TechOnPurpose Logo

Episode 0: Series Launch

by | Oct 20, 2021

Happy October and welcome to Cybersecurity Awareness Month at TechOnPurpose. Today, we officially launch our new video blog series titled “Who’s in Your Cloud?” – 23 episodes created to help simplify a very complex conversation about cybersecurity.  We invite you to journey with us on the road to secure, reliable, trusted technology in what we hope is a simple but comprehensive look at the #TOPcyber21.  (21) vital tools, best security practices, and products purpose-built to help organizations of any size establish end-to-end cybersecurity from the office to the cloud and beyond.

Welcome viewers and subscribers and a special welcome to our VIP cast who will be joining us throughout the series. With us today for Episode 0 we have Ivan Paynter and Patrick Chen from Intelisys. From our friends at TBI, we have Jim Bowers.  Also please welcome Jay Ryerse from Connectwise and our own TechOnPurpose Founder & CEO, Matt Tankersley.  And guiding us through the vlog episodes to come we have the lovely Lauren Lev, TechOnPurpose Marketing Manager.

We’ll be releasing a new episode every Tuesday, starting today 10/20/21 through late spring of 2022 with brief time off for holidays with family & friends.  We’ll also follow each Tuesday episode release with subsequent Wednesday, Thursday, and Friday posts highlighting our (3) contributing solution partners from that week’s episode.  We hope you’ll find this an immersive, hopefully simple, educational and enjoyable experience.  So how do you tune in?

To easily follow the journey ahead we’ve diversified your access options to all (23) of our coming episodes.  You can follow long here on our blog, or by any of the following methods:

  • Email Newsletter: sign up at techonpurpose.net/blog and have each episode delivered directly to your inbox when released.
  • LinkedIn: follow here
  • YouTube: follow here
  • Facebook: follow here
  • Podcast: follow here

Buckle up – it’s time to hit the road to #secure, reliable, trusted technology!

Read Transcript
Lauren Lev
Happy October and welcome to Cybersecurity Awareness Month at TechOnPurpose. Today, we officially launch our new video blog series titled Who’s in Your Cloud? Twenty One Steps to Secure, Reliable and Trusted Technology. I’m Lauren Lev, marketing manager for TechOnPurpose, and I would like to formally welcome our viewers, subscribers and of course, our VIP cast who will be joining us throughout the series. With us today, we have Ivan Paynter and Patrick Chen from Intelisys. Welcome guys. Got it from our friends at TBI. We have Jim Bowers.

Jim Bowers
Hello.

Lauren Lev
And a special thanks and warm welcome to Jay Ryerse from ConnectWise. Jay, Welcome to who’s in your cloud.

Jay Ryerse
Thanks, Lauren. Glad to be here.

Lauren Lev
Yes. So last but not least, we have our TechOnPurpose. Founder and CEO Matt Tankersley.

Matt Tankersley
Hi Everyone.

Lauren Lev
So what exactly is who’s in your cloud? That is a great question. So we created this video blog series to simplify a very complex conversation about cybersecurity and to help our prospects and clients better comprehend what are all the factors and simply chart a course to get started on the road to secure and reliable, trusted technology. So Matt, is there anything that you would like to add on the what, why or how of who’s in your cloud?

Matt Tankersley
Great question, Lauren, I first I want to say you guys are all rock stars and you guys are critical partners with us every day in our entire service portfolio, not just cyber security. So thanks for joining us. Honestly, Lauren, you did a great job. Let me just say besides what we hope is a very simple and highly educational series for our viewers, we’re doing two particular things for those who sign up and follow along and learn, right? One is we’re giving a free, NIST cybersecurity assessment for anyone who wants to take the 30 minutes of time that it takes to sit down and walk through the questions with our team. Now that survey itself is exceptionally valuable resource to help your organization rapidly identify what may be critical, high or medium areas of risk along with some remediated remediation steps, right? We thank our friends at ConnectWise for giving us a platform that does that, so we’ll hear more from Jay on that, hopefully here before we’re done. Secondly, I think even more valuable as we’ve created this top cyber twenty one best security practices matrix, and we’re going to chat more about that in each of the twenty three episodes that we have coming down the pipe. But that’s the tool that simplifies the conversation with prioritized list of best practices, best processes and literally best products to get your organization quickly launched onto that road of secure, reliable and trusted technology. So I think I already mentioned this twenty three episodes, we’re going to be releasing an episode every Tuesday, starting, if I’m not mistaken, next Tuesday. And we’re going to follow up each of those episodes Wednesday, Thursday, Friday with some highlights on each of the solution partners that we have in each of those areas. So this should be an immersive, hopefully simple, hopefully enjoyable process for all of our viewers. And so how’d I do Lauren? Good. Are you ready to keep going?

Lauren Lev
No, that was the good thank you. Spot on. So let’s shift for a second and take a deeper dive now into the background of our VIP cast. So let us know a little bit about your individual passion and purpose in the cybersecurity space. So to start us off, let’s have Patrick Chen and Ivan Paynter. So, yeah, again, will you both of us just tell us, like what your cybersecurity stories are and what’s up at Intelysis that partners like us here at techonpurpose need to know?

Ivan Paynter
You want me to go PC? Yeah, absolutely. Right on. Right, well, that’s my cohort in crime right there. So thank you, Patrick. I’m Ivan Paynter. I’m the national cyber security specialist for Intelysis. I’ve been with Intelysis coming up on three years. Actually, I think three years this month. Prior to that I was with UUNET, MCI, WorldCom, Verizon Business, Verizon, Masergy. And then I’m really proud to be here at Intelysis. We help our partners and customers and suppliers all kind of come together in a convergence. So we pick the right solution for the correct problem and make sure we follow through with them and give them that white glove type treatment. How I got involved with security, I think I watched a movie and somebody was war dialing. And then the next thing you know, I was war dialing. And then I got with an organization called MCI and I was doing digital cross connects, and one thing led to another and I got a radio scanner. I think for a birthday president, I figured out that there was data on that, and I created a A to B conversion RS232 and used my scanner to figure out how to break two factor authentication. And that’s how I got into cybersecurity and I haven’t left yet. My favorite is still to this day, anything that comes across of its own free will and volition, therefore radio signals. I love SSID’s, war walking anything of that nature that is not going to get me into trouble. So, leave the rest to you, Patrick.

Matt Tankersley
Thats awesome. You guys, if I had a propeller on my hat right now I would be flying off. That’s just, that’s just awesome.

Patrick Chen
That’s Ivan. He is our specialist for a reason and he is just absolutely amazing. And our partners, our suppliers just love him so much. And he brings a wealth of knowledge to our team, for sure and to Matt and Lauren.

Ivan Paynter
Just having fun, you know that.

Patrick Chen
But hey, guys, no thanks for having me as well. You know, I work with Ivan, like you said, and my name is Patrick Chen. I’m one of the solution engineers at Intelysis and our worlds have been colliding. You know, my background historically has come very much from the networking and the network security side. I work with a lot of companies designing their network and helping configure their firewalls from the S&P case all the way to the large global enterprises. And then even before that, I had a big focus, focusing on infrastructure, helping ensure application performance is there, as well as I ran an MSP at some point, and that’s actually the first time I really, really had a passion for for security and it happened a couple of years ago. You guys might remember CryptoLocker. You know, when we were running MSP, it was our motto was always, let’s make sure we catch everything and let’s make sure we put antivirus. Let’s make sure we back up everything, right? To make sure our companies that rely on us to stay in operations, they’re well protected and their operations or IT’s, our operations are smooth. And then all of a sudden we walked in one day because we get a notice that their servers are down, we show up and everything is encrypted and we’re thinking, what is going on right? And we thought, no problem, no issue whatsoever. We’ll just restore the servers, blow everything away, we’ll be good. That didn’t work. When we restored it, within a couple of hours all the files got encrypted again and we realized that something was different about this, and from then on we saw more and more encrypting type ransomware. And so for me, you know, that always stands out in my mind. Now that was one of the first stage uh-oh’s that I encountered on the security side. And ransomware has always been a big, big passion of mine ever since. And I would say the next closest thing is something that Ivan and I were actually just talking about distributed denial of service attacks. You know, it kind of has, sits in a little venn diagram of security and networking, and it’s something that I deal with a lot and I have a passion for that as well. So, thanks for having us.

Matt Tankersley
Awesome.

Lauren Lev
Awesome, thank you both. And yeah, thank you for being a part of our VIP cast, we appreciate you guys. So next up, we have Jim Bowers from TBI and TBI is actually one of our newest portfolio partners. So welcome, Jim.

Jim Bowers
Thank you very much. Man, I hate going after Patrick and Ivan, I mean, big shoes to follow, but I’m the cyber security architect at TBI. Very similar to intelysis. We have an engineering team in several disciplines that enable our vendors, our clients, our partners to leverage us from a consulting business outcome perspective to dive deeper and more strategic in their clients on security or voice or infrastructure. What is my? I got a couple of things on why I got into security. I think the first one is I’ve always been the type to break down computers, throw them back together, break and build them. But more importantly, it was during my college days, I helped write. You can be a programmer, and I wrote some code that enabled some of the satellite providers to turn on all the channels. So they didn’t really like that. So they actually used my code to help them strengthen their electronic control measures to enable people to not be able to break into the smart chip and put code, BBcode on top of the chip to turn on all the channels. From there, I had the pleasure of working with a little company called Take-Two Interactive that does Grand Theft Auto and helped them roll out their whole infrastructure for US mitigation. I work for a company called Arbor Networks, so that’s really where I started to get into the security arena is when DDOS attacks. And, true story I was sitting there on Christmas. I don’t know if my son was more excited or I was more excited, so we got the latest Xbox. I was like, oh man, I’m ready to play some games. We went to hook it up, went to connect Xbox Live and nothing. And that was due to a DDOS attack. So that’s really where I kind of pivoted from network into security. And from there is, I think what I love about it is, it’s not a destination. It’s a journey, it’s constantly evolving, constantly changing. We do a countermeasure, they change it right? And it’s constantly learning. And it’s the most interesting space. And I think, hopefully that through this video blog series, through the experts that you have here or the evangelist – I like what Ivan said. I’m not really an expert because it’s, I’m always learning, that we can provide some value, assets, and conversations to the video blog viewers to enable them to strengthen their security posture. So really glad to be here and thank you, Lauren for including me in the video blog.

Lauren Lev
Of course, yes, we’re happy to have you here. So lastly, but certainly not least, please help me in welcoming Jay Ryerse from ConnectWise. Welcome to the show, Jay.

Jay Ryerse
So a round of applause. Alright there we go. Alright. A round of applause there we go. Alright, so I’m the guy that takes what all these really smart guys figure out behind the scenes and translate it back to English, so we can actually understand what they’re talking about. So if you’re on here today and you’ve just heard a bunch of acronyms and all kinds of terms you’ve never heard of before, but you really want to know is, is how does this apply to your business and how do we have that conversation? Now look, I’ve got a technical background. Mine is not quite as probably as fancy as, as Ivan’s, but I remember back in the mid 90s, we had a company that we were registering domain names back and forth. It was really cool to do so. We could still get good names and we, we broke the code for Infoseek. So now I’m showing my age and we figured out how to put any site in the top two spots on any set of keywords at Infoseek. And we did it for about nine months and they finally called us and said, What are you doing? And we shared the code and figured out how we we broke their algorithm. I never got back to that level again there, but my journey started there right? Because you know, as Jim mentioned, it’s truly a journey. I spent most of my time in a technical career in the managed services space. I deal with with your protection, detection and response. I actually enjoy the response side, the most of it. When the house is burning down and you see people running out of the building, you know, because of a cyber attack, I like to be the one helping run in and figure out what happened because I want to understand where we broke down, where we missed an opportunity to do the right thing. And we’ve all got the stories, the ransomware stories. You know, I only had one client in my MSP days hit by a ransomware attack, and it was it was a very simple that they brute forced RDP. And literally, you know, we had the backups. We had them back up and running in an hour wasn’t the end of the world, but to me, that client never looked at me the same way. You know, I was bruised at that point, and I set out to make sure that never happens again. And so you spend a lot of time working in the in the channel and with service providers to really isolate and identify what’s important, what matters, and that we focus our attention on the assets that you care most about. You know, when we start talking about security, there’s there’s too much to do. I’m sure that we’re going to cover that in these series all over the next year or so. There’s so much going on. How do you figure out what to do first and where to start?

Matt Tankersley
That’s right.

Jay Ryerse
And once you’ve identified, you know what the assets are and what you care about and what you need to run your business to continue, you know running your systems in your business, then you can focus the really smart people to show you how best to solve that. It does. You know, Matt talked about this. It starts out with assessing and understanding your risk, and I’m going to be the first to tell you not all data is created equal, right? Five year old tax records are not as important as this week’s payroll numbers or that big quote you’re working on or whatever it is you’re working on day in, day out. And so we’ll cover a lot of this content, I’m sure, over the over the upcoming weeks to help you start to understand how to take all this really smart stuff these guys are talking about and translate it back into your business.

Lauren Lev
Mm-Hmm.Yes. Awesome. Thank you. Those are good points. So just going to take a second to acknowledge and show gratitude that all that you guys do to help TOP and our peers around the globe to successfully deliver on the promise of secure, reliable, trusted, technology. With that, Matt, do you have anything to add?

Matt Tankersley
No, I don’t know that I can follow any of that, and I told you these guys are rockstars, and we’re just so grateful to have each and everyone of you. I love, I love Jay, how you started your conversation about simplifying the conversation to speak in their language. And honestly, you started with that and you ended with something that clearly did that. So I’m glad you’re here, I’m glad you’re gifted at that. And you know, that’s something that we’re all striving, striving to do here. So I can tell you with the shared interest that I hear in the room, we might have to have an episode Twenty Four Out in Florida, somewhere on the beach because I need to see, you know, Jim and Ivan put some computers together and pull them apart because I know y’all both share that passion.

Ivan Paynter
Oh yeah, right on.

Jim Bowers
Oh yeah, that’s right on this.

Matt Tankersley
These are great stories, and I know and hope that you get a chance to share those with people often and that translates into wisdom that they can use in their own businesses right? So that’s all I’ve got. Lauren, I’d say, let’s keep it going.

Lauren Lev
Okay, awesome. Alright well, thanks, Matt. And if you guys are all ready, we’re going to get down and dirty with the WHO and the WHAT of our VIP cast? So, Jim, are you ready?

Jim Bowers
I think so.

Lauren Lev
You’re in the hot seat,.

Jim Bowers
Fire away. Fire away.

Lauren Lev
Hey, luck of the draw. I guess it’s whoever draws a shorter stick. OK, Jim. So, tell me what you think or what you see the value in having a series like this for who’s in your cloud and if you also will share with us, what is this cybersecurity statistic that scares you the most?

Jim Bowers
Ooh alright, so I think the value of a video blog series that you guys are doing, it gives some structure around what are the key pieces of an organization needs to put in place in a defense and best approach or a layered approach to security. Because there is no silver bullet that’s going to protect an organization, especially with what we’re dealing with, what I like to call the pandemic effect, right? The eroding of the perimeter, working from anywhere, working from home. That has put a lot of challenges on organizations in a lot of areas, right? At the end of the day, security solutions revolve around, in my opinion, three simple questions – It’s where’s your data and application? Who’s accessing those data and applications? And where are they accessing them from? Right? Those three pieces, if you look at the list that you guys have put together in the video blog, really address and solve back to one of those three main points, right? And it’s always evolving. And what I think I like most about it is, if any, why this series is so beneficial is it is a moving target. Vectors attack, vectors change. I just read something about Discord becoming an attack vector because gaming has become a big aspect. I’m going to send a text to a disboard, I’m going to launch it, it’s going to get a landing page. I’m going to put in something saying, Hey, you can get the the hack for Call of Duty and at the end of the day, that hack attacking you. So that landscape is constantly changing and providing a foundation of what organizations can do. Viewing this video blog is a first great step to provide a strong security posture. What is the statistic that scares? There’s actually two. Ransomware is going to be a six trillion dollar a year industry by 2023. That scares the hell out of me. It’s not because we’re doing things good it’s because we’re doing things bad. The second is there is going to be a ransomware attack every 11 seconds. Put that in perspective. So if you think that I’m a, I’m a small to medium sized business, I’m not going to get attacked. I make duct tape no one wants my intellectual property rights. That’s a misnomer. You have data that makes your business run and that’s valuable to you, and that’s valuable to the threat actor. So those are the two statistics that really scare me the most.

Lauren Lev
Yes, absolutely. Well, let’s pass the baton to the Intelysis team. So, Patrick and Ivan? Same questions. What do you think that people will find in the value of a series like this? And then what is the cybersecurity statistic that frightens you most?

Ivan Paynter
You’re up first, Patrick. I’ll take it, I don’t care.

Patrick Chen
So yeah, you know, I think, you know the way Matt and Lauren are setting up this series it allows us to kind of break apart the different elements, the layers that Jim was talking about for cybersecurity, so we can really focus on each technology and dive in a little bit deeper and explain to the customer and our listeners about why it’s important, right? What we’re seeing in that particular thing, I think it’s a fantastic point because a lot of times when we talk about cybersecurity, it’s just like one big, you know, throw up about, Hey, what technology is out there, right? You just need cybersecurity, but where do people start, right? I think that’s a big question a lot of people have. And I think this is going to do a great job in doing that. So I’m really excited to be a part of this. In terms of statistics, I think a lot of where my concern and my my where my wariness lies around security going forward actually mirrors Jim’s a lot, you know, so I want to use that specific statistic. But I will say, you know, for me, you know, when I think about security in general, right? A lot of times the damage that people talk about is the fact that there might be data loss, there might be financial loss, right? And that’s all important. And I think what scares me the most is the fact that health care organizations are being attacked more and more. And ransomware is still evolving constantly. Now I don’t have a specific number I could throw at you, but I will say this we are now seeing situations where hospital life saving equipment are being hit by ransomware, where it’s down now, right? People that are relying on these machines to stay alive and those machines are no longer working because of ransomware. And that scares me, right? The last thing I want is a situation where you think, you know, I’m going to a hospital to get health care and all of a sudden the machine that’s supposed to be saving my life is inoperable. That scares me. Ivan, I don’t know, what about you? –

Ivan Paynter
Theres- I have so much to say, you know. Give me the microphone and I’d never shut up, right? So I want to piggyback on all of them. Patrick, you were spot on. The first woman that actually, she passed away because she wasn’t able to get surgery was in Germany. It was this past year. I believe it was sometime during the summer or so where the hospital was under ransom, and it’s unfortunate that she she actually did pass and that was actually the first death that we saw due to ransomware. I agree with Jim. I think it’s actually great that they’re doing this because I just kind of tripped into cybersecurity. I never really thought anything of it. Now, all of a sudden, it’s like everybody wants us, right? It’s like, Oh, baby, I’m going to write this ticket. But look at on the real side. I believe that that, you know, Jim said it the best. There’s a lot of people out there that believe that I don’t have anything to worry about there, nobody wants my stuff. And I go around, I look at a lot of small companies. My wife runs one and I’m like, You’re going to get ransom. And when you do, it’s going to be really expensive to get out of it because I’m not cheap. And no matter what happens, that backup is not secure, either, you know, it’s just not. But there’s one that’s even scarier than that. The ones that believe, well, I’ve got a firewall and I’ve got an AV or maybe an EDR because God knows they don’t have an XDR, but they have those, those things in place and that’s all they need. Now, mind you, they’re also still running Windows 98 or maybe there’s actually an NT out there somewhere. The fact that we are not staying to the same level of evolution as the bad guys, Patrick said it very well as we evolve, or maybe Jim said it, as we evolve, they evolve. They’re using, and I don’t believe in A.I. It’s machine learning, but as as we use A.I. or M.L., they use A.I. or M.L Sometimes they have the lead. Sometimes we do. It’s a constant battle. For us, it’s, it’s one time and you get it wrong and that company is done. For them, they have all day to constantly hit at that door and to get in, right? So at the end of the day, to me, it’s exciting. It’s growth. I love what I do. I get goose bumps over it, but the sad part is this is all I do. So because it’s so consuming, if you don’t stay on top of all that – we talked about this discord for a minute. You know what a great way to hack into somebody. Now we have compromises that don’t even have a payload that can’t even be identified anymore. How do you do that? Oh my gosh, there’s so much out there that we have to constantly learn and be involved in and stay connected with. And to me, I think that is the fun part about cybersecurity. Yeah, I did say cybersecurity is fun. It is. I think when you really like it- Jim’s having a great time. When you really like it and love it and immerse yourself into it, it’s a good time. It really is. And the last bit, Jim, I fall into remediations real quick. I love doing IR. It brings me back to my good old days of MCI, and it just started happening instantly and I was like, oh that’s right, I don’t do this anymore. But sometimes it’s fun to be able to run those things. So for me, cybersecurity is something that’s going to be here forever. We all have to be part of it. We all have to be vigilant. I want to lead with one other thing. It’s no longer if and when we all know that, but we all have to be vigilant. Every single one of us is the human firewall, and that’s why this video blog is so important to get that data out there. We all must be cognizant of what we do, and God knows what we’re clicking on, right? That’s that’s a little verbose, but that’s the bottom line.

Jim Bowers
So, to add to that, I’m going to break your stress. I just have one thing, I went for one more statistic and I want, I want to come off of what Ivan said is we are the weakest link. We are. And that’s why threat actors go after endpoints. I like to call them starting points because they they know they can get through us. But I want to share one more statistic and hopefully this will hit home. Two hundred and forty plus days is the average time malware sits on an organization’s infrastructure. Dwell time, that’s right, dwell time. So maybe put it into perspective. What happens, Lauren, if I came into your house for 249, watched you sleep, watched your kid, sat on your couch, ate your food, and you found that out. What would you do? You’d do everything possible, you’d put Ring Doorbells, you’d put cameras, you’d put sensors. What this blog does is enables the viewers of this blog to know what to do to stop that malware or that person sitting in your your home or your infrastructure for 240 plus days.

Matt Tankersley
Yeah. Yeah.

Lauren Lev
Yeah, How can you address it if you don’t even know what’s there?

Matt Tankersley
I’m anxious to hear Jay’s follow up on all that. I do want to say, Ivan, it’s funny. You talk about it being fun and you know it can be, right? Especially for people that have constant spinning propellers, you know? And the reality is, the thing that gets lost in there is it’s not an option. This is not an option. It’s not something to just think about as a pastime of fun. It’s not an option. And I’ll tell you one of the things that scares me as we talk about this machine learning, we haven’t even started talking about quantum computing yet. And the fact of the that and what that’s going to do to change the entire game is just that. I got goosebumps even saying it right. So yeah, there’s a there’s a lot. We’ve only just begun let’s leave it at that. Yeah. All right, so I know you want to give it over to Jay there.

Jay Ryerse
OK, so I can go about 19 different directions here with what you guys all set up, like you tee’d up all these softballs I can go hit. I’m going to start with the fact that it’s fun when you’re the person coming in to an incident who gets to solve the problem. It’s not fun for the victim. But like think about the last time you saw a car crash in the side of the road. All the cars on the other side of the road, they’re slowing down and they’re all looking to see what happened. But the person who just got out of the car, who just got rear ended, just hit somebody, who just was apart of that, that car crash is not thinking it’s fun. And unfortunately, cybersecurity incidents are exactly that. You know, it’s fun for the team that goes, were gonna learn what happened and how we’re going to fix and defend against in the future. But the victim, the business owner, the the the team that was hit, you know, it’s it’s a bad day or week or month. I think the average, average time to get back to normal after a cyber attack is 66 days. Not back to operational, back to normal. So think about the impact of that and what that would mean to your business, but where I really wanted to go was the talent. You know, one of the problems that we all face is that there is roughly three point one million unfilled cybersecurity positions worldwide. That’s commercial positions, not military, not government, right? There’s only 2.8 million of us in the first place. So we’re not going to be able to solve this problem any time soon. So that’s where cyber becomes a team sport. It takes all of us working together, sharing threat intelligence, learning from one another, learning from those of you that are on this call right now watching, you know what happened to you that we should know about so we can get the word out. So when I start thinking, though, about the impact and that deer in the headlights look that business owners have after they’ve been hit by a cyber attack.

Matt Tankersley
Wow, wow.

Jay Ryerse
Okay, the FBI keeps stats of complaints, and I’m pretty sure that most of us don’t call the FBI after every attack, but those that have, last year the numbers from the Internet Crime Complaint Center is the average complaint was ninety four thousand dollars. So ninety four thousand dollar lost where money got wired out inappropriately or sent inappropriately. That does not include the mitigation, the remediation, the forensics, the insurance, the whatever else has to happen behind the scenes, just ninety four thousand dollars in lost cash. Now look, there are plenty of businesses that are probably going to listen in that, you know, it would not be fun, but they’d be OK. But how many of you in a smaller business that might be listening in, you know, ninety four thousand dollar wire transfer going to the wrong place that you don’t know about for two months would be a problem. Maybe you pay the vendor to the wrong account. The other one that jumps out at me is the average ransom payment right now is somewhere around one hundred and thirty thousand dollars. Again, excluding response, breach notification, compliance issues, legal fees, and reputation. The impact on your reputation both with your clients and your colleagues, your employees because they’re the ones that are leaving after cyber attacks, because they don’t want to be associated with a business that knew better and didn’t take action. So when you know all these things are going on, those are happening, at the end of the day, there’s not enough talent, so we have to work together. We have to solve for the most common attacks that are causing financial harm to businesses. Your size, whatever that size is, you’re only going to solve that by assessing that information and ultimately by sharing and understanding these stories because they’re scary, but they’re also true. And that means that we need to rethink exactly what that means in our business and our livelihood.

Lauren Lev
Absolutely.

Matt Tankersley
Well, it’s funny, Lauren I’ll just take the helm and move us into that next section that we talked about. But you said 19 and I swear just you’re touching the tip of those who gave me another 19. We could just spend hours having these conversations, unfortunately. And what a brilliant segway to, I was going to share a little bit about the origin of this campaign, right? And it’s ironic because it focuses on two areas that we’ve been talking about. And the first and foremost one is, is the failure to adopt simple, best security practices. We had so many clients that we’ve been telling for multiple years what you said or Ivan a little bit earlier, and it is factual. It is not a matter of if it’s a matter of when. And yet we’re telling these folks day in and day out and they’re just refusing that and adopt these best security practices. We reached a point where we said, we love these guys. Some of them been with us 10 20 years, but there was a point where maybe it was time for a divorce. And how do you have a nice divorce right? And so we, we subsequent to that had an opportunity to consider onboarding a client who had just been through a ransomware event. Now, theoretically, they were clean on the, on the other end of that. And we had to ask ourself a question at the same time we were asking the other question is, do we want to bring that into our environment? What’s the risk to our existing client base and ourselves if we bring in a client that thinks they’re clean and they’re not right? And so we ended up reverse engineering where they came from, what they didn’t do that they wish they had done, what they ultimately did in the end, and that’s how we came up with our top cyber twenty one best security practices. And interestingly enough, we’ve actually, hopefully accomplished both missions. And we’ve turned that breakup, let’s call it a breakup instead of a divorce – We created what we call the Security Awareness Declaration Matrix. We’re requiring all of our existing clients and new clients to sign this thing. If you want to do business with my company, you got to sign this thing. There’s no obligation other than you have to fill it out. And we take our Cyber Twenty One and we say for each of these twenty one things, starting with let’s talk about security awareness training, right? That’s at the top thought list. Do you declare that you refuse to adopt security awareness training or do you declare that you already have it or that you’re in the process of adopting it? Or even better, if you don’t, maybe you want TechOnPurpose to give you a quote. Here’s three vendor solutions, which one of the three would you like or would you like to see all three? So it’s it’s interesting. All of these stories tie together and I and I and I think it’s I love what you said. It’s what I heard one guy say. In fact, I saw their website and it first insulted me. It said Cybersecurity is a team sport. I mean, it really did. I’m like, Man, that is a horrible way to look at that from the victim’s perspective. But when you put it in the professional perspective that we’re having with a very intentional goal of driving people to sustainable, secure, reliable, trusted, technology, we can have a little fun and say those things. And the more we work together, the more we collaborate and share best practices, the better off we’re going to all be. So Lauren, I think we just go around the horn real quickly. We give our VIP cast the opportunity to share some last thoughts. And Jay, let me start with you, man. What, what are any final closing thoughts on this Who’s in Your Cloud series? Any words of wisdom, more importantly, that you have for viewers trying to simplify the complexity of cybersecurity?

Jay Ryerse
I think one of one of the guys recommended it before. Think of it like your house, you know, if you’re worried about somebody breaking into your house, you’re going to lock your doors, you’re going to close your windows, you’re going to get a doorbell camera, motion sensors, you know, alarm system, those kinds of things. And who knows for sure if you need all of that, right? If all of your important stuff is, you know, on your laptop, right? You know, if they steal your TV you don’t care, but if they get your laptop, you might be thinking differently. So you know working through with with the professionals that you have working with you as a client and or if you’re looking for them, you know, trust TechOnPurpose to help you guide that process to figuring out what matters most and then look at how you protect it. Because as much as we like to say you should buy every single technology out there, you can’t, it’s not practical. So let’s figure out what’s appropriate for your business and then make sure that you’ve got that. Because if you’re just trying to go to the grocery store and back, you’re going to need something different than if you’re on the racetrack, you know, trying to get around one of the fastest lap. So there are so many different ways to solve those issues. But you know, ultimately, Matt’s team is going to help you solve those going forward. And of course, ConnectWise is here to help them deliver the staffing and the capabilities necessary to keep an eye out on your business. 24-7.

Matt Tankersley
Hey, Jay, you nailed it. Thanks so much, and we’re grateful for your partnership. And let me reiterate, you know, it’s that assessment part, right? Let’s assess where your risk is, and you guys are crucial in helping us to answer that question for our clients. And hopefully we get a lot of folks are going to follow up and try to get that free assessment that we’re given for the period that we’re giving it. So, Jay, we’re so grateful for having you here. Thank you. Ivan and Pat, last thoughts on episode zero of Who’s in Your Cloud?

Ivan Paynter
All right, Patrick, well I’m going to do my soliloquy here. There’s so much still left. First of all, thank you all for having me. Patrick, thank you for conning me to being here because he knows I hate doing anything because I feel like I’m obligated to do everything. What I want people to walk away with, what I want them to do- I want them to slow down. I want you to start thinking about what you’re doing. I want you to pay attention to what you’re doing. You cannot multitask. That’s impossible. You have to pay attention to what you’re clicking on. If you don’t know where you’re going on that third click when you get to some link that’s in the cloud or wherever, don’t click on it. If you don’t know who sent you that email- every day I get an email that says, Oh dear, dear dearest, you already know it’s spam. You know, I almost want to write back to them let me give you some better English. Let me help you out a little bit. So that’s the first thing. Slow down. Pay attention to what you’re doing because yeah a hack is a hack, but there’s scams out there as well. And if we don’t slow down and really pay attention and open up our eyes, you’re going to miss it and you’re just going to fall into another lapse. There’s something else that Jay said that I really want to do pay attention to where you have your, your crowns, where you have your value added merchandise, if it’s in your laptop and somebody steals your TV. Don’t be fooled by that because your television has access to your laptop via your modem or via your router. I’m not going to come in through the front door. You’ll never see me through the router. I’m not even going to come in through the window. You won’t see me. When I come in through a radio wave that possibly came from your television, or I know what the password is because I stole your TV. So now I can gain access into your network. Everything you have is connected in one form or fashion or another. Pay attention to what you’re doing where. What information are you giving out? There’s a reason why we have multifactor authentication. Passwords are obsolete and we need to walk away from them. There’s a lot of old technology out there that is trash. We haven’t moved away from it yet, but we need to pay attention to it. Last bit, when you’re in that car accident and it sucks for you, make sure you have that insurance when you’re driving the other way. Because there’s a lot of folks who go, man that’s a bad accident, that’s too bad. That’s great, but if you don’t have that insurance, you’re butt’s going to be hit from the rear next. OK, pay attention.

Matt Tankersley
That’s right.

Patrick Chen
Well, gee, Jim, now I know what you’re talking about, how much it sucks going after Ivan and Jay as well

Patrick Chen
You know, I think you know, I mean, obviously all these guys are experts on here, you know, so very thankful that, Matt, you invited me to join and be on here as well. You know, I will say just to kind of piggyback off of what some of them have said. Look for all of you that’s out here listening, it doesn’t matter what size you are, right? You know, you know, I said before that I ran MSP and most of my customers back then were in the SMB, you know, the medium sized business space. And I’ve also worked with customers on the enterprise side. You’re just as likely to get hit. The reality is, you know, we hear about these like big time attacks out there that are targeted. Sony gets hit, targeted, sure you know. That some people decided they wanted to make a name for themselves, spend a lot of time. But the reality is the easiest way for them to make money. And that’s why they’re there. But why they’re doing this stuff, they’re just casting a wide net and they’re seeing what people will click on, right? Ivan likes to say, don’t click on stuff, right? And it’s because everybody, no matter how big of a company you are, how small of a company you are you’re clicking on things right? You’re curious. You know, it’s part of our human behavior. And the easiest way is just to get you guys to click on something. And that’s it, right? And the other thing is, you know, Ivan’s exactly right. You know, everything’s connected these days, you know, we don’t think about it, but we got so many devices all connected and exposed to the internet, and we don’t know who is on there, right? I have I have thermostats right now. I have a thermometer for like an aquarium. You know, my my lawnmower, you know has

Patrick Chen
Wi-Fi capability. I have no idea if something’s on my lawnmower. I can’t tell you right now and that’s probably a bad thing, that’s a really bad thing, you know? So, yes, you know, be vigilant and there’s a lot of things we can do to protect ourselves. And obviously, it’s going to be a situation. It’s a cost versus risk, right? And that’s up to guys like Matt to be there working with you guys to really help you assess and decide what’s most important. What’s the biggest bang for your buck to protect you as much as possible?

Matt Tankersley
Awesome. Awesome. Jim, we’re coming to you last here. Just a second, let me just piggyback on those thoughts for a second. We talked about statistics earlier, and Pat, kind of picking on what you said there in the middle, if I remember correctly, one of the stats I saw is that 85 percent of attacks are targeted at SMB’s, right? And so, yeah, while the big fish are out there, they’re getting hit, and when you hit it, you get hit, they get hit hard and you hear about it. But if you’ve got a business, we said it now three times. It’s not a matter of if, it’s a matter of when. And guys I kid you not, last Friday, it was four forty five in the afternoon and I got a call from one of our clients going- Something’s happened. Somebody is on my computer and I just lost $100,000. This is a small business, right? And he started to tell me about how he’d managed to get with the bank and get the $100000 back, reset some passwords and two hours later, it happened again, right? And this guy is one of those people that we talked about, right? They refused to follow best practice and the adoption of just simple network infrastructure and advanced threat protection firewalls and those sorts of things. And it didn’t have endpoint security. I mean, you talked about the guys that think that they can just get by with those two or three things Ivan, this guy had none of it. And he’s just begging us to show up on site at five pm on a Friday and help him out, and we did and come to find out. Guess what he did? Ivan?

Ivan Paynter
RDP?

Matt Tankersley
He clicked on something, he clicked on something. And guess what, he’s got some network infrastructure now and he’s got some endpoint security, and we obviously took care of that. But he’s in damage control mode with six figures here and there going in places that he hadn’t didn’t plan to. So let me switch over to Jim-.

Patrick Chen
That’s a good point too. You know, it’s like I just wanted to touch a piggyback on what you just said. You know, it’s about money. That’s what that’s what a lot of. That’s what ransomware is about. You know, for all the small businesses out there that are listening and thinking, I forget who said it, like, Oh, they don’t, they don’t care about my data. They don’t care about your data. You know, what they want to do is make sure your data is inaccessible so they can take your money, right? We’re not on statistics anymore, but I do remember that happened recently. There was like one ransomware group recently that made so much money within a span of like two years, like lifetime money where they never had to work again. And they said, You know what, we made so much money in such a short little amount of time that we’re retiring and then released all the keys for everything that have ever been infected by them and just disappear from the rest of the world. It’s about money.

Ivan Paynter
They didn’t disappear, but they but OK.

Jay Ryerse
Okay so Patrick I’m gonna take that one step further, though, if you think about it from a from a business use case. You said that, OK, they want to deny access to your data. What does that mean to these business owners that are listening in today? Think about how long you could run your business with no access to your data. Could you go five days? Well, how about four, two, one? Well you can’t do more because we need the computers in the data. Everything is in the cloud, which is ultimately why I think that this session is so valuable. And sorry, Jim, I don’t mean to jump on top of you.

Ivan Paynter
And but I want to jump on on top of Jay because there’s one thing and I know we keep on going on here and this is the best part about cybersecurity I love because it just never ends. We didn’t talk about once compliances, right? Not once. Now just think about this. You own a small business and you have names in numbers or credit cards or whatever it is. If you break one compliance, the hell with the ransom. Do you know what your compliance charge is going to be. For Facebook, just charge in a paid GDPR two hundred and forty million dollars for Facebook. Good. I hope they get them again because they can’t stand Facebook these compliances are adding up and they’re putting small businesses out of business. So it’s not just the ransoms anymore. Compliances are massive, too.

Matt Tankersley
Yeah, it is. And Jim, we’re going to switch over to you and let me just tell you, stay tuned because episode 19 and 20 of this series are focused on compliance fully, right? So there’s a reason why they’re on the top twenty one. Jim, thanks for being patient and help us close out episode zero.

Jim Bowers
Dude this is great. I mean, you’ve got such a great panel. I think when we start talking, all of us feed off each other and know that the light bulb. And I mean I agree, compliance with Ivan, I’m gonna touch on that. Yes, that’s a critical component. But what I also want to say is just because if your compliant doesn’t mean you’re secure, right. That’s a good, good starting point. Second thing I want to build off of is what Patrick said. Don’t fool yourself. It’s a business. Threat actors are like salespeople. Everybody’s going well, what would you just say, threat actors like salespeople? Yes, they are. They’ll go after the elephant for 80 percent of the revenue is made off the small guy. Right? So again, don’t think that because you’re an SMB or don’t think that because you don’t have intellectual property rights, you are not going to be a victim of a cyber attack. Second thing I want to copy, think it was Jay that said it, is the threat landscape has exploded and historically I worked to secure security, did not share information. We always hear this. We’re greater together than by ourselves. Threat actors share information left and right. Once one gets in, they share it. And I promise you another threat actor is going to try to get in on the back door. Historically, we haven’t shared threat intel telemetry that has to change right? And that has to change because we will be better together as one. But setting the foundation that you laid out in this video blog series is a great foundation for organizations to follow. But more importantly, don’t stop there. Leverage TechOnPurpose because even though those are all critical, different pieces may be more critical to an individual business than other ones, right? How is your workforce? Where are they coming from? Already in your office, you know, do you need zero trust network access? Do you need all these pieces as you do, but other areas you could focus on within that list of 21? So I am so happy to be here, work with such great panelists in the industry, and this is a great opportunity and it’s a great opportunity for our video blog listeners on TechOnPurpose too, to follow this series. Thank you very much.

Matt Tankersley
Although I’m a little biased because I agree you guys are the amazing rock stars we have the pleasure of working with every day. Thank you for choosing to be part of our program. And Lauren, I’ll just ask you to close this out and then we’ll all get ready for what’s to come.

Lauren Lev
Yes, awesome. Well Jay, Jim, Ivan, Patrick, and Matt, thank you guys. Thank you for your time and sharing your knowledge and expertise. And thank you to you guys, to all of our subscribers and viewers for following the Who’s in Your Cloud journey. Twenty one steps to secure, reliable, and trusted technology. I’m Lauren Lev, TechOnPurpose marketing manager. Coming up next week, we have episode one security awareness training. Find out why it’s number one on the top cyber twenty one best security practices. See you all next week.

Lauren Lev
Awesome. That’s a wrap. All right.

Ready for your free cybersecurity survey? Discover potential vulnerabilities for your business and get a copy of our #TOPcyber21 Best Security Practices to help get you started on the road to #secure, reliable, trusted technology!

Subscribe to our blog to get episodes of “Who’s In Your Cloud?” delivered direct to your inbox weekly.

Claim Your Free Cybersecurity Sruvey

View Next

Diagram showing how Texas cybersecurity law applies to every business, with two outcome paths — documented before a breach leads to safe harbor, documented after leads to full legal exposure

Texas Cybersecurity Law: What Every Business Must Know

⏱ 6 min readKey Takeaways Texas cybersecurity law already requires every business, regardless of size, to protect sensitive personal information and report breaches within 60 days of discovery. SB 2610 offers a safe harbor from punitive damages — but only if you can...
CVE dashboard showing NIST's "Not Scheduled" status replacing CVSS scores — patch prioritization without a score

NIST Just Derailed Patch Prioritization — Here’s Your Fix

⏱ 3 min readKey Takeaways NIST stopped automatic CVSS scoring for most CVEs on April 15 — the patch prioritization signal most organizations relied on just changed permanently. Only CVEs on CISA's KEV list, federal software, and EO 14028 critical software receive...
AI-Enabled Device Code Phishing — TechOnPurpose Identity & Access Management MFA Bypass Prevention

AI-Enabled Device Code Phishing Is Bypassing MFA — What Your Microsoft 365 Users Are Up Against

⏱ 4 min readKey Takeaways Device code phishing abuses a legitimate Microsoft OAuth flow — no passwords stolen, no MFA prompt triggered, full M365 access granted. AI-generated lures are now role-specific and hyper-personalized — standard phishing training won't catch...
Chrome Zero-Day Patch — TechOnPurpose TC21-05 Endpoint Patch Management Urgency

Chrome Zero Day Patch: Update Now

⏱ 4 min readKey Takeaways This chrome zero day patch isn’t routine maintenance — it covers two vulnerabilities already being weaponized. CVE-2026-5289 scored a 9.6 CVSS — a full sandbox escape. If exploited, an attacker owns the endpoint. CISA added CVE-2026-5281 to...
Russian CTRL Toolkit remote desktop hijacking — TechOnPurpose TC21-15 secure remote access defense

Russian Malware CTRL: Remote Desktop Hijacking Undetected

⏱ 4 min readKey Takeaways Newly disclosed Russian remote access toolkit called CTRL is enabling remote desktop hijacking attacks that bypass all known threat intelligence platforms — including VirusTotal CTRL is a newly disclosed Russian-origin remote access toolkit...
Old vulnerabilities cyber risk — TechOnPurpose patch management defense-in-depth

#CYBERinsanity: The Vulnerabilities Attacking You Today Were Published a Decade Ago

⏱ 5 min readKey Takeaways 32% of the most active exploits are old vulnerabilities, more than ten years old — patches exist, they're just not being applied. Attackers start with the low-hanging fruit: automated scans for known, unpatched flaws before deploying anything...
Defense in depth strategy — TechOnPurpose TOPCYBER21 cybersecurity framework protects your organization from vulnerability exploits

Why Patching Alone Won’t Stop 40% of Cyberattacks

⏱ 4 min readKey Takeaways A defense in depth strategy is no longer optional — it's the only architecture that holds when patching alone fails. Nearly 40% of all intrusions in Q4 2025 were caused by exploited vulnerabilities — not phishing, not credential theft. Some...
2026 National Cyber Strategy Blog Post image

2026 National Cybersecurity Strategy: What It Means for You

⏱ 5 min readKey Takeaways The White House's 2026 national cybersecurity strategy introduces six strategic pillars — the clearest federal signal yet that passive cyber defense is no longer acceptable. All six pillars align directly to the TOPCYBER21™ framework — if...
TechOnPurpose achieves MSSP Alert's prestigious 2025 Top 250 Managed Security Service Providers (MSSPs) list, ranking #159 globally—a significant jump of 32 positions from last year's #191.

TechOnPurpose Named to MSSP Alert’s 2025 List of Top 250 MSSPs – Climbs 32 Spots Year-Over-Year

TechOnPurpose is proud to announce its inclusion in MSSP Alert's prestigious 2025 Top 250 Managed Security Service Providers (MSSPs) list, ranking #159 globally - a significant jump of 32 positions from last year's #191. This marks the second consecutive year...
#STOPtheCYBERinsanity image - Is Pen Testing a Dollars-Before-Defense Mistake

#CYBERinsanity: When Pen Testing Becomes a Dollars-Before-Defense Mistake

The Fallacy of Pen Testing as a Priority in Cybersecurity If you’ve been following our STOP the #CYBERinsanity series, you already know this uncomfortable truth: Most cybersecurity failures aren’t caused by brilliant hackers or exotic zero-day exploits. They’re caused...
en_US