Martin Hinton (00:01) This is the Cyber Insurance News and Information Podcast. I'm Martin Hinton, Executive Editor. Every week we talk to the underwriters, brokers, and security leaders shaping the market. Let's get into it. Martin Hinton (00:16) Today we are looking at why MFA is no longer enough on its own, the rise of phishing resistance and passwordless authentication, and what zero trust means when you strip away the sales language. Joining me are Isabel Castillo, lead InfoSec ops engineer at Lastwall. Julien Richard Vice President of Information Security at Lastwall. Isabel, Julien , thanks for coming in today. How are you? How's your day been so far? Julien Richard (00:42) Good. just Friday. I don't know if this is gonna come out on a Friday, but it's Friday, so Fridays are always good. And we're a couple days away from Hacker Summer Camp in Vegas, which is always exciting. Martin Hinton (00:52) That's right, that's right. I g there's been no shortage of news about Hacker Summer Camp and I've never heard it quite referred to as that. I'm gonna I'm gonna go with that for now. I will credit you in any usage going forward. Isabel, how about you? It is Friday, so if we seem jovial and you're watching this on a Monday, that explains it. How's your day, Isabel? Isabel Castillo (01:07) It's been great. It's Friday. We're wrapping up the week, preparing for next week, but definitely looking for the weekend. Martin Hinton (01:14) All right, well well Julien, let's dive right in with a with a provocative question. Is it fair to say that MFA is no longer enough, or does that risk giving businesses the wrong message? Julien Richard (01:24) yeah, I mean it it's absolutely not fair to say that it's not enough. It's it's it's enough. I think that there's multiple ways to see MFA. There's multiple factors at play and it all depends on which type of MFA you're using. And yeah, we're definitely giving businesses the wrong messages. We're talking about security in depth, and I think that that's gonna be a a topic that we're gonna touch today. Martin Hinton (01:45) Yeah, that's true. Isabel, from from an operational perspective, what does security team still get wrong after senior management says, We have MFA, so we're protected, right? Isabel Castillo (01:55) They see it as a task instead of a continuous control. MFA is not a task. There are gonna be exceptions when you're trying to implement it. And because of that, if you overlook that fact, you will expose your company and your your customers to to risk. Martin Hinton (02:11) Got it, got it. So let's step back from from the topic for a second and establish some language. Julien, when people say MFA, what different technologies are they grouping together under that one label? Is is it is is it important to differentiate the the the kinds of MFA? Julien Richard (02:29) Absolutely. So we we're looking at two different kinds. There's one that's phishing resistant, and we'll get that we'll again we'll get get into that later today. But we're talking about you know phishing resistant, non-phishing resistant. So anything from SMS messages that you're getting, one code, authenticator apps that you same thing that that do give you a code, push notification, click links that you gotta click when it sends your email, and then we're looking at things like UB keys, pass keys. in fight two web auth n technologies. Martin Hinton (03:01) Got it. So so maybe Isabel, could you give me sort of the spectrum from, you know, which is the the most secure or strongest, maybe the better way to put it to to to l le least strong or less strong? Is there a is there a category or a way to rank them? Isabel Castillo (03:16) Yeah, you can escalate it. If you if you think of your house, right? If I just close the door, that's my password. If I use MSS, you you close the door and you put a lock. If you use an authenticator, you put a deadbolt. If you use your Fighter Two keys or your pass keys, you put a deadbolt, a chair, and another chair on top of it. That's how we that's how I would write them. Martin Hinton (03:40) the the the the the the the old the chair under the doorknob. I I I like that. I like that. Do you do you think in in in in the the broader context, beyond your own professional experience, do you think when companies are buying these products they're understanding what threat each product is designed to stop or is there a you know a a an understanding gap in this space? Isabel Castillo (04:01) I will say there's an understanding gap because well there's there's so many there's so much technology there available, but before you even buy something, you need to understand what your needs are and what you're trying to protect and what you're applying each each technology to. I will say there's an understanding gap and companies will benefit by really sitting down and looking at what they're trying to protect and see what they're trying to buy will cover that need. Martin Hinton (04:28) I mean there are a lot of variations here and I'm just gonna read from this list of of I guess terms. There's authentication factor, one time password, push based MFA, and number matching, pass keys, it it goes on, session tokens, conditional access. I I wonder whether or not are those all very different things, almost like a different beverage you might get at a a deli? or are there are there ways that they work together or are complementary to each other? Isabel Castillo (04:57) They would definitely work together. I will see it as beverage, a different quality and different price tag. That's what I will see. They're they're all gonna be go ahead. They're all gonna help you protect your company, but one is gonna do it more and more securely than the other. One is your water, if it's just a password, if it's just an MSS, or the other one is gonna be I'm not a drinker brand going to assume it's gonna be your I think it's black labeled whiskey. That would be your your I think that's what that is. Forgive me my lack of knowledge, but that will be your fighter two and your passkeys. That is the the expensive one that is gonna give you more protection. Martin Hinton (05:35) So the the premium beverage we'll call it, we we would want we don't want to exclude anyone's personal choices, would be a pass key or fido, i the the top of the tier or the most secure. Great. Okay. Understood, understood. Now before we move on, is there anything about the sort of terminology or or or this part of it, Julien, that you think needs greater clarification or explanation? Julien Richard (06:01) I think one thing that people get wrong is when we talk about factors, a factor is something you have, something you are, something you you you sorry, something you know, something you are, and something you have. And you can add three of something you have, it doesn't make it multi-factor. That's still one factor. It's just multi- multi-step authentication. It's very different from multi-factor authentication. So you need to have at least one of each, at least one one. At least two of these three factors to to make it pure multi factor. Martin Hinton (06:33) So there's that that's a the there's a there's one of my favorite quotes is and I'll butcher it, but I it it's a Mark Twain line and and his line goes like this the difference between the right word and the almost right word is no small matter. 'Tis the difference between the lightning and the lightning bug. And multi-factor versus multi-step sounds incredibly similar. In fact they're only off by one letter or a third. But there's a dramatic difference in what that creates for the security of a network or any kind of system, right? Julien Richard (07:04) Yeah, exactly. Martin Hinton (07:06) understood. So I asked early at the beginning why MFA isn't enough anymore and you pushed back on that. And I and I I I I wonder whether we might sort of explore that a little more t to to to help the audience understand where we are and the great s sort of range of MFA's p potential application or the way it can be applied. So w was it oversold as a solution or do you feel like it's just you know, run its course as a as a As a a tool for security, I that may be a bit aggressive, but you t tell me that. Push back on that a little bit. Julien Richard (07:41) Sure, I I mean listen, as even if you go with SMS, which is probably the one that people know the most about and probably has the most vulnerabilities, still better than nothing at all. Like, you know, I if you have SMS in your in your environment doesn't mean you should just throw it away and just go back to passwords because you know, people are saying that MFA is is is not the golden solution that it was once sold to be. that doesn't mean that you shouldn't be strived to getting something more secure. one one big theme in in this whole conversation I think is gonna be that and I like to say your threat model is not my threat model. If I'm protecting, you know, government information, specs for highly specialized weaponized systems, I may want to have Maybe SMS is not enough at that point. And I would argue that it it isn't. But if you're protecting, you know, your the amount of times that somebody watched Gangnam style on YouTube, well maybe that's can be okay with SMS because if it gets leaked it's not that sensitive and people are not gonna die. Martin Hinton (08:38) Got it. I I mean I I think that this is a very important distinction that to make, that the the idea of not doing something is that that that nobody would advise that. If you have any kind of variation of MFA, you should employ it. And it's i i y you know, I always try to in the podcast particularly is sort of move that into human terms and and that means, you know, maybe you can't run a marathon, but you can walk. And the idea that some level of physical activity is better than none for your health and for your well being, and that holds true in this space too. So I I just wanna be very careful for the audience's sake that we don't put them in a situation where they think, if I can't get a passkey for it, then it's just not worth it. Never mind, I won't do anything except use a you know, a silly password I've repeated with my you know, my pet's name in it. Is that is that a how how important a point is that do you think, Isabel? Isabel Castillo (09:25) I'm laughing because of your pet's name. It is very important. You need to add a little bit of friction there. And no, no like you will never leave. Your you will never just shut the front door of your house. You will at least lock it. It is important that you at least put at least one way of MFA to protect yourself. Martin Hinton (09:41) Yeah, yeah. So so Isabel, within what does poorly implemented MFA look like? You know, if I if if I'm watching this or listening to this podcast and I've got a company, what are a few of the sort of canaries in the coal mine or or telltales that I might know I might look for to make me realize, ooh, I've got to adjust this or fix that or maybe we need to to dial up the security level or the MFA quality here or there. Wha wha what what what would someone see if they looked around an organization? Isabel Castillo (10:11) Inconsistent implementation on MFA. So some employees have it but the admins don't have it. so employees have it but the contractors don't have it. The C the executives don't have it. That's a very poorly implemented MFA. Because the control is there, it can help you, but you didn't because of X, Y, and C reason, perhaps people had too much friction, you didn't implement it fully and to be effective, regardless of which. which level of MFA you're gonna use, it has to be consistently implemented for everybody and leadership will set a great example if they a hundred percent embrace MFA for them as well. Martin Hinton (10:50) Julien, so I I guess the the the the obvious issue with inconsistent employment is that an attacker can look for someone who's doing it incorrectly and that one account creates a doorway into the network, the system. Is that fair? Julien Richard (11:09) Yeah, absolutely. again, this is not a technology problem. This is a process, it's a policy problem. if you're not implementing your MFA correctly, then you're probably not patching your systems correctly because you don't have the right processes in place. You're not a mature organization. So we're gonna talk a lot about defense in depth. this is just one way to to protect your environment. If you're not patching your your your front-facing firewall and they can just completely bypass authentication, you can have the most secure authentication system available on that on that on that device. But if there's a flaw that you haven't patched that you can just walk around it, there's not a whole lot of authentication can do. So we really need to talk about defense in depth. We really need to talk about other controls that are in place. And badly implemented systems are not just tied to MFA. They're tied to any other systems in your environment. So you comes down to pot process policy. If you're being audited, you need to show that you're doing the right things at all the right places. Martin Hinton (12:08) I w what you're describing I I think is the i i and and Isabel touched on this is that to make something secure you have layers of defense, not one one defensive point. And and the way they work together strengthens them and I'm I'm searching for an example of that in nature, but it's a bit like weaving a piece of thread, right? You y you know, a a a piece of thread is quite weak, but you can weave it into a blanket that can hold weight. Is that too simplified an analogy? I don't know, Julien, Isabel, which one of you wants to? See whether I've made it. Julien Richard (12:37) the way I like to see it, it's it's very simple. Hackers are lazy. I I I was an ethical hacker for many, many years. I'm lazy. I'm gonna take the the path of least resistance. And in my case, ethical hacker, I'm being being paid to to see stuff in an environment. But for a a malicious actor, if they're not targeting you, they're just looking for opportunities to ransomware people and things like that. They if if if they keep hitting barriers after barriers after barriers, they'll move on to the next person. So it's the analogy is, you know, I don't need to run faster than the bear, I just need to run faster than the other person next to me is kind of is kind of the appropriate analogy in nature. Cliche, but you know. Martin Hinton (13:15) W Isabel, I asked about what a company with poor MFA looks like. And in our in our pre-interview for this, I think Julien mentioned sometimes executives get preferential treatment when they call the help desk, and maybe they don't have to go through all the the the controls, which we we know is a problem when it comes to social engineering. People pretend to be people. But then there were also the phenomenon where you get sort of emergency access accounts, the quote unquote break glass accounts. When you have a you know, i as as Julien was just talking about, the the the what you need to sort of adhere to your system and your guidelines. So that that's that that's the the protocols you create. And when you vary outside those, that's that creates vulnerability that is you know, the inconsistency we you've touched on. Tell me about that sort of break glass, sort of these weaker controls that exist around maybe certain people who are grumpy, if you will, 'cause it it does break down to that kind of thing to your point about it not being a technical problem. Julian's point about that part of me. Isabel Castillo (14:10) So breakfast account by definition, they don't have MFA. Why? Because if MFA fails, then it can access my account and now the crisis is just going to be a catastrophe. You cannot access your system and recover it. touching on exceptions. So the way I see security is that when security or the process of security fails, the company pays. And nobody pays more than seeing a company paying the executives, right? That's where Leadership comes into play. That's where your procedures and your policies come into play. Nobody is accept from efficient scam. Nobody's gonna be accept from run so we're no company is bulletproof in terms of that. And because of that is that you cannot create exceptions unless the exceptions fulfill a security need for that. That is your break class account. Martin Hinton (15:00) Got it. Thank you very much for that clarity. I I I get it. So I wanna pivot now sort of the the the the insurance world, the the underwriting experience. And you you the phrase is MFA deployed, right? y you you're asking whether that's there, but it's being bypassed. So how are attackers bypassing MFA in the present, today, if you will? Julien Richard (15:20) There are many my my I've got a dog behind me, so if there's weird noise, that's why. so there are many attack vectors for for attacking MFA. One is your classic social engineering, hey, what's your code on your on your thing? Because I see that your account was gonna be locked out if we don't do it. We need to do something from the admin panel. Can you give me that that information? And then they basically go ahead and and log into your account. Now Every one of these accounts except for one kind of falls under the the assumption that they have your password. A lot of us reuse passwords. There's been a lot of breaches. They can try to reuse passwords. Once they have your password, all they need is that second factor. That's something you have or that's something you are. Hopefully they're not knocking your door down and cutting your fingers because it's a biometric thing, but you know, if you want to get dark. But but then there's there's there's adversary in the middle, and we can talk about that a bit later. But there's a bunch of different types of ways to bypass it. Martin Hinton (16:16) Well d Julien s take us into adversary in the middle. T w tell me about that. What does that mean? Julien Richard (16:22) Basically an attacker gets you to visit a web website, whether they they send you a t a text link, they send you a phishing link through an email address and it looks like it's coming from your bank, right? And they've registered this domain name that's called, you know, your bank is bank.com. they're they registered bonk.com and you go on bonk.com and it looks exactly the same webpage. They get you to put in your username, password, and then they simply send that password over to your bank. They log in with that, then it says, Hey, you need an MFA code. So let's say it's an SMS code, you get it on your phone, you're the one that's starting to log in. So all they do is they go, what's your MFA code? You put it into bonk.com against they proxy that that request, they send it over to your real bank. And once you're logged in, you have your authorization token, your session token. They steal the session token. They don't steal your password or your TOTP code or your code that's being sent, because it's usually one one time. It's a one time use. So they'll actually steal your session. and I don't want to get too technical, but basically with a website, you need to pass a thing that's called a session token every time you visit it so that it they know it's you. There's no state. website is not stateful. So if you have that session token, you can log in as the person you just put in your browser is trivial and then you get access to the account. Martin Hinton (17:39) So so Isabel, wha whether it's this or session and token theft, what what type of monitoring might be the kind of thing that that helps you know an unusual device, location? H how how might that what are the workarounds here? What are the solutions to some of this that people could employ? Isabel Castillo (17:55) So this is where you have your alerts and your monitoring. So what happens is in perspective, you're trying to look for a pattern, right? Like you people that have children, they know when their children are doing something weird because you know the pattern of your children, right? The same concept for a company, you know the pattern and the behaviors of your employees. You know either so where they're supposed to be logging in from. We can implement geofencing, we can take into account something that's called impossible travel, which means if Martin today logged in from Texas. He's not gonna log in an hour later from the Philippines. That's weird. That's that's hopefully one day that'll be possible, but right now it is not possible. That way that that will get flagged right away. If Martin is looking is trying to log in from a device that's not recognized, that's another flag. If Martin is trying he's failed his authentication sixty times in thirty seconds. That's really weird. That that's that's not the Martin that we know. That will trigger an alert. Martin Hinton (18:57) Flag. Yeah. Julien Richard (19:00) I mean, we did talk about black label whiskey, so maybe Martin's just having a hard time typing his password. Martin Hinton (19:05) Yeah, Isabel Castillo (19:06) Yeah, that will be flagged yes. Martin Hinton (19:05) no, that's true. It is Friday like we've we've discussed. I mean th there are other things that Julien, like the you know, the one that I I I still well, I understand that I've had it explained to me, the sim swapping one that that that would affect the SMS MFA, how how does that work? Julien Richard (19:23) We we're lucky that we haven't seen that that attack vector in a long time. I the telcos, the the telephone companies are have have put in the right processes, the right things, they've left they've learned their lessons. But basically, if you're using your phone as your as your something you have, right? So your phone number is something that you have, it's not something you know. you get something sent to your text message and you need to you need to fill in that code. We've we've all we all all still have accounts that do that. if I can call the telephone company and convince them that I'm Martin. and i I lost my phone, they can they can basically give me a sim, so a a a card that holds Martin's phone number. They do believe that I'm really him. And then I have his phone number. If I have also have his password because I've fished him somehow or or or Martin reused this password in one of the the the previous breaches. now I can log into the site. When it asks me for my for the SMS code, is gonna be sending it to Martin's phone number. And that's a very important part when we talk about something you you have, is that it doesn't mean that it's Martin or Isabel. It's just that somebody has Martin or Isabel's phone number. That's very different. so that's what attackers do. It got to the point where they were actually physically attacking workers at the Verizon store to seal the iPads, to to change the the sim and things like that. But the companies of the the technical companies have really cracked down and putting the right controls in place and we're not seeing it often. It used to be very common in like high high theft in cryptocurrency world, like high huge amounts of cryptos. If you knew that somebody had a lot of crypto, it it would be worth to go in. and and physically assault staff. And I I I'm I I laugh, but like it's just it's you know, to get you out of your your basement and going to the Verizon store and and and hit somebody's knees with a baseball bat probably need a lot of money in that account. Martin Hinton (21:18) I mean I I I listen, I mean I think you may you y the the the headline, if you will, right here is that a problem that used to exist in this world has improved. And I think that, you know, if you're in the space a lot, it would seem like the sky is always falling, but there is a lot going on to solve these problems and solutions sometimes take time and I and I think it's important to keep in mind that to your point, this used to be worse and now it's better, which is the trajectory you want generally, Isabel, help desk and recovery attacks. Tell me about that and and what processes you can have that are that are weak password resets and strong. Isabel Castillo (21:54) We password research, sending you immediately your password in plain text in the email. You forgot your password, here's your new password. Here, enter it. And that password doesn't expire. That is, you don't, you don't go ahead and change your password. That's a weak recover account recovery. A strong account recovery is I'm gonna send you this one-time link. This one-time link is gonna expire in about five minutes. And then on top of that, you have to enter a different code from your authenticator app. That's a strong account recovery system. Martin Hinton (22:26) Got it. This is an area where it falls into the mission impossible world, doesn't it, Julien? This is where the social engineering and deep fakes and personal information found on a public, you know, maybe social media channel. It's a cousin for the CEO. T talk about how that part of this is you know, it's a procedure, a human issue. It's n it's not really a technical issue. Julien Richard (22:48) No, and and we're here we're talking about identity, right? So so if you think about the triad of of of of access control or or or or things like that, you've got authentication, which you authentif authenticate against the system. You prove this is who I am. you prove that you have the right, you are the same person that registered on that site, basically is is what it means. And then you have authorization. What am I allowed to do? The one thing that we always forget is identification. So there's a reason why your bank gets you to go to the bank with your passport to set your password or set your PIN on your on your card because it is a high risk area. again, I not to say that Netflix is not important, but like for me to register on Netflix, I probably don't need to get anything not notarized. I don't need to to go and get my passport stamped or or or or or set. So again, when we talk about resetting stuff, if I have access to a high-side top secret environment and I lose my password, I shouldn't be able to call the help desk and ask them to reset it. Like is Isabel's examples of of magic links and everything else, those are beautiful. They work well for certain environments. But at the end of the day, if it's a again, high side top secret place that I'm trying to log into, somebody could have broken into my email address where that magic link is being sent. I could be the one that's calling and asking for those things. So I'll repeat it again your threat model is not my threat model. It depends on the system. And identity is a very different problem than authentication. Martin Hinton (24:16) It is. So so keep keeping us in the authentication world, all this has necessitated a rise in fishing resistant authentication. So Julien, we we touched on some of the examples of this early on, but t tell me about what what that is and the I guess the names of the devices or the tools that you can use to utilize it. Julien Richard (24:36) Sure. this is where I can get very deep into weeds and technical, so stop me if if if I if I go off. it's it's you need to understand the technology underneath it f a little bit to be able able to understand why we call it fish fishing resistant. First off, doesn't mean that you're not gonna get any fishes in your emails. You're still going to get all the fishes. I mean what n over sixty percent of traffic on the internet right now is bots just trying to fish people. So A a a fishing resistant solution just means that you can't it the that fish can't succeed. So we're you know, we talk about FIDO two, WebAuth and these are the types of technologies that you use. You talk about Yubi keys and pass keys. but at the end of the day, when you register on a site and they prove that it's actually you and you you get that credential, the credential is a key pair. So you have a private key pair and a public key pair. They're tied through the magic of math that is way over my head, they work together. And you store the private key and it never leaves your device ever again. It shouldn't. We'll talk about like you know, being able to transfer it from one side to the other and why that's a problem. But at the end of the day, you're creating one for every system that you're logging into. So back to my example of bank and bonk. If bonk is trying to do the adversary in the middle attack, I see the request coming from Bonk. It's not that. I'm trying to log into it, is that I can't because I do not have a credential for bank.com. I just don't. And I'm not going to release it to anybody else but bank.com. And there's a way for me to to to make sure that it's actually bank.com. Again, kind of technical, and we can get into that. But the reality is that every credential is tied to a specific system and you cannot use it anywhere else. And it's not going to work. And you cannot take it from me and pass it over and proxy it over to the other side. It just doesn't work. Martin Hinton (26:29) So d the let me see if I make sure I understand this for this for my sake and the audiences. If you have a passkey, for example, the s when you say system, do you mean like my phone is the only phone that that is recognized? Is that y you you create like a unique identifier for each device that you might want to use to go into your bank account? Julien Richard (26:50) No, you you create a private certificate or a private a pass key that is only tied to that website, right? When I say system, I don't wanna you know, I don't wanna bind myself just a websites you can do this for applications and all kinds of stuff, but in in to simplify it, my bank, right? So I have a private I have a a PASCE or a certificate that only works at my bank. It's not gonna work on any other system. Martin Hinton (27:13) Got it, God that that th I think that the the the word system is what threw me there. Thank you very much. Isabel, wha where does this w you know, obviously this information needs to be s secured, secu secured. And I wonder about the the storage of these private credentials and and and that element of all this. How how are the what are the best practices around that? Isabel Castillo (27:31) I'm drawing a blank, I'm sorry. Martin Hinton (27:33) No, that's that's that's okay. That's okay. No, no, no, no. So well let me let me let Isabel Castillo (27:37) Here in this in this one and drawing a blank. Martin Hinton (27:39) me ask you a very simple question then. You know, if you're if you're using pass keys and you lose a phone or a laptop or you know, well like what what are the protocols there? What w is it something as simple as, you know, mi cancel that credit card as soon as you realize it's lost or you know, you've got all this feature now where you can freeze your debit and eight an ATM card or your credit cards temporarily if you misplace them? What about that part of this? You know, that the the more sort of human part. Isabel Castillo (28:05) No, you need to revoke everything. The moment you you the moment your private key is compromised, you need to revoke everything. Just say everything becomes I I we like to say they would throw the computer away, but truly you kinda almost have to throw it away because now you have to generate a new set of a new set of baskeys. So bas key is private public key, right? The public key is what everybody uses to authenticate into that website that holds a private key. But if those are compromised, forget about it. you're revoking absolutely everything and you need to reissue, recreate those keys to secure the system again. Martin Hinton (28:39) I mean is that I mean, the obvious reality there is that's a very you mind your Ps and Q's, you look after your things and you keep them in in a a safe place and you know th like very old school kind of mindset about, you know, these things are valuable, take care of them with that mindset. Julien Richard (28:57) There there are protocols you can use. Like you create one. They're device they're we're we're talking about device bound passkeys There are there are passkeys that are not device bound that that is stored in software where you can actually transfer them. But the device bound ones are stay stored basically in a safe, in a chip on your on your computer, your mobile phone, your laptop. it it doesn't mean that it's the only thing that you can log into that site with. You can create a second pair of of public and private. keys that you can store on another device. So that way you can still log into the device to to to your application, let's say your bank, you just need to revoke the ones that were lost on your on your laptop. So the pair that was that the public key that the bank has, that is the the the the equivalent private keys on your laptop, you just wipe that one away because somebody had access to it. And if you've done your things right, if you've if you've backed things up correctly, you can still log in with your phone and create a new one on your laptop because you can log in with your phone. The problem is that when you only have one key pair and that is gone, that is gone. then you have to go to the bank, show your passport and say, Yes, I'm really Julien. Martin Hinton (30:05) Yeah, exactly. I well I mean this is one of the lines that I've been hearing a little and I was just writing something today about friction, not all friction being bad and I I've heard a few people talk more about the the idea that maybe a little more friction would would help us in this situation, particularly when it comes to you know, the fact that we've been trained for twenty years now to click one click to buy and you know, you don't even have to think about whether you want something anymore and the next thing you know it's at your door. I I guess you know, the the the the idea that fishing resistant and is something that you mean MFA gets asked about on the cyber insurance application. So do you have MFA? Might be the question. Would you well what are your thoughts either of you about the idea that that question needs to be a little more pr precise? Should it be do you use phishing resistant authentication, you know, to to to to make sure that it's it's drilling down on what we really care about, right? You know, how secure are you trying to make it and what tools are you using? Julien Richard (31:04) I'm gonna give an opinion here and Isabel's gonna maybe laugh at me because our security security questionnaires that we send to vendors may have some of these questions, but there's nothing worse than a yes or no question. Because of course they're gonna say yes. yeah, we have MFA. It's implemented in the key system to get into the building, but it's not in the system that holds everybody's financial information. But we do have MFA because it's implemented in somewhere, right? So it's easy to say yes and not lie. Now Auditors are not doing themselves any favor when they ask that question because the question that you should ask is talk to me about your access control system. What do you do? what inventory do you have? How do you protect things in your inventory? Show me all your systems and tell me each system how you protect it. Is it through you know, just a common identity solution? Do they have their own identity components or access control components in that system? But at the end of the day, zero or one questions, binary questions, they're not great for auditors. and and customers were not doing them any favor because all of a sudden they get popped. And they, when I say popped, they get breached. and the cyber insurance come back. So it's like, well, you said you had MFA. We did, you know, on that system, not the one that was breached. So they didn't lie, but the insurance is still not going to pay out. Martin Hinton (32:21) Yeah. Isabel, you you were you you were mentioned there. Do you have any reply to that? Isabel Castillo (32:28) No, no. No, he's right. you really need to find out the scope the scope of what your MFA is covering because like Julien said, it's really easy to say we have MFA. But truly you're asking what you really want to ask is where is your MFA implementing, which critical assets is your MFA being implemented. It's not just whether it's there or not, it's where, how, what and why. Martin Hinton (32:52) Yeah. I mean it's it's a bit like asking the question does the the the the door to your house lock versus do you lock the door to your house, right? Back to my Mark Twain line, right? How you ask the question can can open yourself up to to to a lot of things. Julien Richard (33:07) You lock the door and leave the windows open. Martin Hinton (33:09) Yes, exactly. I lock the door but I leave the windows open, exactly. Isabel, one of the things that we we we talked about in the pre interview was passwordless authentication. What does that mean? Passwordless? Isabel Castillo (33:22) That just basically means that you're not you you're not using a password, text password to authenticate every time. You're using something else. Maybe you're using a YubiKey. Maybe you're using your authenticator app. But that's basically just what it means. You're no longer typing your pet's name to to gain access. Martin Hinton (33:41) Got it. Julien, is d is that fishing resistant then to to to come back to that idea? Julien Richard (33:47) yes or no. yes and no. Some passwordless solutions are phishing resistant, some aren't. it it depends on what the technology is. Passwordless just means no password. Mo most phishing resistant solutions do not implement password. One of the factors may be password, but the part that is phishing resistant does not does not require passwords usually. Martin Hinton (34:10) One of the big is about one of the parts of this that people are familiar with is is unlocking something with their face or their fingerprint. But so pardon me, I have to use the language, biometrics, right? Is i is that ha well, what do you think about that? Isabel Castillo (34:27) Well hopefully like Julien said, you're not gonna get your fingers chopped off or your or your cornea stripped off, right? Let's just hope that doesn't happen. It's not like the movies. Let's hope that doesn't happen. so this is where this is where AI comes into place, right? This is where you read a lot of reports about metrics having bypassed because somebody is AI to replicate your face, to replicate something, or to distort. something and now that has been bypassed. So now I think we have to ask how is biometrics in the face of AI? I think that's where our the next podcast is gonna be like 'cause that's a very, very long conversation. Martin Hinton (35:04) Yeah, yeah. D I'm you know, one of the things we know that, you know, the one of the burdens on the help desk is password resets get problematic. Did d you know, and money being spent in the cybersecurity world is still viewed as a cost center and the idea of it being, you know, something that really is integral in protecting the profit center is, you know, maybe an evolving mindset. Is this one of those things that can can reduce that workload and free up, I guess, budget for other things? Julien Richard (35:34) I mean the obvious joke here is that nobody loses their face, but I mean f literally, figuratively, people lose face, but you know. Martin Hinton (35:43) Nick Cage, for example. Julien Richard (35:45) people are still like people are still gonna lose credentials no matter what it is. They're gonna lose their device, they're gonna lose these things, they're they're gonna need to log into a new device that doesn't have that pass key. It's it's like we're not going away from the help desk having to deal with some of these things, but it it I mean, yes and no, 'cause at the end of the day, losing a password is a lot easier than than losing a a hardware device or not remembering your password. Martin Hinton (36:12) Well well in this in in in this context and in within this you y you know one of the things we we know about and we hear about is, if you will, identity sprawl and the idea that as you touched on earlier, that when someone leaves a company their permissions exist and logons linger and and it's you know it's a bit like having a lot of keys floating around to your Airbnb that you you don't collect or maybe maybe that's too simplified. But companies do hire a lot of temporary workers, whether it's contractors or whatever it might be. How how Would you suggest someone manage those situations where you've got people who maybe you're somewhere in an office for six weeks or they have na need access to a network for a a a set period of time? Wha what do we what do we do there to help secure things? Julien Richard (36:54) So I like to say sometimes that things are simple, but they're not easy. This is a very simple solution. You audit your accounts, you set reminders that says you you only activate the account for the amount of time that the person is there. if they stay longer, yeah, their account's not gonna work, you're gonna have to help call the help desk and and and implement it, but it's a lot easier doing that than having all the sprawl that you have. This is not a technology problem, this is a process problem, this is a business process problem. Martin Hinton (37:22) Yeah. I mean on that on that note, Isabel, you know, one of the things we know is that I mean I've had jobs where I had the, if you will, church and state phones. One was personal and one was work. A lot of people don't want to have to carry two phones. What about employees who use personal devices? We we know that's a soft soft spot in cybersecurity generally, but COVID revealed that with all the work from home, which isn't going away. What about that space? Isabel Castillo (37:47) When the the moment that employees are allowed to use your personal, let's say your phone device, the company has to accept that you're assuming a risk, right? You can't separate what what the employee is allowed to use. You can have a work profile that is completely separate from what your personal staff are, but this is a company decision. This is based on the risk statement of the company and the company decides what you're allowed to access from your phone, which tools you're allowed to access, and to what level of access you're gonna have. Martin Hinton (38:18) So I mean in the context of the insurance, put it simply, if you can say yes to password less passwordless authentication, is that something that should should help you on your cyber insurance bill? Julien Richard (38:35) It's a hard one for me to answer because at the end of the day, like I said, you can have the best technology when it comes to authentication if you're not patching the device that you're logging into and you can just completely bypass authentication. And these things exist. Like this is not a theoretical exercise or thought experiments. There are a ton of internet-facing devices that people log into that have very strict authentication controls. that have bugs in them where an attacker and I was gonna say a a talented attacker, but at this point some of these things, like if you can find the code on the internet, you run it, you gain access to the system. So giving a a premium rebate on your cybersecurity insurance for one technology does not make a ton of sense for me. It needs to be that You're getting audited with all of these different controls that are in place. Some are more important than others. You know, that's one of the things that I'm I'm I'm juggling in my head sometimes is that we we spend so much time on making sure that the policy is well written. And that is that carries as much weight as having all your devices patched. Like there should be levels of like certain things that should make you understand that this the the The environment is much better. A well written policy does not protect you from a unpatched VPN that's sitting open on the internet. Martin Hinton (40:03) I mean what what you're what you're saying is that cyber s good cybersecurity or you know better cybersecurity is is like a complex diet, right? You know, the you've got the I don't is I don't even know if it's the food pyramid anymore. I can't keep track of all that stuff. But the the idea that you can't just do one thing and think, that's it. You gotta have a holistic approach, I guess. Is is that Julien Richard (40:24) You can't outrun you can't outrun a bad diet. Martin Hinton (40:27) Yeah. They can't run you can't outrun a bad tire. There you go. Yeah, yeah, six six parts are made in the kitchen. I'm so uncold apparently. Julien Richard (40:35) there there's a well known cybersecurity professional, and I'm I'll give him credit, Joe Sloick, who once sat at a conference where I was at, he goes, You gotta eat your cybersecurity fruits and vegetables, and that is in my phone, in my notes, and I'm using it everywhere that I can. You gotta practice proper cyber hygiene. So eat your cybersecurity fruits and vegetables before starting to start doing all the the the the sexy, you know, the latest, greatest tools and everything else. Just make sure that your foundational levels are great. Martin Hinton (41:04) So I want to shift into a phrase that gets thrown around and i it's one of the many ones in in this in the in is it lexicon the the the the dictionary of cyber insurance and cybersecurity because you could definitely publish a dictionary. The phrase zero trust. So what does zero trust actually mean, Julien? Why don't we start with you? You know, explain it to me. Julien Richard (41:27) First of all, I can hear my friend Ian screaming, well, there it is. Every time that somebody asks me that question. Zero Trust is just it's exactly what it means. It doesn't mean you're not trusting your employees. It means that you're not trusting the mechanism that you're logging into. It means if I log into my laptop, I'm obviously logged into my laptop. So all of a sudden I'm a known entity or somebody who has the right information to log into the laptops, as Julien has logged into that laptop. When I open up my Gmail account, I'm not logged in unless, you know, the the session is still there. But let's just say that it's a brand new laptop. Just because I'm logged into my laptop, we can't trust that it's actually me and I should get access to my Gmail. Now I open my Gmail, log into it, I get a link to a document that I need to sign and I need to log into Office 365. Well, at this point, you know, I'm logged into my laptop, I'm logged into my Gmail account. I mean, it's obviously Julien, so we should trust that zero trust means. When you log into Office 365, you're still still asking you for your username and password. Now, when you think about internal systems and internal applications at a company and things like that, a lot of times you log in once in the morning and you have access to everything. I'm not saying that you should be logging into every single application that you use day to day. I'm saying the one where you can actually reset the admin account for the financial system. There should be zero trust there. There should be, hey, I'm gonna ask you for your full login information. Martin Hinton (42:59) Isabel, in this context we hear the phrase least privileged. w what does that mean in this context with regard to sort business operations and and and zero trust? Isabel Castillo (43:09) That means that I'm gonna give you the permissions that you need and only the permissions that you need to do your to do your job. So for zero trust I like to have you ever seen the movie Wreck It Ralph? Martin Hinton (43:22) Okay. Isabel Castillo (43:23) Okay. You know when Record Ralph is is leaving the Pac-Man meeting, he has a little cherry, he gets stopped, who you are, where are you going? He passes, he crosses again, and they're like who you are, where are you going before he's allowed to enter? That's zero trust. You're gonna be asked who you are every time you're trying to log into something. and then ask Yeah, no go ahead. Martin Hinton (43:43) So this so in the in the in the human context sorry, go ahead. Isabel Castillo (43:47) No no go ahead. Martin Hinton (43:49) No, I was gonna say in the human context, this is like you you don't hold the door open for the person behind you, they've gotta swipe their own badge, right, through every door. Isabel Castillo (43:55) Yeah. Martin Hinton (43:55) Right. This idea that that that but again, when you come back to social engineering, that that that is quite literally we wanna help, right? That's one of the things that you hear. We we're we're helpful it but by default in some places anyway. And it Julien Richard (44:08) And that's why you take the human out of the loop, you just present the logging page. Martin Hinton (44:11) Well so that's what I was sort of getting to. The idea is you you don't create a situation where someone can, you know, share their password with you because there it that it doesn't work like that. Back to the whole idea of protocols and guidelines and and the system, you know, the way it's designed removes the ability for those sorts of things to happen. Like you, for example, the door will only allow one person through or an alarm bell goes off in the physical world sense. If two people go through with only one pass being pa swiped. alarm bells go off and the guard who's watching Ten Gates sees that and says, Okay, everyone stop, we gotta figure out what's going on here. That's the system side of this in a in a physical world sense. Is that a right is is that a s sort of safe way to think about it? Julien Richard (44:53) Yes, absolutely. Martin Hinton (44:54) Yeah, okay. All right. So I I I I wanna move down to the the cyber insurance and underwriting sort of reality of all this and would spend some time talking about that. Julien, what should insurers stop treating should insurers stop treating MFA as like a binary control? I th th that idea that it's well, there's the question. I I I won't belabor it. Go ahead. Julien Richard (45:18) Yeah, absolutely. I I think I touched upon that a bit earlier. Like it's not a zero or one, it's not a yes or no because MFA is what type of MFA do you have? Where is it implemented? Is it protecting you know, we we like to say crown jewels, like the one thing that would hurt you if a cus an attacker or a a competitor gets access to. Those things are the ones that should be protected the most and they should be protected with the highest level of MFA that you can implement in that system. So it's not a zero or one control, it's Hey, what's your inventory? Like what are all the systems that you have? What data are you protecting and how are you protecting that data? And authentication is one part of it. Martin Hinton (45:58) So in that world Isabel, what evidence could an a company organization provide to demonstrate that the control is operating? You know, we w one of the things we hear about is this idea of moving away from the checklist to constant monitoring. What about what about that space? Isabel Castillo (46:13) That's where your logs and your configurations come into play. That's where you can show where MFA is configured, how is it configured? You can show your conditional access policies. You can show your login records. You can show reasons why logins failed, right? You a s 100% can see if MFA was successful or not. Those are some examples that our company can provide to show yes, we are in fact correctly and consistently applying MFA across our environment. Martin Hinton (46:41) So in a in a in a situation where you might want to sh show that you're you've it it's a bit like due diligence in reverse, right? You can show all the work that's done and all the times it worked properly and and that's proof of the system being implemented properly and executing its tasks properly. Do I have that right? Yeah. So could you verify that Julien, is this something you could verify automatically? Is there an automated way to do this? Or y i y again we the questionnaire and the trust and yes and no questions, you touched on all the flaws that exist there because you can be honest and still be wrong, right? That's that's one of the things about the questionnaires that always comes to my mind. What about the the the verification of all this? Julien Richard (47:22) Yeah. So w one of the main things that we talk about a lot when it comes to audits a point in time and we're trying to move away from that because you're doing all the right things. The the classic meme is like a dirt road into a paved section, back into a dirt road, and the paved section is during the audit, everything is perfect, and then you know, things get turned off, things get changed, everything else. So when we talk about continuous ATO, like in in the FedRAM space authorization to operate, or or you can you can implement this anywhere you want to. basically it's showing every X amount of time, let's say weekly, monthly, uploading your logs. Logs are machine readable. You know, they're made, they're they always look the same way. You have the ID, you have the timestamp, you have like it's very machine readable. And there should be a log entry that says that MFA was not enabled or was disabled at one point for an account or something like that. That's something that's gonna show up in the logs. So you upload those. I mean, if you're missing a full weekend of logs and nothing happened. I mean, the auditor should be asking questions because somebody obviously turned off the login for a reason. Maybe they turned it off for the for the weekend. So you got to catch those things. But yeah, absolutely. Logs get uploaded automatically. It can be an automated system. Logs typically do not contain sensitive information. There may be information that you can infer what's happening in the environment and things like that, but it doesn't log, you know, usernames. It doesn't log IP address. It shouldn't log IP addresses where people are logging in. You can sanitize them, upload it to a system, system reads it. Gives a thumbs up and then you're good. The auditors or the company, the the cyber insurance company would have a dashboard of all their customers. They go like, there's a couple of reds there. Let's go see what it is. And they notice, like, they turned off MFA for an hour. They call the company up, they go, Why did you do that? They give a very valid reason. Exceptions have been documented and everything else. And they turn that dashboard item back to green and everybody's protected. That it's how I would operate a SOC inside of an environment. and there's no reason why a a cybersecurity a cyber insurance company can't do that. And if you hit all the controls, then you can give the rebates you want. Martin Hinton (49:27) So on that and you sort of touched on this, Isabel, the authentication logs. An incident response situation or a subsequent insurance claim, what logs become the most useful? And and d tell me a little about that. Isabel Castillo (49:41) Your login logs become really useful. So what you're looking for in an instant response, let's say in this case, somehow MFA failed and a risky login was detected, you're tracing that the activity of that user. So you want to know when did they use login, where did they log in from, what device they used to log in, and after they logged in, where did they go? What did they do in that environment? That's you really are just tracking all the API calls that the person did. you're trying to track what systems they access and you're just building a timeline and the proof of that is the logs. Now keep in mind that sometimes logs can be modified. So you're looking you're you're looking for the log, you're looking for the degree of the log to make sure that a let's say a scale attacker or a scale chat GPT prompt did not go ahead and delete delete your traces. Martin Hinton (50:34) Got it, got it. I I mean, I I guess this is a question for both of you. Account takeover, business email compromise, ransomware exposure. This sort of well stronger authentication broadly helps reduce the exposure to those and the losses. I I wonder if you could sort of talk about what 'cause one of the things we know is it's it's easy to see things when they exist. showing the value of something that doesn't happen and avoiding something is is sometimes a bit hard for people, particularly when they're the ones doing a budget in a corporation, for example. So the the sorts of exposures that this reduces and the potential losses this reduces, talk to me about th that space here. You know, I don't know how to what degree you can put it into financial terms. you know, we know that there's reputational damage from this sort of thing. And to to be frank, looking back and to use the log sort of framing of its reference, if you look back at a company and you realize that they were kind of inconsistent, that's a bad look to put it very, very basically. W what about that that that reduction that the in these concerns and the costs of these things if they do happen and the ability to claim on an insurance policy? What what value does stronger authentication bring in that space? Julien Richard (51:45) I don't know if Isabel, if you wanna tag on. I I I that's the last twenty five years Martin Hinton (51:47) Isabel, you c Isabel you go first. Isabel go and then Julien Richard (51:50) of my career. Isabel Castillo (51:53) I would tell you that so the challenge the the challenge to repeat security is that the outcome that we put is not tangible. It's not a new feature. It's not not a new biometric recognition software. The value that we put, the output of security is no losses, no ransomware, no hacked accounts, no well trained staff that did not follow for a fishing scam. That's the value. Now if you do look at the reports, if you don't look at statistics, reputation people tend to forget the the reputation of X company was had but the moment a company loses money, the moment ransomware hits, it's that's that's really hard to forget. So for security the value of MFA is because of MFA, you didn't get had because the well consistently applied MFA across the board, you didn't lose money. Martin Hinton (52:44) All right, Julien. Julien Richard (52:44) The the challenge is you know, one of the big things that we try not to do in cybersecurity is to produce FUD, which is fear, uncertainty, and doubt. Like you do not want to scare people into doing the right things. And the reality is is that there's so many breaches happening that there's so much data. You look at the annual reports of all these companies and everything else, and they're showing how people are getting in. Initial access, of course, is the number one way to get into an organization. Hackers are lazy, if they can just log in, they'll just log in. They don't have to write code, they just have to type admin admin and they're in. Like that's a lot easier than writing a a proof of concept that's gonna that's gonna take weeks to do. so using in in in a way that you're not scaring people where they they do not want to do anything. I've been I've been in or I've been on calls where I, you know, I want to ask a question to someone, and because I'm the security guy, the They get on and they're white. They are scared. They think that they did something wrong. And I'm not gonna name names, but I like there you know, there's people that actually really act that way. They're scared of us. And we don't wanna create that environment. We don't want to create that culture. So you don't want to use pure uncertainty and doubt. But at the end of the day, I mean you can't prove that something hasn't happened. There are certain things you can do. For example, If you're using device bound certificates and you're only use you're only allowing certain system to access your account, one thing that's going to be true on the internet forever is that people are poking. There's spin up in you system and look at the logs, people are poking and poking and poking. And if I can show you a log that shows that there were 10,000 attempts to log into the system that were stopped because the person didn't didn't present the right certificate. They didn't even get to a login screen. The system did not accept them because they did not have that certificate. There's a lot of value there that can be can that can be implied in that just in those logs. So there are certain things you can show that your system is working as designed and you are actually stopping attacks. Martin Hinton (54:50) So you know, one of the questions I had prepared was is is MFA something that should be an important part of the underwriting control? And and the conversation to this point has made me realize it's really MFA is just a part of the the proper authentication and all the parts of that. There's there's a layered reality to this that the you know, the cute acronym MFA is only a part of. I is that I mean, is that how you feel about it? What do you think about that take? Julien Richard (55:15) So yeah, the the you have three different types of controls, right? You have your your your your technical controls that are actually stopping stuff and you can detect people going in. So yeah, they were successful, but then you can detect them. So you have to have a right the right logs, you have to have the right alerts, you have to have the right things if somebody actually bypasses the controls. And then you have your administrative controls. Everybody needs to have MFA. It's hard Some of the administrative controls are very, very hard to implement. You shouldn't log into the account on your account with a certain device or things like that. Like those are more things that you you're not able to put a technical solution around it. I'm not giving you the right ones. Those are all you can all protect that with technical information. So and that's ju we're just stalking authentication here. Like, you know, I talked about logs, alerting. we we we talk about not deploying your management interfaces on the public internet. Like if it shouldn't be connected on the internet, don't connect it on the internet. Connect it behind a firewall somewhere. You should segment your network in such a way that even if somebody exploits a system, there is no way for them to get to the system that has more information that they need. We talked about least privilege. Least privilege is not about trust. Least privilege is about maintaining that blast radius. If an executive gets their account compromise. If they don't have access to all the source code because they don't write source code, then the attacker, it it limits that blast radius of what an attacker can do with that account. So again, we're only talking authentication here. You do all of that and you forget to put in a good malware solution on your Windows laptop and somebody installs an info stealer, they're just going to s rip the the session tokens straight out of your browser. They're not even going to log in. So like, yeah, you have the best MFA in the world. But the session tokens are still in your browser and you don't have any malware detection. Somebody clicked on a link and installed something they shouldn't, and all of a sudden all their information is being sent out to another user and you don't have any detection on the network side. Again, I can go on and on and on. There are a thousand I mean, a a FedRAMP audit or a NIST SB 853 audit can have up to 400, 600, 700 controls that they're looking at. And If any one of those controls is not well implemented, that's the way the hacker can get in. So you need to implement everything really well. Martin Hinton (57:34) I I mean Isabel, this is where the the phrase that I've heard re and I've repeated now, extremely fragile. Like the the all of our points create a fragility. If bound together well, it's very strong, but then the the the one one weak link in a chain creates a real problem. Is is that again, I mean, I know I keep coming back to these simple analogies, but I I'm trying to give myself a capacity to understand it and you know an audience that this matters to, and we know this that there are tons of non-technical people in positions of leadership and power, we have to make decisions about this. Is that is that a s too too silly a way to think about it? Isabel Castillo (58:09) It's an accurate way of thinking about it. There's a lot of controls in a frame environment. You need to make sure that they're all they have to be well implemented, they have to be provable and you need to be able to provide evidence that you implement them right. It's not just it's implemented, yes we did that. It's how and can you show me? Can you prove it? And Can you re keep repeating this implementation? Because a one time implementation also doesn't cut it. It has to be continuous secured implementation to continuously protect your environment. Martin Hinton (58:47) Yep. So as promised, we've been talking about an hour and we haven't gotten to everything. I I have a couple of sort of quick fire questions to wrap up with, but before we move to the close, I wanna offer you the opportunity to say some more about something we've touched on or perhaps there's something we didn't get to or that you you've cut come to that's come to mind while we were talking that you wanna say something about. Julien, I'll start with you. Anything to add, anything you wanna wanna discuss before we wrap up? Julien Richard (59:12) Sure. So, you know, I I just went on a rant on getting all the controls right and everything else. if you can segment your environment, if you can, if you can make it so that the places in your network are very, very hard to reach and they're very difficult to reach, the controls that you're putting in place, they don't have to be as perfect as you think they need to be simply because nobody can get to it. Right. You put when we talk about zero trust, if you put your crown jewels in a safe, inside of another safe, inside of another's face, it doesn't matter if that first safe has some vulnerabilities and keep people can go in and everything else. They need even more tools and more things to go deeper, deeper into your environment. So if you go and you protect things and you do the right things and you do you eat your cybersecurity fruits and vegetables and you do all the right things. Your environment that is very, very sensitive is going to be tucked in the corner somewhere where people can't get to. doesn't mean doesn't mean that you're not gonna get reputational harm when people brag that they hacked into your network, but they're not stealing your financial information, your credit card data, your your your your your whatever your customer trusts you to do. So that's the very important part to understand is that. We don't need to always be perfect. And I think that's one of the things that cybersecurity professionals are engineers, right? We're used to it works or it doesn't work. Security is never going to be perfect. And security is never going to be a zero entity. It's always gonna be somewhere in the middle and your threat model decides how far down the perfect path you wanna go. Martin Hinton (1:00:50) Isabel, anything to add? Isabel Castillo (1:00:53) To Julian's point, the point of security is to continuously reduce risk. The point of MFA is to continually reduce risk. If you completely reduce risk, you don't have a network, you don't have internet, you're in a bunker somewhere in a cave with sticks and stones. The point of security is to slowly reduce risk. That's that's all you're trying to do at all times. Martin Hinton (1:01:14) So I I'm gonna put one question to both of you. Isabel, you you you you go you go first. A board, a C suite, what's one question they should be asking the CISO about their security situation? I know there's more than one. We touched on how many there are. but it but the what's the what's the first question that they should ask? The the the you know, explain it to me like I'm a fifth grader question. Isabel Castillo (1:01:42) For MFA or for identity? Martin Hinton (1:01:44) Just just just yeah, for MFA identity or even if you want to broaden it route route to a to if a member of the board is brand new and they don't know anything about the company and they want to know something about the cybersecurity mentality, environment. Wha what w what would be a a real baseline question to to ask if you were a leader in this space and y you didn't really know anything? Isabel Castillo (1:02:05) Are your securities okay if I don't know anything then I wouldn't use in a lingo, is your the security that you're using in your company gonna be able to defend us against modern attacks and evolving attacks? Can your security program keep up with modern attacks? That's what I would like to know. Martin Hinton (1:02:23) Julien, what about you? What about Julien Richard (1:02:25) I would ask if the technical department understands everything that's on the network and knows about everything that's on the network. That's number one. Visibility is number one. Do you know, do you have a good grasp of what you're protecting? You can't protect what you don't know doesn't exist. And it's a weird Martin Hinton (1:02:44) Okay. Julien Richard (1:02:44) question. And, you know, you're never gonna get a real answer because they don't they're either gonna say, yes, I know everything that's there, and then they There must be something that they don't know about, but to get an answer that goes like, Yeah, we're not a hundred percent sure what's on that network is not the answer I wanna hear. And that's where I wanna spend my money. Martin Hinton (1:03:03) Alright, final question, Julien. You're gonna get it as well, Isabel, so you can prepare. You've listened to this whole conversation. What's the most important thing people should take away? W if they remember one thing that they repeat or they say to try to share with their family or friends or grandparents about protecting yourself, what what what's the the big takeaway? Julien Richard (1:03:26) Don't protect everything to the same level. You're gonna go. I don't want to I wanna use bad words, but it's not possible to protect everything to the level they should be protecting. If you have a main email address, that's that email address that you use to reset all your accounts, that should be very well protected. Your bank account should be well protected. the information that you care about should be well protected. and that's where you should focus your first go-through. People that get, hey, you're reusing your password everywhere. the goal is not to change those passwords on every single site that you've ever been on, including the ones that you have no clue that you've ever logged into. I'm sure my my my my space password is password one two three. Like that's probably what it is. Do I care that it gets popped? Absolutely not, right? I guarantee you my bank account. Password is not password going through three because that's the one I care about. So really do an inventory of where the information that would really hurt for you to be stolen or people to get access to, and those are the ones that you gotta start and protect. Again, threat model is not my threat model. Martin Hinton (1:04:37) I mean you you touch on insurability, right? We we we insure things that we care about more to a higher degree. Home may have insurance, but maybe not every couch in your house or, you know, lamp, right? Yeah. Isabel, what about you? What's what's what's the one thing you would hope people remember from this conversation and and pass on? Isabel Castillo (1:04:57) In a very spectrum in a spectrum of protecting your family. Yeah, I w I hope to remember the security. Truly is meant to keep you keep you happy and stress free. That's the goal, right? The security is basically telling your kids where your help may wear kneepads and elbows, so you don't end up in a hospital with a broken something. That's all security is is especially with the older older generation. Truly it's meant to keep grandma and grandpa safe so they can keep going fishing and traveling is so that they don't fall for silly scams. Martin Hinton (1:05:25) Well said, well said. Anything else? Julien, Isabel? Go. Julien Richard (1:05:28) I imm immediately thought of those password books that people write their passwords in and everybody laughs at that. It is probably the most secure way to store passwords for a certain demographic of our of our population, right? Martin Hinton (1:05:40) Yeah, well if it ain't broke, don't fix it, right? Just don't share it. Isabel Castillo, lead infosec ops engineer at LastWall, Julien Richard, VP Information Security at LastWall. Thank you both so very much for taking your time today. It's been really, really interesting. And I think there's a lot in there about how there's much we can do. It's a bit complicated, but that doesn't mean there aren't things to do and and and there are solutions to a lot of the the fears that get thrown around in this world. So again, b both of you, thank you very much. Everyone else, thanks for watching and listening. We've mentioned a few things here, and obviously there'll be links to some of that in the show notes, as well as links to Julien and Isabel, so you can find them and you can find Lastwall. Finally, thank you very much for taking the time today. Really hope you enjoyed it. If you've got any questions or comments, please drop them in to wherever you are, and we'll do our best to get you an answer. I'm Martin Hinton. This is the Cyber Insurance News and Information Podcast. Thanks for the time. Enjoy the rest of your day.