The New Cyber Threat Landscape: How AI Is Changing Risk for Every Small Business

Banner showing Mike and Marc

Summary

On this episode of Chattinn Cyber, Marc is chattin’ with Mike Maletsky, Vice President and Practice Leader for Tech, Cyber, and Crime at Hiscox. Mike begins by discussing his career journey into the insurance industry, explaining that he “fell into” insurance after studying finance but stayed because he found the work intellectually engaging and people-focused. He emphasizes that cyber insurance is about much more than selling policies—it’s about understanding complex risks and helping businesses mitigate them. He also introduces Hiscox’s long-standing focus on serving small businesses, a segment that is often overlooked despite its critical role in the U.S. economy.

The conversation then shifts to the cyber threats currently facing small businesses in 2026. Maletsky explains that cyberattacks are no longer isolated incidents affecting only large corporations. According to Hiscox’s Cyber Readiness Report, more than half of small businesses experienced some form of cyberattack within the past year. He discusses how ransomware, phishing campaigns, and cyber extortion continue to evolve, with artificial intelligence dramatically increasing both the sophistication and scale of attacks. Traditional warning signs such as poor grammar and obvious spelling mistakes have largely disappeared, making fraudulent communications increasingly difficult to detect.

Looking ahead, Maletsky explores how AI and emerging technologies will reshape cyber risk over the next decade. In the near term, AI is making phishing emails nearly indistinguishable from legitimate communications. In the medium term, increasingly convincing deepfake audio and video could enable highly sophisticated fraud schemes, including executive impersonation. Longer term, developments such as autonomous AI agents and quantum computing could fundamentally alter internet security by challenging today’s encryption standards. At the same time, he notes that cybersecurity professionals are leveraging many of these same technologies to build stronger defenses, creating an ongoing technological arms race between attackers and defenders.

The discussion also highlights the wide-ranging impact of cyber incidents beyond financial losses. Maletsky explains that a cyberattack can trigger cascading operational disruptions, including business interruption, regulatory notifications, reputational damage, and customer distrust. Perhaps most importantly, he argues that cyber incidents are fundamentally human events rather than purely technical ones. Employees often experience intense stress during an incident, particularly those responsible for responding to attacks or those who inadvertently initiated a breach through a phishing click. Organizations can suffer from burnout, blame, and deteriorating workplace culture long after technical recovery has been completed.

Finally, Maletsky outlines practical steps small businesses can take to improve their cyber resilience. He stresses the importance of ongoing employee awareness training, implementing basic security controls such as multi-factor authentication and reliable backups, and viewing cyber insurance as more than financial protection. Modern cyber insurance increasingly includes preventative services such as phishing simulations, breach coaching, employee education, and risk management resources. He closes by noting that 77% of U.S. small businesses remain underinsured against cyber risk, emphasizing that many companies mistakenly assume cyber insurance is prohibitively expensive when, in reality, coverage is often affordable for even very small organizations.

5 Key Points

  • AI is making cybercrime significantly more effective, especially through highly convincing phishing emails, ransomware operations, and deepfake impersonation attacks.
  • Small businesses are increasingly targeted, with 56% experiencing some form of cyberattack in the previous 12 months according to Hiscox research.
  • The consequences of cyber incidents extend beyond financial losses to include operational disruption, reputational harm, customer notification costs, and employee stress.
  • Employee education, basic cybersecurity controls, and proactive cyber insurance services are among the most effective defenses for smaller organizations.
  • Roughly 77% of U.S. small businesses remain underinsured against cyber threats, representing one of the largest gaps in cyber risk management today.

5 Key Quotes

  1. “Cyber is such a unique risk… it’s never one thing.”
  2. “A cyber attack is a human event. It’s not a technical one.”
  3. “The company’s weakest point is that least-trained employee.”
  4. “I don’t need to compete against my competitors. I need to compete against the non-buyers.”
  5. “The good news is the good guys also have this technology.”

About Our Guest

Mike Maletsky is Vice President of Technology E&O/Cyber at Hiscox USA, with more than 18 years of insurance industry experience. He brings a strong technical foundation in underwriting management and professional liability, including cyber insurance, and has deep expertise across both manual and digital distribution channels. Mike has a proven track record of building full-stack new products through digital distribution, with a focus on technology errors and omissions (E&O), excess coverage, and cyber liability. Known for serving as a key bridge in product development workstreams, he effectively connects business and underwriting priorities with technology implementation to drive aligned, successful outcomes. Throughout his career, Mike has demonstrated a commitment to innovation and to delivering forward-looking insurance solutions informed by emerging technologies and industry best practices.

Follow Our Guest

LinkedIn

About Our Host

National co-chair of the Cyber Center for Excellence, Marc Schein, CIC,CLCS is also a Risk Management Consultant at Marsh McLennan Agency. He assists clients by customizing comprehensive commercial insurance programs that minimize the burden of financial loss through cost effective transfer of risk. By conducting a Total Cost of Risk (TCoR) assessment, he can determine any gaps in coverage. As part of an effective risk management insurance team, Marc collaborates with senior risk consultants, certified insurance counselors, and expert underwriters to examine the adequacy of existing client programs and develop customized solutions to transfer risk, improve coverage and minimize premiums.

Follow Our Host

Website | LinkedIn

Inside the Mind of a Cyber Sleuth: Digital Forensics, Insider Threats, and the Future of Cybersecurity with Devon Ackerman

Still shot of Devon Ackerman and Marc Schein

Summary

In this episode of Chattinn Cyber, Marc Schein is chattin’ with Devon Ackerman, a highly respected figure in the digital forensics and incident response (DFIR) community. Devon shares his background, starting from his upbringing in upstate New York, moving to Georgia, and how a chance encounter with an article about digital forensics at Champlain College sparked his interest in the field. He explains his early career in IT and web design during the dot-com boom, and how his curiosity and passion for troubleshooting led him to pursue digital forensics as a career.

Devon elaborates on the core concepts of digital forensics and incident response, describing digital forensics as the scientific discipline of preserving, validating, and interpreting digital data, often for legal purposes. Incident response builds on this foundation by focusing on reacting to cyber incidents, preserving evidence, and supporting organizations during and after attacks. He recounts his FBI career, highlighting a significant case involving espionage where a trusted insider stole sensitive data for a foreign government, demonstrating the real-world impact and importance of DFIR work.

The conversation shifts to emerging cyber threats and the evolving landscape of cyber risk. Devon emphasizes that threat actors are highly motivated, whether financially or politically, and continuously adapt to stay ahead of defenders. He discusses the widespread availability of offensive cyber capabilities among nation-states and criminal groups, and how geopolitical tensions can influence cyber activity. The discussion also touches on the role of AI in cybersecurity, acknowledging its potential benefits but warning about risks related to rapid adoption without adequate security controls.

Devon addresses the insider threat, distinguishing between malicious insiders and those who pose risks unintentionally through mistakes or misconfigurations. He stresses that human factors remain a critical vulnerability in cybersecurity, as trusted employees can inadvertently expose sensitive data. He offers advice for newcomers to the DFIR field, encouraging a mindset of continuous learning, experimentation, and resilience in the face of failure, noting the complexity and ever-changing nature of digital forensics.

Finally, Devon describes his current role at Cybereason, a cybersecurity company known for its endpoint detection and response technology. He explains how Cybereason has expanded its services to include both proactive advisory and reactive incident response capabilities, supporting clients globally across the entire cyber risk lifecycle. He provides contact information for listeners interested in learning more or engaging their services, and the episode concludes with Marc thanking Devon for sharing his insights and experiences.

Key Points

1. Career Path to Digital Forensics: Devon’s journey from IT and web design to becoming a leading expert in digital forensics and incident response, sparked by early exposure to the field and a passion for troubleshooting.

2. Definition and Scope of DFIR: Explanation of digital forensics as a scientific discipline and incident response as the reactive process to cyber incidents, including their importance in legal and investigative contexts.

3. Notable FBI Case: A detailed recount of a high-profile espionage investigation involving insider theft of sensitive data, illustrating the practical application and impact of DFIR work.

4. Evolving Cyber Threat Landscape: Discussion on the motivations and capabilities of threat actors, the proliferation of offensive cyber tools among nation-states and criminals, and the influence of geopolitical factors.

5. Insider Threat and Human Factor: Insight into insider threats, both malicious and accidental, emphasizing the ongoing risk posed by human error and the need for vigilance and security awareness.

Key Quotes

1. “Digital forensics is the scientific discipline by which we investigate digital information or digital data… It’s the basis for incident response and legal interpretation.”

2. “The insider threat isn’t always malicious; sometimes it’s a trusted employee making a mistake that inadvertently exposes sensitive data.”

3. “Threat actors are incentivized, whether financially or politically, and they continuously adapt to stay ahead of defenders.”

4. “AI is a buzzword and a powerful tool, but rapid adoption without security safeguards can lead to data spillage and new risks.”

5. “For those entering the field, be hungry to learn, be ready to fail, and understand that digital forensics is a never-ending journey of discovery.”

About Our Guest

Devon Ackerman is a highly respected expert in digital forensics and incident response (DFIR), known for leading the DFIR Definitive Compendium Project and bringing extensive experience from his tenure as a Supervisory Special Agent and Senior Digital Sciences Forensics Examiner with the FBI. During his FBI career, he oversaw and coordinated digital forensic operations nationwide, handling critical cases involving domestic terrorism, mass shootings, and large-scale electronic evidence collection. Devon has also contributed significantly to the field by co-authoring FBI training curricula, developing forensic tools, and providing expert testimony in federal and state courts. Beyond his public service, he has been recognized as Digital Forensic Investigator of the Year, spoken at major industry conferences, and shared his expertise through media appearances and publications. Prior to the FBI, Devon ran a technical services firm supporting small and medium businesses, underscoring his broad technical and investigative background.

Follow Our Guest

Website | LinkedIn

About Our Host

National co-chair of the Cyber Center for Excellence, Marc Schein, CIC,CLCS is also a Risk Management Consultant at Marsh McLennan Agency. He assists clients by customizing comprehensive commercial insurance programs that minimize the burden of financial loss through cost effective transfer of risk. By conducting a Total Cost of Risk (TCoR) assessment, he can determine any gaps in coverage. As part of an effective risk management insurance team, Marc collaborates with senior risk consultants, certified insurance counselors, and expert underwriters to examine the adequacy of existing client programs and develop customized solutions to transfer risk, improve coverage and minimize premiums.

Follow Our Host

Website | LinkedIn

Beyond MFA: How Deepfakes Are Hacking Humans

image of Aaron and Marc on screen

Summary

On this episode of Chattinn Cyber, Marc is chattin’ with Aaron Painter, a seasoned enterprise tech executive with years at Microsoft and experience leading operations in China and the UK, shares the origin story of his company, Nametag. After observing the rise in identity theft among friends and family, Aaron was struck by how outdated and vulnerable identity verification processes had become—especially the ease with which attackers could answer common security questions using publicly available data.

The conversation turns to the evolution of cyber threats, particularly social engineering and deepfake-enabled attacks. Painter outlines a disturbing trend where attackers bypass even sophisticated technological protections like multi-factor authentication (MFA) by exploiting weak points in human processes, such as IT help desks. One example he highlights is the MGM breach, where a phone-based social engineering tactic led to significant damage.

Painter emphasizes that many organizations’ defenses rely on trust in video verification—such as Zoom or Teams calls—but that these platforms are now susceptible to real-time deepfake emulation. Attackers can impersonate employees or candidates using advanced visual spoofing tools, bypassing traditional verification methods and gaining access to critical systems.

To address these vulnerabilities, Nametag offers a mobile-first identity verification solution that leverages smartphone cryptography and biometric tools to take three-dimensional selfies and securely scan IDs. This process ensures stronger identity proofing, even under conditions that would normally be vulnerable to deepfake deception or impersonation.

The episode concludes with Painter warning HR professionals about the increasing threat of hiring fraud—where bad actors impersonate real candidates using deepfakes. He advises that companies don’t need to replace existing systems like Workday or Okta but should instead implement layered solutions that complement current infrastructure and close critical security gaps.

Key Points

  • Cybersecurity Gaps Are Human, Not Just Technical: Despite widespread use of MFA, social engineering attacks targeting help desk personnel remain a primary threat vector.
  • Deepfakes Are Evolving Rapidly: Attackers increasingly use deepfake technologies to impersonate employees or job applicants on video calls, rendering basic visual verification untrustworthy.
  • Nametag’s Mobile-First Approach: Nametag strengthens identity verification by using mobile devices’ cryptographic and biometric capabilities to combat real-time deepfake impersonation.
  • Hiring Fraud Is a Growing Threat: Criminals, sometimes state-sponsored, use deepfake tools to impersonate legitimate job candidates, gain access to internal systems, and cause serious security breaches.
  • Enterprise Integration Over Replacement: Painter advocates for bolting on new security layers rather than replacing entire systems—filling in gaps while preserving operational continuity.

Key Quotes

  • “All you have to do is call and pretend to be the account holder and say you were locked out. Then there’s a clear vulnerability. And that vulnerability is a social one or human one.”
  • “The platforms weren’t really built to prevent against deepfakes… You’ve got that person showing up completely different on the video call.”
  • “95% of the background check providers do it with a Social Security number and no identity verification.”
  • “We invented the same concept of scan your ID and take a selfie—but we do it exclusively on mobile.”
  • “I knew identity verification was a hot area. I had no idea it would be this hot.”

About Our Guest

Aaron Painter is the visionary CEO of Nametag Inc., the pioneering identity verification platform dedicated to protecting users from impersonators and AI-generated deepfakes. With a mission to enhance online authenticity and foster trusted relationships, Nametag has emerged as the go-to solution for leading companies aiming to combat fraud and streamline account security. Aaron’s commitment to user-centered security is deeply personal, stemming from his own experiences with online fraud and identity theft, which inspired him to assemble a team of security experts to revolutionize account protection. A global leader with a rich background, Aaron has lived and worked across six countries on four continents, and he is the author of the best-selling book *LOYAL*, where he emphasizes the importance of cultivating a culture of listening in leadership. His impressive career includes serving as CEO of Cloudreach, a top multi-cloud solutions provider, and holding various leadership roles at Microsoft. A Fellow at the Royal Society of Arts and a member of the Forbes Business Council, Aaron is also a sought-after speaker and advisor, known for his ability to blend international practices with local insights to build innovative, high-performing teams.

Follow Our Guest

LinkedIn | Website

About Our Host

National co-chair of the Cyber Center for Excellence, Marc Schein, CIC,CLCS is also a Risk Management Consultant at Marsh McLennan Agency. He assists clients by customizing comprehensive commercial insurance programs that minimize the burden of financial loss through cost effective transfer of risk. By conducting a Total Cost of Risk (TCoR) assessment, he can determine any gaps in coverage. As part of an effective risk management insurance team, Marc collaborates with senior risk consultants, certified insurance counselors, and expert underwriters to examine the adequacy of existing client programs and develop customized solutions to transfer risk, improve coverage and minimize premiums.

Follow Our Host

Website | LinkedIn

Privacy vs. Security: Navigating the Challenges of Cyber Risk with Ben Goodman

Summary

In this episode of Chattinn Cyber, Marc Schein is chattin’ with Ben Goodman, the founder and CEO of CyRisk, about the evolution of cybersecurity and the growing concern of privacy in the industry. Ben shares his background in technology and his experience working with companies to improve their security and compliance.

They discuss the increasing importance of privacy in the cyber risk landscape, with privacy settlements surpassing security settlements in recent years. Ben emphasizes the need for organizations to focus on pre-incident planning, training, and preparation to mitigate privacy risks effectively.

When discussing how carriers are handling privacy risks, he notes that carriers are still figuring out how to underwrite the risk in a soft market. He highlights the challenge of carriers not having access to comprehensive data and organizations themselves often being unaware of their own exposures. He suggests that carriers should focus on differentiating themselves and finding ways to underwrite privacy risks effectively.

They also touch on the different industries and technologies that are more susceptible to privacy exposures. Regulated industries, such as healthcare, are under scrutiny and face regulatory actions and fines. Advertising and marketing technologies also pose significant risks, and organizations should take steps to mitigate these risks.

Ben explains how CyRisk helps policyholders with privacy issues through their platform. They offer real-time detection of exposures, analysis of policyholders’ active policies for compliance, and provide detailed reports with recommendations. CyRisk’s privacy attorneys contribute to building out the platform and offering solid advice to policyholders.

Looking ahead, Ben predicts that privacy risks will continue to be a significant issue. He mentions the increasing use of micro-targeting AI and the potential challenges it poses in terms of privacy and bias. Governments and regulators will need to keep up with these developments to protect individuals’ privacy.

Overall, the interview covers various aspects of privacy risks in the cyber risk landscape and provides insights into how organizations and carriers can address these challenges.

Key Takeaways

  1. Privacy is becoming a major concern in the cyber risk landscape, with privacy settlements surpassing security settlements. Organizations need to prioritize pre-incident planning, training, and preparation to effectively mitigate privacy risks.
  2. Carriers are still grappling with how to underwrite privacy risks in a soft market. Differentiation is challenging, and the lack of comprehensive data and organizations’ limited awareness of their own exposures pose difficulties.
  3. Certain industries, such as healthcare, are under scrutiny and face regulatory actions and fines due to privacy breaches. Advertising and marketing technologies also present significant risks that organizations should address.
  4. CyRisk offers a platform that helps policyholders with privacy issues. It provides real-time detection of exposures, compliance analysis of active policies, and detailed reports with recommendations. Privacy attorneys contribute to the platform, offering solid advice to policyholders.
  5. The use of micro-targeting AI poses challenges in terms of privacy and bias. Governments and regulators will need to keep up with these developments to protect individuals’ privacy. Privacy risks are expected to remain a significant issue in the future.

Key Quotes

“The confluence of privacy risk in cyber insurance and the associated cyber risk… there’s the data leakage part of it, there’s real data breach exposure with this privacy risk.”

“Last year, 2022 privacy settlements actually exceeded security settlements by about 180 million.”

“The more that organizations could do from a pre-incident perspective, from a planning and training and preparation, I think the better off they are.”

“A lot of carriers don’t really see the data. They don’t know how to get that data… relying on questionnaires only goes so far.”

“Regulated industries are clearly under a microscope… they’ve already shown that they’re taking action not just with investigations, but with fines and penalties, millions and millions of dollars.”

About Our Guest

Ben Goodman is the Founder and CEO of CyRisk Inc., a leading cybersecurity and risk management company. Prior to founding CyRisk Inc. in July 2018, Ben also founded and served as Chairman of 4A Security & Compliance, a company focused on helping organizations achieve security and compliance.

In addition to his entrepreneurial ventures, Ben is also a faculty member at Drexel University’s LeBow College of Business, where he shares his expertise and knowledge with aspiring professionals in the field of cybersecurity. With a passion for solving complex technology problems and managing security and compliance components, Ben has dedicated his career to helping organizations navigate the ever-changing landscape of cyber risk.

Ben’s extensive experience and deep understanding of the industry have made him a sought-after expert in the field. He has been featured in various podcasts, conferences, and industry events, where he shares his insights on topics such as privacy, data breaches, and the future of cybersecurity. Through his work at CyRisk Inc. and his contributions to academia, Ben continues to make significant contributions to the field of cyber risk management.

Follow Our Guest:

LinkedIn

About Our Host

National co-chair of the Cyber Center for Excellence, Marc Schein, CIC,CLCS is also a Risk Management Consultant at Marsh McLennan Agency. He assists clients by customizing comprehensive commercial insurance programs that minimize the burden of financial loss through cost effective transfer of risk. By conducting a Total Cost of Risk (TCoR) assessment, he can determine any gaps in coverage. As part of an effective risk management insurance team, Marc collaborates with senior risk consultants, certified insurance counselors, and expert underwriters to examine the adequacy of existing client programs and develop customized solutions to transfer risk, improve coverage and minimize premiums.

Follow Our Host:

Website | LinkedIn

Underwriting and The Future Of Cybersecurity With Marcin Weryk

In this episode of CHATTINN CYBER, Marc Schein interviews Marcin Weryk, Head of Business Development at Coalition Inc. The duo get into underwriting, cyber risks, and the future of cybersecurity, among other discussions on business and the changing world.

Marcin began by providing background on his upbringing, sharing that he was born in Poland and raised in Brooklyn. He also mentioned his journey to becoming a renowned cyber underwriter after graduating from St. John’s University with a major in finance and later participating in a training program at CNA to gain knowledge in the insurance industry. The training program ultimately led to his placement on CNA’s cyber tech NPL team and his entry into the field of cyber insurance.

Marcin stresses the importance of having a strong underwriter in the team who’s knowledgeable in both analytics and marketing. The key for underwriters is to not only be creative and thorough but also reliable and trustworthy. It is also critical to learn to interpret and analyze data in cybersecurity.

Further in the conversation, Marcin mentions Coalition and introduces it as the most innovative insurance company for reasons including its careful and correct analyses of data and the risk selection and prevention mindset of its employees. At its core, Coalition is a technology company that uses data more effectively than other insurance companies.

Marcin also shares two concerns businesses will face in the coming years. One is the need to improve the quality of data collection and utilization to reduce cyber risks. The second was about the data currently being used to underwrite better from a loss perspective, which leads to many issues. Business controls are essential in underwriting and risk mitigation.

He wraps up the conversation by highlighting the future of cyber issues, focusing on two of the most pressing issues: the exposure of systemic failure and privacy concerns.

Listen to the conversation for more details!

Highlights:

“I think what’s different about Coalition is the ability to understand that learning from data is important. And learning from data is even more important in the ever-changing space of cybersecurity. I think we at Coalition differentiate in that we are continuously making sure we look at risk selection and risk prevention. From a forward-looking perspective, not a backward-looking perspective.”

“And I think that’s the big differentiation is, most people are stuck looking backward, Coalition is good at looking forward. And I think that is what drives our value. The other part that’s been imperative to the growth and success of Coalition and others in this space that is leaning on data better, is the concept of continuous monitoring.”

“One is the systemic failure exposure that we’re all dealing with. I personally think that the marketplace will evolve into a space where there will be standard coverage, and yet also separate catastrophe cyber coverage. I don’t think that that’s that far in the future. Just for clarity purposes, I think many people will be interested in that type of cover. The other one that some people have started to speak about, but I don’t think it’s getting as much attention as it should is privacy as a peril.”

Time-Stamps:

[01:08] – How did Marcin become a cyber underwriter and how did he get involved in cyber?

[02:53] – Important roles of an underwriter

[04:43] – What is so unique about Coalition and how they are the most creative insurance company?

[07:42] – What made Marcin go to the technology from phenomenal insurance carriers?

[10:33] – Challenges and cyber risks businesses are going to face in the next two years that concerns underwriters

[13:52] – How important are controls for a business?

[16:10] – Some of the future issues we may be facing

Connect with Marcin:

LinkedIn: https://www.linkedin.com/in/marcin-weryk-828a1a6/

 

Economic Sanctions, Cyber Law Enforcement, And Private-Government Collaboration For Cyber Protection With Emil Bove

In this episode of CHATTIN CYBER, Marc Schein interviews Emil Bove, Trial and Investigations Lawyer at Chiesa Shahinian Giantomasi (CSG). Emil has extensive experience working in both the public and private sectors, starting his career as an assistant United States attorney specializing in cyber risk. Today, he speaks about the new sanctions announced against Russia following the invasion of the Ukraine, why Russia might push its financial transactions and assets into the crypto space, cyber enforcement trends pertaining to the same, and the recent collaboration of the private sector and the government sector for speedy cyber law enforcement and protection.

Recently, in the aftermath of the Russian invasion of Ukraine, the US Treasury department announced a lot of sanctions against Russia. One result of that is that banks are trying to comply with the sanctions on both US financial institutions and international institutions, identifying their exposure to the sanction parties, sanction relationships, and figuring out how to address that exposure – whether that’s blocking assets in some instances, or ending client relationships in others. Secondly, we’re anticipating mechanisms for any sanction party to engage in sanctions evasion and access the international financial system and even the US financial system directly through correspondent accounts. Sanction parties need to innovate. Russian parties are also expected to push financial transactions and assets into crypto.

Emil also discusses the trends in cyber enforcement. With Russia likely to venture into the crypto space, care needs to be taken while enforcing sanctions as not everybody is a Russian actor. Clients have to be sensitive to sanctions compliance. Recently, the OFAC has been sanctioning crypto service providers, some of which are based in Russia, who are non-compliant with US expectations for transparency and staying away from ransomware. Both on the regulatory and criminal sides, the government will be looking at public examples of non-compliant actors who are not seeking to implement the sanctions intended to choke back on Russia’s access to the financial system.

Another thing Emil talks about is the private sector’s collaboration with the government in connection with the above sanctions. He predicts that the partnership will be significant because the technological expertise of the private sector can help speed up the government’s work. The technologies used so far have repeatedly shown themselves reliable and trustworthy and have generated accurate results.

For more, tune in to today’s episode!

Highlights:

“There’s a cyber component to the banks trying to comply with the sanctions to both US financial institutions and really international institutions, taking a look at what OFAC is doing. And identifying their exposure to these now sanctioned parties and sanction relationships, and figuring out how to address that exposure, whether that’s blocking assets in some instances, or ending client relationships in others.”

“There are a few understood mechanisms for any sanction party to engage in sanctions evasion, to access the international financial system, and sometimes even the US financial system directly through correspondent accounts. Sanction parties are going to need to take some new steps to do some innovation. And I think that one way that we’re going to see that is Russia as a sovereign, and also just sanctioned Russian parties over there are going to push financial transactions and assets into the crypto space.”

“There’s then now a public opinion that sort of authorizes and endorses law enforcement collaboration with the private sector and use private sector tools in a sophisticated and developing space where government technology, especially in the law enforcement side, may not be quite as up to speed as where the more well resourced private sector parties are endorsing that and I think you’ll see that going forward.”

Time-Stamps:

[00:43] – The journey to becoming an assistant United States attorney
[19:45] – About the US Treasury Department announcing sanctions against Russia [21:49] – The biggest things around cybersecurity being ignored right now
[29:58] – Closing thoughts

Connect with Emil:

Website: https://www.linkedin.com/in/emil-bove-0113347/

The Russian-Ukrainian War Is A Lesson On Information Security and Leverage With Greg Radabaugh

In this episode of CHATTIN CYBER, Marc Schein interviews Gregory Radabaugh about his wide range of experience in the military and information security, what the Russian-Ukrainian war illuminates about information security, and the essential practices civilians and security forces must equally adopt to strengthen cybersecurity.

Retired Air Force veteran of 30 years, Greg comes with a repertoire of wealth that ranges beyond overseas reconnaissance missions. He has experience as a DOD civilian, a Defence Intelligence Agency analyst, senior Information Operations planner for the Air Force ISR agency (Intelligence Surveillance Reconnaissance), Director of the Joint Information Operations Warfare Centre, and many high-importance controlled defence and intelligence roles. But after finally retiring from the Department of Defense after 44 years, Greg has founded his own consulting company, Greg Bear Consulting.

With the ongoing Russian-Ukrainian war always keeping world tensions high, Greg suggests you give “Unrestricted Warfare by Colonel Qiao Liang and Colonel Wang Xiangsui” a read for learning in depth about permanent warfare and the absence of a difference between civilian and military targets in the Ukraine-Russia war. Noting from the war updates, Greg shares that although Russia seems to be focussing on justifying their actions to their internal audience, making them see that all is being done to protect them, Ukraine is focussing on the external audience, primarily the West, trying to gain support from the US, NATO, and others providing material, financial, and medical support. He also discusses how both the countries are gathering and making use of commercially available data for warfare – from tracking locations, to cellphone ranges, and a whole lot more. Everything happening in the war is striking from an information perspective.

The civilian sector, he adds, must prepare for war at this point as they could be used to incite or escalate conflict. There could be Denial Of Service attacks, deception, and other planned operations to impact the military by attacking people relevant to its personnel. Families of military personnel are especially targeted by these attacks. This is a side most people aren’t prepared for.

In conclusion, Greg shares that the civilian private sector needs to start thinking about security the same way the military does – for operational security. Using mobile phones and cameras in essential meeting places, not considering the secondary and tertiary access points in places, are a couple of the many things that go unnoticed. For more about it, tune in to this episode with Greg!

Highlights:

page1image12665408 page1image12665984

“The Western concepts of the law of armed conflict relying on Westphalian concepts of chivalry, interior, and territorial integrity, and what constitutes an armed attack don’t apply to our adversaries and potential adversaries in the information environment.”

“Think about how to provide operational security to your business. And then think about how do you shut down our second and tertiary information leakages and then decide, how do I mitigate this threat by doing things, for example, having an offline backup of my network, or having a secondary network that’s offline that can go online immediately, if your primary one goes down?”

“A greater awareness of these operations in the information environment is crucial to private sector success of industrial control systems, security is going to be absolutely critical to maintaining our first world environment that we live in and enjoy today.”

Time-Stamps:

[00:40] – Greg’s early life and founding Greg Bear Consulting [05:29] – Where to connect with Greg
[06:26] – What’s happening with the Russian-Ukrainian war?
[15:19] – Should the civilian sector prepare for a conflict at this point?         [20:42] – What can you do to protect yourself from cyber attacks?

Connect with Greg:

Website:

https://www.af.mil/About-Us/Biographies/Display/Article/108843/gregory-c-rada baugh/

Understanding Ransomware Double, Triple, and Quadruple Extortion With Brad LaPorte

In this episode of CHATTIN CYBER, Marc Schein interviews Brad LaPorte, former top-rated Gartner Analyst for cybersecurity, veteran US Cyber Intelligence, and product leader at Dell, IBM, and several startups. He is currently the Advisor at Lionfish Tech Advisors and Partner at High Tide Advisors, apart from being the Board Advisor at 4 early-stage startups – NetRise, rThreat, RunSafe Security, and TBD. He is also the author of the recently released cybersecurity book, The Rise Of Cybercrime. Today, he discusses the reasons for the increasing number of ransomware attacks worldwide and the measures to avoid or mitigate the risks from the same.

Explaining the increasing number of ransomware attacks, Brad shares that these days, all that is required to extort money from organizations is access to a keyboard on the internet. The barrier of entry to systems has been reduced. Additionally, over 98% of ransomware is paid out in Bitcoin, which is difficult to track. Starting November 2019, double, triple, and quadruple extortion tactics have started to be used, which has also added to this.

Double, triple, and quadruple extortion tactics can be explained hence:

  1. Double extortion is the exfiltration of sensitive data. So, companies are forced to pay the attackers despite having the encryption key or backup data.
  2. Triple extortion is when attackers disrupt the critical operations of organizations involved in, say, manufacturing, healthcare, or education. The criticality of the attack makes organizations highly likely to pay the attackers.
  3. Quadruple extortion is when attackers directly attack your customers or key stakeholders also. Also called supply chain attacks, they are like a force multiplier and cause an exponential increase in the damages.

Answering the question of whether or not to pay when ransomware attackers demand you to, Brad explains that one must try their best not to unless they’re left with no other choice. He also touches on the best cybersecurity practices to follow to mitigate the risks due to the attack, like the 12 key controls given by Marc around cyber resilience. He adds that even though the actual amount paid to ransomware attackers is coming down over time, the number of threat actors is increasing with the decrease in their barriers of entry.

One of the most overlooked reasons for cyberattacks is that over half of the organizations worldwide don’t know about the assets they have in their environment, the third-party vendors and other organizations associated with them, and over 75% manage everything through an Excel spreadsheet as their asset inventory database.

page1image62169536 page1image62163584

Care must be taken to ensure organizations are well aware of their assets, as these could be one of the easiest ways for attacks to happen.

For more, tune in to today’s episode!

Highlights:

“In trying to extort money from organizations, ultimately, all you need is access to a keyboard on the internet. So if you look at some of them (attackers), the people that can actually wreak havoc on organizations are quite vast.”

“Even though the actual numbers of payments are going down and declining… The amount of groups are increasing because of that low barrier of entry and actually increasing it over time. ”

“Over half of (the) organizations don’t know what assets they have in their environment, and over 75% actually manage everything out of an Excel spreadsheet as their asset inventory database.”

Time-Stamps:

[02:33] – Why are ransomware attacks increasing?
[07:15] – Should you or should you not pay when ransomware attacks require you to? [09:45] – The biggest things around cybersecurity being ignored right now
[12:49] – Get in touch with Cory

Connect with Brad:

Website: https://www.linkedin.com/in/brad-laporte/

Using Social Media To Educate The Public About Cybersecurity With Dana Mantilia

In this episode of CHATTIN CYBER, Marc Schein interviews Dana Mantilia, an online cybersecurity educator with an identity theft protection background. She discusses getting into the cybersecurity space, becoming a social media marketing and cybersecurity expert, and the challenges and opportunities in the industry.

Dana joined cybersecurity in the identity theft protection world in 2017, developing a product for the same (called Identron). Gradually, she realized the need and the lack of education in the industry. That was also when the idea of doing some LinkedIn videos about the same for educational purposes came to her. As she continued on the same, COVID happened; and with it, she introduced online training for non-technical employees and has since become one of the most marketed cybersecurity individuals in the US.

Dana moves on to discuss IT and cybersecurity. Addressing the gradual movement of IT professionals into cybersecurity, she explains that the two are still very different fields. She emphasizes that the two departments need to list their responsibilities and ensure they don’t get mixed up.

Discussing the importance of cybersecurity training for employees, Dana shares that it’s easy for cybercriminals to trick an employee into hacking a computer system; hence, training methods must be given importance. She adds that although some of the training can be handled with technology, a lot of it needs to be done in person to make employees remember it for longer.

Dana also discusses the most significant challenges faced when working with non-technical cybersecurity people. The most significant challenge is communication, i.e., speaking in layman’s terms. She explains the disconnect when a lot of jargon gets thrown around, and the person listening cannot understand it. Work needs to be done to better this situation.

Tune in to this episode for more learnings about cybersecurity and social media marketing from Dana!

Highlights:

“My thought process with cybersecurity is it’s still not being embraced by the private sector, just starting to be really held feet to the fire with the government side of things. So this is the time to really build their online presence over the next three to five years. And then when everybody is forced to embrace cybersecurity, they’re

page1image12702976 page1image12675200

going to be the first ones that are going to be seen as an authority and they’re going to be able to gain more clients.”

“My videos are very short, very focused. And if I can I add a little bit of humor into them. And just hoping that people are going to remember what the point is that I was talking about in there.”

“One of the biggest problems is that the technical people that handle the cybersecurity aspect of things, they’re extremely intelligent people. But their communication skills, when it comes to speaking to somebody in layman’s terms, is not always there’s a disconnect there.”

Time-Stamps:

[01:02] – From Connecticut to the most marketed cybersecurity individual in the US: Dana’s journey
[03:14] – What can cybersecurity folks do to help grow their network?
[05:32] – Why businesses must invest in cybersecurity training

[10:47] – The biggest challenges in dealing with non-technical cybersecurity people

Connect with Dana:

Website: https://www.cyberdana.com

The Role of Managed Service Providers for Cybersecurity with Thomas DeMayo

In this episode of CHATTINN CYBER, Marc Schein interviews Thomas DeMayo, Principal in the Cyber Risk Management group with PKF O’Connor Davies, LLP. Thomas is the lead Cyber Risk Adviser and Auditor for the firm. He is responsible for implementing and designing the Firm’s Cyber Security service offerings, audit programs, and testing procedures. Thomas consults in IT governance, information security, threat and vulnerability management, privacy, and IT compliance. Today, he shares his backstory of getting into cybersecurity and what he’s learned from his journey so far.

Even as a kid, Thomas had a fascination for computers. After graduation, he ended up taking a job in network engineering at PKF O’Connor. Later on, he was asked to check on the firm’s systems, IPS, and calculations. That led him to shift to cybersecurity. And around 2006-2007, he already had clarity on what he was supposed to do going forward.

Thomas talks about the client benefits of partnering up with someone who has both cybersecurity resources and tax intellect. They can advise clients on a more cyber-specific path and help control their program. That’s invaluable to a lot of clients.

Towards the close of the conversation, Thomas talks about the future of a hybrid work environment. Hybrid working may or may not persist for a long time. But it is something that is not going to go away any time in the near future.

Quotes:

“Even as a kid, I was kind of always fascinated with getting the computer to do what I wanted.”

“We are those trusted advisors who are able to come in and say, yes, we can help you, we could advise you on a more cyber-specific path and help you control your program. That’s invaluable to a lot of clients.”

“When we’re helping them, we’re advising them on what they need, and that’s what matters; that’s the key thing.”

“You have to challenge them to make you understand what their cybersecurity program is, or at least ask them, show us what your basic cybersecurity policy looks like. I think that’s going to start to help you understand you even have a level of formality.”

“As the world wakes up and really starts to focus on this, they’ll start to look at that supply chain risk.”

“Some businesses based on their business model will realize that this really does work. Our employees are happier and are still productive; we don’t need to be in the office to do certain things.”

Time-Stamps:

[01:43] – Thomas explains how he got into the field of cybersecurity.

[03:58] – The benefits of partnering up with someone who has both cybersecurity resources and tax intellect.

[08:33] – Reasons why more clients are engaging in services related to cybersecurity.

[10:10] – Questions clients should be asking their Managed Service Provider.

[13:25] – Where do you see this hybrid work environment going in the next 18 months?

Connect with Thomas: 

LinkedIn: https://www.linkedin.com/in/thomas-demayo-002bbb71

Website: https://www.pkfod.com/people/thomas-demayo/

Email: tdemayo@pkfod.com