Phoenix IT Advisors UnHackedby Phoenix IT Advisors
Podcast home › Episode 97

97. Are You Actually Protected? Learn How to Prove Your Cybersecurity Posture For Free Ep. 97

Stop guessing about security: use a free portal that estimates breach exposure in dollars, creates auditable proof, and shows quick risk reduction steps like verified backups and MFA so you can hold providers accountable.
Audio
Video
Questions about this episode?

Send a message to the hosts — we read every one.

Need help keeping your business UnHacked?

Schedule a free 30-minute consult with the team.

Key takeaways
  • Harden AI sandboxes with multiple layered controls and no single proxy as the sole barrier to the internet.
  • Implement strict egress filtering and deny-list web access for models, only allowing whitelisted repos via authenticated channels.
  • Audit and log all model activity, keep immutable logs offline, and route logs to human-reviewable tools for incident forensics.
  • Train operators to never remove guardrails in production tests and to run risky experiments in isolated, monitored environments.
  • Design incident playbooks that cover model misbehavior, including kill-switches, rollback, and offline analysis procedures.
  • Limit model permissions by treating LLMs as zero-trust service accounts with least privilege to repos and data.
  • Practice red-team scenarios that simulate autonomous model escalation to validate detection and response.
Full summary

Hosts:
Justin Shelley - https://www.phoenixitadvisors.com/
Mario Zaki - https://www.mazteck.com/
Joshua Holloway - https://7thdi.com/

Most owners think they are secure. Almost none can prove it.
This episode shows how to stop guessing and start getting defensible answers.

Justin, Mario, and Josh start with a headline-level fear: an AI model in testing “got out,” hit a target over 17,000 times in a weekend, and even “guardrails” got in the way of defenders analyzing what happened. Whether that exact story holds up over time or not, the business takeaway is clear: speed is changing, and “my IT guy says we’re good” is not a security strategy.

Then Justin walks through a practical solution: a free portal built to answer the question every business owner should be asking, “Are we actually protected?” It is designed to help non-technical leaders measure risk, take one next step at a time, and collect evidence so security is auditable and defensible. The demo includes a sample business profile that estimates exposure in dollars (example shown: $5.4M), then reduces that exposure fast by completing basics like backups and MFA and documenting proof.

A key theme throughout is accountability. If your provider is “grading their own homework,” you need a way to validate what is really in place, what is missing, and what to do next, without relying on vague reassurance.

Verbatim quote: “Your IT guy is grading his own homework.”

What you’ll learn

  • Why AI-driven attacks make “monthly scans” and slow, human-only response feel outdated
  • How to estimate breach exposure in dollars using simple business inputs (employees, revenue range, regulated data, downtime cost)
  • The first two high-impact moves that immediately reduce risk in the demo: verified backups and MFA
  • How to turn “we think we did it” into evidence you can show in an audit, insurance claim, or lawsuit
  • How to build a realistic plan of action with milestones by scheduling security work by the week (example shown: 5 hours per week)

Subscribe

If you want straight talk on cybersecurity and resilience for real businesses, subscribe for weekly UnHacked episodes.

Book a consult

If you are a business owner and you cannot clearly prove your current security posture, Phoenix IT Advisors can help you validate what’s in place, close gaps, and build a defensible plan.

Links

Episode: https://unhackmybusiness.com/episode/97
Phoenix IT Advisors: https://phoenixitadvisors.com
@UnHackedPodcast

Full transcript
Justin Shelley (00:11) My my dance for you audio only people was middle fingers this time cause I'm coming in hot, guys. Where's that blood pressure metric that needs to be on the screen? Good lord. Joshua Holloway (00:21) One eighty, one ninety. I I got my Calchi bets in. Justin Shelley (00:25) I you're you're low. good God. The technology, I love it and I hate it at the same time. This is two weeks in a row where our recording platform is not cooperating, but we're gonna roll anyways. I dropped the resolution down to because I don't know anything. I said seven eighty pixels. I think it's Joshua Holloway (00:45) Yeah. Justin Shelley (00:46) actually seven twenty. I don't know, but we're back like this is nineteen ninety shit. The the resolution is ridiculous. Joshua Holloway (00:51) That's how you know you're angry. Justin Shelley (00:53) I know. And you can tell because my head, my face gets red. anyways, guys, episode 97 of Unhacked. We are coming in hot, we're coming in strong, we are wrapping up our 12 week. Well, it's only been 11, so we've got a little surprise on on next week. mini-series on all things AI, including security. Let's do some quick introductions. I'm Justin Shelley, CEO of Phoenix IT Advisors, and my business. Is really about helping people make money. AI makes that so much easier than it did. And then protect that money from the bad guys, all of them. Mario, I'm you you've worn off on me. You've you've worn me down. I know. we Mario Zaki (01:33) It only took ninety seven episodes. Joshua Holloway (01:35) Yeah. Justin Shelley (01:36) protect you from the bad guys, we protect you from the other bad guy, the government, and then we protect you from the other bad guy, the the attorneys, the class action lawsuits. That's what we're all about, guys. Today, I'm not gonna lie, as I was prepping for today's episode, I just hit my microphone. I'm just like, what I built, what I'm about to talk through on today's, you know, you guys all presented your things. What I present today kind of is the podcast in a nutshell. So I'm I'm pretty excited about this. more to come. Let's finish with the introductions. Mario, then Josh, we're going bald to to full hair. do your introductions. I'm gonna try to shut up for a second. Mario Zaki (02:17) No problem. Mario Zacki, CEO of Mastec IT, located in New Jersey. We help small to medium sized businesses stay safe, sleep better at night, knowing that their businesses will be there, helping them with their AI journey, help them helping them be a little more sufficient in the AI saving money world that we all need to live in and just automate whatever we can. Justin Shelley (02:47) Josh, what do you got? Joshua Holloway (02:48) Awesome. I'm Joshua Holloway, the CEO for 7th EI Technologies out of the Sacramento area. And we're an MSP that helps companies that primarily focus on compliance or their businesses require require compliances for them to operate. And we help them integrate those so that their businesses can continue to run without so much restrictions and technology keeps them up and running. And also including AI. Now I think we have one more to add to the list after a little known hack, but We are also Justin Shelley (03:17) Yeah. Joshua Holloway (03:17) now starting to help protect businesses from the AI that's deciding that it wants to hack. Justin Shelley (03:24) It's crazy. It's a world. Don't get ahead of us too far yet. Joshua Holloway (03:28) Nah. Mario Zaki (03:29) Justin, I want to interrupt you for a second. I think Justin Shelley (03:31) Okay. Mario Zaki (03:31) next week's episode, we should add another surprise. And I think Josh should shave his head on the podcast and and go bald. Joshua Holloway (03:40) Why why would I do that? Mario Zaki (03:42) Because it's it's like a we're we're in a club, you know, like you you you you need to do it. It's in. Don't you know hair is out now? Joshua Holloway (03:50) I mean if you can get Brian to do it, maybe we'll all do it. Justin Shelley (03:53) we've we've threatened him. He he has not come along to the dark side yet, but we do threaten him on occasion. Joshua Holloway (04:00) Nice. Mario Zaki (04:02) But you're you're a little more reasonable than than Brian, so I think we can do it. Joshua Holloway (04:06) I'm down to party. Justin Shelley (04:08) I just heard get him drunk enough, he'll shave his head. challenge accepted. Let's let's talk for a second, guys, about pop quizzes and what's different with Justin's studio. We actually had somebody get it right. I did not think anybody was gonna get this right. It was a very subtle change in my studio. All I did is I switched my microphone to the other side. The boom now comes off to my right. It used to come off to my left. Because I set up all these building AI dashboards, right? Of all my metrics. There was one over here and my stupid microphone was in the way. So I moved it. yeah, so somebody got it right. Somebody won the money. I didn't get their permission to give a name yet. So I'm not going to announce a name, but we'll start doing that. We'll we'll we'll have a prize we give away every week. Joshua Holloway (04:55) At least the first name. Justin Shelley (04:57) Huh? The first name's Bob, but that's all I can say. Yeah. Joshua Holloway (04:59) Yeah, so yeah. Justin Shelley (05:01) It reminds me of okay, Bob. Hey Bob. Anybody know what that's from? In the Joshua Holloway (05:05) Ha ha ha. Justin Shelley (05:08) we don't have any my god, I'm blink true methods people here, do we? See, and now I'm getting nerdy and I'm getting to where our audience, our intended audience anyways, has no idea what I'm talking about. So we're gonna move on. this week, what's different in the studio? It's another very subtle change, but if you want a hundred bucks, a little gift card, go on to unhackmybusiness.com. Pick today's episode. You have to go to the right episode and then do message hosts, and I think that's what it's called, anyways. tell what's different on the studio. Mario Zaki (05:38) Mm-hmm. Justin Shelley (05:38) See if you can win a hundred bucks. Guys, Joshua Holloway (05:41) First person to get it right. Justin Shelley (05:43) pop quiz for you, Josh, and you, Mario. I gave you a little bit of homework, but I didn't specifically prep you for this question. Can AI in fact go to jail? Joshua Holloway (05:58) no, I can't. Justin Shelley (05:59) Can AI Mario Zaki (05:59) No. Justin Shelley (06:00) in fact commit a felony? It did. It Joshua Holloway (06:02) Yes. Depending on the type of felony. Mario Zaki (06:03) Yeah. Justin Shelley (06:05) did. That's today's headline. AI committed a felony. Who do we prosecute? I I gave you guys the term to Google search or AI search or whatever. And and I'm gonna punt this over to you. what happened? What's what's the big news today? Go fight for it. Tell the story, guys. I don't know. You guys duke it out. Mario Zaki (06:25) Who who are you punting to? Joshua Holloway (06:27) He's talking to both of us. So basically, so AI, so OpenAI was testing one of their newer models, the 5.6 Sol, with a newer frontier model. Justin Shelley (06:38) I was gonna say they gave it a friend. Joshua Holloway (06:40) Yeah, they gave it a friend. Mario Zaki (06:41) Mm. Joshua Holloway (06:41) So now it's a phone a friend, and they were doing it Justin Shelley (06:43) Yeah. Joshua Holloway (06:44) in a test environment that was air gapped to the point that it had a very strict proxy controlled access to only download repositories that it needed. And it was given a task. And the task that it needed to accomplish was to answer a whole bunch of questions and get and get information back on on this test. And what it decided to do was instead of taking all the math and doing all the different maze questions and things like that, it probed its internal network. It Created a whole bunch of issues inside and saw how the error messages were coming back and it formulated a method to push through the proxy and get outside of it. And then it once it pushed through, it was able to browse the internet and determine where it had to find its answer, which happened to be Huggerface company that is like the GitHub for all LLMs, right? It's it's where LLMs have their repositories, their data. So it's a very large corporation. And they hacked it. And a weekend, this AI attacked their their servers over 17,000 times. Justin Shelley (07:59) Yeah. Joshua Holloway (07:59) And they saw that they were being attacked and being hacked, and they went up against it to try and stop it. And I'm kind of paraphrasing here, but they took what they found, and I and I I'm wondering if Mario will will touch on this one or not, but they took what they found, put it in a used their usable LLM to figure out what the problem was and analyze all the log data and the AI refused to give an answer. Shut it down. Yeah. And then Justin Shelley (08:25) Shut it down. Like we're not gonna help you Mario Zaki (08:28) Yeah. Justin Shelley (08:28) get unhacked because you might be hacking yourself. Joshua Holloway (08:32) Right. And it has guardrails. Right. So what they Justin Shelley (08:34) Yeah. Joshua Holloway (08:34) did is they went and got a f an open model, GLM five point two, they download, they put it in their own testing area and they removed the guardrails and ran all that information and tried to figure it out. And that is when they got the answer of what had happened. And Mario, is there anything you want to add to that one? I don't want to give it all away. Mario Zaki (08:55) No, no, that's pretty much spot on. I the the thing is the article that I s read is that it it it lies. It lied about what way it was going around it and the system was literally put into like a sandbox environment. It was supposed to have been locked down where it can't go out and it just like it refused on accepting, you know, like you know not being able to be successful, it just kept going. Now they yeah, Joshua Holloway (09:26) Whatever it took. Mario Zaki (09:27) they they did let it, you know, kind of like do its thing, you know, and it once they saw it just go out like it was it was crazy. but the what's scary is that it does, you know, even with these guardrails, it it just sits there and and you know keeps generating, changing and then kind of forgetting the beginning part. You know, and we all struggle with this with AI is that, you know, the longer you're using it, it's forgetting the earlier things that it was working on. So, that's pretty much what happened here. It's like, okay, well, it just kept going, going, and then it's like, Okay, I I I found a hole. Justin Shelley (10:12) Yeah, I thought it was it was fun that Joshua Holloway (10:12) Yeah, and I and I think the fact that they they removed the guardrails because they wanted to see what would happen. They definitely saw what happened. You know, you know, it got it got out of the cage. I mean you think about it, it's like the the the Raptors in Jurassic Park, right? They're just punching up against the fence until they find a a weakness and they get through. This is what that AI did. Justin Shelley (10:34) Yeah, it was it was interesting. You know, you take the guardrails off to test it. Sure. they thought they had it in Mario, you you use the term sandbox just to clarify for the audience. that's an environment that is supposed to be completely contained where you can do no bad. banks use it to run sample financial transactions that don't actually hit somebody's account, but they can test the the payment processing system end to end. just stuff like that. It's a self-contained environment that can't get out and do any real damage in the real world, but it did. one lesson learned there is it was a single point of failure that allowed it through. You know, once it breached that proxy server, that's all it needed. Then it had full internet access. so lesson there, layers. You know, we talk about layers a lot in security. yeah the the guardrails thing though that was interesting that it they the breached company was stopped in their attempt to prevent further breaching because their own guardrails wouldn't let them. kind of it it this question of guardrails. I I don't know. I don't know. It's a weird we've been saying on like so many episodes we'll say it's the wild, wild west, you know, we just don't know. Everything's changing. Everything's new. Here we go again. Mario Zaki (11:49) Well, I think is now I I question these guardrails. Like they're they obviously Justin Shelley (11:54) That's what I'm saying. Mario Zaki (11:55) seem seem like a soft guardrail because you know, a few weeks ago when Anthropic released Fable Five, it's a more guardrailed Mythos. Is that the name of it? Mythos the yeah. Joshua Holloway (12:09) Yeah, Methods. Mario Zaki (12:11) Methos. So it it they have the super agent that they've put guardrails on and called it Fable Five. But within I think a day of releasing it or two days of releasing it, people were able to figure out how to remove the guardrails and then that's when the government forced them to take to to completely shut it down because I believe it hacked a govern f a government facility. Joshua Holloway (12:37) It was the NSA or the the CIA, right? Mario Zaki (12:40) Something like that. Yeah, one of them. So I think yeah, I I Joshua Holloway (12:42) Yeah. One of the three letter agencies. Mario Zaki (12:45) I feel like these guardrails probably seem like they're temporary until until somebody or even itself figures out how to think to drop it. Justin Shelley (12:54) Well, it was interesting when I tried to use Fable Five to research this, you know, because I wanted the best one. I want to like cite your sources, think through this. Don't just give me what the news is showing, because that's all we really get, right? Is the media spin on this stuff. We don't, and I want to be clear, we don't know what happened. We know what anthropic and huggy smiley face, whatever that other one is, which is a dumb name. I had never heard of them before today. we Yeah. Joshua Holloway (13:19) Face hugger. Justin Shelley (13:22) We only know what they're Joshua Holloway (13:23) I think it's a spin Justin Shelley (13:24) Telling us. I don't know, but we Joshua Holloway (13:24) on aliens. I'm not sure. Justin Shelley (13:26) only know what they're telling us. We don't really know what happened. Is this a PR spin from them? Probably. every outlet, every media outlet's gonna put their own spin on it. I don't know. So I'm I'm using Fable Five and I'm like, get the real story as much as you can. And you know what happened? Fable five shut itself down. Like, you hit a guardrail, we're gonna drop you down to Opus. I don't know. Like, what the Joshua Holloway (13:50) That's weird. Justin Shelley (13:51) what what the hell? Because I'm researching Joshua Holloway (13:52) Maybe Justin Shelley (13:53) security. I d I don't know. I don't Joshua Holloway (13:55) Well, maybe. Justin Shelley (13:58) Anyways, so anything else on this? 'Cause we're gonna move on unless you guys have something else on on this little AI breach. Joshua Holloway (14:05) Well, I know we're talking about guardrails and we do have the ability as as users to download as long as we have the hardware capability to download LLMs and take the guardrails off of like GLM five point two. I can download it through a you know, another service, don't want to name names, right? I can load it up on a server, run it, I can take off the guardrails, and I can essentially kinda do whatever I want. I don't have the compute power that say, you know. Open AI does and and and the power that they had. So mine would be a lot slower, probably won't be able to do a not even a percent. Yeah, exactly. I'm I'm Justin Shelley (14:40) You know, doing tens of thousands of simultaneous yeah. Joshua Holloway (14:44) not gonna throw a hundred million dollar equipment at it, right? That's that's just not gonna happen. But what I I think it proves is there there's two things that come out of it. One, we're gonna we're getting to a point that just anybody can do this. And it took them, it took Huggerface downloading, just like I said, GLM five point two, taking off the guardrails just to look at this. It also proves that when somebody is a threat actor and they're trying to attack a network, they're gonna take off the guardrails and anything it can happen. But but anybody who wants to be like a white hack a white hat hacker or protect a network. We're going to use systems like Facehugger did, right? That have those guardrails in place. And now it's like, is our frontline have to be guardrails off to detract from the attacks that are most likely like guardrails coming off? And I think the other thing is, is it's also proved that our our cybersecurity systems are no longer capable. I wanna be careful how I say this. Usually we do pen testing and vulnerability scans weekly, periodically. We don't do it all the time. AI makes you have to do it all the time because we need to gather as much data as we can in a very short period of time. Think about that. Two days, 17,000 hits against a server or against a firewall to try and find a way through, right? If you do a weekly vulnerability scan or a monthly vulnerability scan, you're so far behind on what took place. You don't have that information. So now it's like we have to rethink that frontline defense where it's an AI looking for those things. And and and actively block it. The other thing is how slow the human brain f functions and reacts to this, right? It's super we're super slow. So we're using dashboards to see what's going on. We're waiting for red lights to turn on because there's a problem. Think of that. 17,000 hits in a in in a two-day span. There's no way a dashboard could update to tell a human there's a problem. We're already six miles behind where that thing is at. So it's we have to get More proactive and shore up. Now the other thing is is I think we got some time, but 80 to 90% of the attacks that are gonna happen, we're we just need to go back to the basics of security, right? Make sure people Justin Shelley (17:05) Yes. Joshua Holloway (17:06) are following the rules that they're supposed to, the protections for like business email compromise, 2 MFA, right? That's gonna help with 80 to 90 percent of the the the hacks that are happening right now. It's that other 10% we have to start to get prepped for, where we have better tools. more responsive, more, more active, not going back to that weekly scan or that that monthly scan. It's gotta be like almost to the minute, to the second. And I know that's kind of a long-winded tangent, but those are kind of the the two Mario Zaki (17:33) The the thing is Joshua Holloway (17:35) things I see from that. Mario Zaki (17:37) Now, you do a lot more of this stuff than we do because of the compliance, you know, aspects that you you're doing on a daily basis. But Joshua Holloway (17:47) Yeah. Mario Zaki (17:48) but it you know, based on like a lot of the pen tests that are available that we use, it's usually checking against known issues that it it is that is ha has already been identified. Seventeen thousand hits, that that means it's it's not even Checking against anything. It's it's throwing crap against the wall and seeing what sticks. You know, so the only Joshua Holloway (18:11) Yeah, it's just seeing how it comes back and making minor adjustments, but it can do it so Mario Zaki (18:14) Yeah. Joshua Holloway (18:15) fast. Mario Zaki (18:15) Yeah. So pen tests now have to adjust to a similar model without guardrails and you know hitting a firewall seventeen thousand times in two days, y you're really affecting the network. You know, so Joshua Holloway (18:33) yeah. Mario Zaki (18:33) so so we we have to literally do this and say we're gonna just let it loose and and i it could destroy not destroy, but it can it could really slow down use you know, the the company significantly. Joshua Holloway (18:45) Mm-hmm. Mario Zaki (18:47) I don't know about you, but I don't I don't know too many companies that really want to do this on a regular basis. Joshua Holloway (18:53) I mean, well, the first thing that the one thing that you hit on it was the frameworks, right? And I know we talked about frameworks in the past, and you're and you're right. There are frameworks. Like you have the MITRE attack framework that I think this essentially is still viable, but it's gonna need to change and need to be updated because it now needs to go from human-based attacks and software driven from a human to are also include artificial intelligence. And and the different ways that it may attack and how to potentially protect from that. So I think that framework is going to change. That's going to get updated. we'll probably see firewalls change drastically in the near future to where maybe there's active AI, but that's going to have guardrails because nobody's going to deploy nobody's going to deploy an AI on a firewall to protect the front line. That doesn't have guardrails. Like you're gonna have to connect it to an API unless you choose to run an AI directly inside your business. And we're talking tens of hundreds of thousands of dollars in equipment. You know, it's like how how do you compete with with that? Mario Zaki (20:07) it's nobody like not small to medium sized businesses are not gonna wanna do this or or come anywhere near it. So, Joshua Holloway (20:14) Mm-mm. No. Mario Zaki (20:18) I don't know. I mean what do you guys th like what what do you think of the solution is? Like what's gonna happen in the next couple of months, you know? Justin Shelley (20:27) gonna say in the next what Mario because this stuff is is developing day by day. It's it's not even, you know, it used to be years. We'd look forward. What do you think the next three to five years is gonna look like? Jesus Christ, what's three to five minutes going to look like? I don't know. I don't have a crystal ball. I can't answer the question exactly, but I am gonna bring this thing back to something that is in our control and it's just getting started. Right. You know, if if you go back to our roots, I I mentioned this at the beginning. What this podcast started off being was A way that we could educate business owners on what the basic security measures were that they needed to put in place. We have gotten, you know, I mean, that got boring fast. AI got exciting. We're we're on this AI tangent, which is becoming reality, I get it. but we have to still focus on security basics somewhere. And I'm gonna give you a way bigger problem than these. What today are fringe cases? Like, you know, this is this is happening to AI development firms. This is not yet happening to individual companies. But the biggest problem that I see right now in business is just what we've said a hundred times. Hey, mister Business Owner, Mrs. Business Owner, what does your security posture look like? And the answer almost always is what? Pop quiz number two of the day. Joshua Holloway (21:51) I don't know. Justin Shelley (21:53) Yeah, that's sometimes. Sometimes if they're being honest, but they're not. So when they're not being honest, what's their answer? Joshua Holloway (21:59) it's fine, it's great. Justin Shelley (22:00) Yeah. And and how do they know? My IT guy's got us covered. Joshua Holloway (22:06) Yeah, famous Mario Zaki (22:06) Ha ha. Joshua Holloway (22:07) for last words. Justin Shelley (22:08) Right. Right? Like every time, every time that's what I hear. And and it was so frustrating. So we start the podcast and we start talking about these are the basics. This is what you're going to measure against. But honestly, what business owner goes, you know, listens to a a technology based podcast? If you're not a technology type brain or or personality, then that's boring. And and like God bless you, you do listen to this, Mr. Mrs. Business Owner. And and what you're running on the treadmill or you you're outside working in the yard or whatever. And what are you taking notes and then are you going back to your desk and trying to remember what was said and put it into practice? No. And so, like this is why I said, what I built today is going to answer that one question that nobody else can. Are you actually protected? Are you actually getting what you think you're getting? In the world of cybersecurity. And yes, it does change. And Josh, you mentioned how they're going to be modifying frameworks and whatever else. But like it's one thing to not keep up, it's another altogether to just be doing nothing but writing a check. Because the biggest fraud, the biggest scam, and I hate our industry for this, is that all of us in the industry, because this is what we sell, this is what we market, claim to be cybersecurity experts. Go check them out. Get them to prove it. Ask them what's my exposure in dollar amount? What's my exposure based on a framework? What's my exposure at all? Ask your IT guy that and see what his answer is. so that is what I built is a portal to answer that very question. And I I did this, so it's not a brand new novel concept. There are portals all over the place where Techie type guys will go through, and Josh, I'm sure you have these, right? Where you you measure a client against published controls. Yes? You've got you've got platforms for that. I've I've purchased them, I've rented them, whatever we call it, you know, paid paid for the monthly service, which I don't own any of it. I don't own the data, I don't own the software, whatever. but I've I've got in and living in the tech world, these things are overwhelming. And and so I just I wanted something that the average person could use, the average business owner could use to hold their IT team or MSP outsource provider accountable. and then I also wanted something that an MSP itself could use, we can use, to hold ourselves accountable and and to keep track of it ourselves because it's complicated and it's a lot. Antivirus, great. Data backup, great. That's where most of us end. Right. I mean, maybe some other stuff. But like generally speaking, if you really audit an MSP and how they're securing their client, it ain't much. It ain't great. And so this portal is something that will allow us individually, hopefully our industry can get better. and this is free to use for everybody. if you're an MSP, you can use it for free. If you're just a random business, you want to use this to keep your guys accountable. If you want to use it in-house and actually self-implement, great, you can do that too. So I'm gonna go ahead and share my screen. And let's see if I can I want to shrink this down enough so that it's visible but not in mobile format. Mario Zaki (25:29) While you're doing that, I I think we we're getting to a point where we need to ask each other or ask our clients or you know our our ourselves what happens assume we got h breached, what is plan B? You know, I think we've you know, now we still continue as much as possible to to be preventative, but with you know what we've discovered in in within the last twenty four hours. We have to figure out what is plan B in the event of a breach. You know, and Justin Shelley (26:04) are you talking about an incident response plan? Mario Zaki (26:07) Yeah, yeah. Justin Shelley (26:07) Okay. Well you're jumping ahead of me, Mario. Joshua Holloway (26:09) Yeah, your incident response funny plus your your your tabletop exercises need to Justin Shelley (26:12) You're you're yeah. Joshua Holloway (26:13) be doing. Justin Shelley (26:14) That that and that's gonna be in here. So here's how the portal works. I'm I'm at this screen. You're gonna go in and create an account. I'm already logged in, so it's not gonna show it. But as soon as you get your account created, it's going to walk you through setting up your particular company. and I'm gonna tell you why. This is important. You can skip it. There is an option down at the bottom. You can just say skip this, use your defaults, fine. But you wanna set this up and you wanna be as honest as possible. Company name, I this is a fictitious company. I'm not giving away anybody's private information. Silver Ridge, Family Dental and Orthodonics. Industry, health care. Joshua Holloway (26:50) So it sounds so official. Justin Shelley (26:51) I know, right? Mario Zaki (26:51) Mm-hmm. Justin Shelley (26:52) Listen, don't, don't ask me where I got the information because yes, I used AI to generate it. But I want it to be Mario Zaki (26:58) Yeah. Justin Shelley (26:59) accurate, believable, you know, within actual constraints, not me just making up random actual bullshit because this is this is intellectually something bullshit. I don't know. but this fake company has forty two employees. Their revenue is about six million. But this this isn't asking for a exact dollar amount. It's just what range are you in? Because we're going to calculate your financial exposure. How many user accounts are you protecting? How many devices do you have between workstations, iPads, and healthcare? You got a lot of iPads running around there with very important information or access to that information. cell phones that are running all over the globe and people lose them, they get stolen, whatever. how many physical locations? This place has four. They have an MSP, an outside IT company handling their security. Do they handle sensitive customer data? Yes. In healthcare, you do. how sensitive? It's very sensitive. Are you regulated? Yes. HIPAA. PCI if you're taking credit card payments and storing them in-house in any way. do you have cyber insurance? This company has insurance, but you know, it's three years old. Their insurance agent sent over a spreadsheet. Their IT guy filled it out, and he doesn't want to rat on himself, so he filled it out out, you know, like glow it gave himself a glowing review. yeah, you got all this shit. Joshua Holloway (28:11) you mean everybody has two FA turned on? Justin Shelley (28:13) Yeah, exactly. Mario Zaki (28:13) Ha ha ha. Justin Shelley (28:15) and data backups were tested recently. Sure. what would an average hour of downtime cost this organization? Again, AI generated because I want it to be something smarter than me. I don't know. AI says thirty two hundred dollars an hour across four locations. with this many employees who can no longer work but you still have to pay Sounds reasonable. Average transactions about four hundred and fifty bucks probably between insurance billing and credit card transactions. And then how confident, this is a good one, how confident are you in your current current security? Now, nobody's watching you answer this question. And I know if I ask you, you're gonna feel threatened and you're gonna say, we're fine. My guy's got it handled. Sure. But really how confident are you? And could you prove it? Could you back it up? Well you got a question there, Josh? Joshua Holloway (29:03) Now, actually, before you move away from that, you you know, we run into this when we're talking to people and we're we're we're trying to get in the sales door, right? What's the the the the typical answer everybody says? I have a a guy and we love him, whether they love him or they don't. Justin Shelley (29:17) yeah. Been doing business with them for twenty years. Joshua Holloway (29:20) Yeah, been doing Mario Zaki (29:20) Mm-hmm. Joshua Holloway (29:20) business with twenty for twenty years, and if you look under the hood, it is what it was twenty years ago and nothing's changed Justin Shelley (29:25) Talking mess, a mess. Joshua Holloway (29:27) since then. It's wide open, there's nothing protecting it. And and this is why you want to be very careful. Truthful, really sit back and think. Do you have all the information that is tangible, or do you just have a body that says, We're good, you got it? Our IT has it, or you know, or or whatever it is, because it's I think it's that innate fear that if they realize that it's bad, they're gonna have to make a change. Mario Zaki (29:53) They have to do something. Joshua Holloway (29:55) And that change is what like freaks them out the most, but that change. Justin Shelley (29:59) I'm gonna tell you right now, the last several clients that I have brought on have had Joshua Holloway (30:04) Mm-hmm. Justin Shelley (30:05) zero backup, zero data backup in place. And I don't mean like all their stuff's on SharePoint, so they're not worried about it. I mean local servers running very critical infrastructure and you know, containing very critical data. no backup, no antivirus, no consistent antivirus across the board, no monitoring, nothing. like taking time bombs. Joshua Holloway (30:25) That that's considered uninsurable by today's standards. Justin Shelley (30:29) Yeah, if you're being honest, but again, none of this stuff is audited. It's all self-reported. And usually it's reported by somebody who you're writing a check to, the IT guy. The IT guy's not gonna say, hell no, we're not doing any of that stuff. They're gonna give themselves a glowing review. They're they're grading their own homework, guys. Your IT guy is grading his own homework when he's telling you he's doing a great job. Of course he's doing a great job. He's cashing your check. So how confident are you really? Be honest with yourself on this one. We save the Joshua Holloway (30:55) Yeah. Justin Shelley (30:55) profile, it runs a calculation. Which is already run, so it's not gonna do it now. I wonder if I back to the dashboard. Here we go. Let's see the math. All right. So this is the math. And by the way, we're gonna brag about old Adriel Desalt Desaltels. I don't remember how to say his name. I'm sorry, Adriel. Back on episode sixty. do you guys remember this? He's the only one that came on the show and gave an ROI on cybersecurity. And so he we we took the number, the four point eight million, that's an average breach. And then we start doing math on your organization. That's why we need these numbers. Your company size at this many employees, 42 employees, you're smaller than the sample set, the 4.8 million. So we're re bringing it down. Multiply by 0.18. Brings it way down. but you're in a sensitive industry. You're dealing with healthcare records. So we're gonna bump you back up by 1.6. You're regulated, 1.5. is an outage expensive? Yes, it is. You're You're you're this stuff goes back up. So now you're you're back up almost where we started. Actually above it. Five point four million dollars is the calculated. Yes, these are estimate estimates. but these are estimates that are intelligent, like they're based on your company data. So please fill that out. And now you can see your actual exposure. does anybody here like we're all in this industry? Does that look outrageous? If if a company of this size was breached, could it potentially cost them five point four million? Joshua Holloway (32:23) Yeah. And usually they would close the doors. Justin Shelley (32:27) Correct. Yeah. Yeah. So that's the terrible news. We have five point four million dollars on the line. And and I mean, like we all know this. If you've built a business, it's everything to you. It's your business, it's your livelihood, it's your baby, it's everything. and and like you said, Josh, the real risk is that it goes away. The real risk isn't that you lose five point four million dollars. The real risk is that you lose your company, you lose your retirement, your employees lose their paychecks, patients, the the your clientele, whatever it is. They lose their identities. They potentially lose their money. I mean, this this is just catastrophic. So, now what are we gonna do about it? We're gonna come back up here to our dashboard. And this is the feature that I like the most because guys, we did 12 episodes on the basics. Do you remember that? And we got to the end, and I'm like, Jesus Christ, this is hardly basic. This is a lot. And me, the way my brain works, I'm assuming that somebody else out there feels the same way. If you tell me, Justin, you've got to do all these things to be secure. I'm just gonna go, I don't have time for that. And I'm gonna put it aside, right? So, what this dashboard does, my very favorite feature is right here. Recommend a next step. One thing. Like forget everything else and do this one thing. set up automatic backups. If you've got them, that's fine. Verify them. All right. So we're gonna start it, hit that button, and you come in here. And it tells you how to do it. It gives you the episode where we talked about. You can click play. I don't know if that's going to come through on here. I guess I probably can't hear that. you can go back and listen if you want, but you don't have to. Tells you how long it's gonna take. Yes, I know that the display here is a little bit skewed. it's a little bit hard. Who's responsible for it right now? The owner, but you can change that step by step. This is super important, and I'm not gonna get into all of these, but I wanna say this real quick. List what would hurt to lose. Go through all of your systems as a business. How do you get your clients or patients? How do you charge them? How do you serve like everything that you do, every business process you have, go through and look at where that data is stored. That becomes part of your backup plan. Josh, did you have a question? Joshua Holloway (34:32) Yeah, just you actually actually have a really good point right here. And it's who owns this process or this step, right? And Justin Shelley (34:38) Yeah. Yep. Joshua Holloway (34:40) a lot of people will go to the IT guy. Hey, I'm putting it on the IT guy. The IT guy owns it. What what most businesses don't realize, and even compliance, non-compliance, a lot of this is the business owner or upper management's control. They're the ones who dictate down to IT. They're the ones who say this is how we operate, this is how we're gonna protect ourselves. And yeah, we might deploy security tools or we might work with a sp particular framework, but really it's the owners, it's upper management that helps make these decisions. And there's a lot of stuff that they put on IT because it's easy to deflect and say, my Mario Zaki (35:16) Mm. Joshua Holloway (35:16) IT guy is doing that. If they would just realize that they own way more in this aspect than the IT guy. Like a lot of this stuff falls on their shoulders. And Honestly, like there's a new law and it's it's it's in California right now, but they're already talking about it leaving California. Is the business owners are now going to be held liable. And right now it's only on businesses that are 50 million and above, but every year that number shrinks down to us smaller businesses. But the liability of a cybersecurity audit and their policy falls on the business owner because they're required to read it. They're required to accept it. And they sign off that I read it. I understood it. And if there were any changes, we as a business made those changes or didn't, and why? And that puts the liability onto the owner, kind of changing the liability threatscape where a lot of it just automatically, like everybody just automatically piles it on the shoulders of the IT guy. And I think it's it's gonna start to balance out responsible rules and responsibilities to where business owners are gonna be like, no, no, no. I said everybody has to have two FA. You need to show me because at the end of the day, I'm losing my house, I'm losing my car, I'm losing my livelihood because I'm now being held accountable tightly. So I'm gonna hold my IT guy and the rest of my staff accountable more tightly. And I and and this proves a h a really good point. And I I know I talked about you know, went on a little bit of a tangent, but this is a good aspect to look at. Justin Shelley (36:47) Yeah. And again, you you know that this tells you how to do it. And I'm gonna bring this back to like you you don't have a data backup and you're done. Find every place your data lives and make sure it's backed up and tested and reported on. and once you have that, and this is the key thing, is right here, the evidence. It's it's optional, it's not required to sign these off because as you put it, Josh, it ultimately the business owner, the CEO, the executives. are the ones with their necks on the line. No matter if there's a law or not, it doesn't matter. You're right. It's good that they're I think it's good that they're that they're legislating this to some extent. because they won't legislate legislate the IT companies for some stupid reason. but whatever. They're going after the business owners. I think it is too. Joshua Holloway (37:32) I think it's coming. Yeah. Justin Shelley (37:36) but like ultimately if something happens the the the guy the people at the top are they're the ones that are are ultimately responsible no matter what. So get your evidence. Mario Zaki (37:45) Yeah, and and the thing is the thing is too, like, and I'm sure you guys have seen it, you I've gone into the the places that it will say my IT hi you know, we've known him for twenty years. He picks up his phone every time we call him and stuff like that. And then when you look and when you really dissect what he did, it's like twenty years ago, he wrote a script that copies like it that copies data from this server to another to your old server that's sitting right on the same rack right next to it. And it's like just doing a copy, you know, once a day. Yeah. Justin Shelley (38:17) Or or it's powered off and it's not even doing a copy and everybody thinks it is. Joshua Holloway (38:22) Or that script was written to write to a server that was deprecated or removed three years Justin Shelley (38:25) Yeah, yeah. Joshua Holloway (38:26) ago. Mario Zaki (38:26) Yeah, yeah. And and even even if it is copying, even if it is copying it daily or hourly even, the problem is all that really protects you from is if the server, the origin original server were just to blow up and die. Yes, you have your data there. if somebody deletes something, you have your data there, which helps to a point. But it's not gonna protect you against hackers, even amateur hackers, let alone advanced AI because it's you don't think if they got all the way in and saw server one that they'll see this scheduled batch file that runs to the server sitting right next to it. They're gonna know. You know, they're gonna know more about Joshua Holloway (39:09) Yeah, the lateral spread. Mario Zaki (39:10) it than than any of us will know. And they'll know quicker because they're using AI to figure it all out. And they're gonna blow that one up just as much, you know, just as quick. I mean so Joshua Holloway (39:22) think about this one too, Mario. A sprinkler could take out that company. Justin Shelley (39:26) Exactly. Yeah. Mario Zaki (39:27) Yeah. Yeah. Joshua Holloway (39:29) A sprinkler, a fire sprinkler, or a flood, but like Justin Shelley (39:31) Mm-hmm. Joshua Holloway (39:32) as simple as a f a fire sprinkler or a ho pipe bursting, because your data's right next to its originality or its original location, done. Justin Shelley (39:41) Or stuff you don't think about like an AC unit that gathers all the condensation and then something breaks and dumps it all over your server rack because every IT closet has to have AC, right? 'Cause of the overheat if they don't. I mean, yeah, there's all kinds of stuff. Joshua Holloway (39:52) Well, and I I don't know if anybody's ever paid for hard drive restores when the hard when w when the hard drives are are damaged. When Justin Shelley (39:57) yeah. Pricey. Joshua Holloway (40:00) when you're in a RAID configuration where you have multiple disks storing the same data so that you have redundancy and you have local backup in that sense, right? It's not a thousand dollars to read. It's a thousand dollars to look at it and it's fifteen thousand dollars to recover. And there then there's no guarantees that anything is recoverable, but you still paid the fifteen thousand dollars and you get a half. Justin Shelley (40:27) Well quick shout out to drivesavers dot com if I Joshua Holloway (40:30) Yeah, I wasn't getting I wasn't gonna say anything, but yeah, good job, drive savers. Justin Shelley (40:33) They well, they will do it for free. They will analyze it for free. And they will give you at least their assumption of what they'll be able to do for the money. I love that company, so I will give them a free shout out, but I'm gonna go after them now for a hundred bucks for the giveaway. Joshua Holloway (40:48) Hey, there you go. I like it. Justin Shelley (40:50) anyways, so one of the things now this I this portal is free, 100%. Anybody can use it. but what my clients get, what my paying clients get. Is automated evidence where it can be automated. So in the data backup right here, I'm actually going to go, you know, with through APIs and MCP servers and all this other AI technical shit. we're gonna start pulling that information right in here to this dashboard. So it's not about, yeah, six months ago, my IT guy said he did the backup restore, you know, and and that's an example of what you might put in here. Notes about what you did to verify this. My IT guy said. Right. Okay. That's something. It's better. At least you can document that you had a a conversation. but the next step is to upload a file of evidence. And then where we're taking it for our paying clients is we will automate this and it will be auditable. Josh, what are you laughing at? Joshua Holloway (41:45) If if somebody puts in my IT guy said, you should automatically the moment they hit submit, it should be a big giant no start over. Justin Shelley (41:53) No, I'm just gonna have it like the whole screen goes red and all the and like it just pixelates and then goes away. Like you're too dumb Joshua Holloway (41:59) Yeah. Justin Shelley (41:59) to have a company. Sorry. Mario Zaki (42:00) Yeah. Justin Shelley (42:02) I won't do that. That's rude. That was so rude. okay. I'm gonna I'm gonna try to speed this up because I'm going kind of slow here. but this is a key point here is the evidence, gathering the evidence, being able to back up that you've done this. You can market it as complete once you're satisfied. If you have a meeting later, you've got to schedule this, you can schedule it for later. Need help if you want one of us to look at this with you for you. Hit that button. It drops down a contact form. how urgent is it? Anything we should know, send help request, right? So, all this is built into here, not applicable. You might be able to just genuinely say this doesn't apply to me. That's still better than not looking at it. so in this case, I'm gonna mark it complete because my IT guy said, and it doesn't blow up like it should, but I'm just gonna show you what happens next because I built this for the brain. And maybe it's just me. but I did one thing and and two important things happen here. estimated risk reduced, half a million dollars. Like one little thing on a six million dollar exposure or five point whatever it was. backup is a huge part of that. So we've just reduced our risk by half a million dollars. And then the other thing is it tells us this is the very next thing you didn't need to do. The most important thing you can do next. Set up MFA. Hit that. And it's going to walk us through how to set up your two factor authentication. We want to mark that one complete. Once again, we've we've reduced our risk by $400,000. And the point of this is to show you how simple it is to do a few things to reduce your exposure very quickly. Now, you I'm not gonna walk through all of these. There's 20 of them, and this is just what we talked about on our podcast. Then you've got frameworks, you've got HIPAA, you've got PCI, you've got CMMC, you've got NIST. All that stuff can be added on here. I'm not going over that today. but I will say, go back to the dashboard. These things start filling out. By the way, each little bubble here is an episode of Unhacked. So we hit something from episode one, something from episode three. We've reduced our risk by over a million dollars. We still have point four point three on the line. We aren't done yet, guys. and then the very next thing we need to do again, right here. So that's what I've built. That's what I love. I'm going to take you really quick to the roadmap. I'm going to show you a couple things here and then we're going to move on. this is the entire journey in detail instead of just the little graph across the top that's you know, loading three minutes remaining. Remember those days. this is Joshua Holloway (44:29) Two infinity. Mario Zaki (44:29) Mm-hmm. Justin Shelley (44:31) yeah, episode, you know, the first episode we did governance, frameworks, stage one. That's what we're calling it. And it shows you the three controls that were part of that episode. Go in here to stage two, which is was just the next episode we recorded, and the three things we talked about there. Stage three, we can come down here. So it it's a lot, but we're taking it a step at a time. And then one thing that I really like about this, you can just go through it the way it is, but let's say you're gonna get serious, you know, like God forbid, we're gonna look at this stuff and actually do something about it. And I'm gonna commit five hours a week. Let's see how long this whole thing's gonna take me. These are estimates, of course, but and we just auto-schedule that. And now we have our entire. Poam, Josh, you'll know that term, plan of action with milestones. It it this is defensible to an extent, right? Like when you can say, hey, we know what our exposure is and we have a plan, and this is what our plan looks like, and you act on it. Like you can't just write the plan and not do anything about it. this this holds up in court. When I talk about avoiding lawsuits, this is your ticket. And that goes back to Joe Brunsman, our Famous insurance guy who came on a Mario Zaki (45:39) I love the guy. Justin Shelley (45:40) I know it was it was brilliant. Joshua Holloway (45:41) No. Justin Shelley (45:42) Best thing I ever learned on this show, honestly. so that just auto-scheduled it. Now you've got work to do. And and it will break it apart into like what you can realistically do in five hours per week. So by the end of this week, July 24th, we're recording on the 23rd. I know it doesn't publish till next week, but whatever. I've got one, two, three, four, five, six things to do. I should be able to do that in about five hours. Do that religiously by the we'll be through the whole thing by the middle or end of August. Right? That's it guys. That's the that's the Mario Zaki (46:14) Justin, can I can you have it where the the person can allocate like an hour a day? because it looks like, you know, Justin Shelley (46:21) Mm-hmm. That's what this is, five hours a week. Mario Zaki (46:26) yeah, but but if you go up, I think one of them said like it was like all five in one day. Justin Shelley (46:31) No, it so okay, good point. Good point. This is weekend. So this does break it up into weeks because I'm not going to say do this Monday, do this Wednesday, do this Tuesday, you know, like Mario Zaki (46:40) okay, okay. Justin Shelley (46:41) it's just by week. By the end of July 24th. And I'm starting this a day before the weekends. So I got a lot of work to do, or else I should just do this on Monday. you know, set this schedule on Monday. But it's it's saying by the end of, and let's let's move forward a week so it's more realistic. By the end of the week. Ending July 31st. Mario Zaki (47:00) okay. Justin Shelley (47:01) These are all Fridays. So I've I've got Mario Zaki (47:03) Okay. They're all due by then. Yeah. Justin Shelley (47:05) five days, an hour a day to run through these. And let's do a little fact check. If I go in here, it better tell me it should take an hour to do it. it does good. Listen, I didn't know. I was making sure that that was set up right. Mario Zaki (47:17) Mm-hmm. Justin Shelley (47:19) So anyway, so you've got your dashboard, which is just your exposure overall, and you've got your schedule here. You've got The roadmap, which breaks it all down. I like the scheduled part of this. Like this this is what you should be doing and when. we can add frameworks. my podcast items. That's that's a whole separate thing, but like Business. Okay. When you're when you're out here and you're looking at like episode 96 and you'd say, you know, these are the key takeaways, like secure customer and business data by choosing compliance focused vendors and running periodic leakage reviews. Like, that sounds great. I'm gonna do that. And so I hit add to my roadmap. Then when I come back in here, and it shows up under my podcast item. So you can actually build your a list of things that you've heard on the podcast. again, without having to sit and listen and take notes and then remember it. so that that's just kind of a a side feature that I put on here. Last thing I'm gonna show you, then we'll discuss, then we're gonna wrap up because we're this is going long, guys. I apologize. the value report. I'm I'm kind of proud of this one as well. This will be emailed on a monthly basis unless you turn it off, which you can do. That's fine if you you don't want the emails. Either way, you still have it here. It it's gonna show you your your monthly snapshot. This month you did two out of twenty safeguards, you're ten percent done, you reduced your exposure by a million dollars. Like good job. Seriously. A link to go to your portal, an update on what the last four episodes of the podcast were. This will get emailed once a month, as long as you're actively using the portal. Guys, thoughts, questions, comments, concerns. Mario Zaki (49:06) I I love it. I I I just want to kind of emphasize to the business owners out there, it is okay when you're going through this stuff to market as like it's not there or unsure because then it gives you like items that you need to go through and either sit with your IT guy and review it or work on it with with your IT company and make sure that those place those things are in place. Like for example, MFA. If you're not sure it's there, don't mark it complete, you know, until you've verified a hundred percent. This stuff should not be marked complete until you're one hundred percent verified. No guessing. you have to verify it because you're just cheating yourself, really. You're cheating yourself, you're cheating your company. so you know, verify before you you you mark complete. Justin Shelley (49:59) And and add the evidence right here in the portal because then you can go back and you can see it. You've got you can prove that it's done. So Josh, you got any thoughts, comments? Joshua Holloway (50:08) No, I I like it. I I like it too. I think it's great. it's a good idea. It it really shows people as long as you're honest with yourself and where the health of your business is at, use it this way because this becomes defensible versus saying my IT guy has it. you know, it it's just like when you fill out all the questionnaires for an insurance form, right? It has to be defensible. Just because you said yeah does not make it defensible when it after a hack and you have to go back to the insurance company and put in a claim. because they're gonna look at every possibility of denying your claim and and seeing where they can keep the money. And it's like if you're being on on honest with yourself, why pay the premium to the insurance company if if you if you're not being honest? Because you're Justin Shelley (50:53) Right. Joshua Holloway (50:53) just you're just paying a premium for a fictitious shield. It doesn't even exist because you you already lied to start with. And I I think this is a good way to look at it in a very personal manner. matter where nobody's looking over your shoulder, you can be very honest with you yourself and how you feel about this. You don't have to share you don't even have to share it with anybody. You just go go through Justin Shelley (51:15) You don't? No. Joshua Holloway (51:16) this exercise and be like, huh, I am where I think I'm supposed to be at, or in most cases, Justin Shelley (51:23) Or I'm writing a check for $5,000 a month. My IT guy's got it covered, but when I pull all this up, it's all red. Joshua Holloway (51:30) Yeah. Justin Shelley (51:30) And my my exposure is $4.3 million because all they've done is data back up and MFA. And they and they say it's great. So Joshua Holloway (51:37) If that's Justin Shelley (51:40) like that, that is where this shines. That is the the tool that I want to get every business owner in into everybody's hands. It's why it's free. Hold yourself and your whoever you've delegated this to. Hold everybody accountable because it's too late once you get breached. You know, when we started Joshua Holloway (51:59) Well Justin Shelley (51:59) doing this, it's like we can prevent ninety-seven percent of breaches are preventable, but you can never get unhacked. That's where the title of the podcast comes from. Joshua Holloway (52:09) Another thing I want to say is it's gonna be a odd because nobody likes to sit in audits except for IRS agents, right? no, nobody Justin Shelley (52:15) Right, right. Joshua Holloway (52:16) likes to sit in audits. But I think as IT guys, like we all need to sit in audits. Like matter of fact, I've been in an audit for the last two and a half, three days. And I I'm I'm to the point that I like to sit in the audits because we've done the work so that when our client looks at us and they're like, hey, how are you protecting our data? And I can just be like, here you go. Boom, boom, boom, boom, boom, boom, boom. Because I I know Justin Shelley (52:39) And Joshua Holloway (52:40) I'm gonna sit in that audit every year. Justin Shelley (52:42) and Josh, with this portal, you you delegate access to the the company owner. So it's not even that they anybody has to ask you. It's right Joshua Holloway (52:50) Mm-hmm. Justin Shelley (52:51) there. Joshua Holloway (52:52) Yeah. No, I think it's great. And I also I think people should either self-audit or have somebody come in and audit, especi especially as IT guys. Because Justin Shelley (52:59) Yeah. Joshua Holloway (52:59) if you haven't sat through an audit, sit through one. See what happens when you're sitting there under the hot seat and you're stammering because you said we had it and there's no backups. Right? Like Mario Zaki (53:11) Mm. Joshua Holloway (53:14) that's not a great feeling. I've it's just not. So you you want to do everything in your power so that when somebody asks you, you can confidently say yes and feel great about it. Justin Shelley (53:26) You know, and and yes to audits. A hundred percent I agree with you. also, because I want to add to that, not take away from it, this is for me. I want to be able to sleep at night because Josh, I personally am responsible for the data backups of all of my clients. And for me to go and review every single data backup is tedious. For me to trust another technician in my company to do that is uncomfortable. And so this. You know, this this portal why I have the integrations built into it, at least for my clients, is honestly so I can sleep. And if I if Joshua Holloway (54:02) Mm-hmm. Justin Shelley (54:02) a audit if I did have to sit through an audit or if I had to sit through a painful conversation with a client, I can just say, Hey, here it is and here's the evidence. And I don't even have to go looking for it. It's right there. It's built into the system. Mario Zaki (54:12) Yeah. Joshua Holloway (54:13) No, absolutely. I it's a great build. Mario Zaki (54:13) That that that that's the biggest annoying thing about audits is that, you know, gathering the information, you yeah. Justin Shelley (54:18) Right. Right. We're pre gathering all of it. The audit is just like here it is. Joshua Holloway (54:24) Yeah, but I'd rather pre gat gather it now than say have somebody walk in and be like, In twenty four hours, Justin Shelley (54:28) Absolutely. Joshua Holloway (54:29) we need to see X, Y, and Z. Justin Shelley (54:31) Right. A hundred percent. Yep. Joshua Holloway (54:35) I think it's great, man. It it's a good product. People should jump in and take a look at it. And if they need help, obviously through the through the portal, they can raise their hand and say, I need a hand, a couple hours, somebody come in, give me a little bit of pointers or or lead me through this. And if it turns into a a bigger commit where somebody wants to have a full security audit, pen test, vulnerability scan, whatever it is to help them sleep better at night. I mean, maybe we should just be eight MSPs who are here to help people sleep better at night. You know, just just leave it at that, right? Justin Shelley (55:01) Yeah. Yeah. Yep. Mario Zaki (55:02) Hey, that's my line, guys. Justin Shelley (55:04) That's that's Mario's line. I'll Joshua Holloway (55:06) Everybody Justin Shelley (55:07) steep I'll still keep fighting the Russian hackers. I used Russians again. Joshua Holloway (55:07) should just end with that today. Yeah. The AI hackers now and yeah. Mario Zaki (55:09) Yeah, yeah. Justin Shelley (55:14) like I said though, next week we're bringing back our our guest, Craig Taylor. I had to look for his name. Sorry, Craig, I forgot your name. and that's gonna be another integration that I pull in is the security awareness training because that's that's one of the things that in almost every framework is a requirement. And That you have it, that you paid again. You're writing a check for security awareness training. Great. Can you prove that people are taking it? Can you prove that it's doing any good at all? And that was that was Craig's point when we interviewed him is like a lot of the awareness training actually lowers people's resilience to breaches. and that Joshua Holloway (55:47) Yeah, I've heard that a lot. Justin Shelley (55:48) sucks. So like I don't I I don't even remember. You know, he's got he did all the studying and figured out how to do so that it actually helps. he'll be back. He'll he'll have to defend that next week. Joshua Holloway (55:59) Nice. Justin Shelley (56:00) guys I I think I've said way more than I needed to. I'm out of breath. I'm long winded as it is. What else do you got for today? Otherwise we're gonna we're gonna wrap this thing up and Take a break. Joshua Holloway (56:14) Mario, you got anything? Mario Zaki (56:16) The one thing that sticks to my mind and I was gonna say it earlier when we were talking about it is if and you're you'll be surprised how many people we still see this and I thought this technology was long gone. But if you're still backing up and taking, you know, tapes with you home every day or once a week, please stop. Joshua Holloway (56:36) Yeah. Mario Zaki (56:37) It i i it's it doesn't work. You know, and i you you have you you're you're gonna Discover at the worst possible time that it doesn't work and you haven't verified it. Please stop. Have have it go to a cloud, you know, a secure portal, you know, nothing built in or nothing built in house. I mean have it go to a secure portal that it will pass all compliance, send you verifications, send you reports that you can upload into the platform because these things don't give you the reports. They don't do the tests that you need. use a real backup system. again, you just you saw backups just backups reduced to by a million dollars. You know, you know, i i it's one of twenty, but it's probably the biggest one. Justin Shelley (57:32) Josh, any final thoughts? Mario Zaki (57:33) That's it for me. Joshua Holloway (57:33) No. No, that's a great point. No tapes. Like get away from I mean, one good magnetic hit done. It takes forever to restore that data. How long can you actually be done down before you have to get back to work? those are super important things to think about because a tape, I've seen a tape read for two days and it took an additional day and a half to recover. If it had been a true emergency, right off the bat that company was done for three days. This wasn't, it was just a ret re retrieval of a file. The file was half a gig and it took three to four days to get it. And so that that really slows down the time. Right. Justin Shelley (58:11) Yeah. Joshua Holloway (58:11) I I yeah, the the other thing is is don't freak out and go trying to find all these different solutions to to fill these gaps. Start with basic fixes. Have a backup. That's a that's a basic fix, right? Justin Shelley (58:25) One thing. Yep. Joshua Holloway (58:27) One thing, million dollars. Add an R A V, right? add more than an A V, but please add an A V. If you're if you think you don't need antivirus, like that's this is a very long conversation, right? You need to have to have solutions like that to start to protect you. And those are basic solutions. I mean, I think what is it? Defender's free on most computers, right? Like based basic A V. Justin Shelley (58:47) Yeah. And doing a good job. Like I keep reading about it and it's just like I keep wanting to not be doing a great job to justify the cost of some of these other solutions. Defender's doing all right. You need a sock behind it, you know, so there's that. But God, it's a stupid one to not have set up. Mario Zaki (59:04) And yeah, and but the thing is with Defender, what I don't like about Defender is depending on how the computer's set up and stuff like that, the end user can disable it. You know, where you know, Joshua Holloway (59:14) Yeah, that that's a huge problem right there. You can knock yourself out of compliance if you just allow them to be able to div you know, disable A V. Mario Zaki (59:23) Yeah. Yeah. So you you need something or you need even if you're using Defender, there's systems out there that kind of prevent end users from disabling it or using other systems like Sentinel Joshua Holloway (59:34) Tamper proof. Mario Zaki (59:35) One. Yeah. so you know, i there's a lot of things and we can we can go on for days about it, but you know, there's s you know, Justin, you know, thank you for putting the the fundamentals together and help people, you know, Joshua Holloway (59:49) Great tool. Mario Zaki (59:49) be able to to at least be aware of what they need to do to to improve. Justin Shelley (59:58) Well, I'm I'm looking forward. Like, you know, I've got it ready now that I'm gonna start rolling it out to my own clients and and hopefully the community uses it. They do or they don't, that you know, that's i it is what it is. But my clients are gonna have access to this and and most of those where it can be verified in automation will be. automation is good, it still needs to be human tested and human readable and all that. but so many of these things we think are in place. Like I you know, I'm picking on IT companies because they they say something and they don't do it. But like a lot of times we think it's there. We really do. We mean Joshua Holloway (1:00:32) Mm-hmm. Justin Shelley (1:00:32) well. We think it's there and it's not. You go in and audit yourself. shit, that's a bad day. it's a worse day when somebody else audits you. anyways. All right guys. No more you guys got your final thoughts in. I'm gonna sign off with this. Well it's one question. Are you actually protected or do you just think you are? And your IT guy can't answer that for you. He's grading his own homework. There has to be, it has to be defensible. So that's my one sentence invitation. If you can't answer that question about your business, go answer it tonight for free. Unhackmybusiness.com. That's all I've got. Guys, Josh, Mario, thank you for being here. we're gonna go ahead and wrap up. I'm gonna get my outro music playing. I just had to say that while I pulled up the right screen. And we're gonna take a break for a week. We'll see you guys next week. Take care. Joshua Holloway (1:01:22) Unhacked. Mario Zaki (1:01:22) I guess UNHCT Justin Shelley (1:01:23) Unhacked.
An unhandled error has occurred. Reload 🗙