
I know it’s the first week of November, but this is clearly one of our more scary cybersecurity topics. So it seems only fitting a way to honor the close up of October’s National Cybersecurity Awareness Month. Last week, we were joined by our partners from LastPass, IDAgent, OrbitalFire and Keeper, we took a deeper look into the scary reality of the dark web, and how malicious actors use this marketplace to trade in compromised credentials and identities. And that’s why dark web monitoring is number two on the TOPcyber21 best security practices.
If you haven’t had the chance to watch episode zero or one, be sure to catch those on demand on LinkedIn, Facebook or YouTube. And if you’re more of a podcast kind of listener, catch all 23 episodes ahead on Spotify or Google Podcasts. And for direct delivery to your inbox, sign up for our blog at TechOnPurpose.net/blog. Today, we’re discussing #TOPcyber21 Best Practice number two, dark web monitoring. Please join me in formally welcoming our Who’s in Your Cloud cast for today. First up, we have returning cast member Sam Yip, who is the Channel Success Manager from IDAgent. Welcome back and thanks for joining us again.
Don’t forget we’ll be releasing a new episode every Tuesday, starting today 10/20/21 through late spring of 2022 with brief time off for holidays with family & friends. We’ll also follow each Tuesday episode release with subsequent Wednesday, Thursday, and Friday posts highlighting our (3) contributing solution partners from that week’s episode. We hope you’ll find this an immersive, hopefully simple, educational and enjoyable experience. So how do you tune in?
To easily follow the journey ahead we’ve diversified your access options to all (23) of our coming episodes. You can follow long here on our blog, or by any of the following methods:
- Email Newsletter: sign up at techonpurpose.net/blog and have each episode delivered directly to your inbox when released.
- LinkedIn: follow here
- YouTube: follow here
- Facebook: follow here
- Podcast: follow here
Buckle up – it’s time to hit the road to #secure, reliable, trusted technology!
Read Transcript
Welcome back to Who’s in Your Cloud, 21 Steps to Secure, Reliable, Trusted Technology. I’m Lauren Lev, Marketing Manager for TechOnPurpose and this is Episode 3 Complex Passwords and Password Management. Matt, I know it’s the first week of November, but this is clearly one of our more scary cybersecurity topics. So it seems only fitting a way to honor the close up of October’s National Cybersecurity Awareness Month. Last week, we were joined by our partners from LastPass, IDAgent, OrbitalFire and Keeper, we took a deeper look into the scary reality of the dark web, and how malicious actors use this marketplace to trade in compromised credentials and identities. And that’s why dark web monitoring is number two on the TOPcyber21 best security practices. So, if you haven’t had a chance to check out the previous episodes, catch those on demand on LinkedIn, Facebook, or YouTube. And if you’re more of a podcast kind of listener, catch all 23 episodes ahead on Spotify. Also, for direct delivery straight to your inbox, sign up for our blog at TechOnPurpose.net/blog. Today, we’re jumping into TOPcyber21 best security practice number three complex passwords and password management. As someone who previously used to use only a slight variation of the same password across multiple platforms, including my bank accounts, since I was 12, I’m clearly guilty of falling short on this highly risky practice. And clearly I still have lots to learn from our cast of trusted partners. Although I cannot believe I just admitted to our panel of cyber experts that information about my shoddy password management skills, please help me in formally welcoming our Who’s in Your Cloud cast for today. First up, we must be doing something right because we have a three time returning cast member Sam Yip, who is the Channel Success Manager from IDAgent. Welcome, Sam. We’re glad to have you back.
Samantha Yip
Thank you for having me back, Lauren and Matt.
Lauren Lev
Yes. We have returning VIP cast member Patrick Chen, the Solutions Engineer from Intelisys. Welcome back, Patrick.
Patrick Chen
Thanks for having me.
Lauren Lev
We also have Sid Castle, LastPass Channel Evangelist. Thanks for joining us again, Sid.
Sid Castle
Very happy to be here.
Lauren Lev
And on the other end of the lineup, please join me in welcoming first time cast member Marcia Dempster , Senior Director of Channel Sales from Keeper. Marcia, it’s good to have you and we promise to go a little easy on you.
Marcia Dempster
I appreciate that. But I will not go easy on you for your same password over and over again.
Lauren Lev
Oh, I know. I know.
Marcia Dempster
Thank you for having me. I’m excited to be here.
Lauren Lev
And last but certainly not least, TechOnPurpose’s very own Founder and CEO, Matt Tankersley. Well, Matt, why don’t you take it away introducing complex passwords and password management? What’s the big deal about it? And why should our listeners even care?
Matt Tankersley
Thanks, Lauren. As you might imagine, we get lots of requests to reset passwords. And we regularly evangelize the need for complex passwords and ultimately, password managers, right. And it’s real easy to get overwhelmed with the number of different systems we all have to access daily across multiple devices, right? But where we used to think, hey, I can make this simple and just use the same password everywhere that logic just does not fly in today’s marketplace, where we have bad actors who have their own marketplace for selling and exchanging our credentials. So, here’s the good news, right? One, we’ve got a lot smarter people on the panel here than me right to talk about this today. And number two, it’s really not that hard, guys, it’s really not that hard to manage complex passwords. And that’s part of what we’re going to find out from our amazing cast and solution providers that are here with us today. So, how about we go ahead and meet our cast for the day, Lauren?
Lauren Lev
So clearly, this is a vital topic and no doubt why it shows up so prominently in the top three of our TOPcyber21 Best Practices. Let’s take a quick moment to introduce our cast to the audience. Starting with our first time participant Marcia Dempster , please tell us briefly who is Keeper and what is your role there.
Marcia Dempster
Yeah, love to. So, Keeper is an Enterprise Password Manager. We also have a whole bunch of different set of features that enables dark web scanning, dark web monitoring, automatically changing your passwords, autofilling, just really overall keeping your organization or yourself or your family protected by using complex encrypted passwords. My role here, I’ve been here for about a year. In my former life, I spent a lot of time in the reseller space, so an attack for 9000 years. But here at keeper, I lead our Channel Sales team as well as our MSP practice. And it’s, it’s been quite a journey, I’ll tell you that.
Matt Tankersley
I hope I look as good at 90 as you do at 9000 years.
Marcia Dempster
A lot of work done, doing a lot of work.
Lauren Lev
Alright, we have Sam Yip, introduce yourself and IDAgent.
Samantha Yip
Sure. My name is Samantha Yip, and I am with Kaseya IDAgent. And we are a software company that provides security software backup solutions as well as management software for our MSP community. And of course, one of them we’ll be talking about today is a password manager.
Lauren Lev
All right, Patrick Chen, tell us about Intelisys and what you do for them.
Patrick Chen
So Intelisys I think a lot of the people listening here that heard me last time I said it before, they heard it before about Intelisys is a master distributor of a lot of different types of technology services. So, one of the one of the pillars that we have is actually security as a service and password management solutions, is part of it. Actually, Sid is a, and Last Past they’re in our portfolio as well. So, we do work together quite a bit from time to time. So, I am a Solutions Engineer at Intelisys. I’ve helped out a lot of our partners and our customers kind of assess what problems they’re having and try to align them with the right solutions. So, we have a big team. I’m not the only solutions engineer. In fact, I think you guys had met Ivan Paynter, our Cybersecurity Specialist a couple episodes ago, also available as well. So thanks for having me again.
Lauren Lev
All right, Sid, introduce yourself and LastPass.
Sid Castle
Right, Sid Castle, I’m the LastPass evangelist over here at LogMeIn. We’re all about identity as a service, Password Manager, Enterprise Password Management, Single Sign On, MFA, all those different tools. The reality is my role is to bring you from a dumb ass partner to a smart ass partner. Now I understand how these tools work for you. And as Lauren and others have mentioned, I have 350 credentials. I only actually know two passwords today, you need a password manager to help you, will encrypt, salt, hash this data, and we’ll go into much more detail later.
Lauren Lev
And it’s so awesome to have all of you guys here. Thanks again to our returning cast members for your commitment to sharing the journey with us to secure, reliable, trusted technology and sharing with our audience. If you guys are ready, it is time to dig a little bit deeper. So, let’s turn it back over to three time returning cast member Sam Yip from IDAgent. Sam, we’ll talk about your team’s approach to the topic in the next round. So, for this round, let’s talk about the statistics and scary stories around the need for complex passwords.
Samantha Yip
Yeah, sure. I mean, I have scary statistics for us all and I’m sure the entire panelists have heard scary stories themselves. One of the first ones I’ll bring up is that users in general the like login 10 plus applications a day, right? That’s a lot of applications that users are logging in on a daily basis just to kind of get their daily work done, right, or for their organization, not even to mention the personal passwords. And according to research, about 51% of individuals, they reduce their pack, on average at least five of their passwords, right. So that is, let’s say a couple of passwords a user across all 10 of these applications that they are using for your organization just to kind of get the work done. And in our previous episode, we talked a little bit about exposed credentials that are being sold in the dark web that are causing these major breaches. That’s why we really do need to look at, you know complex, complex password management as well. Because we’re not going to, you know, help your users organize their passwords or create these complex passwords. They’re just going to use the same ones or a couple of you know, a couple of variations of those passwords, just like Lauren did for, you know her banking or everything else. They’re gonna do the same thing for your organization. And when a breach occurs with one of those applications that they’re using on a daily basis, that information gets immediately leaked to the dark web and it’s being sold. We see, we have seen this in the news. The Colonial Pipeline, you know disaster a ransomware attack and the JBS meatpacking disaster, that all came from credentials that were being sold, right? They took it easy password that they found and it worked. And it still worked. And it wasn’t turned off. And that’s how that, that whole east coast disaster happened.
Matt Tankersley
This is real scary stuff, guys. It happens every day. And you don’t have to be a giant pipeline to be victim in this. In fact, I think some of the statistics that we may or may not share today are just that very thing.
Lauren Lev
Patrick, you’ve had a very diverse background as a power user, MSP, and now in equipper of MSPs in the channel. What are your thoughts on the statistics surrounding complex passwords?
Patrick Chen
Well, I think this conversation has two different angles to it. One is the individual user’s perspective, right? You have on average now, because everyone is using some form of like SaaS solution, cloud services. I think, I don’t remember if it’s still up to date. But I remember reading at one point, you know, most of us have about 70 to 80 different passwords, that we’re trying to juggle, right for different platforms. And on top of that, you know, when you’re looking at some of the most common passwords that are still utilized today, because of all the different complexity requirements that are either set by the individual organizations that we’re working with, or even by our own organizations. Like, you know, a certain password length, needing special characters, how often you have to actually reset the password, which is, that’s actually an argument these days, they’re asking, they’re wondering if it’s that good of an idea to require us to have to reset our passwords every couple of months, because that encourages the use of similar passwords, where we just add another number or add another exclamation point, whatever the situation is. So, that’s why I think, you know, from a user perspective, it makes a lot of sense, because we’re juggling all these things, we are not as smart as we think we are. And with that, with the fact that technology is improving as well, the the ways that people can crack the passwords are faster, they’re more efficient. And we definitely, that’s those are some of the reasonable reasons why we need it now. Now you have the user side, and the other side that I was alluding to is the administrative side, right? If you are an MSP, if you’re an IT organization and you’re trying to manage all the different systems, not just your your network devices, but also your managing passwords for the users, it can get really complex. And as an MSP speaking from my own personal experience, when you are the IT department for all these different customers, with all these different environments, you have to have a really good way to make sure that not only are you protecting yourselves, but you’re protecting your customers environment as well. And just simply being able to keep track of all the passwords for across all of your different customers is a monumental task. So, that’s, it’s definitely a good good reason why you want to use a password manager.
Lauren Lev
Marcia, from Keeper, you’re up. Your world is all about passwords and password management. So, clearly this vital tool and mitigating cyber risk has created a marketplace for organizations like Keeper and LastPass. So, what are the realities and statistics that keep your team focused on keeping our mutual clients equipped and secure with complex passwords?
Marcia Dempster
Yeah, good question. I mean, there’s so many, I think everyone’s mentioned it so many scary statistics that we can talk about. One that we use a lot here at Keeper is that 81% of data breaches are due to weak or reused passwords. We all heard about the SolarWinds attack, intern that reused a password, which I think was password 123. Um, you know, we hear about ransomware every day, if you’re working in the healthcare field, if you’re working with financial people or anything with compliance needs, if you are not using strong passwords, you’re putting yourself and your company at a great risk. We’re seeing a lot more brute force attacks, where you know, a hacker or an organization is just continuing to try to crack passwords. And it can take minutes, hours, days, but it’s consistent, persistent brach. You know, the influx of cyber attacks that we’ve seen during the pandemic alone. I mean, how many hospitals and healthcare systems have been put at risk because there’s been a ransomware attack? And one thing that Patrick mentioned that I think is interesting is, you know, the concept of requiring employees at an organization to consistently change their passwords. That is kind of, you know, annoying as a user, it’s like every two weeks to change your password. What a password manager actually allows for is it will do that for you. And you can make that password as difficult or as easy as your organization is required and your admin can kind of set those parameters, which is a great place to start, especially considering, you know, the average cost of the data breaches is now over $7 million. So, it’s, you know, can your company afford to pay a ransomware? Or the insurance payout of $7 million? Like, probably not. So, those are my scary statistics for you today.
Matt Tankersley
You know, you know, guys, I say this often to our clients, I don’t know, a single, I think I know one password, right. And you can see, it could be argued that that in and of itself is a problem. But if it’s designed, right, you’re using the right techniques. That’s, that’s good, right. And, but I like to tell my clients all the time, if I can’t remember the password, how can the bad guy remember the password, right? And so I tell you, I’d be lost without password management tools. And we’re so grateful for both of your, all three of your companies that, that do what you do.
Lauren Lev
So, Sid, your team at LastPass has been at this for quite some time. Last week, you shared some fabulous insight on the scary realities of the dark web cyber criminal marketplace. Can you share with our listeners today, what are the complex password statistics that drive your team to develop the solutions you offer?
Sid Castle
Because you mentioned the dark web and everything that we’ve heard, my wife and I got an email alert that T-Mobile had been hacked, obviously. And she got a little stressed about this. And I, you know, I smiled and said, why? I said that password is unique. It’s the only one that’s out there that’s using that same password. We use a different password in every single site. As Matt mentioned, the name LastPass actually refers to the last password you ever have to remember. I know two, my personal and my professional aspects. There’s schemas, FBI talks about how you do that, certain length, different things, certainly hard to crack. But that’s the thing that we focus on is the fact that these passwords need to be unique and different. And Lauren, that’s where I’d love to teach you and work with you personally and professionally. Patrick mentioned personal passwords, if somebody cracks that they could use it professionally, so it can be moved across. So everything needs to be unique and different. We salt, we hash it, and then the last piece about that is this: Why are we using passwords? The next phase, and this is what your cyber insurance is going to require is a multi-factor authenticator. A device like my cell phone, when I go to log in it says, even if they break Matt for my passwords, if they don’t have my face, they don’t have my device, and they don’t fit the geo parameters I’ve set, that multi factor authenticator will stop them and say, it’s not Matt, it’s not Sid, it’s not Marcia, it’s not you, Lauren, it’s not us. That’s the stage we need to move beyond just the password. That’s the start, but so that’s what our team is doing. We’re constantly developing this and making a total solution, this total identity access management solution to protect you.
Patrick Chen
Yeah, Sid brings up a great point, you know, it’s password managers that are fantastic, which is why we’re talking about it today. But if you still have to remember one password, there’s still that vulnerability and goes back to security where they always say the weakest link is between the chair and the keyboard, right? To have that additional multifactor authentication is helpful, because I mean, if you think about the way people create passwords, or let’s, let’s look, let’s take it away, take a look at the way hackers try to do it now, right? I think Marcia, you had mentioned brute force attacks, you know that, that’s definitely one way to do it. But if it’s only a web based, right, a lot of times now there are security features in place where they say, Look, if you try five or six different one passwords, and they’re all wrong, they’re gonna lock you out. But some of the more dangerous stuff comes in the form of like offline cracking, where I think someone had mentioned ransomware, you’re already with the, the, the attackers already in inside the environment. And now even if you have passwords that are hashed right, they could do like, they could do some spidering techniques, they could do stuff like rainbow table attacks, and just find ways to really, really dive in and uncover what those even those those hash passwords look like. And it wouldn’t be possible if it wasn’t for the fact that our technology keeps on increasing. And so their technology keeps on increasing, right? Before, we thought we were clever by saying if you turn an E into a three or an I into a one, you know, it’d be super clever. Now, it’s they, they know all those combinations, you know, they can use a dictionary attack where it’s automated and they try every single possible combination that’s out there to see if they can break that particular password.
Matt Tankersley
Yeah, you know, and it’s sad I almost didn’t bring this up, but I have to do it, right? We see these questionnaires that go around social media and you answer 40 questions. Like, what was your first car and did you graduate before this year and what was the name of your first pet and what’s your favorite kind of pie? Right? And I know, I literally saw a dear friend post that even today. And the reality is it’s fun, right? It’s fun stuff. And it’s fun to see other people’s answers. But I have no doubt that it was quite frankly, malicious people that came up with this idea in the first place. Because if you don’t think that that data is accessible and usable by bad actors to solve this one problem alone, then you’re kidding yourself. I’d stay away from those things.
Sid Castle
Well Matt, Matt that’s. Yeah, Matt, that relies on the idea that when we create a password personally, we’re going to try as you said, I need to remember my one password. So, I need to do something key on things that matter to me and you use different ideas. Jimmy Fallon had a neat bit that was on YouTube that was showing on his show, where he had that man in the street or woman in street asking questions, and they said, Hey, Matt, what’s your grandmother’s last name? What street did you grow up on? What was your kindergarten school? And then they’d ask a bunch of other questions and joke with you and say, Hey, Matt, if you were going to create a password, how would you do it? And you say, well I’d use my grandmother’s name and the kindergarten I went to. And all of a sudden, the guy goes, um, and she goes, you might want to change that, because you just told your password on national television. It’s that same idea that so we need more. Passwords are incredible and we do a great tool with it, to manage it. But you need more, as Patrick said, so let Keeper, let LastPass, let Kaseya work with you to solve this. I can talk about this subject for all week. I could be at channel partners for all four days talking about it because I’m passionate this is something that we all worry about. We’ve all had these breaches and issues. Let us help you, let these companies you’re seeing here help you become the smart as a service partner, be the smart ass. And we can really help you manage this to protect you and your customers.
Matt Tankersley
You know, we’ve said in every single episode, if you’re not adopting even the simplest, the best security practices, it’s not a matter of if but when. I’ll say it again, it’s not a matter of if, but when you’re going to experience probably a devastating compromise, right? And if you think dealing with complex passwords is a pain, try dealing with the fact that your entire company shut down now and ransomware, or something like that. But I’m anxious to continue the conversation, and let’s learn some more about each of your solutions from each of our cast members here today.
Lauren Lev
Listeners, as a reminder, our cast today is representing IDAgent, Keeper, and LastPass, which are three of our TOPcyber21 solution partners for complex password management. From each of you, let’s hear more about your company’s unique solutions to the problem. And I’m curious if there’s any way for measurable ROI on the benefits of complex passwords and password management tools that our audience should be aware of. So, this time we’ll start with Sid. Sid, what’s unique about LastPass’ approach to CPM and any thoughts on CPM ROI?
Sid Castle
Well, you know, we’re unique in that we’ve been doing this a long time, we’ve seen it, and we’ve done it, we’ve been around this. Everything is about a holistic solution. We want it to be seamless, we want it to be frictionless, so you just need you need to make sure to focus on personal and professional. Because everything needs to be seamless. That way, if you’re separated professionally from the personal side, you can still access your bank account, Facebook, and move on. You know, that’s where we’re focusing is making this easier for you to be able to do your job and let IT management deal with onboarding and off boarding and protecting you. So, again, as we’ve mentioned before, you could do this direct, you could do this as a partner, you could do this as managed service. The managed service side gives you that ability to do single pane of glass and administer your customers. And that’s where I think our strength really lies is that we’re easy to use. It’s frictionless and it’s very intuitive.
Lauren Lev
Thank you Sid. So, Marcia, you’re up what’s unique about the Keeper CPM solution and how can we help our listeners to measure CPM ROI?
Marcia Dempster
First things first, Keeper manages your passwords so that you can get back to doing what you do best. So, it takes out a lot of that, you know, having to remember all the different passwords, having to change it all the time. You set that up so that it’s automated, or you can set it up for your organization if you’re the admin. We, what kind of differentiates us is once you log into your vault with your master password, the vault itself is encrypted, but so is every single record. So, your bank login, my Nordstrom login, any type of different login that you have, each of those records is encrypted. So, we follow very strictly a zero knowledge and zero trust security policy that has now become federally mandated. We’re pretty close to finalizing our FedRAMP certification, so we are in Gulf Cloud. So, that’s, that was a big deal for us and we’re excited to do more in the public sector, since it’s becoming such a big thing and we’re hearing about it in the news. And you know, the last thing you want is your government’s information about you to get out, to get hacked, to get leaked. So, that’s scary. We also have a dark web monitoring tool, we call it BreachWatch. So, that is constantly scanning the dark web to see if it can find any of your passwords. It’s interesting, because they’re still encrypted. So it’s using ciphertext and we still, I can’t see any of your passwords. I couldn’t see your password if I tried. So, we do a lot of SSO integration. I think Matt mentioned it earlier about having multi-factor authentication. We partner with a lot of firms like Duo, just to make sure that that integrates with our product as well. Just to make it easier if you’re using Okta, if you’re using, you know, any kind of like Microsoft platform, any Amazon platform, any kind of Single-Sign-On that you’re using, we can integrate with that to make it a little more seamless and have it be a lot more secure. And then your admin can enforce different policies. How often, as Patrick mentioned before, how often do you have to change those passwords, it can do it automatically, they can make it a certain length, or different characters, and it’ll show you how weak it is or how strong it is. And you can also do IP whitelisting, things like that, so that’s just a few of the cool things that I think we do here.
Lauren Lev
Sam, tell us about IDAgent’s approach to CPM? And are there any thoughts that you can share about the ROI benefits of IDAgent’s solutions?
Samantha Yip
Well, absolutely. I mean, our solution is actually from our IT Glue family member and with MyGlue. Really think the tool that we offer is ease of deployment from an organization’s perspective as well as ease of use for the user. So, the tool itself that we offer, you can actually put in your organization’s passwords as well, it will also help you generate passwords for it so that you don’t need to know those passwords. And we’re generating, you know, 28 plus kind of characters in those passwords, where user does not have to remember them. And it’s, Password Manager remembers it for you, and it’s easy for them to kind of copy and paste it or even use a browser extension, so that they don’t actually have to ever input anything themselves. As well as, having an opportunity and a feature that allows you to also share passwords with your colleagues. Say, you know, there’s an Amazon company, Amazon account that you need to access or maybe some other marketing tools that needs to be accessed by multiple people, that can be shared. What’s great about the tool as well is there is an audit log, so there is going to be if you do need to adhere to any sort of compliance, there is an audit log trail for any of those passwords. And if you have the admin privilege, you can also change any of these passwords that are in these vaults, but it also gives them your users within the organization a personal password management as well. So they can, kind of a, kind of a work perk for, for using the tool that is the solution that’s given to you by your company. In terms of an ROI benefit for this, I mean, aside from a centralized place to manage your passwords, as well as create and generate those, those complex passwords, you know, it’s the statistic is that users spend about 10.9 hours in a year just resetting and inputting passwords, right. So, I mean, that’s gonna save in terms of overall productivity value for organizations that they don’t even have to do that, right. I mean, you have that easily it’ll set it for them so they don’t have to input it, they don’t have to create, they don’t have to reset nothing. So, that should also give you that return. So, it’s hard to put a dollar value on that, but in terms of just cost saving time, 11 hours a year, it’s pretty significant.
Matt Tankersley
Go ahead, Marcia.
Marcia Dempster
I was just saying that’s such a great point. And even if you think about you know, your your help desk, within a corporation, like how many hours are they spending, resetting my password, if I needed that to happen? You know, like how many people are calling the helpdesk every day for simple things like resetting a password. So that’s, that was a great point, Sam.
Matt Tankersley
Yeah, absolutely. I think that’s what we’re looking for. And I’d tell you, I didn’t know. We came to this entire series, not just hoping to educate our marketplace and prospects and clients but we were expecting to learn along the way as well. And I’m really grateful for that one, Samantha, because that was the one I was looking for. I think we could Marcia, we could quantify that real quick if we know it’s 11 hours and if we know we have 100 employees, we can do some math on what 11 hours is worth times 100, right?
Marcia Dempster
Absolutely and then you cross it over into your personal life. Like, if you have children or older parents and you’re doing that for them, you know, that’s extra time out of your day that I’m sure none of us have. We actually have a Keeper if you are a business user or an enterprise user, we offer a family plan. So, it gives you five additional licenses to push out to your, you know, whether it’s your parents, your kids, or… It’ll save you some time is really the point of that. So it’s, it’s so true, though, how many hours are we all wasting having to reset all these crazy passwords? Like, let’s just not do that.
Lauren Lev
Especially for people like y’all who are cyber experts, I’m sure you’re the cyber expert of your family. So, think about all the passwords that you’ve had to reset for everybody.
Marcia Dempster
Oh, Lauren, you know, I got my mother setup on Keeper so she leaves me alone. Like, just, I can’t handle you. Like, here use this tool instead.
Patrick Chen
I do want to say, I want to point out something, you know. One, you know Intelisys, we do distribute, I think all three of these solutions, whether directly or indirectly. So, I’ve had the luxury of being able to work with all three of these to a certain extent. And I think one of the common things you’ll find across these platforms is one, you don’t have to only just utilize it for passwords, right? If you have other confidential stuff, like credit card information, instead of sending it in an email to your employee, right, you can put it in there if you want. On top of that, from an administrative perspective, if you’re just trying to onboard or off board somebody, it’s very easy, right, to eliminate access just with a quick password change, because you can just, you know, address all those different applications that they have access to all at once. The other thing too, that I think is also, you know, very common that you’ll you’ll notice across these solutions is you can segment users, right? If you only want certain users to have certain access to applications, you can do that. So, you can really limit and basically say, Look, if you’re not allowed certain applications, you’re not even going to get access to it, right. So even from a security perspective, you’re kind of isolating the risk and minimizing the risk from that perspective. And then lastly, the most important thing that I think is great about all three of these platforms is the user experience, okay? If you look at the rules, right, that you want to have in place for your users, you want as much complexity as possible, you want it to be as long as possible, longer, the better, right? Because now they’re using machines to try to crack these things. So, ideally you want to have a password manager like these solutions that will generate a random, long, complex number, password for that matter, that’s a combination of a bunch of different things that has no relation to any real lot, real-world word, or phrase, right? And if you think about that, if the users themselves also have to create and follow the guidelines of not using the same password for every application they have access to, it’s gonna be impossible to memorize. So having a platform like this, where it’s easy for the users to generate a password, so they don’t have to come up with it themselves. They can even go to a particular website and have the password manager apply this complex password on their behalf. It makes it so much easier for the user to say, You know what I want to use complex passwords I want, I’m buying in to the company policy of trying to protect the, the corporate data, you know, utilizing this platform.
Sid Castle
Hey Patrick, and Matt I just wanted to add on that real quick. I apologize, I kind of skipped over the ROI of CPM a little bit ago. But as everybody’s been saying, these tools are incredible. And I admit I want to scream “me too! me too!” every time the other vendors talk. These are incredible tools and what they’re saying is incredibly important. Hey, the ROI. I was an IT manager back in the day, and I used to joke, press one for passwords, press two for everything else. That’s how much it was, it was part of my day onboarding and offboarding. As Patrick said, these tools are incredible. We federate with other tools, and so if you get knocked out of one tool, because IT does- I used to hate Fridays, the manager, the owner would walk up and knock on my door and I’d say I’m not here. He goes Sid? I go, you let Patrick go today, didn’t you? And he goes, Well, yeah, you know, I like to do that on Fridays. I go, it’s date night, you need to call my wife because I’m not going to dinner. And I’d hand my cell phone to him because it’s gonna take me three hours to deep provision Patrick and offboard him because we got to make sure he’s out everything. Today, I’d lap. I’d knock you out of Active Directory and LastPass and walk out the door. And on Monday I could reprovision something if needed. But this is all about friction and we got to take that friction away. The average user spends about 37 minutes a month on passwords. If that knowledge worker makes $25 an hour, we’re talking about $15 a month just for password time wasted. That could buy all of our solutions easily. Then we talk about protection. We can go in and look at security scores and then the truth is this, password hygiene or security hygiene, that’s priceless. That’ll save all these different processes. So, you tie in all the different identity access management solutions. That’s priceless and that’s your ROI. Thank you.
Matt Tankersley
Man, that’s fabulous. That’s so fabulous. That’s exactly what I was hoping to get out of this that I didn’t have. And I knew with a bunch of smart folks in our room, we’d be able to learn some things. And Lauren, you know, there’s a reason why Patrick is on the VIP list here. Because, by the way, Patrick, we were coming to you next. So, we can skip over that whole section because he just did his thing, which was, which was really awesome. And I have a, I have a crazy confession for everybody. And if you know me, know you won’t laugh at this, but if you don’t, you can have a chuckle. So, I actually use all three of these products every day, every single one of them. And you know, in our goal to be our clients trusted, you know, partners, it’s imperative that we as a team are familiar with all the solutions that we offer. So, my primary motivation is, hey, I need to be able to answer questions about Keeper if a prospect or a client asked me or IT Glue, or My Glue, LastPass, right. But if you guys ever want intelligence on how you know where each of you has strengths or weaknesses, I’ve got a little intel on that because-
Marcia Dempster
Oh I love this.
Matt Tankersley
Each of you has amazing features that are common. And then each of you has some unique features that I wish the other one had, you know.
Marcia Dempster
It’s interesting, though, like think about it. A few of us on here are competitors, but I think what you’re seeing is we’re all incredibly passionate about this topic. And it’s like the easiest part of cybersecurity is securing your passwords. Like, it’s that easy. Like, save yourself the trouble and the drama of getting your stuff breached.
Sid Castle
I don’t care if the part if the partner and the customer aren’t using any of us. Use one of us. Yeah, that’s the thing. Use one of us. Now, as Matt said, we’re like pickup trucks and I’ll be, do the guy thing. Dodge, Ford and Chevy, they’re all great, but one of them’s gonna feel a little better for you than the other. You might have a family allegiance, different things. That’s where these all come in and so that’s the kicker. But if you’re not using this view of saying, I got spreadsheets, I got keychain I got, God forbid a notebook. Oh, oh, please do something because we want you protected.
Marcia Dempster
Totally.
Matt Tankersley
Well, listen, this was a fantastic session, we promised sassy and savvy and we promised focus, and I think we did a good job of that today. Obviously, we’ve got a lot of areas to focus on. And let me say this, it’s not just about complex passwords. Complex passwords are not the silver bullet to keep your organization and livelihoods from being destroyed, quite frankly, by malicious actors. It is vital, it is not an optional piece of the pie. It’s a simple way to get started. So with of course security awareness training, you know, we talked about that recommended best practice number one, we’ve talked about dark web monitoring number two. Those are equally critical. But to jumpstart your onboarding into secure, reliable, trusted technology, you gotta take all three of these things very seriously. And guess what? They work in harmony with one another. And we already breached MFA today, that’s coming up next week, by the way in our IAM conversation. So, let’s go around the room, and from our cast and what more can we say to convey the urgency and motivate listeners to follow these best practice recommendations for complex passwords and password management?
Lauren Lev
Marcia, do you want to start us off?
Marcia Dempster
Sure. Yeah. I mean, I think that we’ve all kind of hit it out of the park here. This is such a such a crucial part of a larger cybersecurity strategy. It’s just not worth putting your organization or yourself or your family at risk. You know, managing your passwords is time consuming, it’s cumbersome. And it gets a little old, because you’re like, how many dogs names can I use? And you certainly don’t want to be the person writing it in the notebook. You know, like Sid said, but it’s, it’s so it’s easy to learn it, it’s easy to get adoption for it. It’s worth looking into for your organization’s and for you just as a person in this very technical and remote workforce world that we’re living in lately. And it’s important to look at, as Sid mentioned, like what fits you best and what’s the, what’s the right solution for your organization? What are people going to adopt and really like take it on and use it and it’ll prevent you from getting breached, which is important. Something that thankfully has never happened to us is been breached. So, yay. But yeah, those are my thoughts. And thank you again for you know, for having me on here. First timer. Longtime listener, first time caller. So thanks for having me.
Lauren Lev
Yeah! You did so good. Thank you. Sam, do you want to share?
Samantha Yip
Sure, I think yeah, I think the panelists did great job. Exactly. I’m going to reiterate and say, you know if, if any one of our password managers are great, I mean, I’ve, I’ve looked at all the password managers kind of out there. But if you don’t give your users a password management solution, they are going to create their own and what they create, it’s going to be scary. You know, like those documents on their desktop as password, or you know, handwritten, you know, on a piece of paper kind of passwords or sticky notes everywhere. So, give them a solution. Don’t trust them with, you know, managing their own passwords, don’t trust your users with creating complex passwords. Give them a solution that will be easy for you to deploy, easy for the user to use, and a tool that they would actually want to use every single day, and this would definitely be a solution that would help in preventing any, any security breaches.
Lauren Lev
Sid, would you like to go next?
Sid Castle
Sure. Sure, as everybody said you know, this is all about protecting you. Passwords scary, you know, we could use things like Single-Sign-on to really manage and control that. The MFA to break away from passwords, but you need a password or security hygiene, that’s what this is all about. Is that you need to make sure you’re taking care of yourself, your business, you know, we don’t lock our doors and leave our windows open. We need a control that manages all that together. So, really look at something like this. Most of our partners here, I believe have free versions that you could use personally, then you can link your professional side and then families is a benefit. We heard a similar thing from Keeper, we have that at LastPass. I manage my families passwords. I have those shared folders that I put credentials and birth certificates, different things the kids go for sports so I don’t have to dig around and find the birth certificate, the copy is there. Patrick mentioned, shared folders, we have marketing teams shared folder for marketing you put last, you put the password for LinkedIn, Facebook, and other things in there, and we hide the username and password. You never see it. You’re given access to the folder and we can manage who comes and goes so we have a report. So, all these are tools that you need to use and it’s all about a security hygiene and that’s the key thing out here.
Lauren Lev
And as our VIP partner, Patrick, will you close us out?
Patrick Chen
Yeah. It’s tough going last, I think a lot of all the good talking points were already addressed by this excellent panel. I think the only thing that I want to leave with the users as they’re kind of digesting the information today is I wanna go back to the ROI conversation, you know, a lot of the ROI that we talked about a lot is on the operational side, right? And I get it because, you know, everything is expensive until, you know, you get breached, right? And then all of a sudden, it seems cheap in retrospect, but there’s also other components of it too. If your password hygiene, as Sid was saying is poor, and you get breached as a result, right. The damage that’s done to the company isn’t always just monetary, right? Certain we hear about that, right? We hear about, you know the major breaches and then there’s fines, right? Sometimes it’s regulatory fines beacuse, you know, maybe they weren’t compliant for whatever reason as a result of their poor password hygiene. But also, it’s a loss of brand trust, right? Your brand recogniton is damaged as well and sometimes, and that part is sometimes tougher to calculate, you know, the monetary damages, it’s hard to calculate the value of that. But that is should be something that your customers or your company for that matter, should really be considering when you’re evaluating something as simple as a password manager.
Lauren Lev
So, Matt, do you have anything else you want to add before we close out?
Matt Tankersley
I don’t. I’m the dumbest guy in the room and you guys are amazing. So, thanks for doing what you do and partnering with, you know TechOnPurpose and our partners to keep our clients safe and secure.
Lauren Lev
Well, that was a fabulous session, you guys. And apparently, you all are going to happy hour without me next week, so think about me, take a shot for me. I’m going to be very salty about it. Thank you all for being here today and for your numerous ongoing contributions to cybersecurity awareness. Hopefully, our listening audience has learned as much as I have today, and we all have a better understanding of how vital complex passwords are and how easy it can be when we use solutions like those from LastPass, Keeper, and IDAgent. Listeners, if you’re interested in learning more or about getting underway with a free trial of complex password management technologies from our solution partners, send an email to . Again, and don’t forget you can sign up our free cybersecurity assessment by visiting whosinyour.cloud today. Whosinyour.cloud for the free cybersecurity assessment. Again, I’m Lauren Lev, Marketing Manager for TechOnPurpose and coming up next week as you guys have already mentioned, we have Episode 4 Identity and Access Management. Patrick Chen, actually next week, we’ll have your partner in cyber crime prevention, Ivan Paynter, with us and I for one am looking very forward to having him back.
Matt Tankersley
So, special thanks to all our subscribers and viewers. And if you didn’t pick it up, there may have been some edits there and there’s a reason why I’m closing out and not Lauren, and it had something to do with a password, imagine that. Alright, so special thanks to all our subscribers and viewers for following the Who’s In Your Cloud, 21 Steps to Secure, Reliable, Trusted Technology journey. Remember, you can catch every episode of Who’s In Your Cloud by following TechOnPurpose on LinkedIn, Facebook, Youtube, and Spotify, or sign up for our blog to have episodes delivered to your inbox weekly at techonpurpose.net/blog. Thanks for joining everyone. I’ll see you next week!
Subscribe to our blog to get episodes of “Who’s In Your Cloud?” delivered direct to your inbox weekly.



















