Martin Hinton (00:00.686) Everything's going. All right. So I'll do a little spiel and then we'll come to you and we'll just go from there. Sound good? All right, here we go. chris (00:08.967) Very good. Martin Hinton (00:21.518) All right then. Welcome to the Cyber Insurance News and Information Podcast. I'm the executive editor and your host today, Martin Hinton. And joining us today is Chris Skipworth, the CEO of Passback, which is a zero knowledge password management platform for corporate credentials, data, all that stuff we know we need to keep safe. Chris, thanks so much for joining us. How's your day been so far? chris (00:45.467) Thank you, Martin. It's a pleasure to be here. I'm looking forward very much to having this discussion with you about PassPak, how we help the insurance business and other small businesses manage their credentials and keep safe in this era of ever-increasing cybersecurity attacks and hacks, which is definitely a growing trend, as we've discussed in the past. Absolutely. Martin Hinton (01:05.708) It it it absolutely is. before we get to the present, one of the things I want to do is jump back with the basic idea and the basic question, how did the simple password become so complicated? You arrived. Go ahead. chris (01:18.351) You know, you're gonna say, sorry, I didn't mean to cut you off there. I mean, that's just one of my favorite sayings I use with my staff, especially my engineering staff all the time. And I would say, how did the simple password become so complicated? It's just a string of characters, but it's not so much the obviously the access and the storage of the simple password. It's really the governance of the password. Who has access? And the other bigger problem is... When a password goes rogue, as I say, or gets out in the open market where it really shouldn't be, what damage can that particular password cause to an individual or a business? So there's lots of controls that need to be put around the password to make sure it's governed correctly, especially within a corporate environment, controlled, easily updated, and all those good functions which we come to expect today and we need to do to keep ourselves safe online. Martin Hinton (02:12.942) So so stepping back to to the nineteen nineties when I think I'm right to say that's when you came over to America, a a decade or two after I moved here from the same country. And the the sort of basis of computing and t technology wasn't really built around the idea of security. So I wonder whether you might take me back to the sort of, you know, we all we talk about now is security and cybersecurity and all these layers and we we've we've got AI now in the mix, but security wasn't really foundational element. I don't know if that may be overstating it, but take me back to the beginning of where security existed and the past where it existed in say, you know, the mid nineties when, you know, f I think it's safe to say the internet and the idea of sort of connected commerce around the globe was how do I say it, coming online. chris (02:59.687) Yeah, definitely in its infancy back then. Well, in fact, I think I'm just trying to remember the exact date, but the password has been around since the 1970s. I think it was originally developed by IBM in their mainframe environment just to give certain people's access to certain resources. But back in the 1990s, I'm trying to think that far back, to be honest with you, Martin, was probably better looking and slimmer back then. As we all know, back in the 1990s, the actual web was coming into being really. And there were two sides to that. Certainly security online was nowhere near as advanced as it is today. But also I think the way we actually ran our lives back in the 1990s was extremely difficult. I don't remember getting into online banking until the middle 2000s really when security was becoming more prevalent. I remember actually signing up for various websites and you'd be lucky if it did ask you for password. Sometimes it would just take your money off you and grant your access into a particular resource to check that your subscription was valid. So really back in the 1990s, security was actually very loose. And as I say, we were using the web very differently. We weren't using it to actually communicate the way we're doing today. We weren't doing transactions online like online banking, stock brokering, the social media epidemic hadn't actually come up at that point. So in many ways back in 1990s or the 1990s, online life was a lot simpler than it is now. And in some ways because less was actually online there was less risk back in the 1990s and I think that's where part of the problem comes is is if You look at how services are grown online. It took a lot. It took a while for the security around those services to grow up alongside the The actual requirement of the user to be safe online if that makes sense Martin Hinton (05:00.758) Yeah, I know. I i it it did. And I mean, I think that that, you know, one of the one of the ideas that that sort of presents is that if you don't start out with the right foundation, and we see this a lot now with AI, right? We've got these open letters from various AI companies about the idea that we need to I mean, slow down, pause, you know, have more lateral movement and less horizontal movement is i i i in the sense of progress. And do you think that that's a reflection of needing to make security or being concerned about the consequences that maybe you're not imagining. more present. Do you think that that that the past is informing our present any at all? Or is it just d is it just more worrying? chris (05:42.276) I think in this day of AI, think cybersecurity is much more worrying than it ever has been really in terms of making sure that your information is kept safe and secure out there. I mean, we also hear a lot about these data brokers online who seem to have access to all our information and sell it quite regularly. yeah, certainly the world of cybersecurity and the potential for future hacks has certainly got a lot more prevalent out there, I believe, than it was obviously in the 1990s. as the, sorry, carry on. Martin Hinton (06:14.432) No no no no no I I was I was gonna say, yeah, yeah, but finish finish finish your thought. chris (06:18.503) Yeah, I was gonna say, mean, certainly with the dark web and all the resources which we have online, the need to actually keep our credentials safe and secure is becoming much more evident these days. And the risk to an individual and especially a business is much more prevalent in the event that they should have a breach or a hack. So, yeah. Martin Hinton (06:39.182) So so you've used the the the magic word for today to some degree a couple of times, and that word is credential. You know, as as as we move on in the conversation, if you could just sl slow down for a second and and what's the way to put it, double click on what does credential actually represent inside a modern business environment today? What what does that mean? I think that a lot of people might be imagining a badge with your photo and your name if you'd want to date yourself and that was it. It didn't scan, it didn't have any electronic features, it required a person to look at and then look at you and, you know, see the name or cross-reference that against something in the real world. Obviously it's gone a long way from that. What do we what do we mean when we say credential now? And and then you could sort of if you want to just naturally take me into credential management, the problem that exists there and and pass packs role in that. chris (07:27.139) Absolutely. Well, a credential basically is very simply, as we all know, it's a username and password in its most basic form. Beyond that, there'll be another form of authentication, some form of multifactor authentication, allowing access into a particular resource. And going on beyond that point, there might be some other information attached around that credential. It could be a bank account, it could be a credit card number, it could be some personal information attached to that particular credential. So Really, when we use the term credential, we're not just talking of passwords, we're talking of a bigger picture in terms of identifying information and access information, really. And the passpacks role in that, we call it a credential management because it does a lot more than just store passwords and usernames in the cloud. It stores... information notes and other key information around a particular password or credential, which would have helped with the running of the business. And just stepping back from that, PassPack is really a cloud-based system. It keeps your data heavily encrypted in the cloud. Only you as the user have the keys to access your data in the cloud. Not even past pack employees can actually see the information stored within the past pack environment. That's one of the main reasons why it's so secure. It's called a zero knowledge architecture in that sense. And I think you gave a wonderful analogy when we spoke a little bit earlier, it's bit like a safe deposit box at a bank where the bank doesn't necessarily know what's actually in the vault, but you have the keys to the front of the vault and and have access. The pass back is very similar concept, only you have the keys to your data within the environment. It also provisions the sharing of these credentials to other users in the organization and it also gives a clear audit trail of who owns what credential when they access the particular resource. chris (09:30.309) And most importantly, what happens when a person's role changes within the organization? Do they really need access to all these resources? And especially if a person leaves an organization, you have to make sure that their credentials are revoked and their privileges are actually revoked. It's one of the most common ways a small business is actually breached really out there is the off-boarding process. Yeah. Martin Hinton (09:52.844) Or like d dormant credentials, right? The ones that just linger even chris (09:56.209) Well. Yeah, absolutely. mean, if you look at a business and I, you know, we're actually guilty of it as individuals, you can imagine what it's like for a business. First of all, when you first get a password manager, but you think I've only got 10, 15 credentials, which are key to my life. And then you start to build and then suddenly you've got 100 credentials. Well, in a business that can spread to thousands of credentials. Some of them are old, you don't know who has had access to what in the past, you know, providing a particular security risk to a resource in the business. So yeah, credential sprawl is actually a big issue within an organization and really tying down. Yeah, sorry, Martin. Yeah. Martin Hinton (10:32.674) No no no no no no no please please I I I was just gonna say, you know, j an example of it if I'm not mistaken is Colonial Pipeline was was was hacked through a a dormant credential and and I'll there'll be a note in the show notes to to to confirm that. chris (10:46.471) Yeah, in fact, actually, another great example is actually United Healthcare, of course, they had a very significant hack by hackers that got into a particular area of their system and had a password, a fairly weak password on the front of that system, but it didn't have any multifactor authentication set up on the front of that system. And again, a bit like the insurance business, and we'll talk about this a little bit later on, not only did they get into the top end of the system, it went through to their providers and it caused all sorts of of data security issues around medical information and UnitedHealthcare had to settle up in a very big way after that particular data security breach. Martin Hinton (11:27.64) So in in your sort of journey, w was there something specific about this business problem that you found particularly interesting or motivating to to come up with this solution, or did you just see it as a business opportunity? you know, talk to me a little bit about but the you know, the passion behind it. chris (11:43.942) Well, yeah, well, it wasn't quite as direct as being a business opportunity, even though I could see a business opportunity. Going back in time, I was involved in other startups which had security elements to them. One particularly was a credit card protection company. So it used to issue a master credit card number. A subset of that was password management. And I could see how important passwords were for protecting people's financial information. And then as we got more into the world of the password and the credential, you can see, well, this is a real problem for businesses. a natural progression from that particular business, it was actually into password management and hence is how PassPak really came to be as a credential manager, as you call it, really tailor-made for the business environment. So that's really where it came from. Most of my work and career, Martin, I've probably evolved into things rather than actually being smart enough to identify something straight off the bat. Martin Hinton (12:41.154) Well, you you you you you reveal the level of courage that you possess because that's the case with most people, despite what they might tell you about their well executed plans, I think is you know, I I you one of the things I wanna touch more on the credential sprawl problem, but one of the things about Pass Pack that we touched on and that that I thought was kind of interesting is is there there's a sort of a you know, a a real burden on small and even medium sized businesses with regard to the cost of some chris (12:41.927) That's it. chris (12:52.749) Absolutely, yeah. Martin Hinton (13:11.308) security. And I I'm not saying it isn't worth it, but that's a real friction point for companies when they're looking at their budgets and that sort of thing. And in some respects, this for credential management, password management, and sensitive information access management, Passback provides, in your opinion, a solution to that reality. So I wonder if you might give me the sales pitch, because I've got small and medium sized businesses on my mind at the moment. chris (13:38.568) Absolutely. Well, that's it. mean, you hit the nail on the head there. Really, mean, a lot of small to medium sized businesses are big targets for cyber criminals. And just to give you a bit of knowledge around that really, a bit of just a bit of background, mainly because small businesses don't have the resources in house with that large ones have to actually manage their IT resources. IT is probably a secondary, or IT security is probably a secondary function within that business. I, it's a shared role within the business. People don't realize how sensitive it actually really is. So it doesn't really get the, the focus that which it actually really requires in a small, in a small business. What we aim to do with Passpack is really empower the small business to get up and running very quickly with a strong cyber, cyber security solution that allowed them to manage their, their credentials quickly, onboard people very quickly. know who owns which credentials very quickly, generate the necessary audit trails if required, all at a very cost effective price point for a small to medium sized business. Something which we're not talking thousands of dollars for let's say a small business, we're talking below $1,000 for an organization of 10 to 20 people type of touch. But on the other side of that was actually making cybersecurity friendly and easy to use within the organization, making it very simple to get up and running with a good strong cybersecurity solution. So yeah, so that was the fundamental premise of PassPack. Obviously we can go up to much larger companies if we have to, and we do deal with enterprise scale customers as well as the small to medium sized business. So yeah. Martin Hinton (15:09.816) Yeah. Martin Hinton (15:25.944) So we've established the the resource. I wanna come back to the necessity. So credential sprawl, who has access to what? I I I think that it's very hard for me, and I've been doing this for a few years now. I think it's very hard for a lot of people who are even smarter than me to comprehend what we can't see. So when you think about a computer network within even a small company, there are enormous number of doors, if you will, that or controlled. And the simplest one that we've touched on is the logging on to the system. You use a password, you get a second factor authentication, and boom, your screen just doesn't have a blank space where you went through a password or whatever it might be. What happens is that these identities, and we keep using the word sprawl, but they almost in a weird kind of sci-fi way self-replicate and grow and and they the the vendors come in and contractors come in and Summer interns come in and there is this amazing churn and and growth of them. And they become in some respects by their nature as vi invisible to the naked eye and also their volume a bit hard to manage. So how long would it take a company to determine who owns what credentials and and what can they access and what they they when they were last used for? Like the kinds of questions you would ask for security, which you touched on. Who can go where? You know, the log of it is vital for when it comes to say a cyber claim, like You know, who who who used that credential? When would they use it? How difficult is it in your experience when you're encountering companies to to even inventory the number of identities and credentials that they have open? chris (17:03.291) Well, that's a very good question. actually, mean, fundamentally, it's a let's go back to credentials for how it really happens within an organization. One way it particularly happens is by adding more systems into a company. Okay, I need an automated system over here. I need a CRM over here. I've got online banking and people tend to use passwords, which are easy to remember. around those particular systems. So you're adding more systems, you're adding more credentials. The other thing that happens as a company grows and hopefully successfully, it adds more people and then more people require access to these systems. So you have credentials given to more people that require. So more more credentials are out in the open across time. And to answer your question, if it's a good question to ask any manager of a particular company, CEO of a company, IT manager, if they have such a thing. How long would it take you to actually identify who owns which credentials? How are they using it? And when were the last times those credentials were changed? I would guarantee in a high number of cases without having a good organizational structure like using a passpack product, a lot of owners could not answer that question. It would take them a long time and they probably wouldn't actually know the full answer to that particular question. So. that's a yeah, credential spore is a big problem and identifying the ownership access and where these passwords are actually going and how they're actually being used is a big issue. Martin Hinton (18:34.87) I I mean I i I you know, in the simplest way, it it's hard to know where you stand without knowing what you possess. I mean, i and and it it i it it doesn't matter what it is, right? You know, how how good is our inventory? Well, what is our inventory? I don't know how many we have, boss. Well that like w we don't even know. Like, should we make more, should we make less? Should we order more? Th the that sort of basic understanding of knowing what exists is the underlying problem. And I I guess what what I'm curious about is when you see chris (18:41.751) Absolutely, yeah, you know. Martin Hinton (19:04.056) problems around these emerge, are they and we know this, right? You touched on this. People use if you've got 10 systems and you need 10 passwords, you might use 10 variations of the same thing, which makes it easy for you. But it's also then easy for you to have one stolen and that one then be used to derive iterations of that one that allow them to break into another system with your credential for one part of the box. Is is that one potential problem that emerges? chris (19:32.088) Well, that's definitely one potential problem. the other way, the other, another big issue is how those passwords stored are people storing them in their browser password manager, which is definitely not secure. Are they putting them in a spreadsheet and emailing to each other? Are they keeping them on sticky notes around the outside of the PC? How are they sharing these passwords and how are these passwords being updated? And again, if a password's out on the open, you're not sure who has access to that particular password, which for a company, can be a particular risk, not only for its own internal resources, Martin Hinton (20:08.514) So so you're you're looking then at a situation where if, you know, one of the things we touched on is offboarding, right? An employee leaves, you've got their literal credential and then all the access that that credential created for them for the work they were doing. So there are other layers to that credential that are maybe not obvious to the sort of layman. Is that a like I I guess what I'm trying to move toward is the idea that you've got human and non human identity and credentials. I I wonder whether you might touch on that a little bit. chris (20:38.949) definitely. That's right. Well, I mean, the offboarding problem is probably, it's a huge problem, especially for companies or for legal companies, a very good example of this, where they bring people in for a very large legal project, give them access to resources. Then when the case is finished, they disband that particular team, but they still have access to company systems and those credentials are still active when they leave the organization. It's also particularly relevant to development companies. If a person leaves, to a competitor and they still have access to critical internal systems within the company which can give away the company trade secrets. And there's been some very famous cases of that really. The off-boarding problem is definitely an area where any cybersecurity enhancement could be made to a business easily is definitely an area to focus on. When a person leaves, you wanna make sure you actually change the credentials very quickly and make sure they don't have access to any particular company resources or systems which could be critical for that business. Martin Hinton (21:41.996) Yeah. Yeah. I mean, i it's it seems so obvious and no one I would suspect would deny the idea that if you have a a home and you have a problem with someone who works on your home and as a function of the work they did in your home, you allowed them to know your alarm code or have a key to the home, that you would in the wake of ending business relationships with that person. Consider changing your alarm code and maybe changing the lock or asking for the key back. But then could they have made a copy of the key? Right. All these conversations are seem obvious in the the the natural world. Those same concerns and thus the liability for not executing properly with regard to them exist in the digital space, right? chris (22:26.669) Absolutely, does. It's a bit like not changing the lock on your front door. If you think there's, you know, if there's somebody you don't want to have access to your house and you've let the keys out in the past, you really want to make sure that lock is changed on the front door. And again, it's one of the biggest store, the most common uses for a solution like PassPak is to actually revoke privileges from a particular user. Either they change role or leave the organization. It can be done by a central administrator very quickly to make sure that these people don't have access to what they shouldn't have when they leave an organization. Martin Hinton (23:01.09) So so so if I if I'm understanding pass back just before we step into the insurance space for this, the idea is it gives you almost a control room sort of single point of observation for all the credentials that exist within chris (23:12.215) Absolutely. mean, I mean, typically within a passpack setup, you'd have a central administrator and all the passwords for the organization would be put in that particular repository. He would then invite his team members, his employees to join the admin account. And then he would create teams or folders and actually share particular credential resources to the people that need them. And actually that's one important point. So that only really gives access. to the correct people that need access to a particular resource. Not everybody has access to everything. And you can really pinpoint down who has access to what resource. That is one of two things that actually limits the attack surface area within a business, because you only know that a limited number of people have access to certain credentials. And it also gives you the ability to actually audit user activity much more granularly as well within the business. So you can see who access. is what resource and when basically in the event of an audit trail being required for some compliance report. Martin Hinton (24:20.558) So we're gonna come to the cyber insurance element of all this a little later, but one of the things we discussed that I I don't think I was maybe as up to speed to as I'd like to admit, I'm gonna go with wasn't really thinking about, is that within the insurance business in general, there's a big issue with credentials and access. And it's because of the way the business is designed, which obviously is that there's advantages to. T talk to me about the the insurance problem that's particularly complicated, you know, the the access problem. chris (24:49.253) Well, actually, the insurance business is actually very interesting and it's not the only business that has this problem. I could pull out another few examples, but really fundamentally the insurance business has grown over time. It's a very old industry. And in many cases, a lot of these insurance companies are using old legacy systems, which really didn't have good cybersecurity provisions made when these systems are actually employed. The other problem with the cybersecurity business is you have a lot of third party access going on. You rely a lot on partners and people to access systems. And every time you issue a credential to a particular partner, have to potentially have a point of a point of threat or point of attack because that credential is now out there and you can't really tell where it's going and how it's being used. You had shared operational accounts. You have complex access to chains and supply chains. or actually, I'm sorry, insurance sales change, I should say. And it's just a very big, large attack surface area when you get into all the various elements of the insurance ecosystem and how many partners and people need access to various systems and how you control that basically. And I think we touched on this last time, Martin, but today it's interesting with the insurance business, they are... demanding very high standards of cybersecurity from their clients. And on the other hand, are they really implementing the systems they require internally within their own particular environment? So, that's it. Martin Hinton (26:19.288) What what you're what you're describing is broadly referred to outside of, you know, this specific scenario is is supply chain risk, right? That's sort of third party risk. chris (26:28.867) Absolutely. that's, mean, mean, the supply chain would be the other. mean, they're two very different businesses, but they share a common issue where they have lots of legacy systems and lots of systems interconnected. The further downstream you go in the supply chain business, the more people need access to various resources. If you have an attack in one area of the supply chain, it can ripple through. It can ripple down to a lot more other clients really causing big problems in terms of data loss for end customers and clients. And the same applies to the insurance business as well. You only need one or two breaches upstream and this whole thing can ripple downstream and affects a lot of people in both the insurance business and the supply chain business. which is effectively what I gave the example earlier of the United Healthcare breach. That's basically what happened. It affected a lot of downstream partners that particular breach did. Martin Hinton (27:22.764) Yeah. Yeah. chris (27:24.263) There's another important factor which we haven't really spoke on for the small business, but if there is a breach in a small business, not only is there the loss of business and loss of internal resource, but there's also the loss of reputation. And that can be a huge issue for a small business. I always say everything is relative in the business world. Yes, if you're a big corporation, you're going to get fined heavily, et cetera, et cetera. But if you're a small business, it doesn't take much of a fine to make a big dent in your operational capability of that business really. again, taking some very simple, straightforward procedures to protect your cybersecurity is a key step. Martin Hinton (28:02.998) Yeah, I mean, I I I think that you know, one of the things they say, I think I mentioned to you, I I I spent a significant amount of time doing military history documentaries earlier in my career. And one of the things that involved was spending a lot of time in active military situations from bases to to other places. And one of the things you always talk to them about, they always talk about is access control. Like you, you know, the security of any physical place is controlled by chris (28:13.115) Mm-hmm Martin Hinton (28:32.886) the entry points and the fence and how well is the fence monitored and is it prepared? Is is the guard paying attention? And I remember one of the things I I was in South Korea at the DMZ and the guards on the North Korean side and the South Korean side have a very performative sort of interaction where they're very rigid and they're dressed immaculately in, you know, they're beautiful, almost not quite dress uniforms, but but not you know, fatigues, if you will, or BDUs and they all wear sunglasses. And I remember asking why why are they wearing sunglasses? So you can't tell if they're not paying attention was the basic answer, right? So the sunglasses conceal the eyes that are like, my God, I gotta get home. I'm so tired. I've been here for 12 hours and the sun is baking me. But you create a mask, if you will, that reveals or it limits the ability of an observer to determine whether or not you're actually being secure or paying attention, I suppose, in the in the case of a security guard. chris (29:04.657) Hmm. chris (29:10.087) Hahaha Martin Hinton (29:30.954) And and I I again that that that the the the the appearance is a bit like you know the house with the you know the the looks harder to break into. Well I'm gonna go to the next one, right? What why why change all that? So I it's just yeah, it's just an interesting idea that again, I I I I feel like sometimes I beat this to because I talk about this a lot, but I see a significant problem with the security that exists in the cyberspace. But the kinds of threats we're facing are the same threats that affected us. chris (29:42.21) Absolutely, yeah. Martin Hinton (29:59.118) prior to this reality of our economy, right? Human greed, your selfishness, the desire to steal things for your own benefit. Like these are not new things. And the the practices of protecting us are similar. The mindset is similar. The dilemma in the digital space is the the speed and frequency and reach and the number of identities you need to create for systems to operate properly and allow people to move through them to do their work. And now into that space Has come AI. So what what's AI changed in your space? I mean, it feels like we've been saying that for a while now, even though the reality of, you know, particularly the commercially available LLMs and stuff like that is only a couple of years old, or a little more than a couple of years now. so what do you see with with AI? Because phishing isn't new, theft isn't new, impersonation isn't new, you know, certain certainly so social engineering isn't new. chris (30:30.754) Absolutely. Martin Hinton (30:55.278) a lot of people have said to me, you know, AI is gonna be very helpful for the defender and the attacker, but the attacker was doing pretty well without AI. So, you know, it's a kind of a concern. So what what do you what chris (31:03.193) Absolutely, yeah. Well, I think what AI has done fundamentally is actually make it a lot easier for the attacker and make it a lot easier to do attacks at scale and volume. Also make the attacks much more realistic. AI makes it a lot easier to actually fake a document or to fake an identity of a person online to make you think that, it really is Chris Skipworth on the other end of this, right? I would take his authority or I will follow his actions, right? So AI has actually made it much easier to impersonate a person. You also have a very advanced AI attacks, which would be like basically faking the video. and faking the voice, especially in voice recognition systems. AI is particularly strong at mimicking a person's voice and gaining access or making, you know, can make a voice sound like Chris Skipworth if you actually wanted to, to actually gain access to particular resources. So I think what AI has really done is actually made it easier. It's really made it a lot easier for the cyber criminals to actually go at a much broader base. of attack targets and also the attacks have become more sophisticated or at least more realistic. As you said earlier, fishing has been around forever. It's one of the oldest forms of attack online. I mean, every week, mean, there's lots of fishing emails that go out and we spoke last time about how a lot of fishing victims are much more of the elderly out there from a personal standpoint because they trust much more what comes. in their inbox or appears on their phone in a form of a text. mean, AI has changed the business dramatically in that sense, absolutely. And I think AI will continue to get smarter and continue to get more lifelike, you know, in terms of, of mimicking these attacks. And the other thing AI is actually really particularly good at is actually spotting vulnerabilities within an organization as well. And you've heard some of this chris (33:06.769) from the big AI companies. can analyze an organization and say, this organization has a security weakness here because it's using this particular security solution at that particular point in their security ecosystem. So yeah, there's various ways that AI, and of course AI learns and it improves on itself over time as well. And yeah, so it's really a, it's a golden tool for cyber attackers, unfortunately, which means, you know, us on the other side have to be much more aware of the type of attacks that can come in and be much more up on our cyber security and what we do to prevent it. Martin Hinton (33:43.55) I i i I i I don't think we discussed this, but there's this new initiative out of the US government about having companies take on some of the role of you know, almost like a bug bounty kind of incentive, executive order out of the White House. I'm I'm I'm not that interested in that. What I'm kind of interested in is is the idea that I've heard all along that attributing blame is often quite difficult. Like figuring out exactly who the attacker was is chris (34:10.146) Right. Yeah. Martin Hinton (34:10.732) sometimes a bit of a challenge. And obviously if you're a criminal, the the the ability to conceal who you are is is significant. s creates a significant advantage, right? Because no one knows who to go after. I I just wonder whether you might touch on sort of, you know, whether or not there's a ability within AI or does AI create a a a a a bit bigger cloud or a more obscure view in that sense that that you can, you know, I think we've all seen the movie where someone tries to trace a a log on and the The the map shows the the VPN jumping from, you know, Kuala K Lumpur to Central Africa to Moscow. I I I feel like I'm reliving like half of the scenes in a Mission Impossible movie. But this sort of thing does happen, right? Like that's that that's mimicking reality. And I'm wondering whether AI is gonna make it harder to assign responsibility when things go wrong. chris (34:59.979) Absolutely, think AI does make it very hard to assign responsibility to people when things do go wrong, or to entities when things go wrong as well. Especially if the AI has been mimicking an identity of a particular corporate, corporational person. I mean, it's, and often I think we touched on this last time as well, that when the damage is done, it's normally done very, very quickly. I money's wired somewhere and it's gone within the target account within minutes of it hitting the account, right? And it's very hard to trace because the cyber criminals that know exactly what they're doing when they're inside an organization, they get somebody to authorize a particular transaction. The money is gone. It's out of the target account and the deal is done. And there's very little to track alongside of that. Absolutely. You know, Martin Hinton (35:49.154) Yeah. I mean, I I think, you know, it's i I I I like to mention this. a lot of our audience will know this already, but one of the things that, you know, you'll often get is money transferred into a bank account. Once it's in that bank account, it's very quickly moved from that criminal bank account that you didn't realize was a criminal bank account to somewhere else. Once that happens, it's it's impossible to get back. And and the and I in fact in the in the incident response people I've spoken to, I think I can think of a single time chris (36:12.856) Absolutely. Martin Hinton (36:17.954) that money was recovered in a sort of business email compromise is an often the common way this might happen where, you know, an invoice is made to look like it's coming from a certain company, but it's actually changed and the the bank information's different. People don't check, they wire the money and poof it disappears. The only time they've recovered it is because the the the bad guys didn't remove it from the target bank account very quickly. And and that made it possible to recover. So it's it's you know, it's it's I mean there are banking apps. I think it's Zell that's you know, the is one where it's like if you send money with this, treat it like cash. It's like, well, why am I using a fancy app then? You know you know, like what's the point of that? You know like if if this is just handing money to strangers, wh why are you even here? Like what what is the point? I I'll I'll Go ahead, go ahead. chris (36:53.357) Absolutely, that's right. And of course, if some... chris (37:00.199) Exactly. of course, mean, of course, I'm sorry, Martin, but I gotta say things like money transfer services, cash app and Zelle, mean, there can be absolute targets for cyber criminals. Absolutely. Make it very easy. Yeah. Martin Hinton (37:14.732) Yeah, no, I it's funny. I and and the and because depending on where you are, they're not regulated the same way as banks. So your recourse as a consumer is often limited as opposed to say if you were going into a citibank, you know, then then you also have to get someone to help you on their customer service that isn't an AI. So that's another barrier to to what all of that comes to the sort of the idea that one of the situations we look at is and it drives us crazy when videos don't play right away, or you click something and the page doesn't load right away. chris (37:22.607) Well, yeah, yeah, yeah. chris (37:31.79) Yeah, exactly. Martin Hinton (37:44.76) But that in this context of reducing theft, reducing the the cost of this crime, friction is maybe not all bad. And I I guess, you know, when you think about sort of two-factor authentication, aside from there being two keys that you're using, they're two two things that are unlocking separate locked items, there's a slower process, right? So if I'm transferring money and I have to transfer money from one bank to another, so I need to log on. I have to have my log ons second factor authentified. Then when I go to do the transfer, I need to get a, you know, a a code generated from a a jit an app and that sort of thing. All of that creates steps where I can think, wait a second, do I am I am I sending five thousand dollars to the right person? Should should I not be sending this money? Now I don't do a ton of this. I think if you're doing 50 of these a day, you fall into a routine and you're being pressed to be efficient and and that sort of thing. I wonder whether you just might talk a little bit about the the concept of friction within this in this space and and the value it can create that is very hard to count because I what's the common phrase? It's counterfactual, right? It's hard to count money you don't lose to a cybercrime and point to it as an upside. chris (38:56.999) Right, exactly. Well, it's always been a big trade-off between what I call convenience. The easier a solution is to actually use, the less secure it tends to be, right? And that actually not only applies to the actual solution, it also applies to the policies surrounding that particular solution as well. For instance, mean, know, money is a great example. If you're relying on one person to wire lots of money to various different places, that person's definitely gonna be a target for... for AI potentially and a cyber attack. So you have to look at the procedures around, or the internal procedures around, well, what else is required around that particular person in terms to make sure they're authorizing money above a particular amount to make sure it's going to the correct, what sign-offs are actually involved, which again applies friction to the whole process, but it also helps keep you secure as well. mean, typically within the work environment, was one of the fundamental things about ParsePak was, making it easy to use. If a solution is easy to use and secure and straightforward, people are much more likely to use it than actually a complicated solution, which takes time to learn time to understand and and just makes their life basically more complicated. People are much more concerned about getting the next widget out the door, making the next sales call, you know, whatever it takes to actually run the business and grow the business really. So there's definitely is a trade off between security and actual convenience. in there is there's definitely a balance, right? So, you you can't have things so convenient, they're actually wide open to attack, you don't wanna make things so security heavy that they never get used by people within an organization. So there's, hopefully that answers your question to some degree. It's a... Martin Hinton (40:44.012) Yeah, no, it it it does. I mean, I I I just think it's one of those it's one of those elements of this that you know, you increasingly hear C suite executives talk about and people in the s cybersecurity side, you know, you want employees who think before they click, right? And it and it and we have we've we've been conditioned to just click, right? You know, I mean I think the last time I checked the chris (41:01.88) Absolutely. Martin Hinton (41:09.44) I I I don't remember which corporation it was, so I won't name check them, but it was some new term of service for some sort of, you know, platform. And to read it for the normal person would have taken like 21 hours, right? Never mind the fact that they're they're written by lawyers and and I am not naive enough to think lawyers are always in a rush to help you understand the legalese with within their documents. So I think that there is this sort of, you know, barrier to friction that is in some ways, you know, the last 20 plus years. chris (41:22.042) Right. Martin Hinton (41:38.882) Basically, since the iTunes store, I think might be the fair sort of starting point to to you know, in the professional space, you know, obviously as consumers, we're like one click to buy and all that sort of thing, and your credit card's saved in your browser and you don't have to enter your information and your address autofills. All of these little things are are they increase sales. And I think that that the everything that a criminal knows about behavioral psychology and how to organize a website or a store. is is is is there for them to to act upon. So it's just an interesting idea. You did answer it. I I I want to just pivot now to the cyber insurance reality of this. One of the things we know is that it the market is under a lot of pressure, you know, flat, adjusting, you depending on who you talk to and the level of optimism, I I think it might be fair to say a lot of companies in the last few years joined it without comprehending the difficulty underwriting the risk or even assessing risk in any real way. So what you're seeing is this move away from chris (42:33.468) Right? Martin Hinton (42:36.162) you know, one time checklists at renewal to, you know, constant monitoring and, you know, the ability to confirm in a more what, dynamic or comprehensive way that MFA is properly implemented and that sort of thing. you should should insurers be applying essentially the same cybersecurity expectations internally that they are being asked for of the insured? You sort of touched on this before, and I wonder whether or not you, you know, you you have more to say about sort of the idea that this, you know This ability to say, well, we've got past pack. We should we deserve to pay, you know, X percent less, or, you know, we should the we have all these things in place. We use all these tools to help manage our credentials. Th they should gain us greater trust. We are lower risk as a result. We should, we should have a lower premium as a result. chris (43:25.593) Right, well, actually, Passback does work with several large insurance companies to help mitigate the risk with their end customers and be actually looking to actually work with more. Going back to your earlier question, I think most definitely, it's a bit sort of, I think it's personally unfair that a particular company asks an end customer to actually install these particular cybersecurity. Provisions in their organization without them doing them doing it themselves further upstream So the answer is yes to your question cyber security companies definitely need to actually Implement the actual cyber security policies, which they're putting on to their particular clients In many cases, I fully understand the challenges in that with a large insurance company Which is dealing with many different sales agents brokers and many different facets of its business. It's so it's a lot easier said than done But I think certainly within the cyber insurance insurance space, it's definitely improving. If you look how banks have changed over the years with their cyber security, think insurance companies are taking similar measures internally to actually improve their own internal security. But it does take time, absolutely, to actually get those security measures in place. Martin Hinton (44:35.426) Well t t tell me a little more to the degree you can about some of those insurance company relationships you have now. H how how did they come about? Did you go s you you mentioned you're looking for more business? Did you go to them and say, Hey, listen, we can help you find more insurable risk, right? how how did that all come to be? And and tell me more about those relationships. chris (44:55.643) Well, basically, actually, the relationship started, but really with with insurance people actually approaching us in all honesty, saying, okay, well, we actually very interested in solutions which help us mitigate risk with our end clients, basically. So we were approached by several insurance companies to have these conversations. And, yeah, it's been quite interesting on some levels. There's obviously various parts of that whole ecosystem that need to be managed within the insurance sales cycle. where does Passback actually fit in that wholesale cycle with their insurance brokers and so on. But yeah, and it's fairly early days for us. We've actually only really been actively doing this program for about the last six months. So we are, as we move forward, we also learn with our insurance partners as well, basically. But the whole, yeah, sorry, but I say, yeah, but the whole deal is to actually... Martin Hinton (45:43.778) Well, I mean I I mean you go ahead, pardon me. chris (45:50.182) make sure that the end user is actually safe and secure and is just doing some basic fundamental actions which can really save a whole lot of pain in the event of a breach or in the event of a cybersecurity attack on a particular business. Absolutely. Martin Hinton (46:05.196) Yeah. I mean I mean, is the value proposition that that you know, this is it is it as simple as, hey, here's something that'll help make you more secure and if you use it then you're a better risk for an insurer. Is is it is it that simple or am I am I mistaken? chris (46:21.751) It's that simple in many cases, especially for the small to medium sized business. It definitely is that simple. Absolutely. Yeah. Yeah. Martin Hinton (46:27.65) Yeah. Do you I mean, when you think about where we are now with, you know, MFA and again, I mean, there are so many ways that it works. It it I I almost it's an acronym that can mean more than several things, right? So you can do MFA through an SMS text or, you know, all sorts of other things. Where do you see the the future of this going? with identity security and, you know, passwords and pass keys and and all you know, we've got biometric now, depending on the device and the the access point to get into your iPhone. Tell tell me about what you see, you know, at the horizon and to the degree any of us can predict the future, you know, viable reality going forward. chris (47:09.189) Well, I think actually, in honesty, if you look at the security landscape, it's definitely evolving. have some other, you know, have solutions like pass keys out there. You have various ways of authenticating access into a particular resource. So really what you're having to handle these days as a modern business is actually various ways of accessing particular information. You just don't really have one solution that fits all, especially if you're a larger company. So you're having to actually manage various solutions. And coming down the horizon, I think you're probably going to see some of these solutions blended more together across time. I mean, I presented to a small group of business owners in Arizona a few months back and, you know, the issue of pass keys came up or pass keys are very good for some things, but they're not good. for everything. They're not good if you need to share them. They rely on a technology to actually authenticate the person into the particular resource. What happens when the passkey fails or the authentication device goes down? Well, password is the backup. So you've got to have various contingency plans in place around the various solutions out there. And it's definitely a case of one shoe does not fit all currently. And I think that's going to continue. and going back into AI that only actually complicates the issue in terms of some of these more advanced type of attacks. Martin Hinton (48:35.576) Do you I mean w I sort of set you up here because one of the realities is tons of companies and organizations don't even use the most basic MFA. Never mind what might be cutting edge. I mean, do you do do you think that one of the messages here for companies that are looking to be more secure and reduce their cyber risk and perhaps be able to go to their broker and say, hey, listen, look, we wanna somehow document that we've got MFA across, you know, every login, every credential. Pardon me. chris (48:47.575) Absolutely. Martin Hinton (49:05.006) Do you do you think one of the underlying messages is that don't wait for what's coming? You you can use what's now and you can do a lot to make yourself more secure. chris (49:13.783) Absolutely. Well, actually with MFA, it's a fundamental part of any security posture. I mean, I would advise everybody to set up MFA where possible. And what MFA does, it does say, okay, well, the person logging in also has the MFA code. So it's the real person logging in basically, or an authorized person logging in. What it doesn't do is supply the ownership of that particular credential. You can't tell who owns it via an MFA login. Again, mean, the MFA code could well leave with a credential when a person is off boarded. So it doesn't really solve that particular problem. So again, MFA is part of the whole security landscape. But as a fundamental security action for any business, yes, set up MFA on the accounts which actually support MFA. It's a fundamental good security measure which you can take this afternoon or tomorrow. you know, it's a, yeah, along with actually making strong passwords. mean, so many people use weak passwords every year. It always surprises me. And I know this is probably a bit more on the consumer side, but you know, the, most common password is password one, two, three, four, you know, so. Don't use easy to actually remember, easy to replicate passwords. Again, just going back into the AI threat, AI can do a much better job in cracking weak passwords. It's got the tools at its disposal. In fact, some people are actually foolish enough to actually ask AI to generate a strong password. And of course, that does is it enters into the large language model and then somebody only has to ask a question again and it gets a similar type of password. Martin Hinton (50:55.794) There you go. I I mean I I think you know, y there might be people here who are thinking, I'm so bad with my passwords and I would just say that that the it the password for the security system at the Louvre was Louv one two three. And I think that it chris (50:56.233) Yeah. chris (51:09.287) That is my favorite. I wrote a blog about that. That's one of my favorite hacks. actually, even the Louvre warned about that, you should change that password. And again, it's a prime example, Louvre123 and no MFA on the account either. that's it. Martin Hinton (51:22.678) Yeah, I mean I you know, we we sort of jumped over it. We you know, the fact that I was reading a report that I haven't finished yet today about Internet of Things security. And that means all the things around us, the router in your home, for example, that they often have passwords that are default passwords, and very rarely are they do you s reset them and change them on your own because there's no screen, it's not obvious and that sort of thing. And there are all of these points of access are chris (51:46.124) Absolutely, yeah. Martin Hinton (51:50.602) in some respects, identities that allow people to get into your secure space, your your network, your company files. chris (51:56.088) Absolutely. I mean, yeah, I mean, the most common example of that is the is the wireless router, of course, right, we all have wireless routers. And typically, the password to get into the router is admin or admin 123. And nobody ever changes that. Well, I say nobody. Security conscious people do, but not many people do. Yeah, it's a Martin Hinton (52:14.316) No, I mean I but again I think we you know it it sort of brings us back to the friction. If you get a new home Wi-Fi network or a new router from your your cable provider, your internet provider, you're getting you're you're typically getting it because you don't have one that's working properly. You're ripping it out of the box, you're plugging it in as fast as you can, and you're moving on with your day. You're not thinking about security because I don't I you know, again, I mean I think of the the first time I learned about the idea that, you know, routers could do way more than just route your internet traffic, right? Like it to and from. chris (52:32.44) Absolutely, yeah. Martin Hinton (52:43.842) that the the they possess, if you will, the classic, the most classic of backdoors into what you perceive as a secure environment. And I and I again I think it's one of those weird things that you, you know, is a sort of vestige of back when we were hobbling this internet together and you know, before my time maybe, but but i it it's just one of those things that sort of lingered around that creates real vulnerability that is not obvious to people. That's not something you would think, you know what, there's another thing. It's like my laptop. No, these are all points of access that you know, and you need to control Yeah. chris (53:18.051) Absolutely. Yeah. Well, I mean, heaven forbid if you have a, if you have all your passwords stored in your browser password manager, which again, going back to this convenience thing is actually a very convenient way to live. It just pops up when you're actually on. But if somebody gains access through the front door of your PC, you're wide open and they've got bank accounts, they've got credit card numbers, they've got addresses. I know, and I'm, I'm, you know, I mean, browser password managers are one thing we preach. Please do not use your browser password manager if you're serious about security. Martin Hinton (53:50.582) Yeah, I mean I I I again it but I mean you there you're on that point you made earlier about the the balance between convenience and friction and you know, if it works people will use it. Well, you know, so you know, you know, Martin's cat one two three is is a common chris (54:02.277) Yeah. Yeah, and I forget what the number is exactly, but I mean, Google or Chrome actually controls about 90 % of the browser business or maybe slightly less, but it's a very high percentage of the browser business. Of course, it's a huge attack vector for any cyber criminal go after the browser. It's got so much good information stored about persons, individuals and businesses, right? Absolutely. So be very careful what you store in the browser is the motto of that story. Martin Hinton (54:27.426) Yeah. Yeah, yeah. That's that's been the subject of a a past podcast of ours. So it it it it is. And again, it's a good for a non-technical person, which I think a lot of people are, given how technical everything we touch is, even when we're not in a technical sort of profession, the the the the the the layer of vulnerability that's created by the convenience we enjoy is is very real. I I I s you know, as we move to the close, I just wanted to touch come back to sort of the human side of this, right? Tools, tricks. The technology only works if the person that's k who gets access to it uses it the way it's intended. So I I I wonder y that there's a constant tension between security and convenience. And we've touched on this a little bit. And I just want to talk a little more about how you might approach this from a you know a leadership point of view, or you know, you've touched on some stories you might tell or lessons you might impart, but w what about, you know, This is an example I think I mentioned you when we spoke initially. The idea that if you're doing a cybersecurity seminar and it's 50 people in a conference room and they're sitting there and there's slides and maybe a little QA or a scenario, how important it is for, you know, maybe a C-suite executive of one flavor or another to be in every single one of those 10 sessions. If you've got, you know, 500 employees and you've got 10 C-suite executives, one's in each meeting to impart. the importance of this to show that that no one is immune from this. I think that we touched on the idea that when Archie Norman, who was the chairman of Marks and Spencer's, testified before Parliament about their hack a couple of years ago, he talked about s sort of in a almost aha kind of way, that the they have 50,000 employees. And whether it's a store clerk in Manchester in Northern England or an IT worker in in India, there is Martin Hinton (56:25.216) vulnerability equal from all those points. And and this idea that there is a, you know, a the need to create a more sort of, if you will, system wide or employee wide understanding of why it matters that you use the right tools. So what about the human side of this sort of from a security point of view? chris (56:44.487) Well, that's a great point. mean, I always say that training is very important for an organization just to make people aware of the risks. You don't have to go overboard on the training, but really push home that really it's, I think you touched on this earlier or maybe in a previous conversation. If there is a cyber breach and the company's actually has resources removed, could affect your paycheck, right? It could affect your livelihood. It could affect the actual future of the business, the reputation of the business. In training around the importance of cybersecurity is very, very key. But in order for security to be used within an organization, it has to be simple to use. And you touched on the various levels of people's expertise in cybersecurity. One thing we're very conscious of at PassPack is you want to make PassPack easy to use. not only for the power IT manager, but for the general user that doesn't really have much cybersecurity experience or knowledge, but it's not really gonna interrupt their day if they have to use PassPak to log into a particular resource, especially when they actually understand that it has a real impact on the company if there is a cybersecurity issue, if the company gets breached or some information from the company or it affects the company's clients. So the importance of using the tool. So partly education and partly making tools easy to use. I mean, you're always going to get some people, I've done it this way for 10 years and it hasn't happened to me yet, but it always can happen. In fact, we've had numerous incidences of people, I was using the same password for 10 years, never had an issue. And then suddenly you have a breach, right? So there's various facets to that question, Martin, but I'm a big proponent on training. Martin Hinton (58:17.837) Yes. chris (58:32.515) It doesn't have to be heavy training. doesn't have to scare people into using a product. It has to make them aware and then supplying the tools which are easy to use so you can actually implement your cybersecurity policy within an organization simply and effectively. And it doesn't interfere with the employee's life within an organization. yeah. Martin Hinton (58:53.848) So we've been talking about an hour and I don't I'm sure we didn't get to everything. I got a couple wrap up questions, but before we come to that, I just wanted to see whether there's anything we didn't get to that you'd like to talk about or whether there's anything we did talk about that you'd like to say any more about. chris (59:08.199) The only thing I'd to talk about is that this actual business is constantly changing. Absolutely. mean, the AI threats will only increase across time. The importance to take some very simple, straightforward measures to protect yourself and your business are very straightforward. Yeah, it's a it's an interesting business. And as much as people said many years, I think Bill Gates famously stood up at one particular convention said, the password will be dead inside, inside a year. But he was talking about biometrics and other authentication methods. And that was probably about 20 years ago. Now he said that. So you know, credentials and passwords are definitely here to stay. It is a fact of modern life. And there's no need to be shy of them. They are, you know, you can take some very simple straightforward cyber security steps to really improve your cyber security posture out there. Martin Hinton (59:57.1) Yeah. I mean, I listen, we we we we still carry keys. you know, I think that that that idea that, you know, if you're gonna put what you value into any kind of space, whether it's a real space or a digital space, whether it's your personal stuff or whether it's professional if you will, IP, you wanna make sure it's secure. and the the idea that you yeah, the idea that you care about it is enough motivation, right? Like this stuff matters. And I and I think that, you know, having that mindset and knowing that that doesn't chris (01:00:17.497) Absolutely. Yeah. Absolutely. Martin Hinton (01:00:26.808) Perfection is not possible, but but but you know that that attitude needs to be dialed up a little. So I want to pivot to some sort of you know, b we we touched on small and mid-sized businesses. You know, they don't have a CISO, they don't have a huge cybersecurity budget, the the relatively small IT team that that is also doing cybersecurity, which is a whole other conversation. If if the CEO or owner of this company comes in on Monday morning and would like to address their credential and identity risk. What are three things that they should do or ask their IT manager or, you know, maybe they've got a an outside provider. What what are what are the top three questions you you you would want to know the answer to to chris (01:01:07.919) Well, I I mean, we touched on one earlier. I mean, definitely set up multi-factor authentication on all your critical systems where applicable. It's a very good idea to have a solution like PassPack and put all your credentials in one place and most importantly, know who owns what credentials. The other important part, which we didn't touch on too much, but it was actually the importance of obviously generating strong passwords, but also rotating login credentials regularly. Don't leave the same credential out there for years and years because it's going to get out and you are going to experience a breach further on down the line if you're not too careful. So it's basically multifactor authentication. Make sure you have all the passwords secured in an encrypted area. and shared securely to the target employees, change them regularly, and know who owns what, basically, which you can do by generating a report or just really know who owns access to what. And if you have any doubts, change the credentials on your critical systems and then make sure you know who owns what credential when it comes to logging into particular resources. Martin Hinton (01:02:19.946) And so finally, I mean, it seems to me, you know, we we we started out not particularly secure in the sense of, you know, the early days back in say the eighties or nineties, the password and it was really a you know, a point of access for a log on for a computer within a, you know, college environment where the internet was first accessible to people. And we've evolved and we sort of patched security onto the if you will, the world's tech stack. Do you see a reality where now Particularly with AI, businesses are viewing the importance of cybersecurity as, you know, a a functional element of business operation. It's not just something that can be sort of secondary, that that you that you have to protect, you know, your digital space like you would your physical space. Do you see that evolution ongoing? chris (01:03:07.753) definitely. think cybersecurity is a basic requirement. And you see that in the insurance business is the way that they're actually demanding. And you actually hit on a very good point earlier, I think it's very difficult for the insurance business to really gauge the risk around cybersecurity. I mean, there's obviously significant risk there, but the history of the business is so short that it's really hard to get some very solid numbers around that. But yeah. It's definitely evolving. It's definitely going to become more critical as time goes on. It's very important for a business to take simple steps to actually improve its cybersecurity posture. AI will only accelerate. mean, you look where we were three or four years ago and look at where AI is now and the potential threats out there. So yeah, this landscape will definitely continue to evolve. And we, as the good guys on this side of the fence, have to make sure that we supply the tools to make it very difficult for the cyber criminals out there. So yeah, it's him. Martin Hinton (01:04:09.206) Well, Chris, I think that's a great spot to end on. Like you said, there's gonna be much more to say. I I I I don't think this will be the the the last time you're on the podcast. So again, thank you very much. chris (01:04:21.009) Well, thank you, Martin. It's been a real pleasure. Thank you. Always enjoyed talking. Thank you very much. Martin Hinton (01:04:24.492) Yeah. Chris Skipworth, CEO of Pass Pack, again, thanks very much for your time. Everyone else, thank you so very much for watching. I'm Martin Hinton, the executive editor of Cyber Insurance News and Information. Enjoy the rest of your day.