Martin Hinton (00:00) This is the Cyber Insurance News and Information Podcast. I'm Martin Hinton Executive Editor. Every week we talk to the underwriters, brokers, and security leaders shaping the market. Martin Hinton (00:10) All right then. Welcome to the Cyber Insurance News and Information Podcast. I'm the executive editor of Cyber Insurance News and your host today, Martin Hinton. Joining us is Chao Cheng Shorland, the co-founder and CEO of Shelterzoom, a cybersecurity company that does work in the blockchain-based document tokenization, data privacy, and zero downtime continuity solutions space. Chao thanks so much for joining us today. How are you doing so far? Chao Cheng-Shorland (00:33) Yeah, doing really well. Thank you for inviting me, Martin. Martin Hinton (00:37) it's i thank you so much for taking the time. I wonder if you could tell me just off the top what it is shelter Zoom does. I yeah, I think that when people hear some people I should say, hear document tokenization, they might have to check a dictionary and and I I wonder if you could give me sort of the explain it to me like I'm a fifth grader explanation. Chao Cheng-Shorland (00:55) Absolutely, yeah. Shelter Tun is a deep tech company and we've been around for nine years. So at the very beginning, the problem we try to solve is the data ownership. So as you know, when you send out a documental file and you just lose the control, lose the ownership forever. So we figured out there is a way of fixing this problem is through the blockchain-based tokenization. So that's really where the that tokenization comes in, but I can explain later. So to make it simple and just like your iPhone, when you actually lose your file iPhone, you can trace where it is. If someone else borrowed your iPhone, you can take it back because you own that. But for files and documents or any content, you never had that type of privilege until you have our technology. Now you truly can send anything out in the vast digital universe. You still know that's yours, which is very, very unique, and you can take it back at any time. So apart from that, we are our multi-platform company and we also very much into healthcare and deep in healthcare and we provide healthcare clinical continuity during ransom, during cyber attacks, or any downtime, even planned downtime. So yeah, so that's us. And we also recently launched a very innovative AI solution. It's to eliminate the data inaccuracy. and data leak and keeping everything verified and also there's data lineage very strong data lineage component tracking where the AI data comes from, how the AI data is used and how the AI data actually gets consumed. Martin Hinton (02:39) In our planning for this and in the conversations that we had leading up to this moment, we we exchanged some some notes and some emails, and there were two metaphors that were used, the chicken coop metaphor and the museum metaphor. I wonder whether you might explore those two. What what do we mean? Let's start with the chicken coop. Chao Cheng-Shorland (02:56) Yeah, chicken coop metaphor is really interesting. Because when we look at the cybersecurity, right, and I just feel everyone on this planet Earth is really building a coop. You look at all these technology companies, they're so busy building a coop because they want to keep their chicken safe. Unfortunately, you know, the hackers are so clever, like foxes. They come in, they always will figure out a way how to break. Into the coop and eat the chicken because your chicken is not protected. So we look at the things opposite. We always look at things opposite. Hey, coop is not really what people are coming. Like hackers coming for your data, which is your chicken. They want to eat your chicken. So you have to protect your data. If without protecting your data, your the AI tech, quantum tech, you know, any type of cyber vulnerability will happen. So we build protection on the chicken, which is a file. So every file of our you know in our system is fully protected. So even the coop actually get broken and they will find a way to get in, but your chicken's safe. So that's really our metaphor and the philosophy, which is very interesting because one of the top analysts, like a industry analyst, even a whole cybersecurity team, told us we're the first company ever figured out how to protect data rather than just protecting the database or the some defense. Yeah. Martin Hinton (04:31) Is is is the is the is is the layer defense sort of idea that that there is the exterior perimeter and then each chicken or file has their own capacity to defend as well, so that there are it it becomes more difficult to say, attack that chicken coop as opposed to one that's just got a fence around it, if you will. I I mean i i that's what we're talking about, right? Chao Cheng-Shorland (04:53) Yes, yeah. So this actually comes to the museum metaphor. So what happens you think about in your museum, right? Every painting or some kind of like the collectible is actually mounted on the wall there's a key. So we do the same with our files. So every file it when you break into our door, and first it's hard to break in because the blockchain distributes a ledger. So it's like your house, right? Instead of you just have the front door key and put people just put under the the mat, the door mat, they just open the door and come help yourself take all your content. So the door is not just one door. You have multiple doors you have to hack simultaneously through distributed ledger to get into your door, you into your house. Once you're in your house, the problem is all all your jewelry, everything's locked up because we use cryptography in order distributed ledger tokenization. And ensuring every piece of your content is secure as well. So now in the museum, it's really hard for you to try to take the Monta Lisa away because Monta Lisa is mounted on the wall, have a key, have all the camera, and we basically do the same. So in that way, regardless your hospital, your medical records, your government, your financial service company and your legal company, every document of yours is totally secure in that way. So it's just much more stronger than other technology on the market. I I would say I'm very proud of. Martin Hinton (06:25) Wha so so we we we see a company with this and without this. Tell me what happens in a data breach it in those two scenarios, a company that has this protection within it and a company that doesn't. W where where where does the vulnerability increase if you don't have Chao Cheng-Shorland (06:42) Yeah. So this is really coming from the for example, ransom, right? So ransom attack now is really the biggest I would say damage. And I think two years ago there was a report sixty seven percent of the hospitals actually got ransomed in two thousand twenty four, which is a enormous number, just people don't report on that. And look at the striker, look at the you know the the those manufacturing trend and also look at change health, you know, ascension. And the damage is massive. So how actually hackers do that? It's actually really simple. They come in, they grab your database key, the encryption key, they put their own locker, they change that out and they use their own key. Now you get locked out. So you if they're like the locksmith, they come, they just change the key, you can't get back into your house anymore. Now they say, hey, to be able to open the door for you, give me some money, right? A lot of money. It's not just a little bit of money. So in our case, hey, good luck. You can have your key. We have our data. Data is still with you. So that's really the major mind shift, you know, the change and where actually blockchain-based tokenization comes in could truly fix cybersecurity problem. So we are still on the journey, right? It's not like Hey, the the world is going to be all you know, everything's peaceful tomorrow because of our technology. The technology just continues to evolve and eventually I think that is really the method of fixing those issues. Yeah. Martin Hinton (08:26) You you touched on ransomware and one of the things that we discussed b preparing for this conversation is the first AI executed ransomware attack, where you've got no human at the keyboard. I wonder where you could sort of break down that scenario for me. Chao Cheng-Shorland (08:41) Yeah, so that was the incident. It's called the Jade Puffer. I think that was probably what you're referring to around July first, two thousand twenty six. So if you think about ransom, right? The ransom as a service even's been around for a few years now. People just register the sign up for the ransom as service and hack hospitals, have government, you know, critical infrastructure, it's already really bad. But human actually more involved. So with the AI agent type of hack. So AI agent for in this particular incident, they actually started with an open source tool, the building out the AI workflow and exploited unknown, the unauthenticated floor. So once they get inside, it did all the human operators could do. It's much, much faster. It basically hunted all the credentials, pulled all the API keys, even the cloud. provide the keys and anything, even the keys for AI services. So it's really like a just within a few seconds. And what's also interesting, when its first login attempt failed, it basically read the error and the diagnosis itself very quickly fixed it, just within like a few seconds. So in this case, right, you think about if a human gets involved, humans have to figure out, how do I do this? How do I do that? It would take much longer. The longer it takes, the more the failure you will get. And the you probably the the security system will already discover you've been trying to hack them, they can stop you. But because AI, everything happens so fast and literally you don't even have time to alert the cybersecurity team or you know the operational team. So that's how you know the the AI attack can become extremely dangerous. Martin Hinton (10:38) Do you see this as a a one off or is this the beginning of a new reality? Chao Cheng-Shorland (10:44) it's definitely the beginning of the new reality. It will come very soon. I mean, it will become mainstream. That's why you really have to build the technology, it defends itself. It cannot, you know, just say, hey, good luck, our operational team will supervise that, we'll h have all this SOC, you know, kind of operation center, which is great. This is for people less sophisticated to me. If you have a the extreme level of those vulnerability that kind of attack, nothing can stop you. That's where you have to build the technology to self-defend. So I'm very big on self-defense, self-governance, and because you can't have human governing anything in the AR era. You know, I understand that's a very common term, right, in the now AI world, everyone looking at our governance trust, you know, is so important, which is absolutely why we actually builded a new MITVA technology. But our goal is self-govern. You cannot rely on any human involvement anymore. The AI has to be self governed and self defend. And then the system has to have that self defense capability as well. Martin Hinton (11:58) In in in that in that s within that idea is the idea that AI can attack with such speed and efficiency that humans aren't capable of defending that rate of attack, that volume of attack, whatever the phrase might be, that there is a a speed of machine that humans can't simulate and the only defense to it is something that can react as quickly. Is is that what we're talking about? Chao Cheng-Shorland (12:24) yes, yes. So that actually opens up even another bigger market for hackers to successfully hack you because they can now use AI agents. Martin Hinton (12:35) Yeah, so I mean you know you I mean listen, one of the things we know, well, let me ask, do you we say this is the beginning, how long do you think before it becomes the norm? you know, it becomes the way that that these these organizations and criminal enterprises operate. Chao Cheng-Shorland (12:53) I would think it's in months rather than years. And at the moment of course they're still experimenting, right? The problem is it's already the technology is widely available. So now they just need to figure out how to do that and how to package everything up and make it like a bigger scale. So that as soon as everything becomes a commodity and you can acquire as like a as a service and it just will go viral. So that's really where we have to really be smarter than hacker and we need to stop. Martin Hinton (13:29) I mean, one of the things you touch on is AI has been introduced it seems like it's been around forever, but the the truth of the matter is it's only been a few years. But the pace of its adoption for a variety of reasons has been extreme. And certainly within the if you will, legitimate business world, we hear about efficiency and, you know, cost cutting and the ability for it to to to do things in ways that save money and make more money, right? Those are Two things that occ exist in a symbiotic relationship. What people don't quite appreciate is the industry behind ransomware. And that just like any other organization or company, the companies behind the ransomware industry will be adopting in the same way the latest tools to make themselves better at this job. I mean, one of the things you might touch on is to just if you will, for the point of awareness for perhaps people who don't quite get this, that just How organized the ransomware industry is. Chao Cheng-Shorland (14:28) Right. So the ransomware industry actually has been around for a long time. it's not even just a recent few years and but the scale has accelerated so much, right? Just like every type of crime. So so ransomware initially they were attacking some small systems and locking people out and then they asked for say ten thousand dollars or a few thousand dollars because they know this the kind of repeatability is Pretty limited. They they can't really risk themselves. They have to keep operating and getting more and more money. So after a few kind of like the technological the advancement, and there's so much many systems around now, a lot of merger acquisition, getting old legacy system merged into more modern kind of like a technology. So there are lot of gaps i in the middle. So then the ransom kind of like attacks actually finding a lot of vulnerabilities and to get in, a lot actually you will see a very strong pattern is the legacy system a very reputable company acquired was where they found a door to get into the bigger hospital or big government and other type of you know, the men men systems. So because they actually start to discover the repeatability and they start actually commercialized it like a as a ransomware as a service. So ransomware as a service, now everything's pre-packaged. You just sign up and then you you know pay some money, but you can get a much bigger return, right? So that's really how things getting really out of control. So I'm not sure you know the the actual kind of the the big number, but I know the cyber number last year reached a 10 point five trillion entire year. This is actually apart from the US and China, this is the third the biggest economy in the world, is the cybercrime. And the rancid Martin Hinton (16:33) You Chao Cheng-Shorland (16:33) is a huge part of that. Martin Hinton (16:35) you you you touch on what I refer to as the Moby Dick number, right? This this estimate that last year the global economy lost ten and a half trillion dollars to cybercrime, which as you note put would put it third in GDP after America and China, an astronomical amount of money. And there's some debate about that because it's an estimate that the that came out a couple of years ago. But even if that number wore off by ninety percent, that's t a trillion dollars. And and I and and and it really illustrates, I think to your point, no disorganized, haphazard basement hacker in a hoodie is getting away with these crimes. These are incredibly sophisticated groups that, as you note, have had years to study the vulnerabilities that do exist. And you touched on two things that I just want to, as they say, double click on. The tech stack and the legacy technology when you have new technology, the gaps that get created when those things are combined. And we see this as the sort of vulnerability that exists in a lot of companies. You noticed, you noted companies that might buy a legacy organization and they absorb their technology, and that's where the problem exists. One of the great vulnerabilities is the communication method that we call email. And it still remains one of the most hacked or even the most hacked channels that attackers can access. You know, the social engineering cost possibilities now with AI, the volume of emails they can send, the ability to make them incredibly well written, to design them like a real email that looks like it's from your bank or whatever it might be. I wonder if you might talk about sort of that that vulnerability and how just like a lot of crimes, the the things that we rely on are where People look to to take advantage of us. And they might send you an email at a quarter to five on a Friday when you're hoping to get out of the office for a long weekend. And everything we know about behavioral psychology and how people think and behave, criminals do too in this space. And they're using it against us. So tell me about email. And and and and it just, you know, we we're we've probably all worked or know people work, or we've experienced the phishing email that the company sends out to test you. Whether or not those things are particularly effective is at stopping things is unclear. But talk to me about that vulnerability that comes via email. Chao Cheng-Shorland (18:45) Yeah, it's really something you know, to my heart, the email vulnerability is ninety one percent of all the cyber attack origination. And literally probably a hundred percent ransom attack is from the why floored and you know just so many vulnerabilities coming from email. So the reason is very simple. Email is like most used my by people or pr operations or doesn't matter you know what industry you are in. The other thing is the email attachment, the the old traditional paper clip. That paper clip is already 40 years old, so predated Windows ninety-five, but it's still in use by 70% of corporate users to exchange information, i exchange documents. The reason is because our main technology companies like Microsoft and Google haven't figured out what is a good way of Sending documents out, you still have persistent control tracking protection. So once you send the documents out, they lose forever. That's why a lot of companies switch off SharePoint and document sending out. Google has the same challenge. So that's really exactly why we tackle that in a very, very aggressive way. So we actually build an email extension in the Google and the plugin in Microsoft. And now we we call document GPS. Immediately your attachments get tokenized. So once you get tokenized, when you send out, you're not sending out anything, you're sending out a access to your token. So organizations still have those tokens, which are their files, inside the secure vault, and they can track every step. So for example, you can stop people from downloading, sharing, forwarding, or even screenshotting because you as the company and enterprise, you own your document token. That's your asset. So so where the a and the doesn't matter AI social engineering, it's all email is the the biggest attack and the ransom as well. So you have to fix things from the source. Otherwise you will always have that vulnerability around. You can't you can't train your employees every day. You only can train them to a certain extent But AI's becoming so sophisticated, it just looks like a real. They learn your templates because you you're sending out the PDF, they learn how it looks like and come back to hack you. Yeah. Martin Hinton (21:19) I mean, I again I mean th this this idea that that one of the things about business when it's well done is it's efficient, right? And efficiency requires a level of transparency and trust. And this is something that's taken advantage of. Within this ransomware space, there's one particular industry, and you touched on it, that really suffers, depending on whose stats you look at, the majority or vast majority of these attacks, and it's the healthcare world. I wonder whether you might Tell me wh why does the the healthcare industry keep absorbing this? What what what's the what's the reason that they're they're they're prime target number one? Chao Cheng-Shorland (21:57) Yeah, so we actually also learned a lot over the years because healthcare you can't really stop, right? Because patients still getting sick, the emergency people still need to come into the the ED department and then ambulance still need to arrive. So if you can't save patients or treat them immediately because of ransom, you basically your the not just the Patient safety issue, which is the you know, the biggest problem. The other thing is like you completely stop your whole operation, everything stops. And you can't really last for long and you have to pay. Because the urgency of that and the criticality of patient safety, HIPAA compliance, revenue loss, you know, all these kinds of things, and making hospitals very willing to pay. Even they don't want to pay, but really under this kind of circumstance, they'd rather pay, get back in. But unfortunately, when once they pay, they don't get back in. A lot of times ransom those attacks right very smart, hey, I give you a little like a almost a dangle carrot for you to pay ten million, twenty million, get you a little bit back, but your data is pretty much already on the dark web because it's it costs so much, right, to buy those records, patient records worth a lot of money. So that was another reason they actually prefer to attack healthcare or other kind of like a industry has very valuable data than other industries which probably not so profitable for them. Martin Hinton (23:38) You you touch on something. I I I think it was the UK where this conversation generated the most tension is this idea that they that you take away the incentive for ransomware by banning ransomware payments. And the people I spoke to said that the the the industry that was most adamant about that not being a reasonable course was healthcare. Because as you note, if your records are suddenly unavailable and you've got someone on an operating table. And I know that in Germany there was a case of an ambulance being diverted from one hospital to another and the the patient in the hospital dying and it being attributed to the extended time that they had to wait for arrival at a hospital where they could be treated. so we have a death there associated with this sort of thing. But their attitude is we cannot turn off operating rooms. ERs in busy places can't stop. I I think it was Ireland, where I happen to be right now, that That there was a ransomware attack during COVID and it was on a children's hospital. And the ransomware attackers took they they stopped the attack because they they they're they're so smart about this. They were like, Well, we don't want to attack a children's hospital. So they they didn't demand the ransom and they un unencrypted the records. there'll be a note in the show notes about that to to to confirm that. But this idea that that that comes back to the sophistication. And if you're attacking someone who can't be put in a situation where they can't pay, they have to. And I I wonder whether, you know Given what you do, the the idea that this technology to to protect these documents on, I guess, an individual level, am I am I oversimplifying that? Is a is a is a significant way to push back on this vulnerability that hospitals, I think, genuinely can't avoid, right? They have to be able to treat patients, whether it's a a surgery that's not urgent or a planned or even even elective surgeries like a knee operation, these things have to happen on schedules. It's highly sophisticated. At least where I live in New York City, hospitals are very, very busy and getting appointments and scheduling things is very hard. There there's a real density to the the availability. They they want to y get you in and out. And all of this, the dynamic there creates this vulnerability that ransomware gangs and organizations, I think gangs may undersell it, but but they attack. I do you think I have that right? Chao Cheng-Shorland (25:50) Yes, absolutely. those, you know, given the situation, you really can't go down. Your system has to operate right and regardless of what happens. And now you look at the doesn't matter how strong everything is, so we can provide file level protection and a lot of other great technology companies can provide the level of protection, different level infrastructure, network, firewall, email, w whatever. The problem is now with the AI and the quantum, everything is ahead of you. And you we are just kind of like doing a catch-up work. And you always have to be prepared to be resilient. So attack is one thing, or defense is one thing, defense is no longer enough. And you have to be resilient. So resilient meaning you cannot let the hospital go down, regardless of what happened. So that's actually the other platform we call spare time. We provide as almost like a backup generator, your electricity goes down, immediately your the generator will operate. So if your hospital EHR system goes down, and immediately the spare will kick in and get activated, so all your clinicians can continue their clinical workflow without stopping. You still can treat the patient. If you divert the ambulance, right? And if you're in the metropolitan area, you might be lucky because you still can make to the next hospital in the rural region. And most of those like a critical access hospital or regional type of hospital, they don't have any neighbor neighborhood hospitals in the region for like a two hundred you know miles radius. And h where do you direct those emergency situations and a lot of people really truly die. And the mortality rate and the recent stats was a thirty eight percent increase during downtime. So that's a horrible situation. And you really as a society we have to help fix this. So that's where we actually really took our you know pioneering spirit and help hospitals fix this problem. Martin Hinton (28:04) You you you you just said two things that I just want to explore a little bit more. The first was your generator analogy. Hospitals in many, many places are prepared for electricity to go off, something typically vital for treatment, everywhere. And a generator turns on automatically. What we're talking about isn't necessarily a new concern, the idea to be prepared for when an incident occurs. That mindset just needs to be moved into the digital record keeping space. And I and I say that because I think sometimes this can seem like a a new new thing that's overwhelming and and we don't really have the the the mindset to address it. We we absolutely do have the mindset and we may even have some solutions that are readily at hand. And I and I just think that that's a really, really good way to explore it. The other thing you said that was really interesting is the idea of having a plan, right? And and and d the defender always being behind the attacker. And the analogy I always like to come to is a is a house fire. When your house catches on fire. If you're unfortunate enough to experience something like that, the fire department isn't there when it happens. You have to call them, or maybe you have an alarm that calls them automatically and then they respond. But there's time between the the call for help and the response. And that time is when prior planning, the family has a spot to meet in the yard so that everyone can keep account for themselves. Maybe you've got things like a fire extinguisher so you can, you know, c clear a doorway or the the protocols that exist, the planning. And again, these things exist in other parts of our lives already as a function of the way our our lives have changed over time. And this is just another new moment where we have to adapt with the same mindset to have a plan, to be organized. And then you have resources to call in the case of the fire department or an incident response team or a ransomware negotiator that come in to deal with the bigger problem of putting out the fire or getting your records back. Do you think that oversimplifies it? And what do you think about that idea that we need to remember in this space of the new new and all these new threats and the way they're brought to us. We've met these challenges before in very similar ways, both on a societal level and as an individual as individuals. I mean, am I oversimplifying it that I worry sometimes I oversimplify this stuff because I try to make people think that th this isn't some, you know, impossible thing to deal with. Chao Cheng-Shorland (30:21) Yeah, it's actually this simplification is actually really good, put things in perspective because very much like the fire hose, right? And even with your house you want to protect. And you have a big hospital and you have so many patients there and needing help, and yet you don't have a fire host just immediately put something off or get your electronic record back immediately and continue the care operation, you know, that actually is unthinkable. So just like older days, right, when you drive the car, you always have a spare tie in your trunk. You quickly put in, you get to the next destination. It doesn't have to be as big, as expensive as your mental, because that costs a lot, you know, understand hospitals all under huge stress, right? In their the cash flow margin, everything. So totally understand. But you should at least have a spare tie to get you to the next destination, which is when your EHR system gets restored. So I don't think it's oversimplifying, but it really like put things in perspective. Hey, you you are defending your car, you're defending your house, you're defending all the small things. But when it comes to hospital, everything's pen and paper. So this is how hospital runs without spare time. They when the it doesn't matter if the ransom or even plant down time, every month some hospitals go down four hours, eight hours because of the plant down time. And everyone go back pen and paper. They have the paper procedure now kicks in. And now you have hundreds of runners, they call paper runners. And once you have all the medication order, you put down, you write it, and then you run to pharmacy. You run back. there's a mistake, or you run back again. So that's how everyone stands by 724 in case something happens. But when they have the plan down time, so they already have all this the army full of people sitting there, or the they pick the time. the hospital is relatively quiet. But it's still a huge problem. You have an emergency comes in, you just can't handle. And if you have a like a kind of a really very life threatening situation, typically you have tons of orders, like a several blood tests have to be done, medication, radiology procedure, and you it takes you like half an hour just writing those orders up. And by the time the the chance to save that patient is much, much less. So that's really how the spectra has to actually work or in all these areas to keep you going really is a continuity during failure. So that's a education we need to continuously educate hospitals and the society. We're really talking about continuity during failure, not recovery after failure. Everyone knows once you recover, then Of course, you know, after the failure, you recover, you go, you continue going, you do reconciliation, all those. But what about the time? There's a big gap between the time the system is down the before the system is up. That is most vulnerable time, impacting lives, impacting your the hospital reputation, you know, all kinds of things. So yeah, I actually like how you just said about fireholes. I actually haven't thought about that one. I usually just call spare tile or generator. Yeah. Martin Hinton (33:41) Well y y b by all means you can take that and run with it. just credit me, okay? you you Chao Cheng-Shorland (33:47) Yeah. Martin Hinton (33:49) you you you y you know you the the example you just went through with the hospital, I I don't I don't know whether you've seen it, but there was a t television show that it's on its second season called Pit, and it's about a hospital and Chao Cheng-Shorland (33:59) yeah, and it's Martin Hinton (34:00) so th and I I and I know this sounds silly, but one of the hardest things about this this this space and reporting on this space as a journalist is all of this stuff is very hard to visualize, right? It's hard to explain to anyone. And most of us don't get why this works the way it does. And Netflix can play all the movies and creation on it or the ones they they have on their library. And and what what we what we encounter, and you touched on this, is we only really realize something when it's gone. And if you learn how to use your hospital system in a digital computerized way and suddenly that's off, people who didn't use the paper way all have Play catch up. Never mind how much longer that takes. They also have to learn a new way to do it. And I think that the the reason I mention the show is that it's a really, really, really good illustration of how something like a ransomware attack affects real people. These aren't abstract realities. There's real time, real money, real health consequences to this sort of thing. And it is sometimes a little bit hard. You know, you hear about a data leak here and credentials stolen there and a ransomware tech here, and it just seems like Something that isn't really real because it you can't touch it. And and I say this, for example, the example I always use is the Jaguar Land Rover hack, where if if there had been a fire at that factory, and that was the reason it closed, and or heaven forbid at some sort of malicious attack like a ransomware attack, and they'd blown up the factory, it would be on the news all the time. The rebuilding would be the subject of ongoing coverage. But that's not what happened. And it's this sort of, you know, invisible problem. Not unlike some kind of virus that maybe hard for people to comprehend is actually dangerous to you, that that it betrays our demand for visual evidence and and as a weakness in a real way. And and it's just again, if you haven't seen that show, it it really is worth a look just to understand what this looks like when it unfolds. Because they do exactly what you talked about: having to go to paper, runners bringing things places, you know, stairs and floors and all the sorts of things that take time. It i it it's a real problem and it and it happens. You you you you t that's my that's my last pitch for for the this the show the pit. the the Chao Cheng-Shorland (36:08) I actually wanted to share the PEED has been our biggest promoter for spare type concept. And we are not associated with them, don't get me wrong. But what happened was I think it because of this E D downtime, you know, the people madly taking for quick take a photo for the the E D dashboard, the tracking board because before it goes down, it generally gave us like it's just so much easier for us to explain to people what spare does. yeah, we saw that in Pit. We had so many people telling us this is actually amazing show and give the society such a level of education. And Martin Hinton (36:51) Yeah, well, I mean I again I I I couldn't agree more. And I think it's a we'll pause the cyber insurance and cybersecurity conversation to do a an an unbridled endorsement for the value of art, right? Like that's what it creates, right? That the this this make-believe TV show illustrates something in the real world. You you touched on quantum recently, and and and we we've touched a bit on AI. We as much as it feels like this is now everywhere we turn and everywhere we look, we're really at the beginning of this. On a scale of one to ten, where does readiness sit and and what would you move you know, what would you do with with with with right away? What what are the big things to address? Chao Cheng-Shorland (37:30) you mean like just the quantum side or Martin Hinton (37:32) Yeah, I mean, you know, so so I think it's in January the new presidential I think it was an executive order to deal with quantum computing in the States is Chao Cheng-Shorland (37:39) Yeah. Martin Hinton (37:39) is going into effect. So, you know, is quantum computing again, this is one of those things like you know, alignment and, you know, AGI th this idea that that that this thing is coming, most people think it's coming, and quantum computing creates the situation for people who maybe don't know where, to put it very simply, all the ru rules around our current encryption and the ways we've encrypted things could be mute. It'd be like you know relying on notes on paper as a as your security message as opposed to speaking out loud. It's just it it won't work anymore. So is that twelve months away, less, more? W where do you think we are with that space? Chao Cheng-Shorland (38:16) I think the readiness is still very low and the quantum that threats coming, I think it's not going to be that long because initially we're saying out to two thousand thirty, then we got this AI move everything forward. so now the technology's just advanced so fast. I would say within the next twelve to twenty four months it will arrive. And so everyone really needs to be prepared. So one of the reasons we actually went into the cryptography and the distributed ledger base back in two thousand eighteen, we're genuinely miles ahead of everyone in ways of thinking, cybersecurity, quantum, AI, all those, is because it builds a foundation for postquant readiness. So the now now post quantum you know solutions have to have those type of ingredients, right? Cryptography, you know, all those So if you actually even start preparing now, it it's going to take time. And it's especially you have so many databases. That's why there there's a saying a lot of hackers just come and just steal the data first and even you can't equip, you just wait for quantum to come and now you can get all the data back, right? So it's Martin Hinton (39:33) Yep. Chao Cheng-Shorland (39:33) a very scary situation and I but one thing I actually do have to say Hyperscalers are very much stepping up. So they do start providing a lot of services, the post quantum, readiness, all those, and already built into their service offering, which is great. Because you know, even us as a deep tech company, very innovative, we still rely on hyperscalers to also provide the right services, right, for our clients. Because we don't hold like we're not hosting company. So it's a really partnership in order technology companies need to step up, step up and provide our clients the the best protection. Martin Hinton (40:14) You I mean you you quantum computing, I think you you pegged it at twelve to twenty-four months. And I think one of the things that illustrates that on the criminal side, there's great belief it's coming is the point you made about people stealing encrypted data now, knowing that in in your case, twelve to twenty-four months, the key to open that lock is gonna be available to them. So it's a bit like stealing a safe that you can't break today, but you're gonna get the code in in a combination rather in in in two years. And knowing that in two years you can, you know, reap the rewards of having stolen this this data and th this this material, this valuable item. And and I think that that is, again, what you know, if you look at predator and prey type behaviors, you know, they are anticipating this. That there's there's no doubt on that side, and people who are involved in that, that's their that's their hedge against the future. That's their, you know, their long buys that that they're gonna be able to break into this stuff and then it'll have value to them outside of this. You you you had touched earlier on legacy tech stack. So in in dealing with the quantum threat and the encryption vulnerability that it brings to companies, you you compound that with the sort of legacy tech stack. What does it look like at a company that that's dealing with that reality where they've got, you know, the the the joke I sometimes make is it's like trying to take a car from the 1950s and make it fast enough to drive on the Autobahn, right? You'd have to do a lot of work and how and yet you can't change the shape. And and and I just wonder whether you could explore that sort of You know, for companies that are looking at this and thinking, I know I need to deal with this. I know this is a problem. How do you approach it? Chao Cheng-Shorland (41:46) So you basically in in my mind, okay, you go through your the scanning of your tech tech stack, the landscape, and you find that the to me, right, one of the things very important throughout my enterprise enter architectural career, you do rationalization. You try to rationalize your land landscape as quickly as possible. You don't want to hand so many different types of systems around, so many applications, how to maintain, how to upgrade, and a huge amount of cost, you know, labor, support. And you try to take this as an opportunity, rationalize. So once you rationalize, you but bring to the most robust stack. And then that stack will become your foundation to add quantum protection, AI, resiliency, downtime resiliency on top of that. So when you actually go through this, you do need to go through fast. So I actually led one project in the past with a very large listed company and with McKinsey working alongside with them as a chief architect. And we rationalized like from a thousand five hundred applications and very quickly reduced down to a few hundred. I think it's a four hundred fifty was our target, but we got down to about 600. You know the amount of money you can save is is really, really crazy. Plus, now you have a clean stack, you have the right skill set to support, and you know, all these legacy systems, obviously it's not like an immediate overnight, right? You transition them out, you put the data into the secure vault, and then you actually back them up. But you also will realize after 10 years, probably only one percent of this data you really need. I can tell you, majority of data you don't even need. So you just waste your space, waste your money for so many things. And it you know the to me, right, everything's about lean efficiency. You don't need so much in your life. So i f for example, if you're running a bank, right, why do you need to know all this internet, all this noise? It's like irrelevant to you. And for enterprise you truly have to focus on purify. reform, get to the best, most efficient you know, stack. And then from here, all your innovation go on top of that, make it a really robust. And so now you solve your problem and it you reduce tons of costs. So that that's just my experience, you know, from many, many years before I started Shelter Zone as a chief architect on a lot of large programs. And generally that's how you deliver. You deliver fast, you deliver smart and are you very efficient. Martin Hinton (44:41) So go ahead, pardon me. Chao Cheng-Shorland (44:43) No, no, that's actually yeah. I just w w what I kind of want to share my thoughts on that. Martin Hinton (44:49) No, no, I that it's very interesting. So I I I I do need to bring this back to cyber insurance and cyber insurance underwriting. What does all this mean for cyber underwriting? What what what do you think about that? To take take me into that sort of, you know, all of this threat, all of this potential liability. W where does that where does that leave that part of this conversation? Chao Cheng-Shorland (45:09) the cyber insurance is actually a very interesting area for ourselves to understand the pricing model, why actually certain hospitals do things like this or different. And we engage with quite a few cyber insurance companies, right? Because we thought our technology stack truly can one is reduced the hacking two is i in case they get hacked, then how they can be resilient. So we regardless very aligned. But the insurance the underwriter is actually look at things quite differently. So for the primary insurers, right, it it's not a huge difference. this you have to pay, like two million, five million, whatever that your insurance premium is. So in during ransom or any incident, because each incident is already over ten million. So to them, it's not a huge amount of incentive to you know, kind of do something like un unless it's a crazy amount of money they can save. But the access insurer is a huge deal because if you get ransomed, you have to pay 50 million. The primary insurer paid you five, right? Because there is not much difference. Now you cop 45 million and whatever the percentage you you have to pay. So the secondary the insurer that we call access insurer, they genuinely will care a lot and they want hospitals or government, whatever the organization to be really resilient. Because if you keep going and you have time to negotiate the ransom, you can reduce the price by far, right? Because the ransom all the attacks they also they are humans. They they get worried. you're not paying me tomorrow, you're not paying me in one week. Then the longer it waits, the more chance for them to be caught. So they don't also don't want to go to a prison, right? So when this happens, you have a lot of advantage to negotiate a much lower price. So access insurers very keen on resiliency type of solution. They don't want hospitals to go down. Hospitals at least can keep running while they're actually sorting out the insurance part. So so that's just my observation over time. Another thing is hospitals, because they have this insurance coverage for certain technology right be activated during downtime. So they actually can kind of like a link, say for example, spare time type type of technology with the cyber insurance. And because it's a like a kind of during the downtime, you we have to pay you, we have to use the technology to keep going. So they may find that's a more efficient way than just paying regular type of technology stack. So I think it's just interesting how everyone's looking at how we benefit from the technology, but an another major part is how we actually can cover our costs. Martin Hinton (48:12) So if if I'm a broker, what should I be asking my client about their downtime resiliency? What are what are the what are the the pointed questions you should ask or expect to be asked? Chao Cheng-Shorland (48:24) So you should actually really have a kind of simulator model based on the industry standard, right? every like a small hospital when they go down to one million per day, and the high ones, the big ones, eight million or even more. And if you have an extended time of ransom or downtime, and what's the total cost involved? So you do this math, it's so simple. And then plus the payments to the ransom kind of like the the ransom attackers, you literally should simulate how quick you should recover those system or you should actually have a continuity system in place. Because the those systems add up, it's just a fraction of what you have to pay out. So you basically get the stats from the hospitals how robust they are, have they thought about the continuity, have they thought about b you know the resiliency. So that actually could force hospitals to really step up because insurers say, hey, I'm not going to insure you unless you have already got all this planning in place or the technology in place. So so yeah, for the the insurers, I think it's a big deal if you have to pay out that much, right? Every ransom or every cyber incident, or even just every downtime incident doesn't have to be a major cyber attack. Could be some hospitals went down for many days because of engineering mistake. So all of those will come back to the insurer, hey, you have to pay me because I had all this damage, right? So yeah, the I think the cyber insurers should be very much you know, aware what actually fac affects your premium payout. Martin Hinton (50:10) I mean, d we we know that things like MFA and backups create pricing credits and that sort of thing. Do you think that being able to demonstrate this kind of continuity capability and resilience broadly is another area where it should affect pricing? Chao Cheng-Shorland (50:27) Absolutely. I actually just just think about if Martin Hinton (50:29) Yeah. Yeah. I mean I mean Chao Cheng-Shorland (50:30) you want to insure a car, right? Now that's the E Eve is a little bit different. When you insure a car, if you don't have a a spare tire put in your trunk, it probably will reduce the kind of like the by fear bit and say, Hey, this I I need to increase your premium because you don't even have a spare spare tire to get you to out of the trouble. I always have to have the low side assistance or other kind of things, right? So I think it's the same thing with the insurance you know, for organization the the if it is any chance for them to go down not being secure, not being resilient and then will cost you a lot of money. And also for their sake as well to have that operational resiliency and you should actually really have a very serious conversation with those organizations. Martin Hinton (51:23) I mean i i it stands to reason that in a ransomware negotiation resiliency creates leverage on the part of the the person who's the subject or the the the person being attacked. What what about how Chao Cheng-Shorland (51:33) Yeah. Martin Hinton (51:35) does that change the conversation in a negotiation? Chao Cheng-Shorland (51:39) So I heard several hospitals right at the end that they were able to recover, they didn't pay the ransom, but that was already like a twenty something days later. They be able to restore everything. They were able to kind of recover from the backup, they manually keep in all the data. So one is it's already not very good because you're done for so long, right? The insurance have to pay anyway. The other one is you you know, kind of even you got out of this type of mess, not paying the ransom, but this is only like you're lucky. And for the for a genuine continuity, so you still can actually continue operating without stopping, right? Still can use all the you know patient charts, do the orders, medication, you know, do all the vitals and not getting impacted at that front. Now you genuinely have to your leverage to negotiate with the hey we we're not needing you. We have everything backed up. We we already have another system going. And you either give us back or you just wait for the FBI to come to get you. So you you can actually have much bigger leverage in this kind of conversation because you have to face those hackers anyway, right? They they do hold your key and you try to get them back out. And I think yeah, it it's just a a you buy time, you buy your confidence and you actually mitigate the the damage as well. Martin Hinton (53:14) I mean, a a lot of what you've touched on sort of demands that we reframe the the line item in a company's budget for cybersecurity in some ways away from being a cost center and more into I don't know, revenue protection. And I and I wonder whether or not you could make the case that given the scale of this threat and the the the the likelihood certain industries are to be attacked or the the the likelihood of an attack, it you know, it's we we hear again and again. It's not a matter of if, it's a matter of when with regard to these sorts of things. Make the case that that the tools like the the ones your company offers and and even just broadly, you know, well well-established MFA or even employee awareness, the these things are are not the same as, you know, you know, new chairs for the office. Chao Cheng-Shorland (54:04) Hmm. Yeah. So I'll give you some examples and these are pr pretty deep. because we do work with a lot of hospitals, got ransomed, right? And at the time they only looking at okay, this is how much we need to pay and how much we need to recover. And I can tell you quite a few of them after two years, they couldn't survive. They actually go bankrupt. They're looking for acquisition at the hospitals to take them over. they never recover from ransom. So if you have something, the protection in place, the continuity in place, you wouldn't have had that type of disaster, kind of like after a few years, you still have to sell your business. And then you have the hospitals at January just closed after 45 days. The reason is because most hospitals only carry cash for 45 days. Some carry for 60 days. That was like already very, very good. A lot of them only carry thirty days. So when you have a the this experience, that's why they're so nervous. Once you get to the thirty day period, you can't get a insurance claim back, everything frozen, you can't get a cash coming back in, you can't pay your doctors anymore, you can't do anything. And that's when the c hospitals go bankrupt. And forty-five days is the is kind of the borderline. And literally if you can't recover and I I have seen several hospitals actually completely close down. So that is why is a a revenue protection not cost centre. Martin Hinton (55:43) I you're touching on the question that in this landscape every CEO or C-suite executive needs to have on their mind is sort of the minimum viable business test. And if if we suddenly couldn't do anything on our computer screens, the the proverbial everyone's monitor is blue moment, how long can you exist without bringing in more revenue, without bringing in more, you know, money to put it in simpler terms? That idea is is one that you know, a lot of companies when That I've spoken to when they sit down and they think, wow, we only have, to your point, 30 or 40 days of reserve before we are, you know, in a position where closing, and and this has happened to companies, you know, a prolonged, you know, again, like putting it to into the real physical world analogy, it's it's not on like say a hurricane hitting a region, right? And and knocking out a bridge or, you know, taking out a dock, and and these things are enormously disruptive to the both. the economy of an individual business, but the whole region. And again, I think, you know, I mean, why do you think there's this resistance at the the sort of Swiss C C-suite and board level to sort of adopt this? Because it would seem, given what we know about the threat, that it would be a little more obvious to sophisticated executives. Is it just a matter of finances and and and maybe a a bit of too much of the teenage mentality that it won't happen to me, it'll it'll happen to someone else? Chao Cheng-Shorland (57:09) So I actually observe two to three different type of behaviors. So one is the regional hospital, rural hospitals, they struggle to survive. They absolutely don't have money. Doesn't matter how cost effective our technology is that like a spare tire, right? It's continue is really, really cost effective. But their priority is to survive, have keep the lights on. That's the words they told me. They know how important it is to have that resiliency. They love to have it, but they can't get a budget approval because of the survival comes first, payroll first, right? And whatever that we already have need to keep the lights on. The other end is leading hospitals. And the especially the big brands, they genuinely f fast track us. They we we had a several situations now because they know it is nothing like this on the market. This is the The way to for them to be resilient and that they know everything's coming. The AI is not going to slow down any of those ransom, right? It's only going to increase. So they genuinely like a you know, getting fast approval, you know, fast POC, putting in a lot of resources, really get across the line so they can be resilient, they can actually at least can sleep at the night. hospital CIOs were telling us at least we can sleep at night, the don't need to be kind of really worried every minute now something happens. So that actually is another the the other end of the hospital systems. They do have budget, they do have strategic kind of you know, direction and plus they know the problem so real. Then you have the middle ones, the mid size to maybe say, let's say three thousand bets, the you know the decent size, but they kind of like try to balance out what is the priority, what actually how we do the change management. It's actually the good thing is our technology is so easy, they don't even need to do much change man management. Of course the change management is to replace pen and paper during downtime. It is still a organizational initiative, right? Yeah, doesn't matter how Martin Hinton (59:21) Yeah. Chao Cheng-Shorland (59:22) simple, how good your technology is, it's still there's a change management. People need to move away from that paper. paper-based kind of downtime and then how you actually re-engineer your you know the kind of the continuity. So I think it's really three I see very clear three tiers of hospitals how they respond. And it seems like I would say probably 90% or more genuinely recognize, my goodness, we really need this. But the reality is Do we have budget? Do we have the resource? Do are we going to survive, you know, just even with the current budget paying our staff? So so we do want to kind of provide a lot of flexibility. And for example, the recently we helped one regional hospital, we understand that the stress they're under, and we offer them, hey, you can actually get a spare time in just ASAP because that's life saving. And we can actually pricing it all these other human affect right you how you actually just like a payment plan or things like that. So we are you know for for us the saving lives is most important. Then obviously, you know, as a CEO you always have to worry about ARR or those because otherwise investors wouldn't be very happy. But at the end of the day, the priority for hospitals come first. Martin Hinton (1:00:48) I mean, we we we haven't touched on it, but one of the things that that that people need to remember is that increasingly we're seeing this long tail of liability that exists where, you know, costs are coming up years later and and there's a class action lawsuit around privacy and certainly encrypted data in that quantum space. So there is a real argument for for people to take a much broader attitude about you know, where the threat can come from. so a as as as is expected, we've been talking about an hour and I think We probably haven't gotten everything, but i is there anything we didn't get to that you you wanna ha wanna say anything about? Chao Cheng-Shorland (1:01:23) actually I do want to share some of my thoughts while we're talking, right? And I feel people all have a s kind of some misunderstanding about say blockchain or some type of like AI type of technology, like a cutting edge. They will think, you're just tracing some you know, the trend and you just want to be like a look very fashionable. But if you think about over the years, like When we watch old movies, like nineteen fifties, ninety sixties, and just so many beautiful classic movies, the music, and then you have the fashion, the people just so elegant, so you know, like a sophisticated. And those things doesn't change. And you just like your wine, the vintage wine, the reasons because we're here to solve real problems. We're not here to trace them, you know, just a fashionable for the next couple of years. And you when we started the blockchain was 2020. Two thousand seventeen. At a time we just believed that technology one day can solve huge problems. And then everything just proved. They use a Bitcoin or other type of cryptocurrency to send the money. Millions of people use that now, just exchange the, you know, without Those flawed, no human intervention can take some money away from you. So same same thing here. When your data actually has this type of technology back you and you own that, and just like your Bitcoin, you own this, and you you can track, you can control that, and you no longer worry about a hacker coming in to steal your Bitcoin. How many hackers actually attacking Bitcoin? I I haven't actually seen any. So that was the same for our data, medical records, you know, government data, financial data, all the transaction, MA, everything is really your digital asset. You need to respect that. And you respect that with the right technology. You don't just respect that building some chicken coop, right? It's not enough. So you generally have to think about people building technology try solve real problems for you. And it's not just so against that, not not open minded. You should be open minded why actually blockchain survived after all these years if you found the right application. If you find the right use case, you find the right application. I even remember the cybersecurity top industry analyst told me, two two of them told me once, child, one day The company going to solve cybersecurity problem or the AI problem is a blockchain company. And I hope you are the one. So that was actually very encouraging because they at the top of the pyramid, they see the whole landscape. They say they haven't seen one other technology could genuinely solve those problems. And they bet on blockchain. And they're not even blockchain analysts, which is like incredibly amazing. So I feel you use the right tool for right reason. It's not because your y it's fashionable and things do age, but the vintage one, the classic movies it really survive. Martin Hinton (1:04:45) I I I mean I think that's a great sentiment. You know, a new problem might require a new solution and and broadly once you keep your an open mind to to it as you as you look to solve this very real problem. Is is there anything else before we wrap up? Chao Cheng-Shorland (1:04:58) no, I just really enjoy talking to you, Matt. Yeah. Martin Hinton (1:05:02) I I I I I have I've really enjoyed it again. I I I I I'm really grateful for you taking the time and and and and and certainly do appreciate it. So so again, Chao Cheng Shorland, the CEO and co-founder of Shelterzoom. Thank you so much for your time today. Really, really interesting conversation. We've referenced a few things here today and there'll be some links to articles and other resources in the show notes so you can check our facts and all that sort of thing. But but again, thank you so much. The rest of you, thanks so much for your watching or listening. I'm Martin Hinton, the executive editor of Cyber Insurance News. Enjoy the rest of your day.