Podcasts

Cybersecurity Fatigue, AI Threats, and What Enterprises Must Do Next: Insights from Sanjay Deo

Listen on:
Share this:

Episode Description:

Welcome back to The Amplitude of Tech podcast, produced by Amplix, where we bring together technology thought leaders and enterprise executives to explore the forces reshaping customer and employee experience.

In this episode, Shawn Cordner sits down with Sanjay Deo, founder of 24By7Security and now part of Amplix, to unpack the rapidly evolving cybersecurity landscape in 2025 — and why every digital transformation initiative must now include embedded security from day one.

Sanjay discusses the rise of AI-enabled cybercrime, the explosion of ransomware attacks, and why enterprises are becoming increasingly fatigued, desensitized, and vulnerable to sophisticated threats. He also shares practical advice for CISOs and IT leaders on building defensible cybersecurity investments, preparing for AI-driven social engineering, and creating a culture of cyber resilience across the organization.

The conversation covers:

  • Why cybersecurity must be embedded in all CX, AI, and IT transformation projects
  • How AI has changed the scale, speed, and sophistication of cyberattacks
  • Human behavior as the enterprise’s biggest vulnerability — and how to fix it
  • The importance of MFA, immutable backups, tabletop exercises, and cyber insurance frameworks
  • How CISOs can quantify risk, justify investment, and communicate effectively with the board
  • The growing need for operational resilience, not just cybersecurity

If your organization is navigating digital transformation, adopting AI, or modernizing its CX and IT stack, this episode delivers timely insights to help you strengthen your cybersecurity posture and reduce enterprise risk.

Transcript:

Shawn Cordner (00:13.134)
Hey everyone. for joining me today for the Amplitude of Tech podcast. I’m Shawn Cordner, Chief Marketing Officer of Amplix. Today I had a great conversation with Sanjay Deo of 24×7 Security, who is now part of Amplix. Sanjay talks to me about the acquisition of 24×7 by Amplix, as well as the current state of the cybersecurity industry, quantifying and managing risk for enterprises and a whole lot more. Cybersecurity is such an interesting topic and so important, so you don’t want to miss this.

Shawn Cordner (00:46.35)
All right, Sanjay Deo, welcome to the podcast.

Thanks Shawn for hosting me. I appreciate the opportunity.

Happy to have you. And before we get started, I think you’ve got a little bit of an announcement that you can make here on the podcast.

Yeah, this is a surprise, right? I think it’s a surprise for a number of folks who listen to the podcast. Some of your audience, some of our audience. So after doing a lot of due diligence from our side over the last six months and from your side, from Amplix’s side, we have joined forces with Amplix. We liked the Amplix pitch. You you folks are one stop shop for IT services, right? CX.

also call center, cloud, IT services. And we are exclusively cybersecurity services and compliance services. And I think we both companies are looking for sort of a perfect fit. So just short of being 100 % fit, I think we are very close, 99%. And I am super excited meeting Dan, Dylan, you, what you guys represent. Our values are very much aligned.

Sanjay Deo (01:56.394)
And so as of this week, we are a part of Amplix. We are going to be providing cybersecurity and compliance services to Amplix customers and vice versa. Amplix services to 24 by 7 security. And that is not it, right? It’s the combined forces are going to result in, it’s like a one plus one is going to be a three. And that’s what the expectation is going forward. So I’m very excited, Shawn.

We’re excited to have you. Welcome to the family. Why does this make sense? I imagine that lot of your cybersecurity clients are looking for similar kind of value proposition from a company like yourself, except in other technology areas. Was that the main play? Was it to able to increase the breadth of services and expertise and capabilities that you’re able to offer to them?

Yeah, in a number of cases where we are providing VCSO services or we are providing senior leadership cybersecurity advisory services, have a seat at the table. And so we have a unique opportunity to see what the challenges are in the company, what solutions they are looking for. And so for us, it sort of made sense to combine forces. that way we…

can provide these services or we can inject ourselves in the conversations, which where Amplix is a leader in the marketplace. And so we felt that that will help our customers. think at the end of the day, it’s about customer first, right? We’re trying to help our customers get the right outcome. And so this started making sense the more I talked about it, the more Dan and I talked about it.

And I think vice versa, you folks actually have a seat at the table, right? You have long-term engagement, short-term engagement, you’re helping customers find the best solution. And cyber is the one that you didn’t have sort of an in-house expertise. You were bringing in outside partners to come help you. I think we then, we sort of fill that unique, we fill that void in your list of services that…

Sanjay Deo (04:16.46)
that you have. I think that that makes perfect sense to both of us going forward.

Yeah, absolutely. And we’re starting to find that more and more when we’re involved in other transformation projects, like CX or like AI deployments that, cybersecurity is, is part of that conversation or it can be a source of friction and getting those kinds of projects off the ground and implemented. Maybe talk to me a little bit about that. mean, what, what, how is cybersecurity is role starting to expand into other areas of the technology stack?

You know, I have a saying, if you are connected to the internet, you are a perfect target. And it doesn’t matter who you are, if you have an IP address and you’re connected, you are a perfect target. And, you know, in the last five years, I think the digital transformation has accelerated, right? COVID was the catalyst that made everybody connect to the internet because we could face to face, we couldn’t talk to each other face to face. So internet became the perfect medium.

And what we are seeing is as customers are embarking on a digital transformation journey, right? Whether it is customer facing, whether it’s internal transformation, all of those are exposing a lot of information that should not be exposed. They are connected to the internet. And so the bad guys, who are these bad guys? All right, the bad guys are state actors.

the local organized crime, all of these folks are without using a gun or without using a knife. They are able to then use that IP address by which you have connected to the internet and access your data if you’re not adequately protected. So the digital transformation that the companies were using to reduce costs, increase efficiency, provide better service to the customer.

Sanjay Deo (06:10.794)
started to expose a lot more than was anticipated. And that’s why cybersecurity is becoming a commonplace topic. You know, now it’s even funny, you go to a social party on the weekend and people are talking about, you know, hey, this happened, that happened, this breach happened. by the way, I received a letter from my healthcare insurance company saying that my healthcare data was lost.

So cybersecurity has become commonplace because of the digital transformation that the businesses are embarking upon implementing newer technologies. And that’s directly impacting the consumer.

It’s like that old, that old story, Willie Sutton, the famous bank robber. they asked him, why do you rob banks? And he said, that’s where the money is. it’s where the data is right. Like today data equals for these, for these bad actors. so, you know, the, the, the CX suite, just as an example, they they’re collecting a lot of data, right? They’re PII, they’re collecting credit card information. there’s, they’ve got access to the CRM system, which has.

all the company’s client data. you maybe just kind of talk to me a little bit about, you know, how becoming a data economy is starting to drive dire crime and what does it mean for enterprises?

perfect, perfect, perfect. Okay, so you call it data economy, I call it data as a new oil, right? Everybody wants it, everybody’s using it. It’s very interesting you talk about data economy. Data economy has multiple dimensions, right? From a CX perspective, right? You have customers who are trying to provide one call resolution, who are trying to provide a much more smoother experience.

Sanjay Deo (08:04.17)
interacting with the customer. To do that, you actually have to have data at the fingertips. So whatever bot, whatever software, whatever you’re writing has to be powered by all of the relevant data sources that you can get access to. So CRM, ERP, data warehouse, data lake, whatever you have. And all of that contains all the PII, PHI, credit card data. so think about it, right? If that is misconfigured.

That is not adequately protected. In the hands of bad guys, that is precious. Just to give you an idea, Unvalidated credit card data in the open market is 45 cents a record. Validated is $1 a record. If it’s PII, it’s even higher. If it’s healthcare data, every record is like somewhere between $200 to $300 per healthcare record.

This is starting to become so important for the bad actors because they are able to take this data and monetize it. If my cell security number and my first and last name, home address, phone number gets leaked, they can actually create a false identity of me and apply for bank loans and things like that. Similarly, if the healthcare data gets lost, or not lost, but in the hands of the bad guys, they can actually create claims

and find those claims against insurance companies and CMS. So the data is becoming so important, like, know, protecting the data. So the digital transformation, the CX, anything that you’re trying to do in the marketplace is resulting in collecting the data so it’s available to make decision. That data starts to become a risk if it’s not protected from.

Sure. You know, in the case of CX, having all of your data systems integrated can be a big benefit, if not table stakes, right? Because it creates a smoother customer journey and customer experience ultimately. But that could be a fatal flaw when it comes to cybersecurity. The more interconnected and integrated all those systems are, the easier it is. a trade, and once you’re in, you access everything, right?

Sanjay Deo (10:24.494)
But let’s just think about this, right? The next stage of CX is enabling all of CX using AI, right? So for AI to work, to AI to become, result in better outcomes, more and more data is being asked to be consolidated into the same place. And for AI to be better, you have to clean all the data. So all of the companies that are embarking on this AI,

transformation using data, they are now cleaning data so the bad actors have access to better data and they have to do less work to get to the right data that they can monetize in the marketplace. So it’s a very vicious loop that we are all stuck in where we are trying to get better outcomes for our customers, but for that we are creating this data which has value and if…

not protected properly, the bad guys are having a field day on us, right? Hospitals, perfect target. I’m in the middle of negotiations with one healthcare company and one hospital right now where they didn’t have adequate protection and all of the data that they have collected now is in ransom. So these are some of the things that whoever is architecting this digital transformation, this CX improvements, elevations,

They need to have, they need to make sure that the cybersecurity discussion is happening along, is embedded. It cannot be after the fact. It has to be embedded in the conversations, in the design and in the delivery.

Yeah, I like that embedded in those conversations embedded in any project, any kind of transformation project that you’re And I think that’s why Amplix sees so much value in the 24 by seven service offering and, and, know, why we’ve made this move. because we’re doing these large scale, you know, transformation projects and, we’re adding a lot more value by embedding the security conversation in those transformation projects. You mentioned, adequate protection.

Shawn Cordner (12:33.818)
And I’m wondering what is adequate protection? And before you answer, you know, every once in a while you’ll see that maybe a TV show or a news article or something will interview a criminal or a thief and they’ll ask, how do we not be victims? the answer is usually something as simple as lock your doors or have a dog or pay attention when you’re walking through the parking lot.

Is there a simple way to have adequate protection? it like that, that if they jiggle the door handle and it’s locked, they’re going to move on to the next opportunity or are they going to be persistent and you need…

are so correct, right? So think about it for one second, right? The bad actors, whoever they are, they don’t know whether it’s Shawn’s company or Sanjay’s company or Shawn’s IP addresses or Sanjay’s IP addresses. But if Shawn had a 12 character password and Sanjay had a password 1234, guess what happens? They are able to decrypt my password in four seconds flat versus a 12 character password.

It takes them over four years to decrypt. Guess what’s going to happen? They’ll jiggle the door, like you said, so they’re going to grab my password some way, some shape. They will decrypt it. They get my, they get my password. They’re going to leave you alone. And you will never ever know that somebody did come and jiggle the door handle or somebody stand your firewall or something like that, right? They’re going to basically attach the attack.

on my company or myself, and they will never ever, they’re going to basically, they have a list of people. It’s like, okay, Shawn’s company, don’t even bother. And so they’re going to move on and probably never ever come back. Most of the folks, right? The survey, there are so many surveys out there. The most common password still is password one, two, three. And more than that, the funniest thing that we are seeing in the marketplace that people trying to…

Sanjay Deo (14:43.15)
trying to be organized on their desktop laptop will have a file, an Excel spreadsheet called password. And guess what that file contains? It contains all of the passwords for all of the systems that they’re using, bank passwords, password to their office email, personal email. And I can bet money 99 % of the time, most of the passwords are very similar. So guess what?

If a bad guy gets into my system and finds the password Excel spreadsheet, everything that I touch at work in my private life, everything is up for grabs. And then we sit and complain. like, my God, I’m a victim. But, you know, I think, 10 years have passed plus five years after COVID. we have seen so many stories on CNN, on ABC, Wall Street Journal. I think the common.

person has to be a lot more careful about what they put out and how they put them.

Yeah, sounds like I’ve got to change some passwords after this podcast recording. I think one of the biggest security risks that an enterprise is going to have is people, right? Because the human condition is exploitable and these bad actors, know how to exploit it. So we hear about that in terms of social engineering and maybe we could talk about that in a second. But what I’m really wondering too is how can security experts and

IT leaders ensure that they’re not enforcing such draconian security policies on their employees that they feel that they have to resort to writing the password down or putting it in a spreadsheet. In other words, how can, can we make sure that we’ve got robust security measures in place that aren’t so robust that people resort to doing stupid things with that data?

Sanjay Deo (16:40.878)
I think you’re starting to get closer to the problem and possible solution, right? So at the end of the day, the human is the last line of defense, right? You can put the best EDR, MDR, you can put the best email system. At the end of the day, the human is the one that’s going to click on a phishing email, which will have the word free on it, and then all bets are off.

But it’s the CISO’s responsibility, CIO’s responsibility, not to have very difficult security. The whole idea is that security has to be frictionless, right? And when I say frictionless, a lot of folks are starting to talk about multi-factor authentication. We still find in this day and age that multi-factor authentication is absent. So trying to make security easy to use,

is a better way of securing everything than making passwords 20 characters or getting them to carry a UB keys and hard tokens and things like that, because they lose it. then they have a call, excuse me, called help desk to get it. And every time they do that, it’s like $25 to $50 per replacement, right? So the idea right now is what is an easy way

to make it difficult for the bad guys not to come and attack your company or even if attack your company that they see that these companies has what is called basic cyber hygiene. I think those are some of the things that actually need to be implemented. Of course, in a bank, there are definitely higher levels of security in the hospital systems. We’re starting to see higher levels of security that is starting to happen. That takes time. That takes, as part of the transformation that

actually has to be thought about. Right. One of the, one of the cases that we came across is a surgeons, the surgeons completely revolted and said, we are not going to use MFA. We’re not going to use short timeout. We’re not going to use any of this. And when you started to peel the onion and try to understand what the business logic was. It’s like, I have my full PPE on. I’m in the surgery room. I need to access the EHR. Right. I need to know.

Sanjay Deo (19:04.94)
what patient and what condition or what am I treating over here, right? I’m doing 20 surgeries a day and the only place where I can find the information about my patient is an EMR. You guys have put a 15 minute timeout. I am turning to the patient, taking care of them and 15 minutes passed because it’s a longer thing that I have to do and suddenly my computer is locked out. Do you expect me to take my gloves off and type my password and then is that

I need to in most of the surgery rooms, you’re going to see that the timeout is eight hours. But you have to put that in perspective. It’s within an enclosed environment, right? You are in the surgery room. know, common patient cannot walk in and out. So again, you have to design security for a very specific purpose. Those are some of the things that most of the CSOs are starting to learn that the security posture

or the security solution cannot be the same for the user who’s sitting on the front desk, the user who is processing claims, the surgeon who’s taking care of the patient. So you have to come up with point solutions to make it easier for the user and harder for the bad guys to exploit.

Yeah, you can’t have a patient bleeding out while you’re waiting for a password reset.

That’s an acceptable right.

Shawn Cordner (20:32.792)
But you know, sense of urgency, which brings me back to the social engineering topic. since of urgency is one of those things that is a tactic that’s used by con men. That’s just a little time. Right. so the bad actors have harnessed that it’s like, you’ll get that text message. We get this when, we, in fact, your team may see this when, when we acquire a new company or we make a new hire and they join Amplix and it gets posted out on LinkedIn.

they will start to receive scam text messages and direct mail and in-mail that say, Hey, this is Dan Gill, your new CEO. need you to initiate a wire. And so you’re like, my God, the new CEO needs me to do something. And he told me it’s urgent. And so you act before you think, not everybody, but if they do it enough times, one person might make that mistake.

These bad guys are exploiting your emotional mental state. They’re trying to elicit an action from you. We’ve seen cases where the NGM case, the whole casino hotel, everything was brought down. There it was the help desk. The bad actors threatened to hurt the bad actors, the help desk family.

So guess what? The person had to comply with what they were asking for. Now, you know, we can still sit down and argue. It’s like, hey, they are 8,000 miles away. They are not here. They are not one mile away or five miles away. How do you know that when you say to go there? Right? So that is happening. And social engineering is circumstantial. Like we have done a number of social engineering attacks. We have done fishing attacks, but we time it.

Right? Retirement to a point where the human is most vulnerable. Right? After the Thanksgiving meal, we have tested this, right? So one of the most beneficial phishing attack that we did on a company was after the Thanksgiving lunch at three o’clock, we sent an email on behalf of HR that you are getting three months of LA fitness for free. Log in.

Sanjay Deo (22:50.99)
provide a user ID password and HR will enroll you. Guess what? We have somewhere between 50 to 70 % people doing it. They were all walking back from the barbecue that was happening outside. They had stuffed themselves with all of the very nice juicy ribs and now they were sitting and suddenly this HR notice shows up and they’re like, yeah, sign me up.

So it’s all about how vulnerable you are when you get that email and the bad guys are becoming very good at it. using AI to scrape LinkedIn, Facebook, Instagram. So they know what’s going on with you and your life. The example you use about, you know, after the announcement on LinkedIn, both the companies are going to start getting some very sophisticated emails.

Shawn, blah, blah, blah, blah, or Dan or Dave, your CFO, you know, people in my department. And so we all, like I got an email today in the morning and I guess we, maybe we are so hyper sensitive about these things. It was a legitimate email. And I’m like, I’m not touching this. I sent it back to Dylan. said, Dylan, is this for real? And

You know, he smiled and responded back, this is for real. You have to do this, this and this. I’m like, okay, I didn’t know. know, nobody told me that you were going to send me this. Anyway, so, so I think the human vulnerability is very much exploitable. You know, the simplest of the word free evokes so much emotion that the bad guys, use it left, right and center.

Yeah. Well, first of all, your example of the ransomware is particularly devious because not only did you hit people after they’re full and tired and, and, know, feeling social, but you also hit them with a free gym membership after they just over ate and probably feeling horrible about themselves for the amount of Turkey that they just put in their mouth. But, you know, how, how do you know

Shawn Cordner (24:58.226)
Your example for those listening, Dylan is our COO and he runs our &A. Our &A guy, Nick, rolls up to Dylan. how do you know it was Dylan, right? This kind of leads us to the next problem is how AI has revolutionized the landscape of threat actors. because AI deep fakes are possible,

They’re easy, they’re inexpensive now and they’re pretty good. How do know that’s still in? How do you know that that’s whoever you’re reaching out to to authenticate that that’s a real response or real email that you have to respond to? How do you know today?

John, that is a million dollar question. Whoever solves that figures it out. But I think I have a very basic principle. If the email is informational, and I can reasonably believe it’s coming from the user who I think it is, I will read that email. If the user suddenly out of the blue asks for something, right? So our transaction is,

You’re the CRO, you’re the chief marketing officer and you’re sending me stuff to review and edit. Suddenly one day you send me an email, like, hey, we are doing a campaign internally. Can you send us $100? That’s when the bulb will go off. It’s like, Shawn has never done that before. literally what I’ll do is I’ll pick up the phone and call Shawn. Like, hey, I just got this email. Did you send it?

But I have no problem paying 500 bucks for a noble cause, but I just want to check it is Shawn, the Shawn I know, the Shawn that works here, or it is an AI created Shawn by a bad actor. Now, if the answer is it’s you and you’re like, everything’s good, done. If you say, no, it’s not me, then we have bigger problems. That means the bad guys are already inside. That could be one scenario. Or the bad guys have spoofed.

Sanjay Deo (27:06.732)
the IP addresses and the email systems, and they’re doing this from outside of our company. And so then immediately you go into triage and you’re trying to figure out what exactly happened, how did this email get in? But, but, but you’re right. You know, these are some of the things that you have to think about. I’ll you an example. This just happened. And again, people are not thinking. Well, the, the perfect example was about three weeks ago, a customer called us and said, Hey,

Our controller has sent 250,000 transactions out to this company. And by the way, this company has been supplying us material for 28, 20 years. And so we said, okay. And said, what is wrong with that picture? And they basically said that, well, they never received it. So how did you guys find out? Well.

when our payments to them, we thought we had made the payment on August 1st based on the invoice. When they didn’t receive it till August 18th, they picked up the phone and called us. And so in this back and forth, we found out we were not compromised. My client was not compromised, but the vendor was fully compromised. The bad actors were inside the system.

Everything they’re invoicing, all of the payment system are compromised. So all they were doing was they had changed. So they would basically send the invoice with an alternate bank information. And so when my, when my customer received it, he was not paying attention to the fact that the, the bank information had changed. So he just made the change, send the money and we’re done. So there were two invoices that came.

Sanjay Deo (29:03.724)
So now the, the, the, the problem is third party risk. You may have perfect technology. You may have trained all your users, but the artificial intelligence bots that are now running are able to mimic the behavior and the communication. So when we started looking at the email Shawn, what we saw is they had grabbed on on an email chain and they had with the email chain was three months long.

back and forth between these two people. And they were able to inject as if the other party had added onto it with a newer date and sent it back. So if you look at the email chain from the bottom up, you won’t find a difference. The way they greeted each other, the way they signed off, the language, short sentences they were using, there was no way anybody could figure out that this was happening other than the fact that the bank information changed.

So now the controls are if a bank information changes, that person is supposed to pick up the phone and call. So Shawn sent me an invoice, but this invoice has a bank information, which I have, you never told me before. So I’m going to pick up the information and say, did you change your bank? And you’re like, what the hell are you talking about? And that’s when we know that there’s a problem in the middle of this communication.

That means someone has to be very vigilant to catch that that banking.

So low

Shawn Cordner (30:30.732)
Or maybe like anything, AI is both the problem and the solution because they’re, maybe it’s not there today, but there could easily be an AI solution that sees that there’s a variance in the information that’s being asked for, right?

So the AI, you know, so if the bot is doing this to you, you should have a bot which should basically detect a change and kick it out to you for manual intervention. Because if there’s a change that means somebody has made a change, whether it’s a legitimate change or an illegitimate change, that’s the part you have to go figure out how to go detect. But I think this is going to get escalated. And again, this is a fishing exercise. That’s why it’s called fishing.

They will send out a thousand of these emails. If even five fall prey to this, they have made their five, 10, $20,000 that day and they’re moving on. You know, as I speak on numerous occasions, I talk about this is their business. Like we are in business here in the U S and making money based on legitimate businesses.

Ransomware as a service, malware as a service is a business for these people. If they can make anywhere between $1,000 to $5,000 a day, that’s 10 times more than they can ever earn in a day over there in some other countries. So we just need to realize they’re going to try very hard to break our shuttle of trust.

So.

Shawn Cordner (32:03.054)
Yeah. And they’re able to do it at scale now because of AI. So let’s zoom out big picture for a second. What were some of the biggest shifts or trends that you’ve seen in the cybersecurity landscape in 2025 so far? And maybe if you could just kind of encapsulate 2025 from a cybersecurity perspective into one headline, what would it be?

Yeah, yes.

Sanjay Deo (32:30.606)
Ah, that’s a great one. I think, um, I’m going to say this with a straight, I try to say this with a straight face. I think we are having cybersecurity fatigue. Right. If you actually take a look at the numbers from 2023 to 2024 to 2025, we had the highest number of reported ransomware cases in the first six months of 2025. We are already at somewhere between 3,800 to 4,000 known reported ransomware cases.

But this last year, I think the total as reported by FBI and some of the folks for 3,300. But we don’t talk about them anymore. Right? Number of phishing has gone through the roof. We don’t talk about it. So in my opinion, I think we are so fatigued out talking about phishing tests that are being done on a weekly, monthly basis at different companies.

It’s one of those things that we are starting to become numb to this phenomena of cyber crime. And I think that’s the part we have to make sure that if you’re giving advice to our customer, that advice has to be a lot more, I would say, connecting to the user. Right? you give the same…

phishing training, cyber training to the user that you’ve been doing for the last five years. Guess what? In that 45 minutes of training, the person who’s receiving the training is not at his desk. He started the training. He walked up, went to the cafeteria and he’s drinking coffee and talking to his friends. And he’s going to come back after 45 minutes and he’ll be given a certificate. That’s it. The objective of the training miserably failed.

Whereas the compliance officer is very happy that all of his employees took the compliance screening, but the cybersecurity posture is still very poor. So, again, I apologize for getting on my soapbox, but this is what is going on out there. Where people are getting numb to all of these things happening. They’re not finding the relevance. I turn this, it hits them. So the best part of this is this is still happening every day, right? I talked to so many realtors.

Sanjay Deo (34:55.638)
Real estate transactions are going haywire because the person transferred as part of the closing transferred $175,000. But the bank never got it. And then we find out that the real estate agent’s laptop is fully compromised. So any closing statement, anything like that has been altered. The PDF has been altered. So, you know, five years ago, 10 years ago, and between 10 and five years ago, you know, if you’re

It was the big companies that were the target. And so the big companies started investing a lot of money in protection. So the bad guys are like, oh, you know, if this is this company, I’m not even going to touch them. Let me, let me, let me cast my net, the fishing net so wide that I can, I can go get 10 innocent fishes and my quota is over. Right. I don’t know. Maybe the quota is $5,000 a day.

Boom, 5,000 people, they sent out the phishing, 5 % of that they got some, 45 of them, $500 or $1,000 each, they’re done. And so now it’s starting to reach common people. And so that’s why everybody is so numb with all of this that I don’t think people are not talking about it anymore. But we had the topic of cyber in our elections.

Right? Both parties fought about it. And what happened? It was the most secure election. And so everybody’s like, if that’s secure, I think I’m protected. And so I think there’s a lot of noise in the marketplace. So whenever we take on an advisory engagement, we try to get to the root cause of what’s going on.

You know, do you have the right technology? Do you have the right training? Do you have the right content in the training? Is that, is that training content evocative? Or is it the same old plane or one or two dimensional training that’s going on? Processes, do you have the right processes in place? So the, the, the, mindset is very different from some of the others that we have seen. And I think that’s why we have, we have achieved a position in the market where our customers like us. And so.

Sanjay Deo (37:16.984)
You not to put a plug in this, but I think I urge all of the CISOs and CIOs and the cybersecurity professionals to start thinking differently. The world is changing, the adversary is changing, and the common user is just becoming numb. So how do you fix this problem where the end user is getting…

Yeah, how do you, because you’re right. You’re there. People are being fatigued at work. They’re being fatigued in their personal lives or being fatigued in news headlines. people are checking boxes right to your point about the training, the individual and doing what they have to do to submit that test and get the passing score and check that box. the compliance officer might be more interested in checking that box than actually.

securing the network, right? Right. Cause there’s a difference between being compliant and being secure. And I think it kind of goes to intent and how much you’re actually leaning into it. And so, you know, I’ve always found that to, motivate people to do things that don’t come naturally to them or represent change is you have to explain the why and you have to kind of make the case that there’s, that there’s some

That’s right.

Shawn Cordner (38:35.03)
some common benefit in this, right? Benefit. So how do you do that? How do you establish the signal through the noise and get people to understand the mutual benefit of security?

You know, it’s again, case by case company by company, right? Some companies have invested significantly and then they have gotten to a point where it’s a plateau. Some companies have not invested and they are at a point where they need a lot of investment. So a broad set of questions help us understand what exactly is going on. Is it, the, is the user completely desensitized because there is an over burdensome training being disseminated?

Or is it the same plain old plainer? So, so we try to basically get in to go find out, know, one of my recommendation is make the training shorter and entertaining. I don’t know if you remember 10 or 15 years ago, if you got a ticket while driving, there were a number of standard comedians that were doing driver, driver remediation.

training, two hours of standard comedy. And the comedy was all about the traffic rules. I’ve been trying to find a comedian who I can hire and who would come and do cyber training as a standup comedy. They talk about some of these stupid fishing exercise. They talk about not having the password in there. So I think it’s one of those things that it is, there are…

definitely number of companies where they are not investing in technology properly. So that could be it. Unfortunately, there is no one answer I can give you which says everybody should be doing this. Every company, every company’s investment, every company’s people training, so different that until and unless you talk to them, understand, do an assessment, get to know exactly what the problem is, it’s very hard to say, do that.

Sanjay Deo (40:42.892)
because of that is different from a complete company.

Yeah, I used to do sales trainings and one of the things we always teach sales reps is, whoever you’re talking to is always thinking to themselves, what’s in it for me? So you have to kind of answer that question. What’s in it for me. Every time you’re trying to get someone to do something that they don’t want to do. So what’s in it for you? Well, a secure business that you work for that the business is and protected, and that means your job is safe.

Exactly.

You know, learning these skills here in this enterprise environment can help you in your personal life as well. It can help you protect your bank accounts and it helps you your mom and your grandparents and whatever. there is some benefit, but you you’ve mentioned the investment that enterprises are making and I’m wondering, can you invest too much in cybersecurity?

That is a very delicate balance. think last week I spoke upon about this whole delicate balance between investment and cybersecurity. investment has to be commensurate to the risk there is. Now, there is risk everywhere. Like I said, if you’re connected, like we got called into a manufacturing company.

Sanjay Deo (42:09.154)
Right? Think about it, a manufacturing company, what is there to get ransomed? Well, all of the barcoding guns, bar scanning guns, all of those somehow got ransomed. So manufacturing building shutters, how can cybersecurity incident impact them?

We always think about cybersecurity impact at banks and insurance and hospitals, but the investment is very commensurate to the risk and the risk can only be identified by risk assessment. so, what was the question? I think I forgot the question. I apologize.

Can you invest too much in-

Can you invest so much? So, um, I think the answer is no, but, but along with that, you invest more comes, uh, how much is more? But I’ll give you an example, right? I think I can’t remember that exact number. JP Morgan Chase is one of the case studies out there. I think their cybersecurity budget is like a hundred billion dollars or something like that. I don’t have the exact number, but it’s like completely outrageous.

And they have like 5,000 people in cybersecurity protecting the bank. Right? Can you take that ratio? Right? Investment to their total revenue and total number of people in cyber to their total number of employees and apply that to your investment? I think that could be a good baseline. But one of the things I do talk about is if you

Sanjay Deo (43:58.21)
So in my opinion, investment into security at somewhere around B minus is a good one because you can go and invest a million dollars, over invest in, and it’ll take one user to click on one phishing email and all of the security you built is gone. It’s flushed on the toilet. So again, it’s a balanced.

Right? Making sure that you have the right technology, right process, right training, and figure out what is adequate for your company. Great question, but unfortunately, I don’t have a perfect answer where I can say it should be 10 % of your total revenue or your total IT spend. Unfortunately, number doesn’t exist. You have to come up with what is the right number for your company.

Now there are different models out there that will allow you to come up and model those, but each of those models are going to take into account your own situation. Right? so I think using a model and getting some people together to think about it, what are they protecting? From what are they protecting? If that gets lost, what is the regulatory risk, financial risk, reputational risk?

All of those things start to go into what is the right investment.

I’ve also heard cyber security experts, we had a couple of panels recently, webinars that we’ve done. so more than once I’ve heard them talk about having too many point solutions and maybe not having a holistic layered approach and having a false sense of security by having too many solutions that are not being deployed in a more holistic way. Is there something to that? Can you have too many defenses?

Shawn Cordner (45:58.314)
that aren’t cohesive that can lull you into a false sense of security.

Yeah, absolutely. You know, we see this day in and day out that a lot of CISOs will hire one of the reputed advisory company. I won’t take their name. And they will basically look at their reports and pick the top right solution in a top right quadrant companies.

I think you just gave away your company.

One of the questions I ask the CIOs and CISOs, when you’re having a discovery call with them, you try to ask them and they’ll beat their chest and say, no, I’ve got the advisory company, I have a subscription and I have bought the top products from each of these reports in all of their categories. And it’s like beating their chest. And my simple answer, my simple question to them is,

So I asked this and I’ve gotten very rude responses to that. My only question I asked him is, you feel secure? And they will all like sit back and say, what do you mean? I’m like, you just told me you bought the best solutions from the most reputed source. So I’m hoping you’re secure because the security is not about the product you bought. The security is about the product.

Sanjay Deo (47:25.742)
What risks did you mitigate? Did you configure that properly? Somebody is operating it. Somebody’s monitoring it. The output of that is being reviewed and reacted to. 90 % of the times we find that whatever point solutions they bought are misconfigured. Do you really think some of these Fortune 500 companies that are getting breached

have not bought the best solution they have. But not talking about mid-management IT and mid-management, I think our mid-management, that’s one of my pet thieves, is our mid-management is becoming lazy and bloated. They basically say, I’ve got 20 security products, so we must be safe.

But when you sit down and talk to them, it’s like, when was the last time you checked your firewall rules? When was the last time you looked at all of the DLP rules? So when you start talking about those, it’s like you suddenly realize that they may have spent a few million dollars buying the solution, but the solutions are not configured, not being monitored and things like that.

You know, it’s one of those things that, you know, the other posture we have seen companies take is either they will buy the best in breed or they will go and buy a platform, right? EDR, MDR, DLP, SASE, everything from one vendor so they can have a fully trained staff.

that basically can manage the solution end to end. Because one of the big things is if you’re buying point solutions, the best solutions in every quadrant, you have to have experts for each of those and then cross train them because if the guys fall asleep or fall sick or leaves, how are you going to replace that with the right person to operate that? So those are some of the things that when you’re making investments,

Sanjay Deo (49:46.126)
When you’re trying to figure all of this out and then the question you need to keep asking is, you safe? That mystical question keeps you on your toes all the

Yeah. And I would imagine too, if you have too many point solutions, someone’s got to be paying attention to what they’re producing, right? To what risks they’re seeing and someone has to follow up on them. So I can imagine that having too many could also create that white noise and that fatigue. And it’s a very human thing that you are overexposed to something, you start to tune it out, right?

But typically, I’ll give you an example for a company say that has about a thousand users. We are seeing somewhere between 30 to 50 cybersecurity point solutions. Right? How do you manage? that?

And that’s producing a lot of events, I’m sure.

Right. and do you really think these vendors like to share information? They all have their world gardens. Right? And so it’s the CSO’s job to architect a single pane of glass. A lot of the times we hear this word, single pane of glass, but when we start peeling the onions, we just realize that only 30 % of their solutions are basically being

Sanjay Deo (51:12.606)
seen on the single place of pane of glass. The rest of the 70 % are either completely disjoint or you have to go run reports to extract data from them. So the whole point of buying these 50, 60 solutions is completely gone because all you’re seeing is you’re seeing 25 % of all the events that are getting generated like you said.

Yeah. Back to big picture stuff. What are CISOs and boards and CIOs losing sleep over right now? And what should they be losing sleep?

That’s a great question. think if you rank specifically in the space of cybersecurity, I think lack of talent and AI are sort of starting to rank in the top two. Right? We don’t have adequate talent. We have talent shortages. If you actually pull up a LinkedIn or Indeed or something like that, I think it’s like there’s like a million

cybersecurity positions open every company, every company means a cybersecurity resource. So, the interesting part of that is either those job descriptions are, incorrect have not been vetted. They’re asking for an entry level person with five years experience. They’re asking for, a CISO who has every possible tool experience. They’re asking. So.

So there’s, there’s, there are open positions, but they don’t know what exactly what they’re looking for. So I think that’s, that’s an issue that’s out there. AI is becoming a big issue, right? Every company now is using AI, but then the CSO knows it, likes it, because you can, you can literally download, you can go on your browser and go to chat GPT. There’s a free version. Right. So, so we are seeing that the companies are starting to leak data.

Sanjay Deo (53:22.304)
If you take an Excel spreadsheet and upload it to chat GPT or any of these, guess what? The data is getting synthesized and it’s available to somebody else. So AI and shortage of labor, of cybersecurity skilled labor are the top two things that are out there.

When you’re talking about making the business investment in security, because you alluded to the fact that there’s a much higher supply or sorry, a much higher demand than there is supply of qualified security experts and that we all know basic economics, right? That drives the cost of those resources up. You’re also, you’ve, you’ve touched on the fact that there are a lot of things for any one person to know. So it’s really probably inadequate to hire one person because they can’t know all the things. So.

You need to make an investment here and you need to justify that investment. So I guess my two questions, which are really very similar are, how do you have a business conversation about cybersecurity investment and, and how do you build a defensible cybersecurity posture, defensible in the sense that you can prove that the investment that you’re making is the right investment and that it’s, it’s generating the expected ROI.

What was the first question? I apologize.

It’s okay. ask conversations like it’s a, or I ask questions like it’s a presidential debate. I know they’re complex. Your question is how do you keep, how do you have the business conversation around?

Sanjay Deo (54:52.002)
Yeah. Yeah. So, so again, it goes back to the, it goes back to the fact that what business are you in? Right. What are you trying to protect? And, and so one of the challenges that the CSOs are having is most of the CSOs come from a technical background. And the biggest challenge right now for them is they are talking to a person who just knows dollars and cents. Most of the time.

Anything that the CISO wants will go to, you know, if it’s a CIO, then I think the conversation is much easier because CIO is a technical person. But if that request is going to the CFO, that’s when trouble starts, right? You’re asking for five firewalls and DLP and any of those things. The CFO is that, really don’t know what are we trying to protect? So one of the key things that’s

that’s happening right now are the, I recommend the CISOs start getting training in business conversation, right? You have to explain to the CFO that we have this risk. Why do we have this risk? Because we have a 1 million patient health records, 1 million patient health record. If we lose them, this is what happens. So translate all of that into dollars and cents.

There’s enough literature out there to train yourself or get some experts to help you and go to them. It’s like, Hey, we have a million health records. The exposure is $50 million to mitigate the $50 million. This is the investment I need to make. This is the prioritized list of things I need to do. need to, yes, I can. I can get $10 million to protect the $50 million. So in the first, you know, come up with a three year plan and.

actually spread out the capex, opex with that. The other thing I tell the CISOs is make the vendors your partners. Vendors will do a lot for you for free to get their business. So develop vendor relationships, trusted vendor relationships, not one-offs, because you have to invest in the vendor when the vendor invests in you.

Sanjay Deo (57:14.338)
So those are the things because the vendors are the people who are out there who are producing solutions to fix these problems. So you may not know, but if you ask a vendor, the vendor may bring you the best solution at the right cost. So, so that starts the conversation with the CFO to put a plan together. I see a lot of, I see a lot of CISOs getting disappointed and dejected. I didn’t get what I wanted. I’m like, which part of your life?

Did you get what you wanted? Right? So there is a delicate balance. You have to identify what is the top one or two, three things you need to go implement to reduce your risk. But you have to explain to the CFO or the board or whoever is the approving authority that this is what we have to do. Sometimes you will be surprised because if you educate these people well, they may approve your budget in 15 minutes or less. Right? So, but

You have to translate the buying of the five firewalls into how those firewalls are going to protect your data and reduce the risk so that the board can sleep at night, the CEO can sleep at night, and you can sleep at night. If that doesn’t happen, then there’s going to be a lot of friction, frustration, and you’ll never get what you want.

So a key component of this is quantifying risk then, right? need to understand what’s going to happen with your breach, right? So what kind of fines might you be facing? What kind of cost in terms of business disruption? you had mentioned DM ransomware attack, the huge cost to them was that they were down for many, many days, Many, many days.

qualifying risk.

Sanjay Deo (59:03.758)
I just, think they were down.

Yeah, yeah, $100 million lost. Whereas Caesars, who also got hit at the same time, they paid the ransom and they got a lot faster, right? That’s right.

That’s that’s a decision you have to make, right?

And you should probably make that decision before it comes up, by the way.

The other thing I talk about is make sure you do a tabletop exercise at the management level. Tabletop exercise, practice, practice, practice. If this happens, what are you going to do? If this happens, who’s authorized to call the cyber insurance company? What are the coverages? Have you practiced this calling the cyber insurance company before? All of those things, spend lot more in preparation than the actual incident.

Shawn Cordner (59:47.63)
Sure. So, so you’ve got fines, you’ve got business disruption. you had mentioned earlier, reputational damage. Yes. Especially if you’re in an industry that’s, if you’re in a regulated industry, you’re probably also in a high trust industry like health. Right. so, so that breach is also a breach of trust with your fine. there’s also brand equity and brand damage because

It’s going to hit the headlines. That’s just how it is these days. It’s going to spread on social media. So not just the breach of trust with your existing customers, but with the market in general, how will it impact future sales potentially? What are some other areas that you might want to look at in terms of quantifying risks?

Actually, Shant, just as you complete your thought, there are quantifiable case studies now available online on Target. So you remember Target in the last five to eight years had the cyber attack on their POS system. The subsequent EPS drop in earnings actually has been quantified.

Yep.

Sanjay Deo (01:01:02.126)
So you can actually see quarter over quarter what happened, right? A user had a choice to go to Target or Walmart. So they may love Target, but that breach of trust led them to go to Walmart. So there are studies that you can present to your CEO if they start challenging you about these things. What else to look for? I think there is this folklore.

That if you pay once, you become a prime target again and again. And so in these cases, I challenge the CIO and the CISO of the organization. It’s instead of spending money on reactive things, why don’t you sit down and come up with some policy statements? Policy statements like we will never pay.

What is the impact of we will never pay? What that means is you have to have complete control of your data. You have to protect your data. And if something bad happens, you have to have the ability to bring the data back. In two to four hours. How do you do that? So spend money in your backup systems, make sure they are immutable, make sure you have multiple copies of it, make sure. You know, if, if, if you get ransomware.

You can tell your board, you can tell your CISO in four hours flat, I will have everything up and running. Right? So, some of those thoughtful discussions need to happen when you go about setting up your cybersecurity strategy. Yes, there are risks, but then you have to think the other side of this is like, if I don’t pay, what happens?

What do I have to do to get ready to make that statement internally to everybody? It’s like, guys, why are we spending money on the posture that we will get breached and we will lose the data? How do we sit down and talk about, we will never lose our data. We have full control of our data. Right? So if a bad guy gets in and exploits it, we have containment techniques. But more than that, the data.

Sanjay Deo (01:03:31.286)
we can bring back the data and our applications in less than two hours or four hours or whatever. Do a BIA and make sure you can do all of that immediately.

And what I think you’re talking about right now is a broader category than just cybersecurity. You’re talking about resilience, right? You’re talking about prevention, but also continuity.

Absolutely.

Sanjay Deo (01:03:51.694)
Yes, resilience is becoming the key now, right? We’ve been doing this for a long time. We’ve been doing this for like 10 years now, better part of 10 years. And I think that now the thought process has to change. How do you make all of your systems, whether it’s cyber resilience or other environmental issues that are happening, right? In South Florida, we have hurricanes. So we have built resilient solutions, right? A data center, local.

data center up in Atlanta or everything in the cloud. Right. So those conversations need to start happening rather than, my God, you know, how do I protect bad guys from taking my data? Right. So those are the things that you have to change your whole thought process after one or two years and think about a long-term resilient posture.

There’s so much to think about, right? I want to see if I can give a heuristic to the people that are listening that might simplify this process a little bit. And I know it’s highly variable based off of the individual circumstances of the business and the industry that they’re in and the clients that they deal with and probably a million other factors that I’m thinking of. But is it fair to say that maybe two starting points could be number one, what are the minimum requirements for cyber insurance? Because

you want to have cyber insurance in today’s environment. so there are certain things that you’re going to need to do to protect yourself to be able to even qualify to get cyber insurance. And then number two, establish frameworks like the NIST framework. Can that give you a starting point?

so let me, let me, let me share with you that pretty much every cyber insurance underwriter has shared in the last three to four years, a list of items that they will be looking for or asking you for. Right. having an EDR MDR, having a pen test vulnerability assessment, having written policy procedures.

Sanjay Deo (01:05:57.078)
And the second part you said is framework. That question is starting to pop up in the last three years. They ask you as part of underwriting your cyber is what kind of framework are you using? And the most important question to them now is do you have immutable backups? So, you know, MFA, EDR, MDR, immutable backups, there are like five or six things that are starting to show up again and again.

And the new one also, with the frameworks, is tabletop exercise. They want to know that your management is using a framework and your management has conducted a tabletop exercise. What that tells them is that you have started maturing your cyber posture, cybersecurity posture, and you have good cyber hygiene. If they don’t see this, then…

God help you. And you know, we have over the last five years, at a client year over year, as we have implemented some of these things that they’re asking for, although the cyber risk environmentally is increasing, we were able to reduce our customers premium by 35%. Like there have been cases where the reduction in premium paid for

the implementation of CrowdStrike. So we’re also learning, right? So there are a number of these bigger cyber insurance underwriters. They are hiring CISOs. So they have their own CISO who review your cyber posture. So we learned that, and what we do is annually when we complete our cyber security plan,

Before we implement, before we spend even one penny, we take our plan and we call our cyber insurance company and say, hey, we want your CSO to review this so that when we start spending money, you guys give us a break. So last year we didn’t have MFA, but this year we have MFA. Not only we have MFA, we have implemented immutable backup. So how much of our premium is going to get lower?

Sanjay Deo (01:08:17.259)
So literally we have started using the cyber insurance company’s guidance to help us put the right elements in our cybersecurity plan. They are the ones who are going to underwrite my risk. So make them your partner to validate your cybersecurity.

So that’s good starting point and then understanding the frameworks that are out there, trusted frameworks and going down that path. And I’m sure both include this, but it’s worth just reiterating education and individuals, And sharing the why as we talked about, think.

Absolutely.

so all that being said, I think we’ve established that you have to quantify the risk and you have to make the business case, which is, you know, some ratio of expense to risk, right? and that’s maybe a little bit harder to prescribe without understanding the individual circumstances. but so let’s say you’ve been able to successfully pitch the investment that you need in order to have.

the cyber security posture that makes sense for you at the time. What are then the metrics that CISO or CIO should be reporting on in their quarterly board meetings to establish that that investment was a smart investment and it is preventing what we hoped it would prevent or producing the return on the investment we had.

Sanjay Deo (01:09:46.926)
So one of things that we are learning when we interview board members and things like that, the board members are also receiving education on different frameworks and the quantification of frameworks. So I’ll give you some examples, right? So in this CSF framework, 2.0 framework, it has six, again, from an abstraction perspective, six buckets.

And so it’s easy for the board members to remember those. And each bucket has some certain set of controls. And so the simplest form of educating them is telling them that you’re using this CSF and telling them that in 2023, this was your score, 2024, this was your score, 2025, this was your score, and tying it back to the investment in cyber.

That’s a very abstract level of representation of what’s going on. As we get more sophisticated, FAIR, I can never remember the acronym FAIR, but it’s basically the actorials who provided information for the last 200 years to underwrite property and casualty. They have launched their own cybersecurity metrics based on the last 15 to 20 years of data that they have.

And so there is now, there’s not improved methodologies, are highly quantitative. And so a number of our clients are starting to explore how do you use a fair framework to identify what the risks are? How do you assign a score to that risk and what’s an overall risk? And so I foresee that some of, some of the companies will keep using NIST because it’s easy for management.

non-technical management to use it. And the NIST provides a very clean, are you spending in restoration? Are you spending in recovery? Are you spending in identification? So what you’re going to see is in the early build out of the frame, early build out of your cyber program, you spend a lot more time in identify, detect, and then as the program matures, you start to spend money more on restoration and recovery. Right? So if you get hit by a ransom,

Sanjay Deo (01:12:11.724)
How quickly can you recover and what are the policy procedures to actually make sure that you recover quickly and faster? Now, again, this is one of those things where you can get highly quantitative, but do you have a board that will respond to your highly qualitative model? Do you have your CEO and CFO that understand this? So each of these models and adoption of this model requires that you educate the recipients.

So we start to talk about, we are helping clients develop this, we start to talk to the board and the CEO and the C-level of what model is being used, what’s the common language, what is the baseline and help them understand how the dollars tie back up to the maturity score of the framework. So it’s not that you snap your fingers and you’re like, I’m using a framework and I’m done.

It’s a lot of work. You have to adopt it, you have to teach it, you have to come up with a common language, and then you have to make sure you use it diligently year over year.

Got it. I guess I’m wondering if just to wrap things up here, if you had the ability to fix one common mistake that you say you see mid-market businesses making, not the largest enterprises, not the smallest SMBs out there, but the mid-market, what’s the most common mistake that you’re seeing them make that is the most consequential and how should they fix it?

adopt an MFA. That’s the easiest thing you can do because what that means is even if your password, you’re using a weak password or your password is out there, the bad guys can, you’re making it for the, you’re making it difficult for the bad guys to get into your systems because MFA will start to slow them down. They’re looking for an easy way in because you said one, and that is the most common one.

Sanjay Deo (01:14:19.854)
and most cost effective one to slow down the bad guys. Because, you know, can MFA be broken? Absolutely. But for MFA to be broken, what I have to do is I have to go find Shawn’s cell phone number. I have to then send a smishing text to your phone. I have to then come up with a way to exploit the vulnerability on your phone and grab the phone so that when the MFA token comes, I can grab it before you can grab it.

And then I can get into your system. But guess what? If somebody else doesn’t have it, I’m going to leave Shawn alone and I’m going go get to somebody else. So if you’re asking for one, that’s the one I’m going to say. Adopt an MFA and make sure every employee uses MFA in your company. There’s no, I’m the CEO. I’m not going to use MFA. Right? Everybody has to use MFA.

So.

Sanjay Deo (01:15:19.647)
See you especially.

Make sure that when they jiggle a lock, the door is locked, right? Yes.

I love that analogy, so yes.

Thanks so much for your time and expertise today. Really appreciate it. And thanks for joining us on the Amplitude of Tech podcast.

Thank you so much, Shawn, for giving me the opportunity and thanks for Amplix to accept us into their family. So looking forward to a great year.

Shawn Cordner (01:15:48.194)
one of the family, it’s going to be a really big Thanksgiving dinner this year.

Absolutely. Thanks, Shawn.

Thank you.

Show more...