All episodes

Dave Navetta

Apple Podcasts Spotify SoundCloud

In this episode:

Alex interviews infosec lawyer Dave Navetta. News from Amazon, ViaWest, Notion, Ping Identity, ProtectWise, Webroot, LogRhythm, and Optiv.

Ping is a leader (but we knew that already, right?)

Need that Amazon order this afternoon? Well I have good news for you. Amazon is rolling out 2 hour deliver to Denver. Denver is the #8 tech city in the country, and our workers are crazy well-educated. It's a good week for Ping Identity, as it is recognized on Gartner's Access Management Magic Quadrant, and is rated the #1 large tech company to work for in Denver. LogRhythm also had a great week, winning gold in Gartner Peer Insights. Woman leaders at both ProtectWise and Webroot are recognized by Built in Colorado. And Optiv, Colorado's biggest security company, makes some big industry hires.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. We're continually working to improve the show, and appreciate the feedback we get from our listeners. If you discover any audio issues, or have suggestions for our format, let us know.

This week's episode is available on SoundcloudiTunes and the Google Play store. Reach out with any questions or comments to info@colorado-security.com

Feature interview:

Alex sat with Denver's own Dave Navetta, security lawyer at Norton Rose Fulbright. Dave was one of the creators of the cyber security insurance, and offers some great insight from his years in large firms, his own firm, and the insurance industry.

Local security news:

Job Openings:

Upcoming Events:

This Week and Next Week:

Notable Upcoming Events:

View our events page for a full list of upcoming events

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11900 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is episode number 20. This is the newscast for June 19th, 2017.

And we are here ready to talk about security news. Alex, how you doing? I'm good. How are you, Robb? I cannot complain.

I just got out of a family event. My— the rest of my family, everyone but me, is a taekwondo student right now. Wow. And I had the opportunity to watch them gain their brown belt. So they're consistently kicking your ass.

Is that what you're saying? My, my 9-year-old son literally elbowed me in the groin and twisted my arm tonight. Nice. He wanted to demonstrate what he's learned. Uh, I, on the other hand, spent the evening, uh, doing go-karts and, uh, putt-putt golf and other things like that.

Less violent family activities. Less violent, but, uh, slightly more— probably slightly more entertaining and less painful. Yeah, exactly. Yeah. Well, so anything you want to chat about before we jump into the news?

Uh, well, it is Father's Day this weekend, so happy Father's Day. Happy Father's Day. Are you going to spend any time with with your father? Uh, I will not get to see my father. He, uh, he is on the other side of the country.

Um, I'm sure I will call him. Um, but happy Father's Day to him as well. Fantastic. Um, but yeah, happy Father's Day to all the fathers out there that are listening. I'll get to hang out with my family, uh, in Chicago.

So we're recording a couple days early this week. I'll get to hang out with my family in Chicago as I'm there for, for Ping's big industry event. Um, and Kristen tells me I get to pick what we do on Father's Day, but It's in Chicago, and I have no idea what that's going to be. So maybe next week we can talk about it. Exactly.

Something to look forward to. All right. Let's go ahead and dive into the news. Top story of this week is that Denver is named the number 8 city in the US for as a tech city. We're number 8.

We're number 8. I guess the good news is we are ranked number 1 for educated employees, educated workforce. You know, and I had heard that in, in previous years, too. Lots of educated folks in Colorado, which I think helps with the quality employees that we have around here. Yeah, and that is a big part of what draws folks in.

You know, as we were looking at this article, and I, you know, suggest folks take a, take a minute to click through the article and skim it, see what's interesting there. There was one thing that really jumped out at me, which was they have a graph on there showing the number of tech workers throughout the US over the last, I don't remember what it was, 20, 30 years. And you see this huge spike in 2001, and then it goes right back down after the dot, you know, the dot-com bubble burst. But what really surprised me is, as of now, we still haven't reached the number of tech employees as we had back in 2001. Yeah, that is kind of crazy.

Um, you would think with the growth in technology since then we would have more. But, you know, one thing that I was thinking about is, uh, you know, a lot of those sort of entry-level technology jobs, uh, call center workers and other things like that, have been outsourced to other countries. So I think that we may have a smaller pool of overall tech jobs, even though the the technology industry as a whole has grown. I guarantee there were a whole lot fewer security professionals in 2001 than there are now. That's true.

I can guarantee that as well. All right. So next on the list, we had Amazon has more news. I know we keep talking about Amazon just because they're doing some pretty cool stuff, right? They are doing cool stuff.

So the Amazon Prime Now service is available in Denver. I feel a little left out because I think Denver is like the 30th city to to finally get this. But, but now if you want something from Amazon, you can have it delivered potentially within 2 hours, some of some things within 1 hour. Wow, that's, that's pretty neat. And if you really need to have that new iPhone case, it can come same day and it's no extra charge either.

Yeah. And also some other breaking news today that wasn't actually on the list was that Amazon made an offer to buy Whole Foods, which I think is pretty interesting. Again, not security related, but Amazon is going to be our tech overlords and our grocery overlords and everything else overlords here pretty soon. The Kroger/King Soopers people really literally should be shaking in their boots. Amazon coming into your industry is not good news.

I think that just about anyone in any industry is shaking in their boots at this point about Amazon. Yeah, they're pretty impressive. I actually, you know, it's interesting to see the Whole Foods. I do listen to a podcast. It's an NPR podcast.

Called How I Built This. And I recently listened to an interview that featured the founder of Whole Foods talking about how they built, and interesting story. So if anyone wants to spend 30 minutes listening to a fun story, go, go look that up on, on the podcast, uh, store. And I can't take credit for it, but, uh, someone that I know posted that, uh, Amazon with this acquisition is becoming more and more like Buy More from WALL-E. And it's pretty soon that they're going to be giving us everything we want in our little moving chairs, and we're going to be fat blobs that that don't do anything besides, uh, look at a screen and, and eat. Well, as long as we have our virtual reality goggles on, we won't have to recognize that reality.

Exactly. Um, so next story, uh, ViaWest, which I think most people know is a local, uh, data center and services company. Don't forget about their security arm, right? They acquired Applied Trust 2 years ago, something like that. Yep.

So they have a really large, healthy security practice here in Denver, actually in Boulder. Headquartered or headquartered up there doing security services. And they were sold to a North Carolina company for $1.675 billion. That's a lot of dollars. That's a lot of dollars.

I'd take that. Yeah. So congratulations to those folks. I think they actually were already owned by a private equity or actually they were already owned by Shaw Cable. So they had already sold out quite a ways ago.

But I still consider them a Denver company, though. Yeah. Well, and they are headquartered here by a West part is headquartered here and I think they'll remain that way as well. So another Denver headquartered company is called Notion. If you go to getnotion.com, you can take a look at them.

They are a Denver-based smart home company. And what they do is they create little sensors that go in your house that sense if there's smoke, if there's a change in humidity, moisture. There was like carbon monoxide sensors that you can put in your house that will, you know, alert your cell phone and let you know if something bad's going on in your home. I also saw that they have surface tension sensors and that, that really, it detects when you and your wife are having issues. Is that, that's what that does, right?

So it's just $200 to buy these sensors. So, you know, better, cheaper than couples therapy, right? Exactly. So, so anyway, Notion has taken on a $10 million investment round to help them scale. So this is kind of interesting news here in the Denver area.

Yeah, it is definitely interesting. Not a direct, uh, security play here, but I think that, uh, you know, one thing that is very important with any of the Internet of Things sorts of devices is privacy. Um, you know, are they, uh, are they properly securing these devices? Um, how are they securing the data that they're collecting with all these devices? Um, if someone knows when I come home and knows when I leave, um, you know, knows a lot of information about how my family operates, I'd want to make sure that that data is private and secure.

So I do have a quote here from the, um, from the article. The additional funding is going to allow them to amplify their relationships with insurance companies. So basically it looks like the idea is that they're going to try and get insurance companies to offer discounts to, to policyholders who put these in their home and keep an eye on stuff. So I've had, you know, I've had it, we've talked about it, a couple of floods in my basement in the past. It makes perfect sense for me to go spend a couple hundred dollars, put a sensor in there and keep an eye on it, but there are security concerns, right?

So for the many security practices in town, guys, they just got $10 million. This might be a good time to reach out and see if they could use a pen test or a security assessment. Maybe they need a CISO as a service. So I'm sure there are, we'll be receiving many calls asking for help. So next on the list, very close to home for me, Ping Identity had a pretty good week from a, from a press release and a news perspective.

Number one, we were named the top tech company to work for in Denver in the large bracket. So Denver Business Journal had numerous different competitions for small, medium, large, and then extra large companies in the area. Ping Identity falls into the extra large 'cause of how many employees we have here in Denver. We were named 4 overall, but the number one in terms of tech companies as a place for employees to work. You know, that's pretty surprising based on how horrible I've heard you say it is to work there.

Yeah, generally off the air when I make those comments, right? So Alex is going to try and get me in trouble. Ping Identity is a fantastic place to work, and we'll talk more about that when we get to the jobs section.

No, congratulations. It's a great place to work from all I've heard. Being number 4, especially number 1 tech company, that's wonderful news. So you all get a job there. Thank you.

A second piece of news, uh, for about Ping this week, we were named a leader in the Gartner Magic Quadrant for identity— or excuse me, for access management. You know, we talk about this from all the companies. This is a— I'll tell you, if you work at one of these companies, the whole Gartner Magic Quadrant process is, is taken very, very seriously. We know that customers are looking at that, so it's a, it's a big thing. It's something we're rightly pretty proud of when it gets there.

So Ping was not too long ago bought out by a different private equity company. So all that money that you guys got from the buyout, you used to buy your spot on the Gartner Quadrant. Is that how that works? If it worked that way, there would— it would be a whole lot different process, I'll say that. So, no, just kidding.

Just kidding. Gartner, full disclosure. No, it's not how it works. Again, congratulations. It does take a lot of work to, uh, to make that those, uh, magic quadrants, not in the monetary sense, but, uh, having good products and proving that you have good products.

Uh, so next on the list, um, there was an article about, uh, women leaders, and it, it was nice that they, they highlighted a number of, uh, women in technology in Colorado. But, uh, 2 of the folks that they highlighted were from ProtectWise and Webroot. So it was good to see that security was represented. So it was only 5 people throughout the area, um, that they were highlighting women who have, you know, been successful and kind of serve as role models for folks in general. And like you said, 2 of those 5 were from security companies, and I think that's worth commenting on.

And, and definitely kudos both to ProtectWise and Webroot for being supportive of an inclusive environment, and hopefully they can help, you know, help drive that inclusiveness throughout the industry. Uh, next on the list, uh, LogRhythm wins a gold on the Gartner Peer Insights Again, I'll say they must have paid a whole lot of money for that. No, but congratulations to LogRhythm. For full disclosure, I'm a LogRhythm customer and I would completely agree that they deserve this award. Yeah.

So the Peer Insights Award is really a— it's a poll taken of security professionals and it says, you know, how happy are you with this different vendor? It takes into account both the number of people who reviewed each of the products and the overall rating per product. So this is not a, you know, some panel out there that says this is the best product. It's actual customers who really were happy with LogRhythm. Yeah, and I think that's really important.

Um, getting feedback from actual customers is a lot better than, uh, some of the, uh, you know, top 500 lists that we talk about here on the show where, you know, some marketing person submits an application and you get put on the top 500 list. Uh, so next, uh, Optiv, they hired a number of industry veterans to help, uh, forward their, uh, their cause. So Anirban Chakravarti was hired as Senior Vice President of Worldwide Partner Solutions. Michael Lyons was hired as Vice President of Strategy, Risk, and Compliance Advisory Services. And Doug Steelman was hired as Vice President for Managed Security Services.

So, you know, I don't, I don't know 2 of those guys, but I do know Michael Lyons. Michael is a Colorado guy, and a big shout out to Michael. Uh, pretty glad to see, you know, you landed well here with Optiv. He was the CISO at Harlan Financial Solutions, or it might have been D&H when he was hired, that kind of followed me when I was there. I heard nothing but good things about him.

Congratulations. Michael has actually talked at RMISC either 2 or 3 times over the last couple of years. So really nice to see a security guy here from Colorado make a nice step like that. Yeah, and it's always good to see Optiv continuing to grow. Yep.

So congratulations on both sides there. Final news story for this week. We actually have a link in here to a LogRhythm blog, which is around reactions to Trump's executive order on cybersecurity. Not to get too political or anything, but I, I'm usually dubious of things that come out of the Trump administration. This one actually was not too bad.

I think based on what you— what it stated in the article though is Words are one thing, you know, you really need to back it up with some funding and other things to make sure that it's going to happen. Yeah, and as you read through, you know, I'd recommend you guys take a look. James Carder, the CISO at LogRhythm, was one of the panelists kind of talking about this topic. I think his point, as you just said, was yes, these things sound fine, but are you going to give it the funding? Are we going to deliver results?

And let's see where we are 12 months from now. Yep. And Sort of preview to the future. We do have an upcoming interview, not today, but in a future episode with James on the podcast. Yeah, appreciate that.

All right, let's go ahead and dive into upcoming events. Just as a reminder, as we've said the last couple of weeks, we do have a calendar on the website. Go to colorado-security.com, click on security events. It'll show you not only the events over the next week or two, but also the events really over the next 6 months. So take a look there.

You can see what's going on and get your own stuff scheduled. So first on the list, Optiv on the 20th, which I believe is Tuesday. They're having their annual Denver Enterprise Security Summit. So they've got a bunch of folks lined up to speak on that. It's an all-day event.

So if you have interest, go ahead and check that out. On the 22nd, we have the ISSA Denver Healthcare Special Interest Group. They're going to be meeting at Dave Buster's on Colorado near 25. I know registration's open there, so recommend you guys get out there. Also on the 22nd, CTA has a Meet the Board event.

So if you want to meet some of the folks on the CTA board, go ahead and head out there. I think this one specifically was Suma Nallapati, which is— Suma is the CIO for the state of Colorado. I've had the chance to get to meet her a few times. She's fantastic. If you guys can get out there and get to meet her and get to understand more about CTA, I highly recommend it.

Um, SecureSet on the 23rd has a capture the flag event. They actually have 2 events. We've talked about this before. They have their introduction to capture the flag at 5 o'clock, then they actually have the capture the flag at 6 o'clock. Uh, on the 24th, the Colorado Springs ISSA is doing one of their mini seminars.

Again, I don't know that we know the topic there, but if you need some CPAs— CPEs and want to learn some stuff, go ahead and check that out. Uh, so the following week on the 27th Uh, that's, that's Tuesday. The ISSA Denver Women in Security meeting is happening, and that's at the Denver Fieldhouse. I know there was a little bit of confusion with an email that went out last week with incorrect information. It is at the Denver Fieldhouse.

Uh, get RSVP'd now. Last I saw, there was 80 people registered. It's going to be another great Women in Security event. Highly recommend you guys take a look. So on the 28th and 29th, uh, Cybersecurity World, which I believe is a MISTI event, is going to be in Denver.

I think that's the first time that they're here. I don't believe I've ever heard of it. Yeah, if they've been here before, I wasn't aware. So good to see another event coming here to Colorado. Looks like there's some interesting speakers there.

It is a for-pay event. So definitely check that out if you're interested in going. And really over the second day of that is the Avanta CXO event. I actually think it's kind of a bummer because this is a— it's likely that the audience would want to go to both of these. But Avanta does their traveling executive show really focused on getting CIOs and CISOs together talking about strategy and where they're going as a big picture.

So that's on the, on the 29th. Yep. And, uh, I am on the governing board of that event, so you should all come. Um, I will be moderating, uh, and helping to— don't, don't let their poor taste in governing board dissuade you from coming. Uh, thanks, Robb.

Uh, so also on the 29th, uh, SecureSet is doing a cybersecurity career trends event. Yeah, and they're the same night that they do that, they're actually doing their open house. We mentioned it was supposed to be the 20th, the 17th, um, that got postponed. So it's gonna happen the 29th, that same night. Yeah, so this is their, their new location, which is right by Coors Field.

Yeah, absolutely. Um, so let's go ahead and jump over to jobs. We have a little bit of a trend. So we'll go over the first couple jobs, then we'll dive into our, to our theme for the week. Um, Denver Health, this is one we appreciate the shout out.

This was sent over to us and asked us to post. Denver Health is hiring an IS Analyst Security 3. So that is 3 times as good as an Analyst 1, but not quite as good as Analyst 4. No, you have to know where you sit there. Exactly.

Some self-reflection there to understand if you need— this is your job or not. Johns Manville, Cybersecurity Analyst entry-level. Yeah, so if you guys are looking to get into security or you know someone who's graduating or wants to make a career change, this looks like a good opportunity there. We do have— so the rest of this is all themed the security companies in Denver and opportunities at each of those companies. The first one I wanna talk about, it's a really great opportunity, and it's working for just a fantastic boss and at a great company that was recently named the best tech company to work for in Denver.

Number 4 overall for extra-large companies. Yeah, so obviously Ping Identity, we're hiring a GRC analyst. What we're looking for here is someone with Somewhere between 1 to 3 years of controls experience. Maybe you've got ISO controls, SOC 2 controls, FedRAMP controls. We'd love to have you talk to you about that.

Go ahead and apply through the website, or you can send me a note personally and I'll make sure you get sent to the right place. Alchemy Security, they have multiple security operations roles open. So Joe Bonnell, who we've interviewed for the podcast, he is the CEO there. So great company, local here, doing great managed security operations. So if you listened to the podcast last week and you said, man, I like that guy, I wanna work with him, some good opportunities.

I think there was actually 5 positions open, including one as a manager of their operations center. So take a look, whether you're entry-level or way more experienced, there might be a role for you. Red Canary, they are also looking for security operations center analysts. Yes, so similar to, probably similar to some of the positions at Alchemy, someone to really help hands-on and eyes on glass working on alerts coming in. ProtectWise is hiring a DevOps engineer.

We've talked about a couple of DevOps engineering positions in the past. ProtectWise is that, you know, network security visibility company that takes the place of SIEMs for a lot of organizations. They're looking for someone to help them with their infrastructure internally. Swimlane, they're looking for an integrated marketing intern. Of course, Swimlane, they do security orchestration, orchestration and, uh, automation and automation.

Thank you. I knew it was SOA, couldn't remember what those words were. Yeah, so, so there, you know, this is obviously not a security position, but it is an entry-level marketing position for a security company. You know, if you're— you got a friend or a colleague who's interested in that, we'd love to have, have you guys send them over there and let them know we sent you. Cody over there was one of our early interviews and love to help where we can.

And then finally, LogRhythm is hiring a senior security analyst that would be reporting to James Carder. We've now mentioned James what, 3 times on the podcast? I think he owes us something for that. Something. I better get like a logarithm shirt in the mail or who knows.

Absolutely. Uh, well, anyway, I think that takes us to the end of the news for this week. Anything you want to add before we, uh, throw it over to the interview? No, let's get to the interview. Yeah.

So Dave Navetta, uh, he's the information security lawyer at Norton Rose Fulbright. Yes. Yeah. So I had a great conversation with Dave. Um, he's a longtime, uh, local Denver person.

Used to have his own firm, is now with a large firm, so it should be a good interview. I haven't listened to the interview yet, but I'm going to put my prognostication hat on and say, did you talk about cybersecurity insurance a little bit? We did talk a little bit about cybersecurity insurance. Good stuff. All right.

Well, thanks, Alex. We appreciate it. We'll come back to you guys and talk next week, and enjoy your week. Thanks, Robb.

Hi, this is Chris Martinez, CISO at DigitalGlobe. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.

This is Alex Wood with the Colorado Equals Security podcast, and I am here with Dave Navetta. I've known Dave for a number of years. Dave's a cybersecurity lawyer here in town, and we're going to talk about a number of issues today. Excited about that. But first, Dave, why don't you introduce yourself and give us a little background on what you do and how you got here today?

Thank you. As mentioned, my name is David Navetta. I am a partner at the law firm Norton Rose Fulbright, and I'm the co-chair in the US for their data protection, privacy, and cybersecurity group. I've been doing this area of law, practicing this area of law since about 2002. I started out in this area working at AIG and helped them develop their cyber insurance program around 2002 to 2005.

Since then, I struck off and started my own firm called the InfoLaw Group in around 2009, and then in 2014 joined Norton Rose Fulbright, where firm with about 4,000 lawyers worldwide, and we have approximately 12 to 15 people in the US that do data security and privacy work, and globally it's probably 60 to 70 people that do this type of work. Awesome. So when you say you guys do data security and privacy work at the law firm, what does that really entail? What sort of services, what kind of things do you deal with, with your clients? Yeah, so you on some level, data security and privacy is a narrow specialty, but it's also very broad and touches a lot of different areas.

So, you know, when we practice and we break our practice down into 4 pillars, the first pillar is compliance-related work. So this is policy work, whether it be privacy or data security policies. It's also work that involves helping companies with privacy by design and security by design when they're developing various products and services. So we help them understand their risks, understand what they need to do to make their products and services compliant from privacy and security point of view. The second pillar is transactional.

So as everyone is aware, organizations outsource a lot of their data processing activities to third parties, and there are legal issues that arise when you do that type of processing. So we help companies develop vendor management programs to analyze their vendors' data security and privacy practices. We help negotiate the terms around data security and privacy in these contracts, that type of activity. Increasingly, the data security and privacy issues are coming up in the mergers and acquisitions context as well. In fact, we saw that with the Yahoo merger, where there was an issue there.

Just a minor one, only— what was it, only $250 million or something? $350 million. So, they got off cheap. But, you know, increasingly when a company is buying another company, they're also figuring out whether or not they're buying a data breach or whether they're buying data that they'd like to leverage that is actually encumbered on some level, personal information or other types of data. So, we come in and help with the due diligence process oftentimes.

And then there's a third pillar, which is incident response. So that is, you know, data breaches occur, we're kind of one of the first responders. Typically we get calls often in the middle of the night, often Friday around 4 o'clock is when we usually get our calls for data breaches. And so we help companies handle the process, we help them with the investigation by bringing in forensic resources. In certain cases, there may be notification obligations that need to be addressed, and we help with that process as well.

As part of incident response, we have increasingly been doing incident response planning. So we're helping companies who now, their philosophy is essentially to assume they're gonna have a breach, or some even assume they have had a breach, and they want to develop their internal policies to address that. Again, we're coming at it from the legal side of the equation, so there are, you know, obviously forensic and technical issues there, but our planning is broader and more holistic and brings in a lot of different stakeholders, whether it be legal, security, IT, privacy, risk management, PR and communications. We bring all of those stakeholders together in these plans to get them ready for a breach response. Response should they have one.

And then the 4th pillar, which we're seeing more and more activity, is the disputes pillar. So that's regulatory action defense and regulatory investigations that occur as a result of data or privacy violations, and of course litigation that arises out of data security and privacy. We've seen those class action litigations being filed in consumer-related cases, whether it be credit card or Social Security numbers. We're seeing banks increasingly sue companies, retailers, after they've been hit with credit card breaches. But we're also seeing business-to-business type lawsuits where, as I mentioned before, a service provider perhaps has a breach, which is ultimately the responsible— responsibility of the data owner, and there could be a lawsuit back to the service provider for failing to protect the information.

We're seeing lawsuits and activity in the directors and officers context. So shareholders and others going after boards of directors and officers for failing to disclose security weaknesses or otherwise put security measures in place as part of a duty of care in their role as a director or officer of a company. So there's an uptick in that area as well. So it's a It's a very fluid and dynamic practice and world we live in. I enjoy it because, you know, the law and technology and security, they kind of collide into each other and warp each other and kind of create questions that no one really thinks about until they're forced to think about it.

Oftentimes we try to, of course, be more proactive and anticipate some of these issues, but just the warping effect of the law on technology and vice versa, in my mind, is really fascinating and makes this practice never boring at the end of the day. I've got to imagine that you're always seeing something new.

Something that sparked my interest there is, you mentioned the suits against boards of directors. Do you see the attitudes of boards of directors changing? Are these lawsuits forcing them to think more about cybersecurity for their companies? Yeah, I think that's happening. So, in 2013, we had the Target breach, and it was one of the first times where we saw officers and directors, you know, essentially losing their jobs over data security and privacy issues, right?

And in fact, I have a chart in one of my presentations that shows the cyber insurance spend over time. And it's a, you know, it's an increasing trend line, but when you hit end of 2013, when the officers and directors were starting to lose their jobs, all of a sudden that trend line spikes, right? So the risk all of a sudden became more real in a way when people start losing their jobs. So I think over time what we're seeing is a situation where previously, you know, general counsel or CFOs or CSOs of companies would try to push this issue up to the board. Now it's being pushed, you know, down to the officers, and the board is being more proactive about asking questions and wanting more information on these topics.

So I think there's a— there's been a little bit of a switch there in terms of the push and pull around, you know, raising this issue at that board level. Do you guys get involved in that area in terms of, you know, being more proactive? You mentioned mentioned, you guys try and help people be proactive. So, you know, a board might get more interested in cybersecurity. Would they bring you guys in to help make sure that their program is functioning correctly, or— Yeah, you know, again, at the board level, the questions and issues are higher, they're more strategic, and also more tied into, you know, financial performance and financial impact of the company.

So we do get involved in helping advise boards and helping them understanding— to help them understand how cybersecurity, data security-related issues impact, could impact their organization. Typically, we work with like a GC or a CFO or some other officer who regularly reports to the board, and one of the topics they're increasingly reporting on, either because they're again pushing it up or being asked to report on it by the board itself, is data security. Security and privacy, and really what is the nexus between financial performance and, you know, what could go wrong, essentially, you know, in a kind of a worst-case scenario that could have a financial, material financial impact to the company.

That conversation and kind of prepping a board and presenting to the board is interesting because, you know, it's kind of like everywhere, everything else in this space, there's a translation process that has to occur, right? I mean, you're not going to tell the board, you know, the nitty-gritty details of the data security and privacy program and, you know, the technical aspects of it. When you're communicating to them, you're looking at bigger picture issues. You're looking at, you know, what could financially impact the company and what do we need to address that. Often, you know, goes to budget and personnel, those types of things.

So, you know, that process of packaging the information in a way that is relevant to the board, but also understandable to the board, is what we get involved in, and actually can sometimes be a challenge. I mean, boards sometimes are made up of people who've been around the block a few times. They may have, you know, very general business kind of backgrounds, but not technical backgrounds. And so that translation process is really important there. And, you know, even having them ask, you know, arming them with the right questions to ask sometimes can be a challenge.

So, I mean, you have to work with that in that context and try to have that conversation and enhance it as much as possible.

Do you see boards being more interested in things like cyber insurance? You know, you mentioned earlier that you started your career doing— or early in your career you were with AIG doing cyber insurance. Yep. You know, I used to think cyber insurance was insurance was just kind of hokey. It's like, oh, you don't want to— you don't actually do any protections, you know, you just want to cover some financial risk.

Yeah. Um, do you see it at the board level, people more interested in that, that type of coverage? Yeah, that's a great question. So, uh, there's actually SEC guidance out there around reporting cybersecurity incidents and cybersecurity, uh, you know, weaknesses in general, uh, with respect to financial statements. So That guidance basically says if there's a, you know, a security weakness or there's been a security breach that could cause a material financial impact to the company, it should be reported on a public company's financial statements, right?

So, uh, what— and actually, that SEC guidance actually mentions cyber insurance as one component for managing the risk. So, the way you can look at it is you could have a situation where there may be, you know, security issues or vulnerabilities company may have, or maybe they had some sort of breach, and they're holding on to a certain level of risk, financial risk. That risk could be material to the organization. One way to make it less material is to buy insurance. So, if you have a situation where, you know, there could be a severe business interruption, or, you know, like in the case of Target where, you know, 45 million records were exposed, You know, having $200 million of insurance or more to help cover that can help mitigate the financial risk and perhaps mitigate, you know, reporting obligations potentially around the security and privacy.

So, I think boards are looking at cyber insurance as a tool to help them manage that issue and manage that risk and decrease, you know, the materiality of a potential data breach with respect to their financial statements. How do you see the, uh, that cybersecurity insurance market evolving? Um, you know, a number of years back, uh, I looked through a number of the questionnaires and other things like that, and they'd ask very simple questions. Um, you're like, how, you know, how can you even tell if I'm secure or not? How can you, um, you know, what level of coverage do I need?

And, and, you know, if I go one place, I'm going to have a, you know, a small premium and and cover what I think I'm gonna need to get covered. And, you know, somewhere else it's, you know, a really high premium for covering almost nothing, things like that. The other piece that I've seen is that it seems like the coverages are getting more finite. So it's, hey, you know, you have a rider for business email compromise now. You have a rider for, you know, all these little pieces that are part of, you know, cyber issues.

So I'm just curious what you see in that marketplace, how it's evolving, how it's maturing. Yeah, it's still an interesting space in many ways. The evolution of it is often driven by the competition that exists in the market, and there are a lot of players in that market. The pricing, in fact, over time, I believe, has gone down because of the competition in the market for this, for this type of coverage. And many carriers are in there wanting to get in the game, and therefore they're offering broader coverage, they're offering coverage for cheaper.

Now, going to your question about underwriting, are they understanding the risks? Are they, are they truly kind of able to analyze the risks? I mean, I query whether anyone really is able to analyze and understand the risks fully, but at the end of the day, competition has a play there as well. I mean, you know, barriers to entry, making it easy for an insurer to fill out an application and get, you know, validated for the insurance plays into the sales cycle. And, you know, companies started out in this space— when I was at AIG, we had actually third-party vendors doing assessments and helping us figure out exactly what a company looked like.

But that was a long longer process, more like looking under the hood and onerous for the potential customer. And brokers, insurance brokers, actually pushed back on that. And so, over time, in many cases, the process for underwriting insurance became simpler, easier. And I think many security professionals then looked at these applications and said, how can this company, insurance company, know really anything about our security? They've asked 10 questions.

And again, that was sort of the product of competition and what the brokers who represent the carrier, or the insureds, wanted to make it an easier process. Now, that all said, I started in 2002, and that was before there were even data breach laws. So, you know, at that point in time, we were trying to develop the product, cyber insurance product. You know, the demand for it was heavily questioned out in the market. You know, why do we need this?

What is this for? You know, there aren't any real liabilities or risks. If a breach happens, you know, we'll just deal with it. No one needs to know, that type of thing. Now, of course, 2003 breach laws came into effect, and that opened, you know, some sunshine onto the certainly personal information breaches.

But now, you know, where are we now? It's 2017. So companies like AIG and Chubb and Beazley, companies that have been in the space for, you know, pretty 15 years now have data. I mean, they have information. So even if they aren't asking, you know, 80-question questionnaires around security and having a third-party vendor come in and do some analysis, they've got history and they've got their own criteria and data to know exactly what their, you know, risk levels are, where to put their premium, and, you know, what's going to be profitable or not profitable.

So I think right now many of the carriers who have been there for a while are pretty comfortable with the risk.

Some of the newer carriers are coming out with products that are, you know, even having broader coverages and trying to, you know, buy some market space. Now, you have to, you know, have to kind of judge whether you want to go with someone who's been around the block or someone who's newer and cheaper. I mean, that's a question that comes up. Some of those bells and whistles you mentioned before, kind of these riders and things like that, are actually intended to help fill in, you know, potential gaps around the coverage that may be traditionally provided. So, you know, we're seeing issues around coverage.

For example, there's been a lot of wire transfer fraud that can arise out of a data breach. So that's not personal information being taken, but the person in payroll getting phished or social engineered and sending out, you know, $5 million, a check or or something like that to some bank account. And so, you know, there wasn't traditionally coverage under a regular cyber program, so now some companies are adding riders for wire transfer fraud that would reimburse some of the amounts that could be transferred out, that type of thing. Business interruption. We just had the WannaCry virus recently, and people were shutting down their systems and unplugging things to spread the virus, or not to spread it, to contain the spread of the ransomware.

And so, obviously, that causes business interruption. And so, now, you know, there's been coverage for business interruption for a long time. Now, many companies are looking at that more carefully and saying, hey, maybe that's what we really need. If we go down for a long period of time, what's our financial impact and what's our revenue loss? Maybe that's a good coverage to get.

So, I think that the market has, you know, again, it's competitive, it's fluid, and I think The competition has been good for insureds because it's been, it's cheaper, it's broader coverage, and they're trying to plug kind of like obvious gaps that may have been missed in the past. So, beyond them having an engagement with you to get more information, what would you recommend to someone who might be in the market looking for cyber insurance? You know, how is it that you need to go about comparing, you know, know, what other criteria you need to look at from, from these vendors? Yeah, one of the— the competition I've mentioned is good, but what is— I don't say bad, but one of the things that is challenging is that still the forms and the various coverages and the wordings are often very different from insurer to insurer. You know, property coverage and commercial general liability coverage has been around for 200 years, and over time the wording's all kind of became similar, very similar, and you could just compare a few points and, you know, had apples-to-apples comparison across various insurers.

Cyber is still, you know, apples, oranges, pears, grapes. And so, you know, there my advice is typically get a good broker, a broker that actually knows cyber insurance. Again, that's an evolution in and of itself. Many, many brokers kind of just do, you know, general placement of insurance across all lines. They're not specialists.

But now increasingly there are specialists, certainly at the big brokerages like Aon Marsh and Willis, but now at mid-level brokers. Like there's IMA here in town, Denver. They have specialists on board, and increasingly it's being pushed down to even, you know, very small brokerages who deal with small businesses and middle market type businesses. So, you know, they're the best source to help understand. They see the entire market across all of their clients, and they get a sense of what's good, what's bad, what the pricing is, and they're usually the best bet to get a good sense of what you might need or not need.

Now, when you need it or when you don't need it, it goes back to some of those board issues we've talked about, whether it's a board or just a management decision. You know, what is your risk? What does the financial risk look like? What happens if there's a breach? Do we have the resources?

Do we have people that we can bring in? Part of the benefit of the coverage is the— and this is where we get brought in oftentimes in many cases— is the first-party coverage, data breach response coverage, which is not just a financial product. Of course, it does pay for the things that happen in a breach, but they actually bring a team in. Right, to help companies deal with the breach. And that's what, you know, we're, we're a first incident responder through most of the cyber insurance products out there.

And we get calls, and we have a hotline, and we're usually responding within minutes of getting a call, our team, in order to be able to help companies, you know, in the emergency situation get their bearings, understand, you know, what they may need to do, what they don't want to do, and keep them on track that doesn't get them into trouble. And so that, that is a benefit of the insurance that people don't necessarily know about. It's not just a paycheck that's being given to you after something's happened, it's actually getting people on the ground who know what they're doing. You know, we've seen thousands of breaches over time I've handled, me and my team, and so to have someone who can help a company experiencing it for the first time look around the corner, understand the pitfalls and, you know, the directions and things to do and things to avoid, that can be really, really helpful and help that company avoid liability, help it avoid reputational loss, help it avoid regulatory scrutiny. So, that's a benefit of the cyber insurance I think a lot of companies are looking at as very attractive, in addition to the financial kind of reimbursement aspect of it.

Awesome. Switching gears slightly, You know, you mentioned earlier the interesting relationship between the law and technology. There have been a number of new and proposed laws and regulations that are out there. I think that the biggest one that comes to my mind is GDPR in Europe. What's your sense of how that's actually going to affect information security and privacy And how people are, how ready are people and what are they trying to do to get ready?

Right, yeah, so just background-wise, GDPR is basically the General Data Protection Regulation that's coming, well, it's been passed in Europe, but it's going to be starting to be enforced in May of 2018.

And, well, I think again the driver for companies that, and why they're worried about that, is first of all, A, many companies are doing global business, even small companies are doing more and more global business. Jurisdictionally, the prior European Data Protection Directive, really you had to have a closer nexus to Europe. You had to be in Europe or have an office there. Now with GDPR, you know, if you're targeting Europeans or dealing with European residents, even if you don't have a physical presence there, you, you may be subject to the law, maybe a to be hauled into court. So jurisdictionally, more companies are under the umbrella of GDPR.

Plus, a violation of GDPR could be a fine or penalty up to, I think it's 4% of the organization's global revenue. So, you know, big companies with a lot of global revenue, 4% could be a very, very significant issue. So, again, going back to the board, boards are interested in avoiding that type of penalty. Boards want to do business in Europe, and, you know, this is a threshold to be able to do that type of business, is to have this type of compliance. And so companies, U.S. companies especially, who already have more of a, I would also say, culture of compliance in many cases, are interested, looking at, and engaging in these GDPR projects.

The projects— so there's a security component and a privacy component to it, both at the end of the day. But what's interesting about them is they require kind of very— again, this is all around personal information, which is a broader concept out there, but they require very intensive kind of data mapping of the organization. So, it's sort of a different type of data mapping as well. So, I think many organizations and security departments and CAISOs and CSOs I talk to, you know, they will in many cases, especially for complex organizations, perhaps admit that they don't necessarily have a full understanding of where all their data is and, you know, the scope of their systems and where the network ends and, you know, where the things kind of may be missing in terms of gaps. This process requires you to actually go through every area where you're touching personal information and analyze from the collection of that information to the disposal of it, where it is, who's touching it, what consents have been obtained, how you're using the data.

So, I think it's a very illuminating exercise and very intensive exercise to get a full understanding of all of the data processes that touch personal information within an organization, and all of those factors that tie back into the GDPR, consent, access, ability to, you know, right to forget, and ability to delete data, all of those things. Once you go through the process of actually doing that data mapping, you get a really good visibility of what your company is doing and how the data flows and where it's being touched and stored and processed, how it's being handled, who it's being disclosed to. That actually could be helpful for a lot of different things. It could be helpful for security, of course. It could be helpful from a marketing perspective to know what data you have and where it is and what you can do with it.

And so companies, I think, even though it's a painful and pretty expensive process to go through, the net benefit of it once you go through it is much more understand— a better understanding and better visibility as to what the company is really doing with data. So, we're seeing many, many companies going down that path and trying to get their arms around it, all because of, I think, those fines and penalties that are possible. Do you see that, you know, this is obviously focused on European citizens. But if you're a, you know, multinational global kind of company and you have to comply with that, do you see these companies trying to apply the same protections that they're gonna have to put in for GDPR to their whole set of data? You know, do you think this is gonna have an impact positively on, you know, people in the US or other countries that are not affected by GDPR, but, you know, companies that are?

Now they're doing extra measures to protect my data, not just European citizens' data. And many times these, you know, a standard like this that has an impact, you know, in Europe but also globally is used as often, you know, the lowest common denominator. In fact, you know, when California passed the first breach law, you know, 48 other states now have breach laws, and California was the model. But even if there weren't breach laws in in these other states, the fact that California, you know, the 8th largest, I think, economy in the world ultimately, had a law required— basically essentially created a national law in a sense. And so I think the GDPR is having the same effect, right?

I mean, it's such an important economic jurisdiction and it's creating a standard that once you comply with it, you know, assuming it's the most protective in a way, you're often satisfying other standards that may exist in other jurisdictions. And in fact, that's one of the benefits of going through this process. I mean, you're not just— when you look at a process for collecting information, say you're a company collecting information on a website or whatever, e-commerce website, you're collecting information from people all over the world, you're handling it in the same way ultimately. And so, even though you're looking at it from a GDPR perspective, now you know, okay, with respect to, say, South Korea or Australia or something, something like that, we can look at what we're doing with this information and we can map it against their laws and understand whether we have issues and compliance concerns there. So, again, that's a kind of a benefit of doing this exercise is getting that visibility and perhaps having sort of a common denominator that you can apply across different business processes in different jurisdictions.

So, a little bit closer to home, in the US there's been a lot of recent either legislation or proposed legislation, you know, from the most recent presidential executive order around cybersecurity. You know, there's the— what they're calling, I think, the PATCH Act, which is going through Congress right now regarding potential for people to do hackbacks and other things like that. I just wanted to get your opinion on the state of cybersecurity legislation in the the US, and if you feel like these efforts that are happening now are going to help or even hinder or, you know, cause cybersecurity in this country to maybe go sideways, who knows? Yeah, I mean, the US is still, when it comes to passing legislation in this area, I mean, not as sophisticated or not as mature as I think in Europe and other places. First of all, I mean, it seems impossible to pass any kind of actual statute regardless of what the, you know, the subject matter is.

There's always proposed resolutions and regulations on data security and privacy, and there's kind of a big splash when someone sort of says, yeah, here's the new, you know, law we want to pass, and then the question becomes whether it ever does pass. And again, that's kind of our form of government, there are a lot of competing interests whenever any of these laws come into effect or even are proposed, actually, whether they will pass. So, you know, we've seen regulation on the state level in many cases. We also have seen regulators with broad authority, like the FCC or the FTC, kind of use that authority to legislate by enforcement. Enforcement, in essence.

So this is why I say the FTC does, is that they, you know, they have general authority over unfair and deceptive trade practices, which again is a very broad term. And what they do sometimes is they see something they don't like in the security realm and they'll make an example of a company and set up a guidepost or a goalpost to say, hey, this is something we don't like, this is something that you shouldn't do, could be unfair business practice or deceptive business practice. And even though a law hasn't been passed, the effect is companies say, okay, well, that's the new thing we can't do, or that's the new thing we have to do per the FTC. So, you know, even though we haven't had many actual data security, comprehensive data security and privacy laws passed, certainly HIPAA and Gramm-Leach-Bliley were in 1999 and 2000, that era. There hasn't really been much since on the federal level.

From a broad standpoint. But even though we haven't had that, regulators have stepped in and state legislators have stepped in and passed some laws. Now, will we ever have anything like GDPR, a comprehensive federal data protection law? I think something really, really bad would have to happen for that to be the case. And, you know, again, wanna cry, wasn't ultimately— I mean, the impact of it wasn't so bad financially, but something like that that would really bring down the economy on some level could result in something where we get a federal law of some sort out there.

You know, again, what'll be interesting is— and this is just me kind of riffing on some of these issues I'm seeing— like, you know, the Internet of Things and kind of the connectivity of things in our infrastructure kind of expanding, whether it be, you know, automated cars or what have you. The way I see things kind of evolving is we're kind of making ourselves, as this technology comes on, more and more vulnerable in many ways. We're expanding the points of entry in terms of where attacks can happen, as well as, you know, probably expanding what the impacts of the attacks could be, right? You know, we're dealing with a company, it was kind of through the WannaCry experience, this is a healthcare entity, and they're looking at their medical devices and saying, wow, we've got, you know, CAT scans that are running unpatched versions of Windows that are vulnerable to, you know, potential breaches that could impact, you know, actual patient health, right? And so How are we going to deal with this problem?

You know, this vulnerability exists. Should the manufacturers be doing something? Should, you know, is it our responsibility? How do we even patch an MRI machine where we don't even really know the details of the software? And what if we try to patch it ourselves?

Are we going to render the machine inoperable or dangerous even? So those are areas where we might see potentially some legislation where there's going going to be, you know, material, either financial or kind of economic or even bodily injury type impact, is where we might see some more activity. But again, I just think that the way our government works, unfortunately, and kind of the competing interests on both sides and the, you know, kind of standstill that we have in terms of actually passing meaningful of laws is gonna prevent anything coming out of Congress anytime soon that is big picture in my mind. So do you think that we'll have to see some sort of, hopefully not catastrophic, but some sort of event happen before this sort of legislation goes forward? Yes, I do.

I think, you know, power grid going out or, you know, a WannaCry situation where, you know, it's very difficult to unwind and, you know, have business interruption occurring that is very significant.

You know, kind of a mass attack with the Internet of Things type modality to it would also probably be part of it. You know, we've seen the, you know, the DDoS cannons arise by taking over various devices, some sort of big entity getting knocked down with some sort of DDoS attack in that context. I mean, something, something. And then of course there would have to be, if there's some bodily injury or property damage, I think those are things that will ultimately, unfortunately, get the attention of legislatures. Short of new legislation, are there any areas where you see potential for improving those kind of situations in the short term?

You know, whether it's, you know, standards bodies or working groups, other things like that? Yeah, I think standards bodies and groups that provide baseline standards of care, or at least, again, guideposts for companies, frameworks for companies to work on, are extremely important. From a legal point of view, we always tell our clients, you know, you should definitely develop your security program you know, make it sure— make sure it addresses your specific issues and customize it for your organization, but have a framework or a standard we can point to. So if something goes wrong, it's not an ad hoc process that we're talking about here. We can say, oh yeah, they were, they were tying this to the NIST standard, or they were basing that on an ISO standard.

So I think those, those bodies, those, those kind of guidance documents that can help create standards and help companies kind of tether them themselves on some level to something objective in a sense are really important. The other thing, again, a lot of this, what we're seeing around security and privacy, is driven by market forces as well. I mean, so, you know, I gave you the example of a medical institution. Obviously, they're buyers of medical devices, so, you know, they can assert certain contractual rights and remedies if they want, if a company wants to do business with them. We're seeing a lot of flow-down of data security and privacy requirements in contracts between private parties because, you know, the seller has often leverage to get some of these terms in place.

So that's a phenomenon that enhances, I think, data security and privacy-related standards. Again, our form of, our system of kind of government or our society in general also, I mean, we kind of don't like plaintiffs' lawyers, but at the same time, when they get traction and develop some sort of theory of liability around data security and privacy and all of a sudden are getting class actions and getting settlements, That also incentivizes companies if directors and officers are getting sued. So, our legal system, even though, you know, we on the defense side find it very annoying, the plaintiffs have a role and have had a role in shaping, you know, companies and their thoughts around data security and privacy as well. So, you know, it doesn't have to come from a centralized governmental authority. There are other influences that are impacting how companies think about data security and privacy and, you know, the steps they're taking to try to protect themselves as well as their customers, employees, and everyone else.

So I imagine you've seen plenty of lawsuits regarding, you know, personal data and things like that. Are you starting to see any actions where it's more affecting the things that we were talking about, you know, physical devices and know, hey, we're, you know, we're a group of hospitals or medical professionals or whatever it is, and, um, you know, we feel like, you know, we've been wronged because these, uh, these MRIs or these, uh, other medical devices now, um, you know, are insecure, they're, they're causing us as a business harm, other things like that. Are we starting to go down that route? Well, we haven't seen it. I mean, you could even say software companies, right, that, uh, who allow a vulnerable to exist that could be exploited in the first place.

There's always been this kind of theory of downstream liability, right? Where does the buck stop? Can you go after a software company that has an unpatched vulnerability out there? What's their responsibility and liability? A lot of it is contractual, and of course, most companies out there, they'll have warranties that only last a certain period of time, or they'll have disclaimers of liability and that type of thing.

So, you know, it's sometimes hard, ultimately, to go after, again, the downstream company that may have caused an issue. We have seen it, actually, it is still in the credit card or personal information space, where, you know, point-of-sale vendors or companies that implement point-of-sale systems who, you know, allow a breach to occur on some level. We had a client who, had a pretty widespread breach, and ultimately the vendor that was providing their point-of-sale system, we discovered, had been hacked, which allowed the hackers to access via remote access all of our clients' point-of-sale systems. So obviously there we were able to, you know, kind of talk to that client, that point-of-sale vendor, and say, hey, you were hacked, you were responsible for this. You know, you need to basically help us with the cost of having to provide notice to all these individuals and the PR and everything else.

So, we're seeing that type of suit where there's kind of more of a direct nexus between the breach and, you know, what ultimately happened, and companies are saying, you need to be responsible for that. We're seeing, you know, we're seeing breaches involving you know, like service providers where it may be a hotel and restaurant type point-of-sale vendor who gets hit and, you know, multiple hotels and properties are affected at the same time. And oftentimes those companies, the ones that may not have the real finance or may not have the actual responsibility to notify individuals, are stepping up and doing it on behalf of their customers. So that's, that sometimes is a occurring. So, but yeah, we're still not to the point where, you know, the software vendor or, you know, someone downstream who can maybe be the root cause of an initial incident are getting held responsible for that yet.

I think it will happen, but we haven't seen it quite yet. So I think we're getting close to the end of our time. I was wondering, do you have any other issues that you feel like are top of mind or people might need to know about that we haven't talked about yet? Um, yeah, just, you know, something we've been seeing a lot of and just make people aware of.

Hackers these days, the personal information market in many ways is flooded in terms of the value of personal information and records. I mean, over the last decade, practically everyone's you know, Social Security number, credit card numbers are out there somewhere, right, in many ways. So, uh, what we've been seeing is the hackers trying to monetize, uh, their, their breaches, uh, in different ways. So I analogize it to, you know, the American Indian, and they would, they would catch a buffalo and they would use every, every part of the buffalo, right? Uh, here we're starting to see attackers who, once they get access to a system, are you know, using everything they can and taking every step they can to monetize the attack.

So, they may go in and— we have a company, it's a mortgage-related company, that we've seen attackers try to go in and intercept essentially down payments to houses. We've seen attackers go into companies and do password resets for the 401 vendor that runs their their employee's 401 and log in and send out the 401 proceeds. So, they're trying to find a quicker route from, you know, the attack to the money. And so, when they can do wire transfers, when they can reroute, we have one where an employer at a hospital chain, the hospital had their employees' payroll checks routed to different accounts. Accounts when the payroll went out.

So, I would say, if, you know, companies are out there looking for things, think more, think beyond just the personal information attack. Think about where, you know, data could, or money could be transferred out, or money could be intercepted, or phishing attacks. We see a lot. This is, if last year was the year of ransomware, this year is the year of phishing attacks. Every, and we have had many, many breaches where phishing attacks have been employed, and the attackers come in, they'll phish a couple people in the organization, they'll gather intel about who that person talks to, who's in their contact list, send out another round of phishing emails, they'll send emails out to their customers, they'll spoof emails.

There's been a lot of that activity over time as well that's been occurring, and so, you know, as an organization, if you're thinking about these attacks, you have to think about all the ways ways that the company could potentially be exploited if someone were to get access to their systems or their email, that type of thing. And so that's a trend I think we're seeing more and more. And the attackers are, you know, they're pretty ingenious in many ways. And so don't— if you get hacked or think you're subject to a breach, don't assume it's one thing. Assume that it could be a lot of different things and act accordingly.

Great advice. Thanks, Dave. This has been great. Appreciate your time and thanks. Yeah, no, thank you.

Appreciate the time as well and look forward to hearing the blog post. So if people want to get in contact with you or hear more about the stuff that you do, is there someplace that they can go or website or Twitter? Yeah, it's— well, email is the best. David dot Navetta, N-A-V-E-T-T-A, at NortonRoseFulbright.com.

Awesome. Thanks, Dave. Thank you.

Learn more about the Colorado security scene at Colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex. Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes