Listen to this episode

How To Choose A Cybersecurity Provider, Penetration Test Pricing, Zero Trust and The Latest Tips On FTX Crypto Exchange Hack

0:0029:57

Recorded December 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this episode of Encrypted Ambition, the Petronella Technology Group podcast, the host and Blake Rea discuss how to choose a cybersecurity provider. The host argues that IT and cybersecurity are distinct roles, like a general practitioner and a specialist, and says having one company both build and secure a network is a conflict of interest.

He explains that, at the time of recording, the Cybersecurity Maturity Model Certification was the latest regulatory standard and separates these roles, and he welcomes third-party auditing because many breached companies had only self-attested. Together they outline red flags when vetting providers, including reluctance to share references, unfamiliarity with regulations and lingo, and quoting prices without a discovery or assessment. They also explain why penetration testing prices vary, contrasting genuine ethical hacking with automated vulnerability scans, and Blake Rea observes that customers often value tangible products more than intangible services. The host advocates a layered, zero trust approach, promotes the firm's five hundred dollar KAVA vulnerability assessment, and closes with advice on the FTX collapse and cold wallets.

Worth remembering

Key takeaways

  1. Hire a dedicated cybersecurity specialist rather than the IT provider that built your network, since the host calls combining both roles a conflict of interest.
    “You don't want the person building your network to also be the one responsible for securing your network.”
  2. Vet providers through track record, references, certifications and accolades; the host says a firm hesitant to provide references is a red flag.
    “If they're hesitant to give you references or they're kind of hiding behind the curtain, that's a red flag.”
  3. Ask whether a quoted pen test is a genuine penetration test; the host warns some providers misrepresent automated vulnerability scans as pen tests.
    “Well, in the industry, a lot of people would abuse the word, the keyword, pen test, and confuse it with vulnerability assessment.”
  4. Be wary of any provider that quotes prices without first performing a discovery and assessment; the host calls that approach unethical.
    “Pricing cannot be achieved or given without a proper discovery or an assessment process, and that's part of our methodology.”
  5. The host recommends layering zero trust and trustless technologies so the business relies on the sum of layers, not any one.
    “Try to find vendors that embrace zero trust and trustless technologies that are layered.”
  6. Following the FTX collapse, the host urges anyone dabbling in cryptocurrency to use a cold wallet, control the private keys and never share them.
    “If you're dabbling in cryptocurrency, you should be using a cold wallet where only you control the private keys, and no one else never share them with anyone.”
  7. Buy cold wallets directly from the manufacturer rather than resellers, the host warns, because scammers repackage wallets with pre-configured secret keys.
    “never buy a cold wallet on Amazon or any other merchant. You have to buy them direct from the manufacturer of the of the cold wallet.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

How To Choose A Cybersecurity Provider. Learn tips on what to ask for and what to look for. Penetration Tests vs. Vulnerability Scans, Pricing, Zero Trust Technology and The Latest Takeaways from the recent FTX Crypto Exchange Hack.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.