Comms Under Fire: War Stories from the IR Trenches
Every incident response story has a technical arc: the intrusion, the containment, the eviction. But ask anyone who has run point on a breach, and they’ll tell you the outcome usually turned on something else: whether the team could actually talk to each other while the network they normally coordinate on was the thing on fire. In this episode, co-hosts Matt Calligan and Navroop Mitter sit down with Jai Musunuri and Clark Harshbarger, co-founders of Extrordinas, who spent the better part of a decade responding to some of the most consequential breaches in the world, across CrowdStrike and Kroll, and, for Clark, seventeen years as an FBI special agent, before deciding the problem was worth building a company around. The conversation runs on war stories where communication made or broke the investigation: threat actors reading remediation plans in real time, adversaries phoning the responders to taunt them, attackers shopping a victim’s own files for the insurance limit, and the quiet, expensive work of verifying who is actually on the call when you cannot trust the channel itself.
- The technical playbook and the trust playbook aren’t the same. Every IR story has a familiar arc: intrusion, containment, and eviction. But outcomes are often decided on whether the team can communicate when the network they normally coordinate on is the thing on fire.
- The threat actor reading the remediation plan in real time. Jai’s formative case, a decade ago: responders building a remediation plan in Microsoft 365 with a large retailer, until forensics showed the attacker reading the document as it was written, traced to a username belonging to the person across the table. The fix was a whiteboard and manual phone calls; the delay cost hours to days against losses in the millions per day.
- Identity verification is the hidden tax on crisis comms. Without purpose-built Identity Verification tooling, every time a new participant joined a Teams or Zoom bridge everyone had to stop while the newcomer held their license up on camera and a second person vouched for them, an expensive proposition when a company is losing a million dollars an hour. Without that discipline, a recurring tell was the participant with the camera off who drops the moment they’re challenged, taking your plan with them; deepfakes only make the verifier’s job harder.
- Attackers search your files for insurance limits, then leak your comms to force payment. Searching file shares and email for the cyber-insurance policy and extorting you for the same amount is all too commonplace when ransomware is employed, a pattern backed up by forensics who can later see the exact searches they ran because everything was indexed. Some go further, publishing a company’s own internal incident emails and chat to shame it into paying.
- On-prem isn’t a substitute for out-of-band. A government contractor assumed an on-prem Exchange server was safer while a nation-state actor sat on it for months reading project mail and the eviction plan. Out-of-band communication isn’t only for incident response; day-to-day security operations are what long-dwelling actors quietly surveil.
- Global incidents fracture across apps. In cross-border work, teams scatter across WhatsApp, Telegram, Signal, email, and SMS all at once, making tempo, participant validation, privilege, and audit trails all harder. A large, unvetted WhatsApp group is exactly where an adversary (or a well-meaning insider adding a reporter) slips in unnoticed.
- Do it before the root canal. Navroop’s framing: you don’t start brushing your teeth the day of the root canal. Out-of-band tooling belongs in day-to-day security operations, threat sharing, and board-level “classified-tier” communication. So, the people, the muscle memory, and the pre-staged IRP, comms plan, and insurance policy are already in place when the crisis hits.
- What Extrordinas is, and where AI actually sits because action beats reaction. Named for the extraordinarii, the Roman legion’s quick-reaction force, Extrordinas is a reactive platform built to democratize incident response for the organizations priced out of retainers, targeting high-volume scenarios first (business email compromise, eCrime, insider threat) and using AI to compress data acquisition, normalization, and analysis from weeks down to a couple of hours. The thesis is Clark’s law-enforcement mantra (it’s not if but when), so the goal is to make credible response affordable enough that “do nothing” stops being rational.
Navroop Mitter:
[00.00.03.21–00.00.29.18]
This is Navroop Mitter, founder of ArmorText. I’m delighted to welcome you to this episode of the Lock and Key Lounge, where we bring you the smartest minds from legal, government, tech and critical infrastructure to talk about groundbreaking ideas that you can apply now to strengthen your cybersecurity program and collectively keep us all safer. You can find all of our podcasts on our site and listen to them on your favorite streaming channels.
Navroop:
[00.00.29.20–00.00.31.08]
Be sure to give us feedback.
Matt Calligan:
[00.00.31.13–00.00.58.11]
Hey there! Welcome to the show! I am Matt Calligan, here as always, and joining me today is our co-host and CEO, Navroop Mitter — with a particularly unusual format that we don’t normally do here at the Lock and Key Lounge. So I’ll give you a little backstory. Every incident response tale and story you’ve ever heard has the technical arc that we all know well the intrusion, the containment, the eviction.
Matt:
[00.00.58.11–00.01.23.00]
But if you ask anyone who’s run point on a breach, they’ll tell you the thing that decided whether it went well usually wasn’t what type of malware was there, it was how the team responded, how they communicated with each other, the reality on the ground while the network that they were normally used to having these conversations on and collaborations on, was the thing that was on fire.
Matt:
[00.01.23.00–00.01.38.03]
And so we’re really getting into those war stories today with two people who have lived it and breathed it for years in various capacities, before deciding to actually take all of that experience and build a company around fixing it.
Navroop:
[00.01.38.05–00.01.58.02]
Yeah, this is a conversation that actually started before Black Hat — frankly, well before Black Hat, continued during Black Hat, and now has spilled over. Since we discussed so many different war stories, we decided we really wanted to have these gentlemen on. So our guest today spent the better part of a decade responding to some of the most consequential breaches in the world.
Navroop:
[00.01.58.06–00.02.07.17]
First, they were on different paths and then it turns out they came together on one. Please welcome Jai Musunuri and Clark Harshbarger, co-founders of Extrordinas.
Matt:
[00.02.07.21–00.02.10.05]
Jai, Clark — welcome to the show.
Jai Musunuri:
[00.02.10.07–00.02.12.18]
Thanks for having us on. Thanks, Matt.
Matt:
[00.02.12.20–00.02.48.14]
Yeah, absolutely. So I’m going to do the humiliating thing and let’s make you listen to your own bios for a second. Jai is co-founder and CEO of Extrordinas. He spent a decade at CrowdStrike as an incident responder, working some of the highest profile breaches that we know of today. As an early employee, he helped build out the incident response practice from the ground up, including CrowdStrike’s Asia-Pacific IR operations, and was among the first to apply AI to incident response work at scale.
Matt:
[00.02.48.16–00.03.26.19]
He’s also a recognized voice in macOS security. He’s a frequent conference speaker, credited with identifying a vulnerability in macOS and iOS. Jai holds a B.S. in Industrial and Systems Engineering from USC, and an MBA jointly from UCLA and the National University of Singapore. Clark is co-founder and Chief Business Officer at Extrordinas, and former Director of Incident Response at CrowdStrike. Before moving into the private sector, he actually spent 17 years as an FBI special agent focusing on cybersecurity investigations.
Matt:
[00.03.26.19–00.03.56.04]
So experience that gave him that rare vantage point across both law enforcement and commercial incident response, along with direct access to the federal agencies and the Fortune 500 C-suite during a crisis. Clark holds a B.S. in Mathematics and Computer Science and an M.S. in Computer Science, actually with a software engineering specialty, from Utah State University and an M.S. in Information Security from the University of Alaska Fairbanks.
Matt:
[00.03.56.06–00.04.31.03]
So guys, here’s the tension we’re going to sit in today. The moment an incident starts, you all know this. Well, working with the clients and the services you provided. They’re the network you normally trust. As we know. You can’t use that to coordinate the response on the same network that’s likely compromised. So the question today is, like I said, we’re going to focus on these war stories, but we really want to focus on how do you actually run those investigations from your own internal side.
Matt:
[00.04.31.05–00.04.57.10]
You know, from the client side, other parties that come in, like counsel or board members, and how do you do that when you can’t be sure who’s listening, who has access to what, whether these channels are safe? How do you validate those channels? You’ve lived with those questions for years across Kroll, CrowdStrike, Clark with inside the FBI before choosing to answer it by building Extrordinas.
Matt:
[00.04.57.10–00.05.24.18]
So what I’d like to do is really focus on three components here: how your partnership actually started — we’ll key off there. The operational problems that kept surfacing in your side conversations at CrowdStrike. We’re going to really go most of the time here on these war stories. Right. And then where all of those lessons learned then were fed into Extrordinas.
Matt:
[00.05.24.20–00.05.48.10]
And honestly, where AI fits into these, you know, into this model right now, everybody keeps slapping AI on everything right now. But where does it fit? How does it play a role? I’d love to hear that from a non-vendor AI standpoint. Right. Just with your experience and everything you’ve done, I know you wanted to take on segment one there.
Matt:
[00.05.48.10–00.05.50.21]
So you want to kick off that side.
Navroop:
[00.05.50.23–00.06.04.17]
Sure. So let’s start at the top right. Because how did you guys cross paths. What resulted in the partnership that became Extrordinas? Did it start with weekly coffee chats? Was it a company retreat? Walk us through how you two came together.
Clark Harshbarger:
[00.06.04.19–00.06.36.11]
Okay. Thanks. I’ll take this one. So CrowdStrike Services is a remote first organization, meaning all of our folks were distributed throughout the United States and the world at large, and they did a really good job of making sure that we had regular chats and, you know, built up mentors and advocates and, you know, tried to keep team morale high, which is hard to do with a remote team where nobody meets in person.
Clark:
[00.06.36.12–00.07.01.15]
I joined at an odd time in 2021, just after Covid, and they weren’t doing company retreats for a couple of years when I came on, and so there wasn’t even an opportunity for onboarding or getting to know folks face to face. I joined a team where some people had been on teams, where they started in offices and moved to remote, and then others like me had joined and just been fully remote from that time forward.
Clark:
[00.07.01.17–00.07.23.00]
So as part of that onboarding process, CrowdStrike would assign a mentor or a champion to make sure that you learned the ropes and became acquainted with the personnel and procedures that would most benefit you in your role. I had understood that my champion was one individual at my level, another director on the Incident Response team.
Clark:
[00.07.23.00–00.07.56.23]
But this consultant — principal consultant at the time — Jai reached out and wanted to chat and get to know me. And so we started having weekly chats, and I from that time on just assumed that for whatever reason, Jai had been assigned my onboarding champion, and we had these talks and we talked about things that were good in CrowdStrike, how they compared to the FBI, how they compared to other places that I had been, and then what we could do to really optimize and deliver better services as the as the organization that we were working for.
Clark:
[00.07.57.01–00.08.20.04]
So about a year in I’m talking to Jai and it hadn’t crossed my mind because we just talked good business and had a cordial, friendly relationship and things were well, so there wasn’t any need to question that. But I asked him, I said, Jai, so, you know, were you assigned to be my onboarding champion? And he said, no, we’re just having weekly chats.
Navroop:
[00.08.20.05–00.08.32.22]
So wait, wait, wait, I have to ask — what made you target Clark? I was going to let you keep going, Clark, with the story, but I actually want to know what made you target Clark. You just usurped his career counselor’s role as mentor.
Matt:
[00.08.33.00–00.08.34.18]
He’s like M.I.A., the real guy.
Navroop:
[00.08.34.19–00.08.48.08]
You know, the real guy doesn’t need to show up. And Jai’s there every week. What’s going on here? What went through your mind? What made you target Clark? Was it his? The scruff on his face? Was it the green mustache? Is it the great head of hair? Like what’s happening here?
Jai:
[00.08.48.10–00.09.06.19]
I think I reached out to the new employees, especially if I talked to them or interviewed them before they joined. And then with Clark, if you’re just kind of on the same wavelength, you kind of talk about the same things, have the same ideas, you know, you just keep talking to him. Just keep checking in. You know, you can always bounce different ideas off each other, talk about how you want to make things better.
Jai:
[00.09.06.20–00.09.12.04]
It just really grows from there. I mean, you know, if you kind of think the same way, you’re just going to always chat.
Navroop:
[00.09.12.05–00.09.31.07]
Well, fair enough. So given the growth that CrowdStrike experienced during this time, how many of these weekly coffee check ins are you having with people, or at least that initial one to find out whether or not you vibed? Are you doing, like, coffees a week? Was it just Clark? I mean, so we’re trying to figure out here what brought you to Clark, because there must have been hundreds of other new joiners during the time, if not thousands.
Navroop:
[00.09.31.13–00.09.33.18]
What was what was going on there?
Jai:
[00.09.33.20–00.09.48.03]
Well, it was a services team, and I think we had a lot of growth during that time. So I checked in with a lot of people. But I think Clark is probably one of the people I talked to the most besides my direct team, my manager and my director. But for somebody not in the reporting chain, it was definitely Clark.
Navroop:
[00.09.48.11–00.09.49.23]
Interesting.
Clark:
[00.09.49.23–00.10.16.02]
CrowdStrike really liked to promote from within, which is great for loyalty and engenders loyalty to the company and gives you a path to be able to look forward. I was one of the few that came from an outside organization directly into that role, and so it was great to talk about things and differences, and really what we could apply to make our organization better.
Clark:
[00.10.16.02–00.10.20.11]
So it started out great and we just maintained a friendship from there on.
Matt:
[00.10.20.12–00.10.21.04]
Nice.
Navroop:
[00.10.21.05–00.10.42.21]
Yeah. And actually I think that just lends itself naturally to what were some of the differences you noted between the different environments Because, if I remember correctly, you went FBI to Kroll and then to CrowdStrike, right? Did you go straight into the FBI right out of college? What was the journey there and what were the differences you noted between those different organizations and, actually,, frankly, how they handled a crisis?
Clark:
[00.10.42.22–00.11.04.07]
Yeah. Great question. So I entered the fray — my graduation was May of 2001. And at the time I thought, well, I’ll just take a couple of months off before I dive into my career. So you can read the room and understand what that looked like. A few months later when everything in the country was turned upside down.
Matt:
[00.11.04.12–00.11.04.18]
Yeah.
Navroop:
[00.11.04.21–00.11.10.01]
Well, I’m right there with you. I remember how all my plans changed as well at that moment. Yep.
Clark:
[00.11.10.05–00.11.37.02]
Yeah. So it went from a field of plenty for opportunity. And even in the cybersecurity space, everything tightened down after 9/11. And so it was a tough market. And so while searching for jobs I at a career fair at a local university ran into the FBI in person. And the first time I ran into them, it was prior to them even having their application available online.
Clark:
[00.11.37.02–00.11.42.14]
So I had to submit an application — a regular paper application, like we used to.
Navroop:
[00.11.42.17–00.11.45.14]
This is old school. You actually handed in physical paper.
Clark:
[00.11.45.15–00.11.46.16]
Physical paper?
Navroop:
[00.11.46.22–00.11.51.23]
Wow. Did you mail it in? Or did you just walk up and say, here’s my resume, here’s my paper?
Clark:
[00.11.52.00–00.11.59.19]
I ran across them at the career fair. And I went back the next day and handed them a paper copy of their application and my resume.
Navroop:
[00.12.00.00–00.12.10.18]
That’s awesome. Such a difference from how people would do it nowadays. I’m sure the kids are just like, wait, you had paper? What are you talking about? I just went to the website, filled in three details, and they knew everything else about me.
Matt:
[00.12.10.20–00.12.15.23]
Interesting. Clark, was cyber kind of the focus from the beginning?
Clark:
[00.12.16.01–00.12.50.19]
Yeah. So the FBI has always had a list of critical needs. And at that time cyber was one of their critical needs. So, like language and some of the other specialties, That was one of those things that they were actually targeting. So it was a great opportunity for me as I was looking for a job and looking for a way to contribute to the improvement and protection of the nation that met lots of ends, and it was a good means to a good career and a good way to serve the communities that had so well served me.
Matt:
[00.12.50.20–00.13.04.22]
Yeah. Well, and it put you at the beginning of — I mean, in the context of war stories, I mean, you’ve seen every one of them that, you know, of recent memory or of note, you know.
Clark:
[00.13.05.00–00.13.14.10]
Yeah. I know we’ve talked through some of where our war stories are going to go, just as a preview here, but I’ve got some physical war stories that overlap too. So.
Matt:
[00.13.14.12–00.13.42.18]
Well, that’s a good segue. Jai, I’ll start with you on this. Obviously not naming names. You know, maybe sectors, those kinds of things. Where the use cases are focusing on the investigation itself. I guess, when we were pre-gaming this earlier on, This was the segment that sort of goes wherever it goes.
Matt:
[00.13.42.18–00.14.00.18]
So kind of with that background, where did you start? What was that first moment from your background in cyber and things like that, where you’re coming face to face with this scenario, what’s kind of that first one that stands out to you from a from that war story standpoint?
Jai:
[00.14.00.23–00.14.29.09]
Yeah, sure. So I think the first case that really was notable and really started making me very paranoid about the active monitoring of communications was probably almost ten years ago, I did a case for a large retailer in the US. And back in those days we did a lot of work on site. Things change after Covid, you had a lot more remote collaboration, but even being there with the customer on site, most of their team in this one conference room with us, they still had some people remote and at other sites.
Jai:
[00.14.29.09–00.14.49.20]
We’re still doing some communication over Zoom, Slack, Teams, what have you. But we’re sitting with a customer and talking about a remediation plan while we’re doing forensics. They’re trying to fix things, and as we’re doing our forensics, we noticed that the threat actor is reading the remediation plan as we’re building it, as we’re all sitting together.
Navroop:
[00.14.49.21–00.14.55.04]
Was it a Google Doc? How did you spot them? How did you know that they were reading the IRP?
Jai:
[00.14.55.08–00.15.17.05]
So we were going through Microsoft 365 forensics, sifting through there, because they were still using the in-band communication tools to distribute this document internally, because they needed a lot of different stakeholders from security and IT and infrastructure to be on board to get it done. And you start looking through it and you’re saying, I’m telling them, hey, like you’re working on it, but they’re reading it like you need to stop working on this.
Jai:
[00.15.17.05–00.15.24.06]
You need to get this offline. We need to we need to print this out or do something because this is not going to work because they know exactly what your next step is.
Matt:
[00.15.24.08–00.15.33.15]
So what was the tip-off? Was it somebody else’s blinking cursor in there? What was that first, like, what the hell?
Jai:
[00.15.33.16–00.15.47.20]
We were just doing forensics. We were trying to do the standard rundown of what did they access. And you kind of get this trigger and you say, hey, I recognize that username. That’s the guy sitting across the table from me, and you trace it back and you’re like, oh, this is a document you’re working on.
Jai:
[00.15.47.20–00.15.55.23]
And he turns his laptop around and it’s open — that’s the one he’s working on — and they’re reading it as he’s building it, and you just tell him, hey, you’ve got to stop this.
Matt:
[00.15.56.02–00.16.05.14]
Wow. What happened next? How did you get to, okay, we can’t use this thing anymore? What was the pivot?
Jai:
[00.16.05.16–00.16.08.01]
From there? It was writing it on the whiteboard.
Matt:
[00.16.08.05–00.16.11.00]
No good old.
Jai:
[00.16.11.02–00.16.28.11]
Yeah. Basically, you get the whiteboard marker and get it on the whiteboard. I think there were some manual phone calls to other parties. So no in-band communications at that time, just to communicate and distribute the plan. It was challenging. It made it much more difficult once you realized, hey, they’re watching us.
Navroop:
[00.16.28.13–00.16.45.14]
What was the what was the loss of time, though I can imagine at that point when you have to literally pause the shared collaborative document, you’re all working on, that you’re going to distribute, and having to go to a whiteboard. There must have been some pretty significant loss in time and or delays in your response and remediation efforts.
Navroop:
[00.16.45.14–00.16.49.09]
What does that look like? Can you quantify that? I’m kind of curious here.
Jai:
[00.16.49.11–00.17.05.02]
I think at that time it was probably hours to days of delays in the remediation, but they were facing losses millions per day with the kind of incident they were facing. So it had a real impact. We were delayed in doing the remediation because of this.
Navroop:
[00.17.05.03–00.17.12.04]
So every hour is hundreds of thousands of dollars, if not millions, at that point. I’m assuming it’s compounding though, too.
Jai:
[00.17.12.06–00.17.25.07]
Yeah. For a large enterprise, when your business operations are down or even part of your operations are down, like you can’t do online retail or in-person retail or payment processing, it costs money. You’re losing money that you may never get back.
Matt:
[00.17.25.09–00.17.33.17]
Clark, what was your first big moment of kind of wading into those wading into those scenarios?
Clark:
[00.17.33.21–00.18.11.01]
Yeah. So the very first occurrence was an advanced persistent threat and national security case that evolved and developed into one of the largest Chinese APT cases that led to some of those top ten that sit on the FBI’s cyber wanted list. So investigating government organizations that had long embedded threat actors within the environment and were monitoring all forms of electronic communication and out-of-band communication wasn’t part of the incident response plan.
Clark:
[00.18.11.03–00.18.35.11]
By its nature, one of the most fragile parts of that is the potential destruction of those phone trees and organizational trees. So one of the first steps that we learned for remediation was having printed out copies of those phone trees. So the first out-of-band communications that we recognized and recommended were regular telephone, and having those on a printed-out list.
Matt:
[00.18.35.12–00.18.38.08]
Physical dial. Yeah, going back.
Navroop:
[00.18.38.10–00.18.57.16]
I heard a rumor once — and it is a rumor — that I think involved CrowdStrike. No one ever named it, but based on the description of who was helping out, we believe it was CrowdStrike. They said that they got into a situation where the communications plan, or the list of all the phone numbers and everything else meant to be used during IR itself, had been compromised.
Navroop:
[00.18.57.16–00.19.10.05]
It was on like the SharePoint or something, and somebody either inserted a phone number or deleted someone off of it. There’s something critical that had been manipulated about that file. Is that something you actually ran into, in your cases or a colleague’s case?
Clark:
[00.19.10.07–00.19.40.06]
Yeah. I haven’t heard of that one specifically. But you know, it was not uncommon for our phone tree and line of command for those operations to get phone calls from the threat actor. It wasn’t an every incident occurrence, but I would say it was not uncommon. Maybe, you know, every five incidents we would have a threat actor reaching out to prominent incident responders within the organization, either to taunt them or to try and misdirect them.
Matt:
[00.19.40.08–00.19.41.07]
Yeah.
Navroop:
[00.19.41.09–00.19.44.19]
So they had everyone’s contact information. They got it from somewhere along the way.
Clark:
[00.19.44.20–00.19.54.11]
Oh yeah. That’s what I found. I would say posting the phone trees on SharePoint, and on other file share services before SharePoint, was very common, unfortunately.
Matt:
[00.19.54.14–00.20.03.23]
I have a pet theory here, because you started at the FBI — but Clark, did you have a military background before that?
Clark:
[00.20.04.01–00.20.07.04]
No. Straight-up nerd.
Matt:
[00.20.07.06–00.20.45.02]
So you’ve been adjacent to this. This is my pet theory about background — nation-state, and military is the most common one. But when the nation states are the adversaries you’re going against, and there’s — I think it was Jon Schlegel, the CSO of CLEAR. He made a comment during our Field Notes event that he’s flabbergasted that it’s still taken 20 years and the private sector is still catching up to this idea that you need to have redundancy and resiliency built into your communications technologies.
Matt:
[00.20.45.03–00.21.10.08]
The PACE plan and all that kind of stuff. And my pet theory is that when you come from a federal agency or a military background where you actually are dealing with, you know, nation-states who mean you harm, the mentality is, of course, we need various communications tools in our stack because that’s what the enemy does.
Matt:
[00.21.10.12–00.21.36.22]
The enemy tries to intercept your comms because that’s how they’re going to figure out what you’re going to do next. Whereas the private sector, up until recently-ish — the past decade — didn’t really have to face that kind of an adversary where they’re using military tactics, which is where the delay comes from. That’s my pet theory. Being that you’ve been on the federal side and now on the private sector side, does that hold water from your perspective?
Clark:
[00.21.37.00–00.22.03.11]
I’ve got a short anecdote. So, we all get tired of government spending. I think that that’s a pretty fair statement to make. No matter what side you’re on, our tax dollars go for a lot of things that we may or may not feel are valuable assets. One of those, for example, within the FBI — or law enforcement generally — is our SWAT operations. A common mantra in the military is no plan survives contact with the enemy.
Clark:
[00.22.03.13–00.22.33.14]
Comms are the very first thing — communication is the very first thing to break down in any operation, whether it’s military or a law enforcement intervention. So our radios — we used Motorola encrypted radios, extremely expensive compared to what the local law enforcement would use. The difference was that we were encrypted from radio to tower, and tower to handheld radio, so that none of our communications could be monitored.
Clark:
[00.22.33.16–00.22.54.04]
It was not uncommon, and it still is not uncommon, for scanners to be used by criminals so that they can predict — even if it’s encrypted comms, they’re just listening for traffic to see if law enforcement is conducting any operations in their area. So it’s a common tactic for threat actors to use both in the real world and in the virtual world.
Clark:
[00.22.54.04–00.23.06.17]
And it’s something that we protect very securely. And it’s very important within law enforcement. It’s the same level of security that we need within the virtual environment also.
Matt:
[00.23.06.19–00.23.07.19]
Yeah.
Navroop:
[00.23.07.21–00.23.27.15]
Kind of curious — Jai, Clark, coming back for a second. So since it is so common even in the virtual environments to encounter this, right, it’s not just the police scanner on the radio now, it’s the adversary actively compromising your O365 and listening in or watching the shared doc back and forth. What were some of the technologies you pivoted to besides phone calls?
Navroop:
[00.23.27.15–00.23.44.23]
I imagine ten years ago, phone calls, yes. But now there’s probably a desire to pivot to other things, especially with how distributed people are across time zones, geographies, the fact that they need more context. than you can get with a low-context phone call or a walkie-talkie, right? There’s probably more they’re looking for in terms of images or docs.
Navroop:
[00.23.45.01–00.23.52.13]
What kinds of technologies did you get asked to pivot to, and what helped guide what you were going to pivot to in each of those cases?
Jai:
[00.23.52.17–00.24.17.10]
So there were a lot of, I’ll say, high effort ways of solving this. A lot of the instances — companies didn’t want to pivot to anything new. They tried using existing collaboration tools, which I’d say were extremely painful processes. Clark experienced this too. We would have Teams meetings or Zoom calls where you would have to manually verify every single person who joined.
Jai:
[00.24.17.14–00.24.34.20]
And imagine you have IR firms, recovery firms, the internal IT team. You could have dozens of people on these calls, and every time someone would join, you have to have them turn on their video, verify who they are, have somebody else verify who they are. Get them on, and then say, okay, now the room’s safe again.
Jai:
[00.24.34.21–00.24.50.07]
You can go ahead and talk about what you need to talk about. Share files, share documents. But as you can imagine, it’s very laborious, very slow. And the moment somebody joined a call, you’d have to stop talking and verify them before they could be in there. It was not great.
Navroop:
[00.24.50.09–00.25.01.00]
So when you’re losing $1 million an hour, that extra 45 minutes or hour-plus of identity verification out-of-band is pretty costly.
Clark:
[00.25.01.04–00.25.13.10]
Imagine not only that it’s cumbersome, right? Holding up your driver’s license or passport next to your face to verify you. If you don’t have a secondary verifier, administratively there’s a lot of overhead with that.
Matt:
[00.25.13.15–00.25.26.15]
Have you been in these scenarios where there was a deepfake concern as well? I know that’s a relatively new thing, but I’m curious whether that came up while you guys were still out in the field.
Clark:
[00.25.26.19–00.25.27.20]
Yeah.
Jai:
[00.25.27.22–00.25.40.12]
Yeah, I think that’s why there was a secondary verifier, someone to look at your face or listen to your voice, or have your manager on, or someone else who knew you, so that they could try to verify your identity. But there is still always the risk of that.
Navroop:
[00.25.40.14–00.26.00.15]
And if I’m not mistaken, Nature had that article where, under normal conditions, you only get it right about a deepfake voice about 60% of the time — 40% of the time you get it wrong, and that’s when you’re not under duress. So it sounds like that’s not the best bet for identity verification during these kinds of crisis moments.
Jai:
[00.26.00.19–00.26.20.15]
And I think a lot of this came from — to some people, it seems like a very paranoid move to try to do this verification. But as we had seen, we had so many cases where the threat actor would join the Teams meeting, they would compromise an account, get on the meeting where they’re talking about investigating the incident, how to remediate, and you’d realize, oh, wait, that person’s camera’s off.
Jai:
[00.26.20.17–00.26.38.15]
They’re not saying anything. And the moment you try to call them out, they just drop off and all of a sudden your operational information is leaked — especially if you have a Teams channel and everything is in there, it’s all gone. And now they know what the next three steps are. So that’s where these processes came from. And as you pointed out, it costs time.
Jai:
[00.26.38.15–00.26.41.18]
And time is money in these scenarios.
Navroop:
[00.26.41.20–00.26.57.06]
But I also imagine if you’ve given away your operational playbook, or they at least know the next three steps, they’re going to pivot. They’re probably going to find some new place to stay resident in the network. They’re going to change, you know, tactics at that moment and try to find a new way of getting their objective met. Right.
Navroop:
[00.26.57.12–00.27.09.02]
Did you often see that? Did this become one of those things where, great, we were chasing them in one place, they now know we found them over here, and suddenly we’re having to start all over again with our search and forensics to try to find them elsewhere.
Jai:
[00.27.09.06–00.27.24.05]
Absolutely. It ends up as a game of whack-a-mole. They know what your next move is, so you go after what you think they’re going to do next, and they pop up somewhere else. It just becomes so incredibly difficult. And some of these threat actors were really, really good at reading the documentation.
Jai:
[00.27.24.05–00.27.28.07]
We would joke that sometimes they knew the org and the plans better than anyone at the org.
Clark:
[00.27.28.11–00.27.36.02]
They often knew the networks and the shadow technology and shadow equipment better than the organization did.
Matt:
[00.27.36.02–00.27.39.21]
Some of them got job offers after they finished hacking, right?
Jai:
[00.27.39.23–00.27.46.09]
They really understood it better — the whole layout — than anyone in the company. It was incredible.
Navroop:
[00.27.46.11–00.28.00.08]
So actually, here’s the question. Was it principally about staying a step ahead of the remediation efforts, or were they doing it to go listen in on the ransomware negotiation strategy? Why were they listening? Was it always about staying ahead, or was there some other objective for listening in?
Jai:
[00.28.00.11–00.28.20.19]
I think from my experience it was just staying ahead and understanding what was next so they could stay a resident in the environment. There were definitely some scenarios — and I’ll let you chime in if you have some stories — where they read the insurance policy, where they try to get information, or where you see them specifically look for the insurance policy to figure out how much they could ask for.
Matt:
[00.28.20.20–00.28.23.21]
They know the limit.
Navroop:
[00.28.23.23–00.28.25.23]
Finding these insurance policies — where were they really finding them?
Clark:
[00.28.25.23–00.28.29.21]
All in file shares and emails.
Navroop:
[00.28.30.03–00.28.33.04]
Right. So all the in-band normal file share and communications.
Clark:
[00.28.33.04–00.28.56.04]
All very searchable. That’s the hardest part — it’s all indexed and searchable. And when we pull forensics, we can see their keyword searches. Now it’s part of the ransomware and threat actor playbook to conduct searches, both for vulnerability and exposure information as well as for the insurance policy and limits.
Navroop:
[00.28.56.08–00.28.58.06]
That’s interesting, you guys. Oh, go ahead.
Jai:
[00.28.58.11–00.29.15.21]
Sorry, I’m going to stay on Clark’s comment too. You had cases where they would expose the communications to try to almost out the company as incompetent, saying, here are their emails or internal messages about responding to the incident. And I saw this multiple times — just trying to shame them and pressure them into paying the ransom.
Navroop:
[00.29.16.02–00.29.37.03]
I remember seeing a couple of cases like that — like that French retail company where their O365, or their Teams chat, I guess, was posted as live screenshots from inside the ransomware negotiation discussions, a strategy discussion they were having internally, not the negotiations itself, but the strategy around how much to offer and what not to offer. But I got a question.
Navroop:
[00.29.37.03–00.29.52.14]
Have you guys ever put together a piece that lists, here are the keywords or things that they’re likely to go search for? So proactively go clean up your file share and your, you know, your email and everything else so that none of these things will be found when they do break in and they start searching for them.
Clark:
[00.29.52.18–00.30.24.09]
I haven’t done that specifically. There are lots of data loss tools out there and that would benefit from a, you know, a searchable index like that. However, most of them require administration on the front end, getting their systems configured internally. That often just doesn’t happen. They go with a defined configuration. So even providing a list like that isn’t as beneficial because they haven’t configured their DLP tools in the first place.
Matt:
[00.30.24.10–00.30.25.08]
Yeah.
Navroop:
[00.30.25.10–00.30.52.22]
I was almost thinking of an exercise. So you’re running a tabletop of some sort, where the DLP hasn’t necessarily been configured correctly up front. Someone simulates what the threat actor is going to go search for next. Then highlighting the need for why we need to go back and fix the configuration that we should have already had, or at least do some of the cleanup so it’s not sitting out there anymore — by extracting it from there, placing it somewhere else where it’s more secure and out-of-band, and then making sure that it’s all cleaned up right.
Navroop:
[00.30.52.23–00.30.55.00]
And where it would have been in the first place.
Clark:
[00.30.55.04–00.31.17.07]
Yeah. There’s lots of low hanging fruit like that too, right? Why does any organization allow upload to file upload sites that are generic and aren’t used specifically within a company that could have been locked down from the very beginning? So I hear you, and I would love for an organization to do that. I think many of them are just holding on for dear life.
Clark:
[00.31.17.08–00.31.30.00]
They’ve got one person who’s overtaxed and overburdened, doing the very best he or she can with the resources they’ve got. And so I think that’s part of our job as cybersecurity practitioners is to help support that.
Navroop:
[00.31.30.05–00.31.46.14]
That is fair. That is absolutely fair. Guys, I’m wondering, are there other interesting war stories you’d like to share? Other scenarios? Are there any that are sector-specific? I remember when you and I were talking once you had mentioned a couple of things and, and I thought there were some sector specific anecdotes in there as well.
Navroop:
[00.31.46.15–00.31.54.14]
So, kind of curious — do you guys have other stories you want to share? Because this is, frankly, a lot more fun than where the rest of the question document was headed next.
Clark:
[00.31.54.18–00.32.34.19]
So my very first experience with insurance policy documents was with the FBI — a commercial organization that served customers in the local community, and a threat actor, a very popular threat actor at the time. They purchased credentials from an access broker, accessed the network, searched for insurance documents, obtained the limits, extorted the dollars that matched those limits, and then published embarrassing emails and data at regular intervals.
Clark:
[00.32.34.19–00.33.05.22]
So this is prior to ransomware and extortion being a named threat — I would say early in the 2010s. But then that threat actor had set up email forwarding rules. So it wasn’t monitoring out-of-band communication. But the company didn’t have very good operational security, and they were still continuing to use email and phone systems that we had recommended they not use.
Clark:
[00.33.05.22–00.33.15.05]
So they continued to do so even in the face of understanding that the threat actor could be, and indeed was, reading and leveraging those communications.
Navroop:
[00.33.15.08–00.33.20.20]
Interesting. What’s the highest dollar amount you ever saw someone extort in those cases?
Clark:
[00.33.20.22–00.33.30.21]
Oh, boy. These days those levels have gone very high — on the order of tens of millions of dollars for initial requests.
Navroop:
[00.33.31.02–00.33.35.14]
Interesting. What about you? Other stories you’ve got? Kind of curious.
Jai:
[00.33.35.15–00.34.16.11]
There was a case, maybe 10 or 11 years ago, with a government contractor working on, let’s say, sensitive projects for the government. They had a nation-state threat actor sitting on their server. They weren’t using M365 — no cloud-based email, all on prem, which some people may have thought, okay, this is more secure. The threat actor was just sitting on that server, on Exchange, watching the emails go in and out to monitor the kinds of projects and plans that were being sent back and forth with the government contacts, and ultimately reading about the response effort too. They were reading all the updates — how the org was going to take out the threat actor, how they were going
Jai:
[00.34.16.11–00.34.26.21]
to eradicate them. And it became very difficult. I mean, with one of those threat actors, they’ve been there for months or years, and getting rid of them also takes you months or years if they’re always watching what you’re doing.
Navroop:
[00.34.27.00–00.34.31.01]
Yeah. I imagine if your eviction strategy is known, they just keep staying a step ahead.
Jai:
[00.34.31.06–00.34.38.20]
Correct. And they thought on-prem Exchange was the best approach. And, you know, they were still monitoring all their communications.
Navroop:
[00.34.38.22–00.35.07.18]
It kind of confirms something we’ve long said — that these kinds of out-of-band communications aren’t necessarily just for incident response. It’s also for when you’re actually just conducting day-to-day security operations. Right? Frankly, what it means is, is that you were being proactively surveilled, unbeknownst to you, for quite a long time.
Jai:
[00.35.07.21–00.35.25.00]
That’s right. These threat actors, you’ll see in a lot of cases, try to go into the repository — whether it be your SharePoint, Teams chats, what have you, just to gather more information about how you’re running your operations day-to-day, because that helps them figure out how to evade your day-to-day team.
Clark:
[00.35.25.03–00.36.04.01]
It reminds me, though — at CrowdStrike and Kroll, we had documents and preparation to help companies that were in their moments of crisis. And part of that was setting up out-of-band communications and secondary communication channels for exchanging not just voice communications, but data and text. Even with that at hand, in the middle of a crisis, I’d even venture to say most companies preferred to use what they thought were the frictionless, easier buttons.
Clark:
[00.36.04.01–00.36.30.16]
The Teams chat and the things that were already incumbent — because getting that information for out-of-band communications out to their teams and getting their teams on board with using them and then ingesting that data internally seemed like a hill that was almost insurmountable for them. So I think it’s a real challenge to integrate secure communications outside of what they’re already using internally.
Navroop:
[00.36.30.18–00.36.57.10]
Yeah, I think that’s why for us, for so long, a lot of the emphasis has actually been on doing this more proactively. Right. You don’t start brushing your teeth when it’s time for the root canal. You have to have been brushing along the way, before the dentist comes out with the drill. Right. And so I think one of the things Matt and I have often said is, is that this is the kind of thing you need to be using day-to-day as much as possible in security operations, threat sharing, maybe even as a classified-tier communication.
Navroop:
[00.36.57.10–00.37.18.02]
So board members and others are already used to using it for other high value transactions or other high-value or sensitive situations. And that way when it comes time for incident response, they’re better prepared. They already know the tooling, they already know everything else. Because to your point, setting it up in the middle of a crisis — they’re probably afraid it’s going to be a distraction, no matter how easy you make it.
Navroop:
[00.37.18.03–00.37.51.18]
We’ve certainly had customers come back and say, hey, turns out it was super easy. We got up and running in minutes. A lot of our IR retainer partners, that’s exactly what they will do. They’ll actually help their clients set up well in advance, but also then set up during crisis itself. And they do get moving. But I do think there’s a lot of value and already having it done right, already having the insurance policy, the IRP, the comms plan, things like that — architectural diagrams, whatever else you may need — pre-stored in the right channels that are only visible to the right parties, who then take responsibility for getting it to others in the middle of
Navroop:
[00.37.51.18–00.38.10.03]
a crisis. And so, yeah, I think that’s a great point. It’s if you’re doing this for the first time or think about it for the first time in the middle of a crisis, you’re probably going to have a harder time with it. That’s interesting. Moving on from war stories a little bit then — well, actually.
Navroop:
[00.38.10.08–00.38.11.06]
Oh, go ahead, Jai.
Jai:
[00.38.11.09–00.38.17.21]
Yeah, we could talk a bit about communication outside the US as well, for global companies.
Navroop:
[00.38.17.23–00.38.24.09]
Oh yeah. Absolutely. Would love to jump into that. I was going to move to the boring question. So this is far more interesting.
Jai:
[00.38.24.10–00.38.47.01]
So from my time in APAC and working with customers across the globe, communication is different. What we think about here in the US — we have email, we’ll use Slack, we’ll use Teams. Maybe we’ll send an email, send an SMS, just make a regular phone call. Outside the US, people use all kinds of collaboration platforms, and I’ve experienced this with customers who use anything and everything.
Jai:
[00.38.47.02–00.39.11.04]
You would have a WhatsApp group, you would have the Telegram chat, you would also have the Signal chat. And customers are having trouble communicating across the globe because their teams were just using different communication methods, and even from the IR consulting side, we would be thrown into these different platforms and the information was scattered. Some people are talking on WhatsApp, some people are on email, some people are on Slack.
Jai:
[00.39.11.05–00.39.27.04]
You have no way of understanding what’s going on. It’s hard even to get that operational tempo going, because we’re trying to go out-of-band without one solution. It was very difficult. And on top of that, you’re still trying to validate, hey, is everyone on this chat supposed to be in here? And is everyone supposed to get this info?
Jai:
[00.39.27.06–00.39.45.04]
Because you also don’t want to leak this information out. We may not have been concerned that the threat actor was in the chat, but you also don’t want to expose the info to people who don’t need to know in the organization. And that’s another problem that would come up in these chats is now you have somebody who doesn’t need to know the information.
Jai:
[00.39.45.04–00.39.50.06]
It leaks to the media, and gets leaked to other sources that really don’t need to know this at this time.
Navroop:
[00.39.50.08–00.40.10.21]
When you were working overseas, were the technologies that people proposed when you said, hey, we need to move to something out-of-band, were they different from the common ones we would hear? It would be like a Signal or a WhatsApp, or occasionally you hear someone talk about Telegram — and it’s like, please don’t, unless you’re going for real end-to-end encryption. But otherwise, please don’t.
Navroop:
[00.40.10.23–00.40.13.22]
Were the suggestions that came up in APAC different?
Jai:
[00.40.14.00–00.40.38.12]
Most of the time it was WhatsApp, definitely. I did encounter Telegram. I think with WhatsApp, you encountered people who used it for their day-to-day communication. They would often just ignore the company collaboration tool and use WhatsApp to talk to each other for normal day-to-day business. So they’d say, hey, let’s just make a WhatsApp group and do the incident response in there — which, once again, just made things more complicated.
Navroop:
[00.40.38.14–00.40.52.14]
It’s like the wild, wild West. You’ve got a large WhatsApp group. No one’s checking every single phone number. You don’t know if you actually just added the adversary in or if a rogue insider just did it for you. Right? Like, oh, here’s the reporter I want to let in because she bought me a drink last night.
Navroop:
[00.40.52.18–00.40.53.22]
So she’s in the chat.
Jai:
[00.40.54.01–00.41.07.04]
And even beyond that, when you’re trying to disseminate information, especially if you have a US-based company trying to maintain privilege, you’re trying to keep the attorney in the loop or keep other stakeholders in the loop. It’s much more difficult if you don’t have a centralized communication channel.
Navroop:
[00.41.07.08–00.41.30.23]
I also imagine, though, that producing an audit trail of who said what to whom, when it was said, how it was consumed, also becomes difficult because you’re probably having to go back and image devices or maybe make backups of their WhatsApp chats, How are you, from a forensic standpoint later on, going back to your client saying, hey, yes, we captured everything — or was that even your responsibility to say, yes, we’ve captured everything.
Navroop:
[00.41.30.23–00.41.43.00]
We know what was said and done, and here’s how we’re certain that it wasn’t tampered with, because there was a coordinated effort to go delete something before we could actually do the imaging of the devices. Did you ever run into those challenges?
Jai:
[00.41.43.03–00.42.01.07]
I don’t think we gathered the communication trail for the customers. We try to work with counsel to make sure that there was no aging off of the data. But beyond that, it’s very difficult to track back, trace back, who was doing what, who said what. I mean, you preserve as much as you can, and it’s almost like the attorneys figure that out later.
Navroop:
[00.42.01.11–00.42.23.12]
Yep. My job is done, see you later, lawyers — have at it. That makes sense. It really is up to them at that point. We’ve talked to lawyers in the past who’ve been responsible for it, and they just talked about how expensive or time consuming that gets and how many unknowns that linger, because that process just wasn’t something they normally do day-to-day themselves.
Navroop:
[00.42.23.13–00.42.53.03]
Right. And so they’re scrambling for how to get that part done because there is no official tool for this. That’s really interesting because I’m kind of wondering, is there a house rule the two of you follow on every engagement now, just because of scar tissue from all of these stories? Is it that we’ve already proactively got our own Signal chat set up, with the files already in there? Or, hey, you’re becoming an ArmorText customer tomorrow and you’ve already got all this set up? What are you guys doing as a result of all this scar tissue?
Jai:
[00.42.53.07–00.43.09.14]
It’s almost ingrained in us. We’ve learned so much that I have to think about how we incorporate all these things. I think they’ve become default behaviors for us — how to operate out-of-band, verify who we are, make sure we know who we are. I think it helps that we’re a small org, so we know who each of us are.
Jai:
[00.43.09.20–00.43.13.16]
Clark will probably know very fast if it’s not me talking to him.
Matt:
[00.43.13.21–00.43.17.22]
Yeah, you two have worked together — that familiarity is all you need.
Jai:
[00.43.17.23–00.43.27.16]
Yeah, I think that carries through today — we know when somebody is not one of us.
Navroop:
[00.43.27.18–00.43.39.11]
But as you grow towards your billion dollar valuation, you’re going to have hundreds, if not thousands of people. And I fully believe your tech is getting there. So, you know, I imagine that’s going to become more and more difficult to maintain at scale.
Jai:
[00.43.39.12–00.43.42.19]
Yeah. Well, maybe that’s where our own tech comes in.
Navroop:
[00.43.43.00–00.43.46.08]
Well, it could help on the secure comms side, and on IDV.
Matt:
[00.43.46.09–00.44.12.00]
Obviously, having seen patterns emerge from so many of these various experiences, that created sort of a lessons-learned playbook. I’m assuming that playbook, from both of your perspectives, is what informed how you went forward with Extrordinas. Is that a fair assumption?
Jai:
[00.44.12.02–00.44.14.02]
Yeah, absolutely.
Navroop:
[00.44.14.04–00.44.36.07]
Guys, shifting gears for a second, right. I don’t want to skip the opportunity to talk about Extrordinas either, because I think what you’re doing is quite impressive — I’ve seen the demos, but I’m assuming our listeners probably have not. And so given that, I’d love for them to get the elevator pitch, the elevator version of the story, where does the AI actually sit in that process versus what’s just the marketing side of it?
Navroop:
[00.44.36.07–00.44.43.18]
Just give our listeners a feel for what it is you’re building and why, and what’s so different about it from everything else that came before?
Clark:
[00.44.43.22–00.45.25.14]
You bet. So what we learned as practitioners was that incident response was often out of the price range and out of the capability of many teams that really needed that assistance. So all but the largest enterprises and organizations that could afford retainers and incident response assistance from some of those great teams out there, like our former employer — it was really left in the hands of large enterprise and government organizations that could afford to pay for the services directly or afford the insurance that would leverage these more capable teams.
Clark:
[00.45.25.15–00.45.45.13]
And everybody else was kind of left out in the lurch. So in the beginning, when Jai reached out and recognized this gap in the market and the ability for AI to assist in democratizing some of some of this incident response activity, it was a perfect fit and a no-brainer for me to jump on board.
Clark:
[00.45.45.13–00.46.13.04]
So, Extrordinas — the name comes from the Roman legion. Their quick reaction force was the extraordinarii. When the legion got into a situation where they couldn’t defend themselves or get out without assistance, they called the extraordinarii to come bail them out. Like the Roman legion, we hope to be that for those who get into a situation they can’t afford, that they can’t survive, and where they just need that assistance.
Clark:
[00.46.13.04–00.46.47.03]
And we want to come bail them out. So we aren’t attacking all incident response activities, or all of the things that every threat actor does. What we have done is categorically chosen those areas that we can most offer assistance in. And that starts with the activities that have huge impact and lots of volume — meaning there are lots of attacks going on, and many organizations are just choosing to overlook what has happened and not even go through containment.
Clark:
[00.46.47.03–00.47.16.02]
And incident response exercises. We’ve provided a platform to allow that to happen and not only allow it, but make it a necessary part of every organization’s response to any of these activities. And that starts with business email compromise, eCrime, insider threat, and then a litany of others that are on the roadmap and coming. But those are the deliverables that we’ve got right now to really help those companies that are seeing these kinds of high volume attacks against their organizations.
Clark:
[00.47.16.03–00.47.18.10]
Jai, do you want to chime in and help me out here?
Jai:
[00.47.18.13–00.47.39.05]
Yeah, sure. I think I’ll get to what Matt asked about — how AI plays into all this. The way we see AI work with our solution is being able to get through that data and get that analysis done faster. Clark and I have seen sometimes analysis just between acquiring and normalizing the data and doing the analysis can take hours, days, weeks.
Jai:
[00.47.39.05–00.48.01.06]
And a lot of companies just need to get back to business now. They don’t want to be losing money because their operations aren’t working, because people have cut them off for payments. They need the answers today to make business decisions, to get back to business. And what we’re trying to do is just speed that process up, bring it to everybody, and make it cost-effective for all these organizations.
Matt:
[00.48.01.09–00.48.22.16]
Do you find that the typical business that would find this kind of solution useful? Are you going after the giant organizations out there with the deep pockets, or are you sensing that this is a better fit for something below that, below the giant enterprise?
Jai:
[00.48.22.19–00.48.43.13]
Yeah. Well, I think this is a great way to help improve efficiencies for enterprises and those big organizations. We’ve also found that a lot of mid-market to smaller orgs, including people like MSPs, are finding this very valuable, because in the past they may not have had this capability at all. They had to go to an expensive consultant, file an insurance claim.
Jai:
[00.48.43.13–00.49.01.10]
Now they have a capability to just be able to investigate, ask the question. Hey, what happened? I got this alert or my user’s reporting that they fell for a phishing email. What happened? How bad is it? What did they take? What did they look at? And how do I get back to business? So they’ve gone from no way to answer this to a way to answer this.
Jai:
[00.49.01.10–00.49.03.06]
And they find this very valuable.
Matt:
[00.49.03.10–00.49.34.14]
And do you see that impacting how those companies engage? The way you’re phrasing this, it sounds like there’s a layer of companies — obviously still very much critical, and they will be targeted. This is something they’re going to need, But they’re now not forced to make the choice of, we’re not going to do anything, because doing something triggers this cascading cost for us, and just to investigate or dig into this a little more is too expensive.
Matt:
[00.49.34.14–00.49.49.18]
So we’re not going to look at all. It sounds like now the opportunity is that these small organizations have access to that retainer — that advisor retainer, that consultant retainer — but in an automated fashion. Is that a fair description?
Jai:
[00.49.49.20–00.50.09.18]
Yeah. You hit the nail on the head. This really lowers that barrier to entry. So they’re not just ignoring it or trying to solve it themselves, which leads to a variety of results and really depends on the skill level of a team and what tools they have access to. We really want to make sure that they have access to the best information and get a quick answer so they can get back to business.
Jai:
[00.50.09.20–00.50.28.00]
We’ve seen time and time again where ignoring the problem just makes it worse because all of a sudden your data is leaked on a leak site, or the threat actor gets back in. We’ve seen where a different threat actor gets back in, because the original exploited vulnerability was just left open — they never figured it out — and now it’s a party for how many different threat actors.
Matt:
[00.50.28.06–00.50.30.05]
Just tag team basically.
Jai:
[00.50.30.06–00.50.32.04]
Yeah, we’ve seen that too many times.
Matt:
[00.50.32.09–00.50.55.07]
If I am a small business right now, what am I looking for? Am I aware of the problem that this addresses, or do you find that there’s some education around why you need to up-level here? Who’s usually coming to this table and where are they in their awareness of the issue.
Jai:
[00.50.55.12–00.51.17.09]
I think small businesses sometimes aren’t aware of how severe this can be until an incident actually hits them. So what we’re finding is that going to MSPs, or those who provide IT services or security services, has been really valuable for us, because they’re able to do that enablement for their customers. And a lot of the time they’re the ones looked to for that response effort.
Jai:
[00.51.17.10–00.51.33.05]
They’re saying, hey, something’s going wrong. You’re my MSP. Can you go and take a look at it or figure this out? And we’re saying, hey, here’s now a tool and a platform where you can just say, yeah, I can go look at that for you. Get the data through here, tell you what’s going on. Let’s just fix it and you’re back to business.
Jai:
[00.51.33.09–00.51.45.08]
And it doesn’t have to become this arduous process of calling someone else to investigate, doing all this work, and then your systems don’t work for a whole week or two weeks. You should be able to get the answer in a couple of hours.
Matt:
[00.51.45.09–00.51.57.02]
Clark, as the Chief Business Officer there, how does that inform your activities? How are you engaging folks on that side to get that message out?
Clark:
[00.51.57.02–00.52.20.08]
So, you know, from my law enforcement days, we used to say action beats reaction every time. And so many organizations, as Jai said, simply sweep it under the rug, don’t deal with it even after having an incident. That pain point hits. But incident response takes specialized knowledge. It takes time and energy that many organizations just don’t have.
Clark:
[00.52.20.09–00.52.42.00]
So I think the problem doesn’t surface until they have an incident. And we are a reactive platform, meaning we step in where an organization would normally reach out to insurance or to an incident response firm, but in a much more democratized and affordable solution. So getting the word out isn’t difficult. This is happening.
Clark:
[00.52.42.00–00.53.02.05]
It’s not if, but when. That’s a common mantra in cybersecurity. No matter what type of offensive activities you take in order to secure your perimeter, eventually the threat actor is going to get through. And everybody knows, on some level, that they need to have an incident response plan and a way to deal with that.
Clark:
[00.53.02.06–00.53.24.15]
So getting the word out that we solve that is my job. And part of that is making sure we inform the players in that space. So MSPs, enterprises, insurers and that they have a tool in their arsenal that doesn’t have to cost hundreds of thousands of dollars and take weeks to months to deliver.
Navroop:
[00.53.24.17–00.53.42.19]
I don’t know if you want to do it here or offline. Sometimes you don’t want to give away the secrets to your playbook on that, but I would love to learn more about how you’re actually going about that education process. Are there some guerrilla tactics you’re using? Some Jedi mind tricks you learned at the FBI? How are you disseminating that message?
Navroop:
[00.53.42.19–00.53.54.22]
Because it feels like a lot of folks have been trying to do that for a long time, and it hasn’t been sinking in. So if you’re seeing success that others aren’t, I’m curious — what are you doing differently?
Clark:
[00.53.55.00–00.54.18.17]
So one of the key players in this space is the law firm industry. Every organization, at some point, if you have something that rises to a level or raises a question about your finances or company structure and organization, you’re going to reach out to counsel. Counsel is a critical part of any incident response plan.
Clark:
[00.54.18.21–00.54.42.15]
But not only that, counsel’s recommendations protect you from litigation in the future. It doesn’t stop the litigation, but it makes sure you’ve done your diligence to protect your company, your assets and your customers. The choices being made now are often in the face of counsel’s recommendations. We know that from speaking to our law firm partners.
Clark:
[00.54.42.15–00.55.03.16]
So having partners in the delivery of that message I think is one of our key assets here. It’s not just us, it’s the insurers. It’s the law firms. Everyone’s got the same basic communication strategy. We have different targets and reasons for wanting to communicate it. Ours is that we’ve got a solution, that we can provide answers.
Clark:
[00.55.03.16–00.55.06.08]
You don’t have to just think that it’s out of your reach.
Navroop:
[00.55.06.13–00.55.20.22]
Yeah. I mean, likewise, I think we’ve been spending a lot of time talking to lawyers over time. It’s why we’ve made so many friends — our friends at Lowenstein Sandler, now Holland & Knight, and Crowell & Moring. We spend quite a bit of time with all of them for that very reason.
Jai:
[00.55.21.02–00.55.24.04]
And we can talk more offline, too. I have more thoughts on this.
Navroop:
[00.55.24.05–00.55.45.22]
I would love to get the guerrilla tactics straight from you guys, because I’m sure you’ve strategized this to no end. I know we’ve gone significantly over, and that’s probably my fault for asking so many questions about war stories, but I just wanted to capture as much as we could. I know you both have a heck of a lot more, so maybe let’s jump a little ahead.
Navroop:
[00.55.45.22–00.55.50.08]
Any final thoughts before we get to kind of the fun closer that we normally do?
Clark:
[00.55.50.11–00.55.58.03]
I think I’ll leave it with my last one, which is action beats reaction. We want to be part of the action that you can take.
Navroop:
[00.55.58.05–00.56.21.10]
That makes a lot of sense. Well, guys, for both of you then. Imagine you’re at the bar. It’s a really nice one — like the Lock and Key Lounge would be if we had our own physical space. You guys are the kind of people who like to talk to folks. But this is kind of more that quiet place where secrets are held in close confidence.
Navroop:
[00.56.21.11–00.56.34.17]
At the end of the bar is someone in security you’ve been dying to talk to. You finally see your opportunity — they’re there by themselves. First, what cocktail are you ordering? And second, who’s actually at the other end of that bar?
Jai:
[00.56.34.23–00.56.40.15]
I can go first. No cocktail — I’ll take a Laphroaig 25, neat.
Matt:
[00.56.40.17–00.56.41.18]
Nice.
Navroop:
[00.56.41.20–00.56.43.00]
Really good. Okay.
Matt:
[00.56.43.02–00.56.45.00]
Strong pull.
Navroop:
[00.56.45.02–00.56.51.01]
You are a man after my own taste. We are doing that next time. Now that I know what you like — there we go.
Matt:
[00.56.51.03–00.56.57.02]
You want the smoke to precede you as you approach the guy, right?
Navroop:
[00.56.57.04–00.57.00.06]
You would have enjoyed the Boss Hog I had yesterday.
Jai:
[00.57.00.08–00.57.08.06]
You’d be surprised. The Laphroaig 25 is not as smoky as some of the rest of them, and it definitely has a very unique profile to it. We’ll have to do it next time.
Navroop:
[00.57.08.11–00.57.09.13]
We’re going to have to do it.
Jai:
[00.57.09.17–00.57.10.05]
Looking forward to it.
Matt:
[00.57.10.05–00.57.11.04]
Absolutely.
Jai:
[00.57.11.06–00.57.26.21]
But who’s on the other end of that bar? I’d want to talk to Cliff Stoll. I’ve seen some of his content, heard his stories, and I have his book. He’s one of the first people to do incident response and digital forensics — I think it was in 1986.
Matt:
[00.57.26.22–00.57.28.20]
Oh, wow.
Jai:
[00.57.28.22–00.57.37.19]
For a breach at the US government. Very interesting guy if you watch his content. But it’d be fun to have a one on one conversation with him.
Navroop:
[00.57.37.21–00.57.41.04]
Have you ever met him before, or heard him speak live?
Jai:
[00.57.41.06–00.57.47.21]
Not live, no. But I’ve seen his content, and he wrote a book too, and it’s very interesting.
Navroop:
[00.57.48.03–00.57.57.21]
Very cool. Okay — Cliff and a Laphroaig 25, I like it. Clark, what about you? What are you drinking, what are you ordering, and who’s at the other end of the bar for you?
Clark:
[00.57.57.23–00.58.24.22]
Yeah, I’d say I’m pretty generic, pretty classic — I’ll drink an old fashioned. And that’s a tough question. There’s a variety of hackers, I guess, from my law enforcement days. I’d love to — I always want to ask the question why. Interviewing was my favorite part of being an FBI agent. But I guess, opportunity-wise today, it would be Kevin Mandia sitting at the other end of the bar.
Clark:
[00.58.24.23–00.58.34.18]
Of all the weird coincidences, he was one of the first instructors in Wi-Fi hacking I had in the FBI. He taught the class himself.
Matt:
[00.58.34.22–00.58.35.09]
Wow.
Clark:
[00.58.35.14–00.58.46.23]
Early on in his days. And then to see where he’s taken his business and his success today — I think there’s a lot I could learn from his journey.
Matt:
[00.58.47.04–00.59.09.13]
Absolutely. I always enjoy the answers to that question, because it gives you insight into how people are thinking through the next steps, what information they’re going to find useful next, and where they’re heading. Well, gentlemen, I do appreciate you guys taking the time today.
Matt:
[00.59.09.15–00.59.17.07]
I know we asked this before, but before we wrap up, any closing comments or thoughts you want to leave us with?
Jai:
[00.59.17.10–00.59.38.07]
I think it’s an exciting world out there. I know we’re an AI company, and there’s a lot going on, but — I probably said this a little bit earlier — it’s important to focus on what’s actually driving value, AI-wise. I think we’ve always kind of kept it as a North Star, like we’re using AI, but what is the ultimate result for the customer?
Jai:
[00.59.38.08–01.00.02.07]
What problem are we really solving? And we’re always focused on how do we make incident response more accessible to people with this new technology? Right. We don’t want to bolt this on to every random thing and try to sell some snake oil. But what is really actually helping them get back to business, deal with these problems, deal with the threat actors and not just be another person out there peddling some weird solution.
Jai:
[01.00.02.07–01.00.07.06]
So we’re really focused on the customer and how to help them.
Navroop:
[01.00.07.08–01.00.25.06]
At the end of the day, it’s kind of like the blockchain hype cycle. We’ve already seen it in the recent past, right? Blockchain got added to everything, including where a database would have been dramatically more valuable and more efficient, but at least temporarily. If you wanted to get that VC check, you added blockchain. And I think the same thing is going to happen with AI.
Navroop:
[01.00.25.07–01.00.43.03]
So I love the fact that you guys are focusing so much on how to actually make AI valuable and truly deliver for the customer, and not just trying to force it into every single possible nook and cranny you can. It’s why it excites me to talk to you guys about the potential for partnerships and everything else in the future, too.
Matt:
[01.00.43.04–01.01.06.20]
And if there’s one thing that’s clear to me through all of this conversation, it’s that there’s certainly the technical arc of an incident that’s always present — that framework we’re all familiar with. But it’s the insight from the people on the ground, from all the angles, everyone involved,
Matt:
[01.01.06.20–01.01.31.08]
That is actually where those lessons are learned. And unfortunately, Clark, as you mentioned a couple of times, most folks aren’t finding that out until mid-incident, or the hard way. So it’s great that you all are bringing these lessons learned — beyond just the standard framework — into these organizations that oftentimes can’t access it.
Matt:
[01.01.31.08–01.01.37.21]
It’s making it more accessible. So, gents, thanks for taking the time to pull the curtain back on this one.
Clark:
[01.01.38.02–01.01.38.20]
Thanks, Matt.
Jai:
[01.01.38.20–01.01.40.05]
Thanks for having us.
Matt:
[01.01.40.11–01.02.05.08]
Absolutely. And for everybody listening, thank you for your time as well. We’re all busy, we’ve got lots of things to do, and spending 30, 45 minutes with folks like us — it’s an honor that you’d spend that time with us. But until next time at the Lock and Key Lounge: be well, stay curious, and do good work.
Matt:
[01.02.05.10–01.02.38.08]
We really hope you enjoyed this episode of The Lock and Key Lounge. If you’re a cyber security expert or you have a unique insight or point of view on the topic, and we know you do, we’d love to hear from you. Please email us at Lounge@ArmorText.com or our website ArmorText.com/podcast. I’m Matt Calligan, Director of Revenue Operations here at ArmorText, inviting you back here next time, where you’ll get live unenciphered, unfiltered, stirred—never shaken—insights into the latest cybersecurity concepts.