
Last week, our viewers were treated to a special episode to discuss the cybersecurity implications of the ongoing Russia/Ukraine conflict. We were joined by an awesome cast of cyber experts who broke down what we do and don’t know about the bad and the ugly of Russia’s growing impact on global cybersecurity- and how to keep yourself cyber-safe amid these ongoing cyber threats.
Today, as we take a greater look at TOPcyber21 best security practice number 13, we will be discussing all things Network Security. Here in Episode 13, find out why just a few minutes of downtime can cause widespread disruption and massive damage to an organization’s bottom line and reputation without the defense of advanced threat protection. We’ll also hear from our partners as they provide our audience with their available solutions to ensure protection against this ever-increasing threat. We’re very thankful to our cyber expert cast joining us today from Fortinet and Privafy, as well as Jim Bowers, Independent Cybersecurity Consultant, as they help us educate our clients and prospects on the road to #secure, reliable, trusted technology!
As a reminder, we began releasing a new episode every Tuesday, starting 10/20/21 and will continue to do so through late spring of 2022, with brief time off for holidays with family and friends. We’ll also follow each Tuesday episode release with subsequent Wednesday, Thursday, and Friday posts highlighting our (3) contributing solution partners from that week’s episode. We hope you’ll find this an immersive, hopefully simple, educational, and enjoyable experience. So how do you tune in?
To easily follow the journey ahead, we’ve diversified your access options to all (23) of our coming episodes. You can follow along here on our blog or by any of the following methods:
- Email Newsletter: sign up at techonpurpose.net/blog and have each episode delivered directly to your inbox when released.
- LinkedIn: follow here
- YouTube: follow here
- Facebook: follow here
- Podcast: follow here
Buckle up – it’s time to hit the road to #secure, reliable, trusted technology!
Read Transcript
Lauren Lev
Welcome back to “Who’s In Your Cloud?” 21 Steps to Secure, Reliable, Trusted Technology. I’m Lauren Lev, Marketing Manager for TechOnPurpose and thanks for coming back for Episode 13 on Network Security. Before we get into it, make sure to listen to all of our podcast episodes on Spotify and for our YouTubers out there, like and subscribe to our YouTube channel down below, it really helps us out. And while you’re here, check out our “Who’s In Your Cloud?” vlog series in our playlist above. We post episodes of this “Who’s In Your Cloud?” series every Tuesday on LinkedIn, Facebook, Spotify, and of course YouTube. And you can get episodes delivered straight to your inbox by signing up at TechOnPurpose.net/blog. Today’s network architecture is complex, every day we’re faced with a threat environment that is always changing and attackers that are always trying to find and exploit your vulnerabilities. These vulnerabilities are present across a broad number of areas including devices, data, applications, users and locations. When just a few minutes of downtime can cause widespread disruption and massive damage to an organization’s bottom line and reputation, it is essential that these protection measures are in place. Today we’ll be breaking it down for you and discussing solutions to this ever increasing threat. But without further ado, let me introduce our cyber experts for today. Back again, we have a very familiar face VIP All Star Jim Bowers, author and cyber enthusiast. Jim, give us a rundown. Who is Jim Bowers and why does he care about cybersecurity?
Jim Bowers
Oh, thank you, Lauren very much. I’m so glad to be back. I can’t tell you how much I love being on TechOnPurpose’s video blog here today. So I think security really drives me for where we are today. So I’m an Independent Security Consultant, worked with multiple organizations, worked on a technology distribution provider, helped the rollout of security portfolios rolled up, man, it sucks. And one thing I’ve realized through my experience and in my career is that security touches every facet. Especially today, cybersecurity is not only our business lives, but our personal lives because it can disrupt our personal lives as well. So, I love being here. Looking forward to the topic. You got a great cast today. So I’m looking forward to a great conversation. Thank you for having me back.
Lauren Lev
Of course. Alright, contrasting our seasoned veteran here, we have two first timers to the vlog. We have Kathleen Goodwin, Vice President of Marketing and Partner Relations from Privafy. Kathleen, it is always good to have another female around here, so I’m so excited you’re here. But introduce yourself to the audience and tell us more about what you do at Privafy.
Kathleen Goodwin
Thank you, Lauren. Thank you, everyone and I’m really looking forward to today’s event. I am the VP of Marketing and Partnerships at Privafy and I am passionate about it because Privafy finds products or solutions actually, that are targeted directly at the underserved SMB market. Where we all know networking is complex, you know, security is complex, it’s confusing. There’s lots of solutions out there and the SMB market has been traditionally underserved. And prior to my role, and I continue to do that, I do a lot of consulting and poaching with Score, which is a US government program where we actually teach young entrepreneurs how to bring business and my focus is all around security and computing resources, so I’m so totally excited to be here today.
Lauren Lev
I love that. Yeah, we’re super excited to have you. And from Fortinet, we have Jonathan Nguyen, Global Field CISO. Jonathan, tell the audience a little bit more about who you are and what you do for them.
Jonathan Nguyen-Duy
First, a big thanks for giving me this time to be with you all today. My name is Jonathan Nguyen-Duy and I’m the Field CISO of Fortinet. I’ve got a dream job where I get to work with security teams of all sizes, public and private around the world on getting security right and applying 25 years of experience. I spent 16 years of that career over at Verizon where I was part of the MSSP leadership team. And my last two years I was in security CTO and that team ran the data breach investigations report. And so looking at about 25,000 data breaches the root cause of that and abstracting complexity and helping people get security right, especially coming out of this pandemic and all things digital transformation and really helping SMBs in particularly mid markets and SMBs cut through all the clutter that’s in cybersecurity and helping them focus in on those insights. Just get it right moving forward, that’s- I think that’s what really drives me. So I’m really just looking forward to this discussion today.
Lauren Lev
Now, probably the most excited is our Founder and CEO, Matt Tankersley.
Matt Tankersley
Hey, everybody, welcome back. I’m glad you’re joining us today, it’s a pleasure to, Kathleen, continue to learn more about Privafy. I’ve enjoyed our recent conversations and looking forward to some that are to come. And as I said earlier, we’ve been afforded that partner for well over a decade. So we love that product. We love what you guys do in the marketplace serving so many different areas, in specific, today’s topic, the Advanced Threat Protection at the edge of the network. And as Jim likes to say, the edge of the network is constantly shifting. And so Jim, obviously, we love having you back, man, you’re a great part of our cast. And so, Lauren, let’s take it away and let’s see where this goes.
Lauren Lev
All right, ladies and gentlemen, now to the fun part. So, Jim, explain to our audience what network security is and why should we care. And feel free to share any statistics or stories with the audience to convey its importance.
Jim Bowers
So why is network security so important? That’s a great question, Lauren. And I think if you look at what- I think Johnson touched on it earlier, I think it’s what we’re going through today. If we look at the network itself and how, for the past 30 years, it’s traditionally been done right? In this castle moat philosophy where all our employees are inside of this castle that we only had to protect them in our closed kind of environment, closed local area network, or even a closed private wide area network, right? The challenges of protecting that perimeter was a lot different than it is today, right? Today, through the pandemic, that perimeter is eroding, there really is no perimeter anymore. I don’t think we’ll go back to pre pandemic levels. So what does that do for organizations, right? It makes them have to shift their mindset drastically, because now their employees are not inside their castle. They’re working from anywhere. So that perimeter now has extended out to multiple locations that are not necessarily within their control. So being able to put more stringent control mechanisms around a less SASE environment, that’s the big buzzword-Secure Access Service Edge- or now I think they’re calling it Secure Service Edge, and you’re taking away the access. Simply because we are on the edge, we look at where 5g is going, right, we’re getting ready to move data all from these under protected copper cables coming out of our houses in our locations now up into 5g out into the open, right, so that network protection and being able to protect now a network that is expanding outside of this comfort controlled environment is very critical for organizations. And I will give a quick example. I actually was working with an organization, just to show you how important it is to protect the network, and a CFO pulled up to his office in his Tesla. The Tesla connected into their WiFi, the threat actor went through the Tesla into the WiFi and ransomware their servers. So what I’m trying to say it’s the network is everywhere nowadays, and it’s a very critical component for us to protect, especially because we got to protect those crown jewels, and that’s the organization’s data.
Lauren Lev
Alright, Kathleen, we’ll take it over to you next. What is your take on network security and why is it important?
Kathleen Goodwin
Well, you know, I’m in complete agreement with Jim, I always am. He’s just brilliant. But for me, network security, in particular at the edge, it’s critical to have a comprehensive network visibility across that whole distributed digital infrastructure to defend against advanced threats and unknown attack vectors. And with us, our experience is in protecting that data as it moves between clouds, locations, applications, devices, including IoT. So again, having a solution that has a different approach, includes some combination of endpoint agents, network devices, email gateways, and so on for malware protection is very critical. I agree with Jim wholeheartedly, we’re right at the edge of the world.
Matt Tankersley
I know you’re going to Jonathan next, but I’ve got to say something that runs with that. You said two things that really caught my attention and I want our audience to be aware of that. And one of them was visibility. For so long we thought well, we have a cable modem, that cable modem is doing that and my small business and I are secure, right? Well, that’s nonsense in and of itself. And we can give you billions of examples and you know, and now it’s not okay. Maybe I do need to afford N and F, afford a gate, or a miracIe, or whatever the heck it is. Using a barracuda is whatever the guy, it will put it out there. But then you know what happens when there is a breach? And how do I know where those boundaries are being pushed? And if I don’t have visibility, right, I don’t have that. And, you know, we try to focus on today on, you know, one topic, which is the point of the 21. But it seems in every episode, Lauren, we can’t talk about one without talking about the others. What I love Kathleen, about what you said, you started talking about endpoints, it’s like, you can’t protect the edge if you don’t know what you’re protecting behind it, what those endpoints are doing, etc. So good kickoff to the conversation here. Jonathan, I’m anxious to hear how you introduce us to your perspective on the network engine and why we need it.
Jonathan Nguyen-Duy
So deconstructing network and network is nothing more than connected computing nodes and resources. And that network is very distributed today. So you can tell how old I am, we talk about castles and kings and modes, right, and so network security has always been about the confidentiality, integrity and availability of the data since day one. And so the reason why it’s so important today is that it really cannot be thought of as its own silo, you know, networking, security, and the computer all have to work together to deliver better business outcomes and better user experiences. That’s the big fundamental shift in the last, I would say six years, is that we shouldn’t think about security, networking, computers as separate silos, we should stop thinking about products as separate silos, we need to start thinking about organizational structures, not sock IT as separate silos. Why? Because the problems we encounter don’t operate in silos, they operate across the domain, and cybersecurity is a multi-dimensional operating domain. Likewise, when we think about solution sets, in order to have visibility, you have to have it on the ground at the data center and cloud edge. And therefore, the big shift about network security is that it shouldn’t be thought of in isolation. And it really should be thought of as a platform. So you have that consistent visibility. And through that, you can have detection, prevention and response. But it all starts with, I think, at this time, it’s a good opportunity for us to think about getting it right. So that’s what we do at Fortinet.
Matt Tankersley
Tying it all together, right? If you think about security in general, let’s talk about physical security. When you want to protect your home or your business, you don’t take the camera and put it in the bathroom for a lot of reasons. What’s the main address? Right?Besides the ingress and egress, right, where does that happen? And that’s what we’re talking about today is the edge of the network. And we have to have that visibility, as Kathleen said, and it’s what are we looking for from the outside? What are we looking at on the inside, you know, what’s going on? That’s what this edge is all about. And I’m anxious to move to the next level of the conversation about individual solutions to protect this edge from each of you, right and the role that SASE plays. And I think we call that something different now, we said we’re changing it.
Jim Bowers
Well, there’s a new buzzword is SSE secure services, you’re taking away the access. And I think if you look at it, think about where the access is. It’s everywhere today. Right? And again, you know, talk without talking too much. But you mentioned some visibility, right, and data in motion. If you think about what we went through, at the end of the day security, I think Johnson said it, it has to follow where the data is. That’s at the end of the day, right? It’s all about the data and securing that data. And if you think of what’s happened to organizations and how that data is moving, digital transformation, acceleration, it’s critical, this type of solution to enable organizations to foster that movement in that change, right? That SASE solution is not right for everybody, but organizations need to incorporate that in their strategy moving forward.
Jonathan Nguyen-Duy
You know, I think SASE as a concept was a dream of delivering integrated and converged networking in the form of secure SD WAN, security in the form of zero trust and firewalls and service secure web gateway as a service and Cloud App Security, brokerage, this whole notion of delivering security and networking from the cloud to an end to end enterprisers SMB edge. But you know, it’s hard to do that. It’s really hard to do that in a converged way across the first mile, middle mile and last mile. And so when you think about this today, and you’re about to buy these types of services, my first question is, how are you abstracting complexity? How are you reducing complexity? In order to get these elements, you’ve got to buy five different boxes with five different management consoles and five different vendors. The complexity of acquisition, implementation, licensing, training, etc, are very high. So the first insight is, look for platforms that are truly integrated across networking and security, like ours, you know, we’re the only one in the industries that have that capability. And that allows you to reduce complexity and optimize the performance across that. So yeah, that’s SASE. It’s a reflection of anything as a service and this desire to converge networking and security. And I think frankly, the emergence of secured service edges is a reflection of the reality that it’s hard to do that. It’s hard to converge access to the SD WAN component with the other components of security. We’ve done that and we’re unique in that ability. But it’s also a testament to just how hard it really is to do that in an integrated fashion. But I think it’s critical. You can’t deconstruct them. Because if you don’t have them integrated, what you have is optimized bottlenecks. Your SD WAN may be optimized, but unless it’s integrated with your security, it doesn’t work very well. And then the entire elasticity and scalability, the cloud is the gate unless networking security and your computer are working in alignment with each other.
Matt Tankersley
Yeah. You know, guys, I hear CIOs and CTOs and directors of IT get excited about the value propositions of SASE all day, every day, right? And there’s all these vendors that are out there trying to sell it. And I think that we get caught up in the buzz of getting these extra levels of protection through these multiple vendors. And what you said, Jonathan, I love is that it’s really easy for that to become complex. And that’s the whole point of this entire series is how do we simplify this conversation? Well, it’s not through deploying 5 boxes. And so that’s why we have partners like Fortinet and Privafy here to talk about these kinds of things and to the viewing audience, don’t make it harder on yourself. These are important topics, you probably need these things, right. So let’s have that conversation. But be sure whoever you’re talking to that you’re asking the question, don’t get hung up on the features and capabilities and also ask about the simple things. How complex is it? Is it going to take me three new staff members with weeks of training to understand how to manage this environment? Or is this you know, do I have a unified solution where I can go to one vendor maybe and get subject matter expertise, or I have a managed service provider that, you know, is gonna be able to provide those things? Alright, so I’m hushing up because we haven’t moved this conversation along. Jonathan, good stuff, man.
Jim Bowers
Yeah, Jonathan, that was- if you don’t mind me hopping on that. I think Jonathan nailed it. I think all of those pieces have to work together for it to be effective. And I think, Jonathan, you said a valuable point, right? If it’s not done right, it produces more harm, the good and the infrastructure, right? It produces these bottlenecks. I think if we simplify security down to focusing on the data, where our data is, who’s accessing it, and where they are accessing it from, it really simplifies. What we’ve got to do as organizations is to protect that data.
Jonathan Nguyen-Duy
Jim, that’s why you’re in demand, right? It’s trusted people like yourselves, and the folks on this call that help SMBs in particular, work through all these complexities, right.
Kathleen Goodwin
And I think that’s very true, particularly among the SMB market, where they just don’t have the security muscle needed in this environment. You know, I spend a lot of time with SMB clients trying to figure out how they configure the firewall, what’s the VPN, what’s intuitive, and so on. And so the whole alphabet, all the, you know, entire pyramid structure of what’s data in motion. And what we found is moving that functionality to the cloud, enabling it as a SaaS solution that is managed, so there’s no hardware for them to install, no software to update, patch, manage, do anything, and then giving them an integrated console that lets them view and provide complete network visibility. See, bad actors and malicious attempts happening by user by device, by location, it’s just a really simple solution for them to grasp. And I think that’s exactly where the whole market is going.
Matt Tankersley
You know, one of my favorite things about what you just said, Kathleen, is that I know a lot of VPs of marketing. And I have very few of them that will say I spent a lot of time with clients.
Kathleen Goodwin
You have to. You’ve got to hear what they’re going through, you know, it’s just, I hear it every day that they’re frightened or getting attacked, attacks against us and these are up 400% year over year. Ransomware is the number one that they’re fighting with, malware is coming down at them. They’ve got employees that are not educated. Man, there’s so much to do in that market and make sure that they’re safe and secure and can manage it.
Matt Tankersley
Yeah, Lauren, I think we’ve got time to maybe share some horror stories that people may have about why this is such an important necessity, the unification of the platform and everything. And I will tell you, I know we were helping a client recently with evaluating a compromise and it was in a cloud VMware sort of environment and because of the way that the architecture was not simplified, right? We found that okay, we saw some activity happening here. We had to go to another vendor, another set of logs, and investigate. Now we’ve got to correlate the data between the two systems. Turns out that points to a third system and a third set of logs and now we’ve got to go do that. Right. And so we’ve got an MDR episode coming up, and we’re going to talk a lot about how we unify all those things to create a clear vision which I know Privafy is fantastic at for is really good at that as well.
Jim Bowers
You know, Tank, another thing I wanted to throw out, and you know, since we’re kind of talking about the SMB mid market space, historically, these types of solutions have not been cost effective. So that’s called the SMB space to piecemeal. And that’s why there’s such a huge target, Kathleen, you nailed a statistic 400% increase, the average downtime of an SMB is 21 to 28 days, right? The average cost is $200,000. What SMB can stomach that right? They can’t now, they can’t. So now all these SMBs that had this shift of this perimeter eroding and the pandemic effect. And historically, organizations not catering to this business. It’s very critical. And we’re starting to see people like Privafy and Fortinet being able to accommodate and provide the same level of protections that enterprises have had for years, right.
Kathleen Goodwin
And simply deploy it quickly. Manage it simply so there’s no complexity. That’s where it’s going.
Matt Tankersley
Yeah, you’re right. It hasn’t been there. And folks like you guys, both Fortinet and Privafy are doing a great job of that. And the reality is, guys, this isn’t slowing down. Right. So first, you’re still trying to catch up on the fact that you need stuff and you don’t know where to start? Well, we need to have a deeper conversation. But now you look at what’s going on with Russia and Ukraine. And by the way, we’ve got a special episode coming up on that topic. It’s not slowing down. If anything, it’s speeding up and the actors are getting bigger and badder and smarter. Why are we always behind? Right? Alright, so Jim, any specific horror stories that relate to the failure of establishing security at the edge in Advanced Threat Protection?
Jim Bowers
Oh, yeah, I mean, I’ve told this probably a couple of times, I think some of the big ones I told the one about the CFO. You know, another I’ve talked about I think in a previous episode was the largest breach was a casino with the IP, you know, thermometer and a fish thing. We talked about that before. And that’s, if they would have had the appropriate network security in there and been able to protect it and the visibility across, they could have mitigated and isolated it quicker, right. Especially today with network security. And it’s so critical, due to the fact that- let’s think about IoT devices. You know, I will talk about this. That’s huge. We’re in environments where I’ve got Alexa, that they decided to turn on the sidewalk without telling anybody where my Alexa will connect to all the Alexa’s in my neighborhood without me even knowing, right? I’ve got an IP connected crock pot, lord knows why. But those are all attack vectors. And I don’t know why I have one, I guess I need to check my roast while I’m not playing golf or something. But the reality of the situation is, this is such a critical component in your TOP21 Because of how it’s changing, because organizations need the visibility into those changes happening, as well as the amount of attack vectors that we have today in play in areas that our employees are in that we didn’t have 15 years ago. Right. So the big component.
Kathleen Goodwin
Jim, do you think that, you know, one of the things that I’ve been tracking is how SMBs are an entry point into the larger ecosystem? You know, we’ve seen that with Target. We’ve seen it with several, do you think that’s going to continue to increase?
Jim Bowers
Absolutely. 1,000,000%. Yeah, I think third-party risk is huge. I think we took for granted all these B2B connections. And I think the threat actors have found ways to get around some of our top security controls via trusted applications, trusted third-party integrations, such as Kaseya, such as solar wind, it’s trusted, right? So if it’s to an organization, like how we protected the network inherently, once you’re on my infrastructure, I trust you. Right. And that’s not the way we got to look at things today. And SASE takes that into component, your solution takes a net zero trust kind of network access component, right, that trust aspect. Yep. Great question.
Matt Tankersley
Third-party risk is an important topic. It’s definitely one of the things we talk about quite a bit with our clients. And suddenly, we have an episode upcoming dedicated to as we talk about compliance, discovery reporting, etc. and the role of third-party risk in that but there’s no question, right? So we keep coming back to: what are we trying to protect? We’re trying to protect the data, right? All that data is shared with third-parties or interacted with third-parties, if that data happens to exist somewhere outside of your environment. Right? What’s that risk? You got to assess that stuff? And I don’t think people think about it. But what’s the role that the network edge plays with understanding when and how that happened? Imperative, right. That visibility, what data went where, right?
Kathleen Goodwin
We had a really interesting use case recently, we had a customer using our CASB implementation. And to catch an employee who was terminated, downloading all of their sales contacted information by just being able to track that activity, that app by activity, by user, by location. So again, it’s a really interesting environment.
Matt Tankersley
So Jonathan, you guys have a lot of network edge security out there, man. And that’s a global footprint. And I’m curious what recent stories you might have to help our viewing audience understand the urgency here and the risk.
Jonathan Nguyen-Duy
There are three stats that I think are really indicative of where we are today. The first one from FortiGuard Labs and my old shop at Verizon said 80% of all the attacks of the breaches and major disruptions could have been mitigated through simple to intermediate controls. 95% of the problems in Cloud Security are the customers’ fault because of the complexity of a shared responsibility model. And the last one is that 99% of all the vulnerabilities exploited were known for at least a year. So here at Fortinet we continue to see not only new threats accelerate, but persistent old known threats. We think about what we spend, what $350 billion in network security, every year, we devote our careers to this area. And yet we fail on basics, because we fail on basics because it’s so complex. We built these multi-vendor best in class solutions that we want, because we didn’t want vendor lock in, we didn’t want single points of failure, we wanted to have best in class. But then we say we never have enough people. So we’re by default, vendor locked in, we never have the tools to integrate everything. And so we have gaps at the end of the day. We have gaps in visibility control because of the complexity of what we’ve built that was never designed to work in this type of operating environment. So the practical reality moving forward is that what we do at Fortinet is this: we build technologies that are integrated at a common OS level that collect and share information. So you’re predictive and more proactive, but what we really do is we take enterprise grade capabilities, you know, that worldwide threat research team, all the technology, and we provide that in a form factor and advice appliance as service at an SMB price point. So that’s the great value there, you get the capabilities of the enterprise at a price point and a value point that makes sense for SMB, and you’re working with folks like yourselves here, right?
Matt Tankersley
And you know, when you’re in that situation where you’ve got all your machines locked down with ransomware, God forbid, guys, you know, you don’t need that multi-vendor solution going like this, right? Yeah, you really need that unity. That’s when the unification of your partners and your platforms in your portfolio are so imperative.
Jonathan Nguyen-Duy
So one word on that, if you don’t mind. You’re never going to keep that from being victim zero, if it’s a true zero day attack, but it’s quite reasonable to avoid being victim three, four, or five. Right, because the vast majority of the malware, even ransomware is already known, or some variation of a known piece of malware. And so having compensating controls, properly configured devices, and a really integrated platform, that’s the key to success and thwarting malware and ransomware in particular. But yeah, it’s all about reasonable care. You shouldn’t be victim three, four or five, it’s hard to avoid being victim zero, one or two, three, four, and five. It’s reasonable if you take the advice on this presentation, right?
Matt Tankersley
Yeah. So our clients, man, they’re just, Jim, they’re worried about, hey, they got any virus in their machines I’m protected. Dude, it’s so much more vast than that. And listen, we had a threat alert come across yesterday if you’re operating a network connected APC UPS. Ability that was just about it, you know, came out on APC UPS, guess what we were doing yesterday, we were scrambling with our clients to find out who had APC UPS’ everywhere and going through some updates on those things. You don’t have time, Mr. SMB. And I’m not saying anything critical, you just don’t have time to keep up with this stuff. And you can go get a great solution from all of our vendors in our portfolio. But I think the important thing that I’d like to take just one second to plug in is we’re sitting here watching this stuff in real time from all of these platforms, so that we can communicate that sort of stuff to you. And that’s one of the things Kathleen, I just, I’m continuing to love learning about you guys. And I’m anxious to get to do some things. Excellent.
Jim Bowers
Amen. Yeah. Yeah, I think Jonathan nailed something earlier. I think threat actors thrive off a couple of things. And I think it’s complex, right? They know that the complex is simplifying that complexity to incorporate the network where data is, where data is moving, data in motion, via platforms such as Privafy and Fortinet really starts to turn the tide for SMBs, for any organization that’s trying to protect that data, right? It’s that complexity factor that threat actors know and they love. And you combine that with how quickly organizations are having to shift from the pandemic to become more agile, more data in motion. Reducing that complexity, simplifying it via unified platforms such as Fortinet and Privafy is critical for organizations moving forward.
Kathleen Goodwin
Yeah. Jim, I agree with you. And I think there are some pillars that an SMB has to look at. And, you know, zero trust is right at the top of that, zero touch, kind of set it and let it run to a certain extent, having a full data security compliance, you know, whether it’s encrypted, including encryption, data, leak prevention, so on and so forth. And threat management, I think, is another one. And then overall performance, you know, low latency is critical in this environment, low latency and low processing power. So that’s very critical. And for us, we’re able to do our whole round trip, while providing all of those solutions, all that technology for under two milliseconds, so we’re adding less than two milliseconds round trip for that. So again, that’s kind of a geeky side of it. But I think the zero trust, the zero touch, making sure you have a good data security that you’ve got, you know, cloud based databases at hand, and all that other stuff is so critically important for them, because it makes their job easier. And it makes their trusted partners’ responsibility easier.
Matt Tankersley
Guys, I think Lauren, we should go around and get some final words, I do want to say, you know, if I think about our client base, especially of SMBs, right, and then you know, we obviously serve a lot of larger nonprofits as well, right, and, and all of the various risks that go along with these guys, if you’re in the barbecue business, some plugs for some of our clients there, if you’re in the dry cleaning business, if you’re in the prep school business, right, a lot of our clients are in these areas, right? You want to run the best prep school in the world, you want to make the best barbecue in the world, you want to provide the best nonprofit health services in the world, whatever it is, you just don’t have time to think about it. And my guess is, if you’re listening to this, which I hope you are, and you’re hearing these terms, like ZTP and dwell times, and you’re like, I don’t know what those things are. Here’s the truth, you don’t have time to learn what those things are, because you need to make the best barbecue. That’s what we’re here to do. That’s what all these magnificent partners that we’re bringing to you in our portfolio are here to do as well. And don’t wait till you don’t have a choice. Because it is devastating.
Kathleen Goodwin
Jim had one thing I think we kind of didn’t do justice to and maybe this is just another episode, that this whole widespread use of intelligent, you know, Internet of Things devices, they’re going to be introducing additional exposure at a maximum level that business owners may not even consider. So really keep your eye on that, on that particular term. I thought that was a great point.
Jonathan Nguyen-Duy
Yeah, well, just one piece of advice before you buy anything, work with folks like TechOnPurpose and people like Jim. Find out where you are today. Find out your current state, don’t buy anything before you really understand where you are. Try to figure out where you want to be and then put together a plan that gets you there. Don’t buy a widget first. Okay, that’s the wrong approach. Work with trusted partners, cybersecurity is a team sport, find the right partners, and the folks on this call are some of the best in the industry.
Jim Bowers
John, I think you nailed it, assess where you are today, right? And just don’t go out- I can’t tell you how many organizations I walk into, they have 35, 40 tools. And they had no clue how to use them. They’re not talking to cook together, they’re causing more complexity and what does more complexity do? It enables the threat actor, right. So I think it’s, you’re at the end of the day you’re spot on, assess where you are. But one thing I think organizations need to realize is, when you do that assessment, don’t take it personal. Security is not a destination, it’s a journey. It’s a journey and it will evolve. And just because you put something in place five years ago that you’re very proud of doesn’t mean it’s relevant today. And probably anything you put in place five years ago, is not relevant today, or it’s shifting or moving. So security will continually evolve and will continually change. And it’s because we’re a cat and mouse game with the threat actors, we see something, they get around it. We solve it again, they get around it. So I agree, Jonathan, assess where you are, just don’t run out to buy the next flashiest tool. See how it enables your organization, where you are today and where you want to go. Security is not an IT problem, it’s a business problem. And it does need to enable business outcomes, agree 100% with you, Jonathan.
Matt Tankersley
So Lauren, you know, I’d like to believe that all of our viewers watch all of our episodes, that these things are enthralling. I’m sure that’s not the case. And maybe one day, we’ll get you motivated to do that. If you watch one, we tell some great stories. And I think in closing, I love telling the story, Jim, this one came from you. Because it helps you as an audience. You know, what does this really mean to me? How can it impact me by not having these best security practices? Well, the obvious thing, right? If you get ransomware and you’re shut down, you can’t run your business. You know, you’re in a bad spot, right? How specifically can that happen? What other kinds of things are happening? Jim, I love the story. Unfortunately, that the guy from Scout DNS told us right? We’re doing the episode on web filtering, right and network edge security plays a role in this right? In fact, you look at the Fortinet solution in particular, I’m still learning about Privafy, right, we’ve got web filtering built into the Fortinet edge as an example. And I don’t think you’ve heard this story, Jonathan. But we had the guy that’s the founder of Scout DNS telling us a story on the web filtering topic, about a retail chain of appliance stores in the UK. And they had all these smart televisions with, you know, video panels on the front of them that were touchscreen, and they played YouTube videos, they did all kinds of cool stuff, right? Well, some threat actor got into that device and was broadcasting pornography in the middle of the retail store with parents all over the place on the screens of these refrigerators. Now, how simple is it to prevent that from happening by not feeding so many of the different factors that are 21 best security practices. But you guys, whatever business you’re in, the thing that you haven’t thought of the bad guys are thinking about. This is imperative. I think in closing, risk assessment, you nailed it, right? We’ve had this conversation, Lauren, and literally this week, we created these TOP21 best free practices, using, you know, experiences and industry data. And it’s interesting, we’ve been discussing how we were trying to motivate you through the TOP21 best practices to do the number one thing which is get a risk assessment, right? I think what we realize is that number one on our list really needed to be the risk assessment. So we’ve got to put the cart before the horse. And, guys, we’re providing all of your viewers and anybody who wants to come to us, we’re providing you a free risk assessment, right? Hard to get to where you know you need to be if you don’t know where you’re at. It’s not hard, guys, we can do that for you. And so Lauren’s going to tell you more about that. I’m going to hush you up, guys. Thank you so much for taking valuable time out of your day to have this conversation. Thank you.
Lauren Lev
That is a wrap for us on cybersecurity. Again, Kathleen, Jim, Jonathan, thank you so much for joining us. Matt, you have to be here, but thank you anyways. And to our audience, join us next week as we get into network security’s cousin, Wireless Security and how it works to ensure that your data remains fully accessible to users and devices that you authorize. Again, remember to like and subscribe and catch up on all of our episodes on LinkedIn, YouTube, Facebook, and Spotify. And get episodes delivered straight to your inbox by signing up at TechOnPurpose.net/blog. If you would like to start a free trial from Kathleen at Privafy, or Jonathan from Fortinet, email us at ">. And Matt mentioned it earlier, you can sign up for our free cybersecurity risk assessment at WhosInYour.Cloud. That is all for us today. Thank you and we’ll see you next time for wireless security!
Ready for your free cybersecurity survey?
Discover potential vulnerabilities for your business and get a copy of our #TOPcyber21 Best Security Practices to help get you started on the road to #secure, reliable, trusted technology! Subscribe to our blog to get episodes of “Who’s In Your Cloud?” delivered direct to your inbox weekly.


















