do I budget for this? And oftentimes, when you ask a customer, "What's your budget?", they may not know. They may truthfully not know. You know, some customers may know, but they don't want to tell you the budget because they feel like they're going to that's going to be that information is going to be used against them.
But some customers have never gone through a security risk assessment. They don't know what that costs, and I think what Blake was trying to say is that some companies will charge five hundred dollars or a thousand dollars for an assessment, and some companies will charge fifty thousand dollars for an assessment. And obviously, they're different, and we could explain why they're different.
Using different methodologies, using different levels of expertise, you know, this comes up a lot with penetration testing. We've talked about penetration testing or pen testing, where typically with penetration testing, a white hat hacker, a good hacker, will try to break into with your permission your computers, your endpoints, your networks, your equipment.
Using public information or reconnaissance and different tools and tactics. Well, in the industry, a lot of people would abuse the word, the keyword, pen test, and confuse it with vulnerability assessment. Where a vulnerability assessment is a tool, most often software.
Kind of like your antivirus software, where you run a tool against the network endpoints, and the tool then scans databases and comes back with typically what's called a traffic light report. You know what's green, what's orange or yellow, and what's red. What are your critical alerts? What's wrong? But it's it's an automated approach. Okay. Well, a lot of
Managed service providers or IT guys that are kind of dabbling in cybersecurity that are not really cybersecurity experts yet, or maybe not as mature as some other firms, they will effectively misrepresent a vulnerability scan as a pen test. So, a pen test typically, you know, all different ranges of scopes and pricing.
The pricing ultimately depends on how much time does the human ethical hacker spend per IP address on your stuff or your application. You know, if if if you've got 50 computers and they spend 15 minutes on each endpoint, you're going to get a price of X.
If you are a company that says, "Look, I want to know if anything exists," take the gloves off, be a hacker. Then, truthfully, you don't give that hack, that white hat hacker, you don't give them a time bracket. You say, "Go have at it," right? Because a hacker's not going to say, "Oh, I'm going to stop in 15 minutes." You know, a hacker's going to spend days, weeks, whatever it takes, to break into things.
So, when you have and you pay a company, an experienced cybersecurity company, to thoroughly and effectively pen test your organization, if you have the budget, it's obviously going to be more money to pay their team to take the gloves off and act like and behave like a hacker, a real hacker would, opposed to.
Oh, I need a pen test because my insurance company said that I had to have one. How do I check this box? What's the cheapest way to do this? Right. So there are companies that do that, and okay, yeah, we can get this done for five thousand dollars. Like Blake said, very limited information, limited scope. What's what's really the cheapest way that that my company can do that? So there's that perspective just to check the box.
And then there's the perspective of how do we do this right? How do we make sure it's done right for the first time? And how do we really get a real pen test? And that in that example from pricing is much like anything else that can be priced. You know the old adage, "You get what you pay for." Right? We all know that a Ferrari, a Porsche, they're expensive vehicles. If you find one for five hundred bucks.
You know that it's a red flag. There's got to be something wrong, right? So it's kind of the same thing, right? I mean, if you're going to hire a cybersecurity expert, some of them might be five hundred dollars, fifteen hundred dollars an hour or more. Some, you know, inexperienced, directly out of school, they may charge ninety five dollars an hour, but it's a different level of expertise you're getting.
The novice versus the seasoned hacker, right? So it's a whole different experience. More expensive specialists, cardiologists. You know, if you're shopping for a heart valve, you know, and and your doctor says, "Look, this surgery is going to cost you a hundred thousand dollars."
Do you really want to find the cheaper provider to do that? You know, or do you want to find the most experienced? That all those specialists do day in and day out is that one thing. They're honing their craft. They're super good at it. Their success rate and their their accolades and their reviews and testimonials from people that have gone through the process are positive. You know, so I think that that has a big effect on pricing. But you're absolutely right.
Pricing cannot be achieved or given without a proper discovery or an assessment process, and that's part of our methodology. We can't just throw pricing out there because we just don't know. It's an honest approach. If somebody throws pricing out for a project without properly doing a discovery and assessment process, then it's just, in my opinion, it's not ethical and it's unfair. and
Unless you're getting a fixed fee, you know, there's a lot of problems that can happen with with an approach where you don't properly assess. I've noticed too, in my experience here, a lot of people attach, and not only here but in in other jobs, people attach a higher value to a tangible product. You know, oh, okay, like we talked about.
Uh, you know the Ferrari instance. The five hundred dollars Ferrari. It must be a Matchbox car. But anyways, you're not going to go to a Ferrari dealership and then go to a uh Ford dealership and be like, oh yeah. Um, I was at the Ford dealership and their car is thirty thousand dollars. How come your car is a hundred thousand dollars? And then oh, okay. Well, you know I can show you this. I can show you that feature. I can show you that feature. I can show you.
The engine, the exhaust, whatever, right? The build, the leather stitching - you know - all these features that people attach to like a tangible product make more sense to the human mind because they can touch it, they can feel it, they can see it. But on the flip side, services don't quite scale, and they don't properly.
They're not properly affixed in that way, unless they're sitting over our shoulder and they're watching us literally try and hack into their own network. They're wondering at the end of the day, oh, what did I pay for? I don't necessarily feel this. I don't. I don't feel satisfaction from paying for this. And that's one thing. One thing that I've noticed: people just don't understand.
Especially in the services industry, you know, you are paying for experience. You know, you are paying for time. You are paying for energy, effort, and you may not be able to feel it like you would a physical good or a physical product. You know, you can't touch it. Um.
So somehow I've noticed, coming from selling luxury products, like people don't - they don't respond in the same manner to it. If that makes sense, yeah. No, it makes sense. I mean, I know we're running up on time already, but I think I think you're right. I think a lot of people can't. It's it's kind of like health insurance or.
Or life insurance, rather, it's intangible. You don't really want to pay for it, but you know you need to have it. And unless you go through some life event, or a friend, you know, gets hurt, or or ultimately dies, and they don't, you know, you find out they did have health insurance, or they did have life insurance, and you know, this is what happened, or maybe they did not have the proper insurance and paperwork in place, and then you see what happens to the family. You know, unless you experience that.
It's kind of like, well, do I really need that? You know, it's it's this mysterious vapor, you know. But the reality of the situation is, it's real. The threats are real. The headlines don't lie. This we believe in a layered approach. You know, a trust list approach. We don't like to trust any one vendor or one type of solution, and we encourage.
You that shop for cybersecurity services to take that approach as well. Try to find vendors that embrace zero trust and trustless technologies that are layered. And the more layers you can layer on top of your business to essentially create an onion or a force field. You're not relying on any one layer. You're you're relying on the sum of all of those layers together.
To make you as unhackable as possible. Yeah, I think that's a good point. I mean, trustless is the way to go. Anybody who you know does it stands out from the crowd in terms of pricing, in terms of value. You know, you're not always going to get the best.
For the cheapest price, it just doesn't work like that, especially in today's world. You know, people know their worth. At least in our industry, people know their worth. People are getting paid by the big companies to serve providers. Is it unaffordable? No, it's not unaffordable. But is it worth it? Absolutely. Yeah, and so one thing I just wanted to kind of close out with is.
You know, we are constantly looking at the market, and we get the feedback from small businesses on how expensive some of this stuff is. And we're always working as a company to give the most value for our clients. And one of the the latest offers that we came up with is for just five hundred dollars, we do a compliance armor vulnerability assessment. We call it KAVA for short.
It's a huge, high-value assessment process that leverages proprietary methodology and patented solutions that are very unique. Can't find it anywhere else. And we deliver it for just five hundred dollars. And basically, we give a taste of what extended detection and response (XDR) technology can offer. And we combine that with the people, and we test the humans on your team, and do an assessment of them. And we combine that with a review of your maturity.
Level, we give you a score. We score you against your peers anonymously, of course. But we show you: look, this is where you are on the scale. This is where your peers are on the scale. It's a letter grade system, and it's just a really high value experience that shows you: look, this stuff is not as expensive as you might have thought it was.
It's pretty easy to implement for most businesses and situations, and I encourage you guys to go to compliancearmor.com to check it out and sign up today. Yeah, yeah, we'll be back. I think next week for another podcast. We've got plenty of ideas to talk about in the future. We're going to try and pack as much value as we can into these podcasts in as little time as we can.
You know, we don't want to drag these podcasts out, hence why we're trying to cap them. But we've got a lot of cool stuff in the pipeline, a lot of cool topics. I think I'm definitely excited for the next one, and yeah, I guess we'll see you guys there. Yeah, one thing I just wanted to kind of throw in here. We'll talk about it in a later podcast, but I'm sure you've seen the headlines around the FTX cryptocurrency exchange and how they didn't have assets, and basically the whole thing went bankrupt.
And quite frankly, a lot of people suffered badly around losing their what they paid for and their assets. And I've said this many, many times before. Don't trust any company or exchange or anything like that. Embrace zero trust and trustless technologies. If you're dabbling in cryptocurrency, you should be using a cold wallet where only you control the private keys, and no one else never share them with anyone.
And you control the information and the assets that you hold, because if you if you trust any company with anything, you're subject to their rules on security. And you know if they don't have their stuff together, you in the end are the one that's going to lose. So protect yourself. We want our listeners to be well prepared and protected. You know, obviously we don't give financial advice, but my point is that.
From a cybersecurity perspective, if that's a world that you're dabbling in, we could probably make a whole podcast episode or series on this. The point is the same point that I've driven home before: use a cold wallet, use zero trust, use encryption, use all of the technologies that are at your fingertips. That, quite frankly, don't even cost that much money. That you know, do the right thing and embrace those zero trust technologies.
I did see an article that cold wallets, hardware wallets, whatever you want to call them, soared 300 in sales after FTX. Well, there's probably a backorder, probably a shortage. Oh, and by the way, I've said this before too: never buy a cold wallet on Amazon or any other merchant. You have to buy them direct from the manufacturer of the of the cold wallet. You never want to buy from a reseller. A lot of scammers will buy cold wallets. They'll open them up. They'll put a there's a card in there with the secret.
Key, and then they'll repackage it up so it looks all genuine. Then the user will set up that wallet with the pre-configured card, which is a big no-no. And then the hackers wipe the wallet; they wipe it clean. So you never want to do anything like that. You always buy it direct from the manufacturer, and you set up that private key from scratch by yourself. Never put it digitally; type it anywhere. It's it's physically written, and you store it.
Like it's a bazillion dollars in a vault or a safe place. Definitely not worth it to save five or ten percent on Amazon. But I did, I did notice because I was looking up pricing on hardware wallets pretty recently, just to see if they were backordered, if they the price has gone up, kind of like crypto, and or down in that case, but.
You know, I have noticed that. For example, I think it's Trezor. Trezor, their Nano S, the new Nano S Plus, whatever Nano is Ledger. Oh, yeah. I am sorry. Yeah, Ledger. Yeah, I did notice that now there is a shipped by Amazon, but sold by Ledger.
What are your thoughts on those? Because it's like five or ten percent cheaper. Yeah, probably not. Again, I don't trust it. I'd go direct. Yeah, that's just my opinion. I'd rather be safe. I mean, I'd rather go direct, buy it direct, know where I bought it from. You know, I buy a lot from Amazon. We got one minute to wrap up. But just in closing, I buy a lot of stuff on Amazon. I'm sure that you do too. But in certain categories where you want something to be genuine.
I won't take the chance. Like I'm sure you won't buy a Rolex on Amazon. You know, I mean, there's people that'll sell them, but unless you've got a high trust of the vendor, and again, supporting evidence and artifacts to prove that what they're selling is genuine, if it's something that can easily be duped or faked, I will not buy it on Amazon, and I don't recommend you do it either.
We'll leave it on that note. We'll see on the next one. All right, thanks, guys. Take care. That's a wrap on this episode of Encrypted Ambition. Subscribe wherever you listen, and if today's guest inspired you, leave us a review or share the show with someone in your circle. To learn more about how we support innovators with AI, cybersecurity, and compliance.
Head to petronellatech.com. Thanks for listening, and remember, the future favors the bold.
Never miss an episode
New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.