Martin Hinton (00:09) Welcome to the next edition of the Cyber Insurance News and Information Podcast. I'm the executive editor of Cyber Insurance News, Martin Hinton. And today, joining me out of the UK is a freelance journalist, Danny Palmer. He's been working in the cybersecurity space for about a decade now. And he has a really interesting story of the arc of cybersecurity, cybercrime, the threats we face, the scale, the damage. So we're going to go through a bit of history today. based on his career, his experience, his reporting. And I think what it'll help people understand is the rise of cybercrime, the rise of the cost, the rise and escalation of the damage that can be done. And also give people a sense from someone who's there on the ground talking to CISOs and cybersecurity experts in a place that's sort of the heart of this in some respects in the UK about where we stand in this scale thing. again, Danny Palmer, a freelance journalist out of the UK. Danny, thanks so much for joining us today. Really, really appreciate the time. I've read a ton of your work, excellent stuff, really detailed, thorough, a bunch of places. And I'm going to ask you to name drop a few so that we can spread the wealth. But Danny, first of all, thanks for joining us. Tell us a little about how you got into this space, how you started in cybersecurity reporting. And we'll just go from there. We'll start at the beginning. So again, thanks for joining us. Go ahead. Danny Palmer (01:36) Thank you for having me Martin much appreciated as you said I've been covering cyber security for a little over a decade now I sort of know my background is as is a journalist I Came out of journalism school in 2008 My first job after outside of that was in was actually the gaming industry It wasn't a very large website, but I was talking to the game developers designers that sort of thing wasn't about the games themselves per se was about how they were made, which sort of pushed me towards investigating the tech side of things. the hard, but back then it was hardware more, more like that. The Microsoft connect was a big thing back then. don't know if you remember that, but then in 2012, I joined a computing magazine, uh, as a staff writer, a long standing, uh, B2B IT publication. Uh, back then it still had a print edition. So that was 2012 and it was. I've still got some of the, I've still got my first front cover around here. I think on my LinkedIn recently, I think it was in a post I made, which it's still cool to see that. So I was there for about three years and my role there was quite generalist in terms of covering B2B IT. One of the big things at the time was the rise of cloud computing, which was the big brand new thing at the time. following that, but Part of this role also involved, no, I basically got to pick out what was interesting to me. And I did quite a lot of stuff on cybersecurity, which is where my first taste for it came from. Then from there, I moved in 2016 to ZDNet, where still here in London, where I joined as senior reporter. And there I found myself gravitating more towards covering cybersecurity. because there's two reasons for that. A, it was always happening, there's always something to write about. And B, it was interesting to report on and I'm sure we'll get on to some of the differences between now and then. But one of my first stories at ZDNet back in 2016 was a ransomware attack against a local council in the north of England. And something that shows how much things have come along since then is that ransomware demand was £350 which is no tiny tiny amount which didn't get paid. Martin Hinton (04:09) For the American audience, I guess that's about $380 or so. I haven't checked the exchange rate lately, but. Danny Palmer (04:16) It was about $500 at the time. I've got that in my article still. I was, even though I was based in the UK, was very much writing for a global audience. So I followed major events that happened around the world. Now I covered things like WannaCry, NotPeture, also the way cyber attacks became more cloud-based as we moved into the pandemic. Now if there's been a major cybersecurity event between, since about 2016 till... till my time at ZDNet ended in 2023, I've probably written about it. So after that, I seven years at ZDNet and I moved into a role that was a head of editorial at a cybersecurity company where I was essentially responsible for building a website that was, I guess you'd call it thought leadership. I was writing features about cybersecurity, AI and where they intersect. It was an interesting role. was challenge having that building something like that. I was there for just under two years. That role, as I'm sure many people are aware, industry can be quite fickle. So to my surprise, that role was eliminated early this year, early 2025. So since then I have been, I've made the shift to freelance, something I'd always considered, but I suppose this kind of forced me into it, but I'm finding it to be very satisfying role as I'm doing lots of things, I'm doing lots of features about cybersecurity, some of which we'll get into. I've had my work appear on various publications that I hadn't appeared in before. Just in the last week or so I've had. Pieces appear in Computer Weekly the Stack and data center dynamics with a few more on the way I also do other other things as well. I a lot of I'll get you to call it consultation work these days as well, so very much involved Martin Hinton (06:27) You are. Danny Palmer (06:28) with cyber security companies as well with their Advising them on thought leadership, I suppose you'd call it Martin Hinton (06:36) Yeah, well, mean, so put a pin in that because one of the things that I find being a journalist has only been at this for two years or so now, but 30 years in the business. I've crossed the spectrum of kind of complicated subject matter. I don't know if I've ever dealt with something as complicated. And then also the language is serves as a bit of a gatekeeper. I mean, if you look at, you know, an incident response company's website and their qualifications and certifications, it's this litany of acronyms. And if they're selling to companies that are not run by people who are, I mean, they could be very computer literate for the purposes of how that works within their own business. But it is this blizzard of alphabet soup that doesn't mean anything. that's something I was curious that we can get into. But I want to get back to the origins. $500, 300 pounds, roughly 10 years ago. What? What was the landscape like then? When that happened, was it sort of a novelty 10 years ago? Were people like, this is going to only get worse? What was the perspective you experienced within the community of people you dealt with in that space at the time? What was the reaction to that sort of thing happening? mean, it's not a unique story, but 500 bucks, I mean, it's a lot of money, but it's not relative to now with regard to ransomware. Danny Palmer (07:58) Back then, this seemed to be one of the first cases that I remember, in any case, of an actual business being hit by this sort of thing, because previously there had been what people, one of most common ones of forms of ransomware is called police locker, where it basically, an image flashed up on your individual home user screen saying, oh, you have been visiting this naughty website, or you have done this crime, pay this to get out. And again, that was a few hundred pounds. So until this point, ransomware is very much focused on individuals. And even back then, there things like phishing messages were the main way it was sent out because, no, it was easy. If you send out a hundred thousand spam emails and yeah, a thousand of those that get clicked and no percentage of those pay you a ransom, you're probably still me up, know, quite a few, 10,000s of dollars or pounds. So it was very much a, it did feel like a bit of a novelty back then and the entire ransomware industry has changed from being what was, I don't want say amateur, but this has become corporate for want of a better term. These ransomware groups have evolved. They operate more like businesses than anything else nowadays. Martin Hinton (09:20) Yeah, I think that you touch on something there that I think that maybe people who don't live in this space like you and I do, there's, this is highly organized crime. This is not, I mean, listen, the joke that's been made recently and the one I think is fair is that our eyes are a powerful sense. So if you ask chat GPT or you read this stuff, the hacker is always someone with a hoodie you can imagine in a mom's basement eating hot pockets. And that is simply not the case. I mean, I was chatting with someone the other day. who's saying, you these organizations have their own help desks if people are having tech problems. these are complex, organized situations because the money's there. There's an enormous amount of profit to be made. Do you think that that's something that the general public has a sense of? And we get these headlines, the Marks and Spencer's hack that, you know, there's a huge lawsuit just filed here with a company that makes things like cleaning products called Clorox. They had a vendor who was doing their help desk stuff that they've accused of. simply giving away a password basically to put it really simply. Do you think that the general public understands that this is not some sort of teenage chaos agent thing, but it's much more on the scale of, you know, like international crime and in the same way that drugs is? Danny Palmer (10:35) I don't think it's reached that point yet of that understanding. No, because as you say, that it probably doesn't help where there is so many of the articles and you see about cybercrime are accompanied by that stereotypical image of a someone, a man in a basement wearing a hoodie. I I always made a point at ZDNet of trying to avoid that sort of imagery at my default for reporting on cybercrime stories. And if it wasn't anything I could use that was related to the company involved. be a bunch of people around an IT support desk looking concerned and pointing basically. But it's an interesting thing because yeah, you've got this idea where there's still kids just doing this on their own, but it's not. mean, there was a ransomware group a few years ago. I think it was the Conti ransomware group, which three, four years ago was one the biggest ransomware operators there was. And somehow a lot of their internal chat logs got leaked, which ultimately brought the group down. mean, the nature of ransomware means the people involved in it went and basically worked for other ransomware groups, their cyber criminal CVs and went elsewhere. But it was literally chat logs about working in an office. They were going to an office to do ransomware. There was chats about someone got locked outside the office because they hadn't brought their sort of pass card. and that sort of thing. So they are very much businesses and even with help desks as well, you know, for victims, they, they want you to pay the money. So if you, if they, if they attack an organization and the business doesn't know how to buy cryptocurrency, if that is indeed what they choose to do to pay the ransom, they'll have people there who can talk you through it because it's in their interests. to get this money. In some cases, the ransomware affiliation groups, it's not even the actual ransomware builders who doing the attacks. So they, like any other software, they sell this package, this tool to other ransomware, to wannabe cyber criminals who can deploy this. They either can use a subscription package, they can buy it outright. Sometimes it's a percentage. of the money made because I guess the ultimate thing here is ransomware is still a big problem because it makes money. Organizations are paying the ransoms because they want, they see, they perceive it as the quickest and most efficient way to get back their network back, which, isn't always the case at all. Cause even if you pay a ransom, things can go very, very wrong. It can still take months. recover. And also in that case, would just a lot of law enforcement agencies and cybersecurity companies advise against paying ransoms, you know, purely because of this. But when it when when some businesses are thrown into this situation, they perceive paying the ransom as the best course of action for better or for worse. Martin Hinton (13:47) Yeah, well, mean, a level of desperation sets in. I think that that's because this is an ongoing argument, right? There's a there's a cyber insurance policy that covers ransomware make you subject to being hacked and have to pay the ransom. And, know, I've heard stories about the hacking group before they request the ransom. They've they've read your insurance policy. So they know the the pressure point to reach without breaking you so that you can pay. And then to your point. there's that phenomenon where once it happens to you, there's this repetition factor, right? Like if you become a victim once and you pay up once, there's an argument to me that you're more likely to do it again. You know the procedure, you understand the process. I mean, you touch on this idea that reporting matters. And in the UK, I forget when it goes into effect, but it's critical infrastructure and... Remind me what it is, because this is another issue, right? One of the issues, particularly in the cyber insurance world, is assessing risk. And in the US, you have to report to the SEC if you're publicly traded, and then health care organizations have to report as a result of laws we have here. But in the UK, they're moving, in my opinion, a little more aggressively than other places with regard to this. Tell me about the reporting that's going to be required in the UK coming forward. Danny Palmer (15:09) Yeah, well, it's only recently sort of been put into legislation where there is the going to be the requirement for bodies in the public sector to report this. So you're talking about things like schools, hospitals, national health service, government agencies, the city councils, that sort of thing to to to report these attacks, because I guess the government wants them to be able to actually know what's going on. there was a quite major ransomware attack against a local council in London a few years back, which had very severe and ongoing effects, the role of people not being able to receive their housing benefits or health services or social care. That, to my knowledge, that local council has never actually officially said in public that it was hit with a ransomware attack. The National Cyber Security Center has in its annual report said this is a ransomware attack. I've seen it referred to as ransomware attack in many different places, but the organization itself has never done that. And I suppose this type of ruling is designed to bring about a bit more openness about this. I suppose with public sector bodies here, I don't think it'd be expected they'd be paying ransoms. No, essentially that means the government is paying a ransom. But I suppose part of the idea is to make sure that there is this reporting there for that. And even though it doesn't direct, it doesn't say that private sector firms need to report this, I guess part of the idea is to encourage them to also do so because you do get some organizations that are very open about what happened with an attack. The British Library was hit. a couple of years Martin Hinton (17:04) Yeah. Danny Palmer (17:04) ago by ransomware attack. some of their services were offline for months. Every step of the operation, they were very transparent about what was happening and have been quite widely praised for this. While there are other companies who will just sweep it under the rug and hope no one notices, to be frank. Martin Hinton (17:23) I mean, this sort of plays back into what we were touching on a moment ago about the idea of public awareness, right? I think one of the things that I mentioned just before we started recording is an article out of Australia that began with why are there so many cybersecurity events in Australia? And the article, they very quickly said it's probably because we have such a higher requirement for reporting, right? If you have to tell people about it, obviously they become more aware. And in my estimation or opinion, that's a big part of making it clear to the public that this is a problem. which then drives action in the parts of companies and governments to find solutions and remedies as long as they might last. So it'll be interesting to watch, just so you know, I have a theory that if we were having a drink, I'd go into more detail over, it's Lloyd's of London's history protecting shipping and insurance shipping. I feel Danny Palmer (18:11) Mmm Martin Hinton (18:12) like there's a legacy there that informs what I see as a forward leaning perspective on cybersecurity, because fundamentally, the inner tubes to to paraphrase an American senator out of Alaska, are the shipping of the modern economy, right? The digital pathways of the internet are, you know, not replacing shipping, obviously, but there's this new space that exists in a similar way. if you will, pirates with cool names are attacking the commerce that exists in these spaces. And again, it's a bit like the analogy I've used recently is if there's an armored car robbery and. It ends with the armored car and the doors open and there's bags of money blowing around the street and there's evidence of a crime. You can see it. You go, oh, that was a crime. That money was in my bank or I've used that bank. And the digital space, that doesn't exist. The end result of it all is a bit vague. Even with a data breach where people are like, well, what does it matter if 160 million logon credentials were stolen? And when you take the time to, particularly now with AI, go through how that information can be then coalesced with other data breaches. and used to paint a picture of whatever password you might be using for the next 50 iterations, because you always use your kid's names, birth dates, and your Danny Palmer (19:27) Mmm. Martin Hinton (19:28) mom's maiden name or whatever it might be, all things that are quite easy to find, you are making yourself an easier victim. You touched on the UK Cyber Center. it's a step aside for a second. One of your more recent pieces within the Stack is an interview with a gentleman who used to be the CEO, Ciaran Martin. Obviously, not unlike you, person who goes back into, I mean, I think he took that job just after 9-11. So we're going back 25 years or so. Am I right about that? Yeah, yeah. Danny Palmer (19:56) He's been in the civil service for that long. Yeah. The NCSC, the NCSC only started in 2016, but he's been with the civil Martin Hinton (20:02) okay, pardon me. Danny Palmer (20:03) service for decades or was he's now not in it anymore. But yeah, he was the NCSC's first CEO. And again, I remember when that was being set up, mean, reporting on this for so long. And yeah, I mean, it was tested as detailed in the article. Now within the first year, WannaCry happened. The WannaCry ransomware attack. which was later attributed to North Korea, which it was ransomware, but not in the even then traditional sense, because essentially encrypted and basically almost destroyed computers. Now there's the idea that they did want, they were trying to get money for it, but it didn't quite work properly. it was using a leaked tool from certain Western government agencies that had been leaked to self-perpetuate. It started, it got out there and one of the major organizations that hit was the UK's national health service. Partially because even back then, a lot of the computer systems and the national health service were quite old. They were running old versions of windows, which weren't protected against this sort of thing. So yeah, national health service was hit pretty hard with that, which is, know, caused the, it was one of the first things that the NCSC had to come in and. and help deal with the fallout of. And yeah, it was just so strange at the time where, already at the time I'd been covering cyber security for a number of years, but it was the first time that people I knew outside of cyber security were really asking me about what was going on. So remember turning onto BBC News and seeing how to explain the concept of ransomware on there. And that was really interesting because people noticed it going on. That's the thing. I guess it's the same as something else that's also covered in the article, I believe is the recent ransomware attacks in May against Marks and Spencer's and the co-op. So two of the UK's major retailers. Martin Hinton (22:13) Yeah, so just, I'll interrupt for people who aren't familiar. As I've mentioned to you, I was born in England. Marks and Spencer's is like saying Macy's or Bloomingdale's or Sears. This is a legacy retailer over a hundred years in existence where you can, I mean, it's a bit like Walmart here in the States where you can buy everything from bananas to sweaters. It is, I mean, my mom at any rate, I remember her well. So tell me a little more about what Ciaran had to say in that piece that you reported for the Stack that you think people need to know. Because some of the historical stuff is really interesting. You mentioned WannaCry. And I think that capturing the public attention, I mean, some of it's down to branding, right? It's like this cool name you throw in North Korea, and people are like, you've got my attention, right? And then the fact that it didn't work quite well, like they were experimenting with a new product, and they debuted it before it was quite ready to do what they hoped it would, which is you vaguely how i i i remember it and look at it and how i let filter out of my mind but what else did he have to say about the state of things and the trend were on what tell me a more about what he had to say Danny Palmer (23:19) We had a bit of a discussion about that of how that reaction to the initial want to WannaCry again, how that even sort of left sort of government even kind of paranoid about what was going on. He detailed to me how he was at a birthday party for one of his child's friends and he got a call from the government saying it's happening again. there was worries that there was a cyber attack happening because I think one of the major British airports, the IT systems had gone down. It turns out it was an IT failure, but it just gave that little bit of worry where there was always that doubt. And maybe there has been since, whenever there's some major technical outage, cybersecurity could be an issue. I mean, this wasn't in the UK, but earlier this year, I think it was in Spain and possibly Portugal as well, power networks went down and there was immediate talk of it, is this a cyber attack? Martin Hinton (24:27) So we touched on the $500 ransom 10 years ago. Now, when something like the power going out, it's not a, there was a fire at a transformer. The other thing, which is an indication of public awareness, and then also journalistic awareness, and we're just members of the public, right? It's now in our Rolodex of potential, don't forget this possibility, right? It could be a truck driving into something or a transformer that wasn't. service properly, or it could be a malicious act by someone sitting in a computer on the other side of the world. And that's an interesting sort of evolution of it all that you've touched on. It was pain in Spain and Portugal, and it was days of it, if I'm not mistaken. And it was in the end an infrastructure issue or a physical problem. I don't know what the right way to put it is, but it was not a cyber attack as far as we know. Danny Palmer (25:16) No, but it just shows to how IT infrastructure has such a massive impact on how we operate, which we were shown again. think this must, I think this was, I'm to think now, it was 2016 or 2017, the whole Maersk cyber attack, that was a ransomware attack, hitting the big logistics firm Maersk, which took out global shipping to an extent. They were having to use paper records in order to do things. prices of things went up because things weren't being transported around the world. Everyone remembers I think it was when the Evergreen ship was stuck in the Suez Canal. Martin Hinton (25:56) Yeah. Danny Palmer (25:57) This was that before that basically, but without the image of a ship actually getting physically stuck, but the impact was arguably much worse. Martin Hinton (26:06) And that's 10 years ago. And this is again back to public awareness and like the ability for us to see and then comprehend, look, a ship blocking a canal. Obviously things can't move. When those are ones and zeros, it's a little more vague. In the last week, NATO released a report basically saying, global ports and shipping is hugely susceptible because of legacy systems. And we won't get into the details of what makes people vulnerable. But a lot of it has to do with the fact that we add layers to whatever process or industry we're in and sometimes they don't integrate well. And that creates vulnerabilities across say, if you will, what is called the tech Stack or all the technology and devices that a company has in its sort of digital environment. That is where you get this sort of the collaboration of these events creates vulnerability. I'm trying to make it simple, cause I'm not a tech person. try to bring us sort of I don't know, something I understand, put it in terms I can comprehend. But that's another really, really good example. That single ship was in the news for days and there was that funny shot of a little bulldozer trying to dig it out. was like, everyone was Danny Palmer (27:14) Yes. Martin Hinton (27:14) like, what's going on? That visual makes the news. That's if it bleeds, it leads kind of journalism. And when it's guys who are trying to recover from a ransomware attack and they're pecking away at a keyboard or scratching their heads as they look at data sets. That's not good B-roll. That's not a great photo that's going to move clicks on a website or once upon a time papers off a newsstand. And I think that that's, again, back to what we were talking about, one of the challenges that I suppose people like you and I face in making this not something that scares people back into the caveman days, but something that they realize that, OK, I need to, whether it's a small business or whether you're thinking about what people are saying with regard to their company or culture around cybersecurity. So that's a really, really clever example. I want to jump forward to something we kicked around and you touched on it already. And it's the Marks and Spencer's hack. And I think that when Archie Norman, that's his name, right? Yeah, Archie Norman testified before parliament on this. I mean, this is just so you know, the Chairman of Marks and Spencer's is one of the, probably one of the more experienced business people in the UK. He was in private business. And then he was a member of parliament and now he's back running this. I think it's a, he's at 156 years old Marks and Spencer's are somewhere. Yeah. Yeah. So Danny Palmer (28:29) It's a yeah, it's a it's goes back to Victorian times for sure Martin Hinton (28:33) we're talking about a company that has talked about legacy and legacy systems, right? It's also global in the sense that it's got employees doing things like helping you ring up a t-shirt at a store in Manchester or it people in India who are helping with the backend management of payment processing or whatever it might be. So there are, he made the point of saying there are 50,000 employees in this company and there's it's the co-op hack and it was happening at the same time, but the Marks and Spencer hack seems to have gotten a lot more attention than that for reasons that I can't say I know, but take me through that, take me through that story and what happened because it was weeks and weeks of this reliable, consistent place. Again, as we've said, you could buy cereal, you could buy a sweater, you could buy a pair of socks, you could get your groceries. So I would say to Americans watching, think about suddenly you can't use Walmart online, you can't go to the store physically. Tell me a little about that from the perspective you had where you are, where the company's based. Danny Palmer (29:36) Well, because the first inclination that maybe I should have noticed something was happening was this is before the attacks were made public. One of my local stores where I live in South London is a co-op. I went there and shelves were not very full at all. And I thought, okay, this was the Easter bank holiday weekend. So I thought, okay, it's probably just Easter bank holidays and people off work, et cetera. That's probably why the stores are a bit empty. Yeah, this happened in the space of the same few days. came out that both Marks and Spencer's and the co-op were, suffered ransomware attacks. I'll speak about Marks and Spencer's more specifically, because we know more about that one, but no, that had the same thing where people noticed because they were going to these stores and the shelves were empty, especially in the, know, the fresh food produce bits. I said, Marks and Spencer's did everything, food. clothes, homeware, everything. And there are those signs that say, apologize for the lack of resource, lack of things to buy. And also their online website wasn't working either. You couldn't buy things online because of a cyber attack. And yeah, it was very big for the company. Obviously it made all the national press here because there was that very visual thing of what is... in some ways an institution sort of getting hit by cyber criminals. And it seems that the way it happened was that the attackers managed to spoof the M&S help desk into thinking they were an employee. So they must have got an employee's actual information from somewhere and they got the help desk. to reset their passwords and that sort of Martin Hinton (31:33) So Danny Palmer (31:33) thing. Martin Hinton (31:34) Archie, when he testified before Congress before Parliament, Danny Palmer (31:38) me. Martin Hinton (31:39) Archie Norman, the Chairman of M&S used the phrase "sophisticated impersonation." He didn't say deep fake, but that's all my mind thought was, but that phrase "sophisticated impersonation. So he seemed to confirm the idea that someone pretended to be someone else and Danny Palmer (31:54) Yeah. Martin Hinton (31:54) that was how they gained access. So a single person created this situation by resetting this password. Danny Palmer (31:59) Well, I think it's hard to say for exactly, but we're moving down the line here. Four arrests were made in the UK recently. In the UK this is to do with the ransomware attack. All pretty much teenagers who are on suspicion of being involved with this big ransomware group, which, the ransomware group is, I think it's Scattered Spider, I think it is. This is the group that's a part of. Like many ransomware groups, it's suspected of being operated out of Russia. But when these reports came through about these kids essentially being part of it, again, this is just my own thinking here, but I wonder if they were part of the process of this social engineering. Because if you are calling up to M&S to say, hi, I am John Smith. Here's my information, but I've... forgotten my password, can you set it for me? I don't think the help desk is going to... it might be suspicious if you're calling up with a Russian accent, let's say. Well, if you are a British kid doing this, okay, maybe you sound a bit young, but people go into the workplace at 16, 17. Maybe that was their real partner. Obviously, I'm just spitballing here, I don't know for sure, but I think that's an Martin Hinton (33:22) Yeah, I Danny Palmer (33:23) interesting thing to think about how this massive ransomware operation clearly had operatives involved in some case in the UK, much like how sidetracking here, but that this week, the week we recording, the woman who was helping to run North Korean sort of laptop farms in the United States, an American woman, was put in jail this week for that. So yeah, it just makes you wonder about. Yeah, I think think I think personally that's how these kids were involved then you get the whole thing about how do they get involved in that to begin with? Martin Hinton (34:02) I, caveat for some people outside the UK are not familiar. One of the conditions of the judicial system in the UK is once an arrest occurs, you really can't talk about it. So in the States, you might get all this information about what the police alleged they did. And that sort of thing doesn't happen in the UK. So you basically get in the case of the people who aren't minors in the four people who are arrested, because some of them were minors. I think there is names associated age, maybe where they were arrested or a little bit of detail Danny Palmer (34:29) Where they're from, Martin Hinton (34:30) about how they were arrested. and then nothing, it is radio silence. it's the law there. So you get that situation. But what I was struck by is that assuming alleged, they're just alleged to have been involved, but their combined age wasn't 80 years old, four people combined. So is this, obviously the allegation that they're involved with scattered spider, which is associated with nation state hacking as a function of Russian involvement. Part of me also thought, to join you in the speculation world and the hyperbolic existence is, is this just teenagers now instead of spray painting the side of a train car or a bridge? This is how kids are breaking glass on an abandoned building instead of throwing, this is the new Danny Palmer (35:16) I'm Martin Hinton (35:16) stone throwing in abandoned buildings windows? That may be much, because back to your example in North Korea, I can imagine them, again, who knows? But this could be one of the things they're like, oh, we didn't mean to do this. We thought it'd be like a day, you know? Because again, we don't know. So it's something to pay attention to. Because the other parts of this story that are interesting is that Marks & Spencer's has fairly robust cyber insurance. I think they have up to 300 million pounds worth of coverage. And they had also in the last year doubled their internal cybersecurity team to 80 people. You know, for those of you in the communications world and concerned about how to react to this, I highly recommend, and there'll be a link in the show notes to Archie Norman's testimony before Congress *Parliament*. And again, this is a guy who knows how to talk to this body. He was a member of it once, but it really is an example in the tone and tenor of crisis comms. And, you know, there was a lot he doesn't know. And he was very forward in the idea that sitting here now with the benefit of hindsight, do we wish we'd done more? We absolutely do. But this is the problem the companies face. It's really, really hard to get CFOs to spend money next quarter on something that may be a problem when there are things that they know will be a problem. And from large corporations down to small businesses, having this new concern with regard to cybersecurity inserted into a full pie, if you will, of already existing realities for revenue to be spent on and costs and that sort of thing, it's a huge challenge. And I wonder whether or not, this, you know, even in the last decade, as it's evolved from $500 ransomware to now, We're seeing reports about boards not really understanding and not communicating with the CISOs and CISOs having trouble attaching financial value to the cost of a ransomware attack So, you know, better to spend a penny now than a pound later kind of things. And there is the need in the, particularly in the publicly traded company world to say, okay, if we don't spend the million dollars this year on cybersecurity, it could cost us $15 million if we get hacked. And I wonder whether not that the... you have any thoughts about that sort of point in this where we see a lot of this sort of communication issues within large corporations and we see these surveys out of cybersecurity companies that seem to indicate this exists at a fairly high percentage of places where the IT people and the CISOs are having trouble getting the resources they need or they believe they need. What do you think about that? Danny Palmer (37:38) I think it's still a struggle in many cases. because IT and cybersecurity are fighting with everything else for budget. And I guess you can boil it down to cybersecurity. If you perceive the idea of just paying for cybersecurity, that isn't profitable in the short term. Let's think it, okay, why do you have to spend money on this? It's not making us money. But then on the flip side, if you're not spending on it, it's going to cost you more down the line if you get hit. by something I remember years and years ago. Now this is pre wanna WannaCry reporting on when I was back doing all generous B2B IT. Sometimes I'd be doing a case study. I'd speak to a IT manager at a local national health service hospital about why they'd chosen to use this software solution to help make this particular type of work more efficient. And you'd see a similar version of the story appear in local newspapers and you'd see comments going, oh, why are they spending money on cybersecurity like this is meant for the public saying why are you spending money on on the cyber security and IT and not healthcare? After WannaCry that kind of flipped on its head people are saying why weren't they spending on this and now there's there's quite a lot of reflection in the National Health Service on this as well because now with how the system works here the National Health Service is a public body it's no paid for it's no the costs are covered by the taxpayer so there's always a there's always the balance of getting efficiency for that spending, which, back then, 2016, maybe cybersecurity wasn't seen as a huge priority. I imagine that has changed now, especially with how technology has changed now, but it can still be difficult to get that funding in especially in public sector organizations, or the amount of times I spoke to CISOs who just in general, who said, okay, we didn't think it would happen to us for one reason or another. And then it happens to them. And then it's like, but that's it. Some of the most interesting things I've done over the years is speak to CIOs and CISOs who have been hit with a ransomware attack to know ask them, you know, who they want to share this information because they don't want others to go through it. And so it's really interesting to hear that because as touched upon earlier, it's still very rare for victims of ransomware attacks to even acknowledge the attacks, let alone speak openly about it. I the M&S is good example. The British Library, I think they put out a full report on what happened and a really transparent, useful report from a couple of years ago. or maybe a bit longer than that was the Irish healthcare service got hit with ransomware. I think it was in 2021. And this is an interesting case where they got hit with ransomware. Then the attackers were basically said, we didn't know you're a hospital. Here's the decryption key. But even then, Martin Hinton (40:50) Yeah, I- Danny Palmer (40:51) it's still took them months and months to recover and appointments were delayed. This was still in the time when we were in the sort of British Isles still in sort of semi lockdown. So people were going to get their vaccinations against COVID and things and couldn't do it. All these different types of appointments were canceled or impacted, which again shows the human cost of these types of attacks. Martin Hinton (41:24) So that's, I want to transition to the human cost and I'll start by touching on something you touched on. We did here at Cyber Insurance News a report on a survey of CISOs and within the corporate environment, within the competitive nature of business, which is broadly a good thing, I suppose, there's a siloing, right? Companies don't tell each other stuff. But the CISOs in this survey were like, well, we really benefit because there's so little reporting. When we talk to each other about what we're seeing and the threat intelligence we're getting from our different providers of that sort of thing, it's really, really helpful to us to collaborate and share information because it makes us more aware of the broad spectrum of threat that exists out there that maybe we're not seeing every day, but someone else is. And again, that's counterintuitive to the competitive nature of, if you will, particularly publicly traded corporations where there is a quarter to quarter enhance earnings, maximize shareholder value kind of mentality that undercuts that sort of collective, if you will, I guess, be a bit socialist about a collective mentality of information sharing for the broader benefit of everybody. it's, again, this is the challenge with the human element, right? That there is... We know this, right? We see this again and again and again, that the vast majority of reasons a cyber attack succeeds is down to some sort of quote, human error. And you and I discussed in the pre-interview and conversations we've had before this taping, the idea that, my idea that one of the crimes where it's still quite comfortable for people to blame the victim is cyber crime. know, someone clicks a phishing link or help desk employee is fooled by a deep fake. voice or, you know, to use Archie Norman's phrase, a "sophisticated impersonation. I wonder if you could touch on this idea, because you did a piece for Computer Weekly recently with a gentleman named Jason Nurse on sort of this topic. And I wonder if you could get into that a little bit for us, the human element of this and how, you we can't remove people from this process, right? And I'm of the opinion personally that even with AI, or whatever you create with technology, there needs to be a human being who is ultimately responsible for the existence of that article or that product or whatever it might be. Maybe I'm wrong about that. Who knows? Time will tell. But I feel that we can't remove people from this because what's the point if we don't have people involved? Tell me a little bit about the human element. Let's dive down into that, the social engineering, insider risk. We've looked at here in America the vulnerability of the K through 12 or the sort of grade school system and that sort of thing. because they're underfunded and they've got all these other priorities, but you could argue their critical infrastructure and the role they pay educating the next workforce and even providing daycare in a very sort of simplistic sense while parents go to work. So, diving into that, tell me a little about the Computer Weekly column. Danny Palmer (44:21) Yeah, so this was based off an interview with Dr. Jason Nurse from the University of Kent. He's a cybersecurity academic. He's also involved with a cybersecurity company called Cybersafe. And he at the InfoSecurity Europe conference, he did a session on the human side of cybersecurity. And I think after this, I met him and interviewed him. We had a chat about this sort of thing. And the line I start a feature with is him talking about how 10 years ago, yet, cybersecurity and IT people had, they would go and blame the user for anything that happened. And he's suggesting that it's a good thing these days that this doesn't happen so much. Or if it does, it's called out because at the end of the day, know, people who click on phishing links and that sort of thing, they're not doing it out of trying to be Malicious and not trying to think okay. I want to click on the link and now give away the password What was in 99 % of cases? I guess the whole thing of malicious insiders might be is it all different kettle of fish? But they have clicked on a link saying okay. Can you sign off for example this? business agreement You click here and you just sign this off. They are just wanting to do their job and be efficient It's only no when you get down the line and here. Okay, they might find out, okay, no, and then you sent that or it could have been from an email, even from an email address for someone they are working with who has been hacked and sent that out. So, I know there's a lot of discussion about cybersecurity training. One of the most interesting things I thought was, oh, it's the app site, it's in to security Europe. The crowd he's speaking to is obviously in to security professionals. And he polled the audience on what they thought the best method of teaching cyber security was and the big consensus among the crowd at the event was gamification, of games, quizzes, that sort of thing. Then Dr. Nurse unveiled the results of a survey he'd done with 7,000 members of the public. Gamification was the least way they wanted to be teach this stuff. People want to be able to see things in short form video. They want to be able to read the text. they want information they can go back to and see again because yeah, people is a kind of self cliche that, know, cyber security is hard. And the reason it is there is to stop bad things happening, but employees want to be efficient. mean, I remember years and years ago in my, my first is pre me being in journalism really, when I was doing this, I was doing a job. And I needed to transfer files from one place to another. This was 2011 or so I put the files in my personal drop box, then no transfer them elsewhere, which at the time I didn't think any different of doing nowadays. There'll be company policies about that, but that's because these days, you know, again, the reaction to the rise of clouds, computing organizations, providing employees with these tools they need in many cases when employees. are sort of, if they get hacked or phished or some sort of attacks in other way, in many of these cases, it's because they might be trying to find a way of doing things that's efficient outside the work system or using their own individual email to transfer a file because they're that they need to know for some reason, say they're going to work remotely somewhere and or they want to work from their home computer. rather than their work computer, which I did a lot back when I was a reporter, they want to transfer that files. They put it into their sort of Google Drive or OneDrive or whatever it is. Maybe they forget about it once it's in there, but if then their personal account gets breached, that corporate information is in there as well. So I think one thing that is organizations are really in my eyes, trying to do and I've spoken to CISOs about this sort of thing is ensure that employees have the tools they need to do their jobs. They're not trying to cut around a shadow IT or these days shadow AI. Martin Hinton (48:54) Yeah, well, you touch on a reality, right? I if you're at a company that has, say, a staffing cut, you know, they lay off 500 people or 1,000 people. And invariably in that situation, no matter what leadership says, that work that was done by those people still needs to be done. And as the company readjusts, there is this added burden. So that's one extreme scenario. But the truth of matter is there is, and we've touched on this, that a lot of cyber attacks take advantage of vulnerable moments in the calendar. Christmas time. There's reports out of Asia during the Lunar New Year buildup that people are distracted when there's classic times that summertime when people are off. There is all this information out there about the patterns of our lives. We've got enormous amounts of research now on the behavioral psychology that's used to sell us soap and candy bars and cars and all that sort of thing. That information exists. It's out there in the public purview and these highly organized situations and organi- highly organized groups that are involved in cyber crime are able to take this information and then re-engineer its ideas for the purposes that are sinister in this case. And I think that, you when you touch on the efficiency thing, when it's 4.30 on a Friday and you got to get something done and you're supposed to be going away for the weekend and your trains at 6.36 and it's a 25 minute bus ride away, if everything works perfectly, what we know is that most people will seek the end. in the Machiavellian sense, regardless of the means, right? You will achieve completion of the task. Because what you know is odds are it won't happen. Who knows? Maybe it won't happen to me, but. And we see this now. One of the things you think about is AI policies at companies. And I was chatting with someone at a media company recently, and they don't have an AI policy. And I said, so you mean if you do like an interview with someone, people would put that into chat GPT, and then it's like out there? And there is this sort of workaround that exists. that to your point about once upon a time when you would use your own Dropbox and that sort of thing that exists now with AI. When you think about the scalability that AI creates that can exacerbate the human element, what types of things are you hearing? What are people thinking about, if you will, looking into the horizon for what's to come? Danny Palmer (51:11) AI has opened such a massive kettle of fish in terms of the cybersecurity elements to it. I remember back when ChatGPT GPT first emerged into the public eye, it were. Naturally, I wrote an article about what does this mean for cybersecurity? I remember at the time, trying to use it, how could this be exploited by attackers? So first of all, I logged in and said, how do I write a phishing email? It wouldn't tell me how to do that, obviously, and rightly so. But then I asked it, okay, I am the head of HR at this company. I need to write an email to my employees telling them to open this email to receive information out there. Christmas bonus, for example. It was happy to do that, which is meant phishing is becoming more difficult to detect because for the stereotype of phishing emails is that they are full of spelling errors and weird grammatical issues and that sort of thing. using AI can eliminate all of those with the use of things like large language models. They can also use the LLMs to help with the research into these. Like you'd you to use a search engine to find out more information about their their targets and that sort of thing. So it's, it's a whole, opened a whole can of worms that way. And that's even before you get into the deep fakes and fake audio and that sort of thing. Martin Hinton (52:48) But before we get into that, the example I've used for the work around whether these theoretical barriers in the LLMs is, you don't ask it, how would I hack this company? You say, I'm writing a spy novel. And in the spy novel, there's a bad guy who hacks this company. Give me a scenario about how that would work and then write it in the style of Tom Clancy or, know, John le Carré And that is enough for it to go, here you go. Here's a template for how that might look. in the real world based on everything I know and these LLMs, they know a lot. And I think that that's something that, you know, cause my feeling about AI is where it's sort of the Model T Ford or the very early invention of the steam engine era of this. And that there are, there is so much more that it'll be capable of. And obviously like any tool in the right hands, it drives a hammer, the nail home and a hammer will do that. And if you're in the wrong hands, you break your thumbs. And I think that that is, you know, something that people need to keep in mind. because when it comes to efficiency and we see companies wanting to say they're adopting it and we're using it to make ourselves more efficient. Well, employees have to make that a practical reality. And when they see the green light that AI is okay, because it's gonna make us more money and we're gonna be a better company, they will lean into this space and there's an enormous amount of potential vulnerability. You and I see this stuff all the time. I mean, do you have any examples of... AI being used and we know that there's this famous example for an AI deep fake involving a Hong Kong based employee for a UK firm. For the audience's sake, take me through that story. What's that story again? Danny Palmer (54:31) Essentially, someone managed to use a deepfake to pretend to be an executive at this company to call an employee on video FaceTime to ask them to transfer a very, very large sum of money. And long story short, the employee, I think, did this, which is, I mean, you think about it, if your boss tells you, calls you up and tells you to do something, you're going to do it. You're not going to go, Oh, hang on. Are you really my boss? Which again, part of the reason why this sort of thing works, people want to be doing a good job. They want to know, be, you know, fill their jobs well, do their jobs well. And so, so they can sort of look back on their work. Oh, I've done a good job today. And that sort of thing. With the rise of deep fakes, it's becoming more difficult to tell things. I deep fakes, I think first emerged in sort of sort of late 2010s. mean, and even back even from then they've come on such a long way. Yeah, yeah, the are the first I think one some of the first sort of major ones who have no someone made it one of Barack Obama saying things he shouldn't be saying in like a sort of comical way. There have been one there've been various deep fakes of Vladimir Zelensky, the Ukrainian. president talking about the war. And the there's all sorts of applications where these are being misused away from sort of the sort of financial crying of deep fakes are becoming a massive problem for harassment now, AI porn, but I think back to the business. So AI porn was the wrong, wrong words, AI sort of nudifying of people, but back to the BC thing, there was one This was a sample of attack, which didn't work. And someone tried to deep fake one of the, the sort of top managers at Ferrari, the Italian, no, sort of a luxury car manufacturer. And apparently this was a convincing call and it sounded exactly like them, but it was stopped because these, the, the, these personnel discussed the idea of, what happens if this happens and the guy being called up about making this financial transfer said to the person calling them, okay, so what was that book you lent me last week? And they had like a specific answer for that to be, you the real person. When the, the caller couldn't answer this, it proved again, it was a very human, a solution to a technical problem. Martin Hinton (57:23) So you touch on one of the sort of low tech solutions that exists out there, the idea that, let's say within your family, you have a family passphrase or a question and answer that is nonsense. Like what was the name of my first pet, my first dog when I was a kid? And the answer is Samsung television, right? That idea that there is this, you know, almost impossible to know unless you start texting it around and putting an email. you know, word of mouth, if you will. Yeah, it's an interesting sort of idea that there is perhaps a quite simple solution to ask them something that you did in person or something that wouldn't have been known. I mean, obviously there's always a way into these situations. Pardon me. I just want to jump back to your point about the deep fake porn. I think what you're talking about just for the audience sake is that people will take an existing pornographic film and very realistically, you can superimpose the face of someone else on it. And we've seen this done with celebrities. And that sort of thing. the idea is that, you know, I won't get into it, but this idea that that exists, there's this phenomenon also exists now. And I did a podcast with a cybersecurity, a personal cybersecurity organization here in the States where they will use children's photos that you might post on the internet. And it's a public post. And they will take that photo and then move it into a, you know, dark web child pornographic space and use your photo of your child on. So this sort of thing is happening and it's monetized, right? This is not just for, I don't know if fun is the right word. It's not just to be a sinister, dark person. There is huge amounts of money in this space that people make. And I think that that's one of the interesting things about it is that you touched on the way it's used to maybe socially engineer via culture and politics, right? know, Barack Obama saying something fake and you posted on Facebook and you know. certain demographics of people are going to be less cynical about what they're seeing and they're going to believe it. you know, the cliche is that older people are more inclined to believe what they see on Facebook. I saw it on Facebook and that sort of thing. And we know Facebook has an enormous amount of AI content now because they tell us they do. And I think Danny Palmer (59:34) Mm. Martin Hinton (59:34) that that's the obvious public awareness. We know that sort of fake video is this real and, you know, people monetizing their clicks and their likes because they've got a cute cat cuddling a dog video and that sort of thing. in the business side and the cybersecurity perspective from a company, all of that faking, all of that trickery can be used to monetize cybercrime. I do think, and I wonder whether this is hyperbolic, but I'm of the opinion we are at the dawn of this, right? We are only just beginning, A, to see the damage it can do. And we're only just beginning to see the defenses that can be employed to protect us and create that moment, right? Because time protects us. If we think for a second, if we get an email from our boss or a text from our boss that's crazy urgent. We're like, oh my God, I got to do this now. I got to get this done. He's screaming at me. I don't like when he yells at me. And we do it quickly. And again, back to my point about behavioral psychology, this is the kind of trickery that's old school street con combined with high tech deep fake that is existing on a massive organized scale now. And even though I say it that way, I feel like that the beginnings of this are only there. And I don't know if this number is true, but you see it every now and then. Last year, 2025. the global cost of cybercrime broadly that I've seen, check me on this, was $10.5 trillion. And that would put it third in relation to GDP, America, China, cybercrime globally. Is that a fair number? Because I've seen people say that that number may involve things like money laundering, which has been around a very, very long time, and as bad as it might be, and as that money might be coming from sinister and dangerous events like drug trafficking. It's not part of the new cyber sort of crime cybersecurity landscape. What do you think about that? Danny Palmer (1:01:21) interesting ones. Yeah, sometimes it is going up. I think every single year I've reported on this, the figure has been going up. And it depends on what you count as cyber crime. We've spoken about ransomware a lot, which is obviously very costly and very, very damaging. But it's a business email compromise, is the last five years has been the biggest, the biggest factor of fraud, according to reports from the FBI. Things like deep fakes are not going to be helping that. And it's just Yeah, as technology evolves, gives attackers more ways of doing it. And it's almost going through the same cycles again, as it were, because, okay, when personal computers first boomed, that gave cyber criminals and other ne'er do wells, more access to do things. When smartphones first appeared, that gave them new avenues and Internet of Things devices, social media, now AI, it's almost as if from a in the general public or public perspective, we almost have to go back and relearn everything we know. Because AI, I was at a talk yesterday in in in central London, and the person speaking there and another AI academic, they know AI is just software. It has no vulnerabilities like regular software does, it can be exploited, like regular software can. And it's just that yet as no with anything, any new technology, seems the criminals and fraudsters are always amongst the first on board to figure out how to exploit it for their own gain and then we're all playing catch-up. Martin Hinton (1:03:03) We should go back and look at when the first car was used as a getaway car for a bank robbery. That's the analogous. I mean, you touch on business email. We haven't even gotten into this. we're going to wrap up in a sec. So we're going to have to do another one of these. But business email compromise, the idea that you're sending emails to someone and it's an invoice for $10,000 worth of a product you sell, but the invoice has a changed account number. customer wires the money to the wrong bank account. 30 days later, you go, hey, Billy, where's that money? send you the invoice. He goes, yeah, I sent it to the new bank account. And poof, it's gone. There's a great example here in America of business email compromise resulting in a Lamborghini that a famous baseball player purchased being shipped to the wrong address. And that's how they stole the car. They stole the car by compromising the email, changing the shipping address as though they were the customer. And poof, I think it was a quarter of a million dollar car is gone. And I think that the internet of things is another thing. The idea, and people probably, I still can't get my head around this, but the idea that all of the things that are connected to the internet, your router, devices in your home, whether it's your smart speakers or that sort of thing, they can be compromised in a way that turns them into tools that are capable of doing things that they're not designed to do. And criminals are bound ways to turn them into things. The famous example of this is the way Wi-Fi routers can be used to create a if you almost visual image of a room where it can see things in the room. again, for someone who's not technical, I I went to computer camp in the eighties and I learned to program in basic and Pascal, and I think I gave up. I wish I'd stayed with it. But that's where I think that there is the reminder that in the same way, someone might know how to fix every element of a specific kind of car, like an old Jaguar or a Ford Mustang. And a lot of people are like, wow, how did you figure out that the carburetor part goes this way and not that way? this sort of knowledge exists on the cyber side and in a lot of respects, it's being used in a sinister way. And I think that, you know, as we wrap up, I wonder whether there's like one big message of takeaway, you know, whether it's for the business community and the CISO is about this and employees or whether it's just individuals who maybe have an elderly parent, there, is there any kind of message that people should exist with that doesn't leave them feeling like maybe they want to, you know, move back into a cave and light fires to keep warm? Danny Palmer (1:05:29) Yeah, it seems that sometimes you can just feel your life throw your phone into the river and be done with it. That's an interesting one. I suppose the one of the key things I think that I have taken on board and tried to sort of always suggest in my articles in terms of how you can prevent these things. mean, for individuals, having a password that people aren't going to be able to guess is a good note. does a lot of work and keeping, keeping people out of your account. The NCSC quite often puts out reports here, like the most common passwords used in, in breaches. And at the top of it, it's still things like password and one, two, three, four, and all those things, all the names of sports teams that people support. obviously say in the UK, for example, there's a lot of passwords that are Manchester United or Liverpool or Chelsea and that sort of thing. Dates of birth and that sort of thing. But Something the National Cyber Security Center suggests is using three random words that know you you can remember but no are completely at random because that can be difficult for Using lots of different accounts because we all have so many accounts these days I mean and I'm sure I've got accounts where no I set up 10 15 years ago where the passwords are probably reused multiple times over but I think yet using a password manager is helpful. I think You don't even have to go out and buy one these days. obviously lots of cyber security vendors sell them, but even things like browsers have their own, password manager. Now there is, suppose there is a tiny element of risk there and that if your browser gets hacked or your passwords are going to be in there. But then also the additional thing is, again, this is both for a business and personal perspective is multi factor authentication is such a big preventer of cyber attacks. That is, having a you log into your password you get a notification come up Usually on your phone saying now was this you did you log into this? and it is still so rarely even I live in this world so I have the multifactor authentication on all my accounts, even though it can be a bit annoying every time I log into a website and asked I have to know check everything and log in again, but So many instances of breaches have happened because there was no two factor authentication involved. Martin Hinton (1:08:01) You touch on multi-factor authentication and if you've made it this far into the show and you're not sure what that means, imagine you're standing the front door to your house and there's not one lock, but there's two. It's that simple. The idea that there's two things that have to happen in order for entry to be gained. And I think that what to keep in mind is if you make yourself slightly harder to hack, there's someone who'll be easier and we know this from many years. before cybercrime, if you make yourself a likely victim or you make yourself look like an easy victim or an easier victim, you are more likely to become a victim. yes, that's just the two pieces of advice you've just given there. And again, everything is hackable. That's the other thing to keep in mind. So all of these security measures are perishable, right? There Danny Palmer (1:08:48) Mmm. Martin Hinton (1:08:48) are bad actors and there's a lot of money behind the barriers that are created by cybersecurity. And that's just the human element. This is a reality of our existence. There are going to be bad actors. But if you make yourself slightly harder, you have a password to your point that's maybe saved in your Chrome browser, OK, yeah, that can be hacked. But that's got to be hacked in order for it to become available. So that's one layer where if you don't use and you're not wrong, you see these lists of the people using the default passwords on company systems and not ever changing them. And it would beg your belief if you and I didn't see it virtually every day multiple times. I think that that's the other thing. And again, multi-factor authentication is like having two layers of security, a fence around your house and then a door that locks. These are just barriers added together, make you slightly more safe. does seem, and MFA can be a little annoying because it's so inconsistent, whether it's a text or you got to go into your authenticator app. there's, which authenticator app do I use for this blog on and all that sort of thing. So that inconsistency is something that the private world needs to come to agreement on, right? They're almost like, you know, so. Danny Palmer (1:09:58) Yeah, yeah. You do get a lot of silence. This happens, this discussion happens quite a lot within the cybersecurity community where a lot, but a lot of people believe that text message or SMS based authentication MFA isn't strong enough because no phones can get no SIM jacked and that sort of thing. But Martin Hinton (1:10:14) Yeah. Yeah. Yeah. Yeah. Danny Palmer (1:10:18) if it's your own personal accounts, having that rather than nothing is still better. I mean, Martin Hinton (1:10:27) Yes. Danny Palmer (1:10:28) I think, know, for example, for my parents, for example, they might struggle to use an authenticator app, a text message they can more understand. And I'd like to think that, you know, super sort of super hackers from the other side of the world aren't coming after my parents. But obviously in major organizations, you have different threat models, but just having that little bit of extra can help. so much because it comes down to, especially when comes to the more sort of basic levels of cybercrime. Cybercriminals are fundamentally lazy. They don't want to put the effort in. They're trying to make as much money as they can with as little effort as possible. So if your account is going to take more time to breach, they're going to wander off and find something that's Martin Hinton (1:11:19) Yeah. Danny Palmer (1:11:19) easier to do. Martin Hinton (1:11:20) Yeah. Well, I think, Danny, we're going to wrap it up there. I fear we could go on and on for a long, time. And I look forward to the next conversation we have about the latest news in this space. for the audience, just a reminder, Danny Palmer is a freelance journalist out of the UK, has done some brilliant work going back to the beginnings, if you will, of things like ransomware and cybercrime. I can't say enough. He's a freelancer, so his contact information is going to be in the show notes. Hit him up. You know, if you're looking for someone to turn this into a more broadly accessible story and a more broad mainstream organization outside the tech publication world, I highly recommend you talk to him and think about using him either as an interview or to author a piece. Excellent work. Really, really knowledgeable. So, Danny, I'm really grateful that you took the time with us today. Thank you so very much. Again, I'm Martin Hinton. This is the Cyber Insurance News and Information Podcast. If you've enjoyed it or if you've got a question for us, please drop it down in the comments, whether it's for me or for Danny, we'll do our best to get you an answer. And, you know, your support is everything to us. So please like, subscribe, follow all those things that you know we need for us to be able to do more of this. So again, I'm Martin Hinton, Cyber Insurance News. Check us out on the web. Here's the address somewhere below me, I think. Again, enjoy the rest of your day and thank you so very much for taking the time to join us today.