Martin Hinton (00:00) This is the Cyber Insurance News and Information Podcast. I'm Martin Hinton Executive Editor. Every week we talk to the underwriters, brokers, and security leaders shaping the market. Martin Hinton (00:11) This episode is brought to you in association with Cyber Tzar, the cyber risk platform from the heart of England's West Midlands, and Source Consulting London. Martin Hinton (00:21) All right then. Welcome to the Cyber Insurance News and Information Podcast. I'm the executive editor and your host today, Martin Hinton. And joining us today is Andrew Horkan. He's the CEO of Cyber Tzar, which is out of Birmingham, England. And before we get into too much about what Cyber Tzar is, Andrew's going to start with an anecdote that presents for the audience the threats that exist out there for businesses and the value propositions Cyber Tzar brings. Andrew, first of all, thanks so much for joining us. Andrew Horkan (00:49) Thank you, Martin. I will just say quickly, if anyone wants to understand where we are in the UK, Birmingham is where the Peaky Blinders are from, and we're also from where the industrial era started. So if you look into James Watt or Matthew Boulton the age of industry came from the West Midlands. So that's where I'm from. And that's where the accent is from, if anyone's interested from that. Martin Hinton (01:09) Yeah. Ver very very very good. We we do have a global audience, so so that'll help. any any cultural references always make us feel relevant. so Andrew, the the the I I touched on the sort of, you know, to to start us off with an anecdote or a a story to to keep all this as clear and easy to understand as possible. There was an incident involving a defense company that you encountered. So I know that there's some things you can't tell us about that for various reasons that probably seem obvious, but what can you tell me about this defense supplier? And what your company found. Andrew Horkan (01:40) So effectively, these are some of the use cases that we've found recently. So we were doing a monitoring. We monitor the supply chain so we can see everything externally that a hack can see. So from open source, we have a look at your ports, your infrastructure, your subdomains. And effectively, this company that we were monitoring, we monitor 2,000 of their suppliers. Now, one of the suppliers is the company that delivers the warheads. The company that delivers the warheads are based out of France, Germany, and multiple different estates and companies. countries and effectively they had NIST, had SOC 2, had ISO 27001, CyberCentral Plus and then DeathStorm level 0. Effectively they had all of the compliance things from January till May. Now effectively that's brilliant, however compliance is always just a bit of paperwork and effectively in June when we were monitoring them we saw there were over 17,000 ports were opening and we were returning data from their server and effectively once investigating this, they admitted that they'd moved their server and infrastructure from France to Germany. And in doing so, they'd opened all these zero-day weaknesses. However, as far as the defense company was concerned, they were secure and they were a trusted supplier. However, we proved they weren't. Effectively, though, month later, all those ports were mysteriously closed. But effectively, what it means is you might be compliant, but there are things that every company, doesn't matter the size or the security, will accidentally let slip from. And that's why Continuous monitoring is so important. Martin Hinton (03:11) So halfway through the year they changed something, didn't check in with the people who said that they were compliant with either their cyber insurance or whatever cybersecurity protocol you might want to pick. And they they they weren't. And as a result, this very sensitive organization was highly vulnerable. Do I have that right? Andrew Horkan (03:30) That's exactly right. So essentially, you don't need to disclose if you make any server changes or website changes to the compliance every single time, but effectively, their tech team had moved their servers from a French based infrastructure to a German based. So they put it onto an open shared port server. and everything was open, so there were Buntlery servers returning data and effectively a hacker or a hostile actor could take advantage of that very easily. So essentially it was a critical level issue that needed to be resolved. However, our software was able to pick that up and they remediated the issue within a week. So effectively no one would have actually seen that until the compliance the year later. without us they would have had that breach there for a good six months. Martin Hinton (04:12) What happens if they'd suffered a loss in this moment or if there'd been a claim? W w what in the cyber insurance sc scope? Andrew Horkan (04:19) So effectively with the with this, for example, we have ISO 27001 of cyber essentials in a compliance document kind of a format. You need at least like a certain amount of boards or firewall settings set up. This would have proved at a time that that was happening, that that wasn't set up correctly. So there was a high chance they wouldn't have paid out. We saw this with Knights of Old in 2023. They were following policy documents. They had also 27,001. However, when they were breached midway through the year, the insurance company didn't pay out because they weren't actually following what they said they were following. So essentially, if there was a breach, there would have been an opportunity where they wouldn't have been paid out. Effectively, though, for the last five years we've been driving, we've had 15 incidents where companies have had to claim insurance. And effectively, they've been able to show that there's not only policies, but they're also committing to a complete, well, they use our platform as a complete system of record. So they can show each month that they're looking for issues. But on top of that, they can show auditing evidence that they are then putting in the remediation or the steps to be remediated. So effectively, we can be used as a tool for people to then say, hey, look, if you're getting a claim put in, here's all the evidence in one location. The auditor can log in themselves and have a look at it without having to stress that you actually got to find all the documents yourselves and are storing them correctly. So it's evidence-based with the compliance on top. Martin Hinton (05:45) So this is the value Cyber Tzar brings. We're gonna get into that a little more in a moment. But where did you start out? How did you how did you come to this this this role in in this company? How did you become the Cyber Tzar? Andrew Horkan (05:58) Effectively, it's very kind of safe. So I put a lot of the work into my father. So so I was always me and my father together. But growing up, I was very, I had a very weird wing in regards to tech. So when I was five years old, my father was the CTO at Sun Microsystems. So in the UK was the youngest CTO, a billion pound organization. And he was building some of their servers and computers there. And effectively when I was five, used to call it a super computer. It was just a very big PC with five different CD-ROMs built into it. But at five years old, we built that together. By the time I was 11, I was able to rewire. So all of the CCTV in my dad's house at the moment is still the CCTV that I built when I was 11 years old. And effectively, thanks to my father, had a very heavy tech upbringing. From there, at 15 years old, I got my first job. Effectively, it was for a company called Voice Mobile. They were the principal partner with E and Orange, which are a telecoms company with the NHS and police, so the largest contract. What they used to do is they'd hire four 15 year olds to data mine. Effectively, you'd copy the data into from the police section into Orange's system. if they were ready to upgrade, you put it into the CRM and that was their sales data. Effectively, effectively within two hours, I got bored and I automated it. using the same type of tools I would use to automate and hack games, essentially. I used the same tool that I used to automate runescapes, mining and tree farming. I used that same macro to automate this data farming. And about two weeks later, the head of tech, a guy called Andy Clark and their head of sales, Dean Sale, put me in the boardroom and effectively I remember getting scared and worried. I text my mom saying, mom, think I've lost my job here. I'm so sorry. And they effectively said, look, on average, compared to everyone else, they do about 80 checks a day. You're doing a thousand. In short, we've tested the data, reviewed it. It's correct. And essentially what are you doing? Because we just see you playing snake on your Nokia. And from there at 16, they took my data and made me head of integrations for their company. And so from there, used to sit and with Andy Clark, who was the head of IT and we'd learn about self-taught TSQL database administration. We improved the dialer speed for their sales team, improved it by 18%. We also worked out the forecasting. So I taught myself a lot about forecasting at the age of 16, they were the head of sales. Effectively we went and they used to do a lot of... it's who is whoever's selling the most, but we figured out actually it's a commission basis that the lady was selling the least was making the most about profit for the company. So I taught the head of sales, those things, and they use that and still use that to this day. And effectively from there, I then jumped into the age of 19. I went to college to get some A level equivalents because from the age of 15 to 19, I was earning 35 grand. So I wasn't really into going to university at the time. I then got a A level equivalent in computer science and creative IT. So that's standard computer science, but also website building and all of your C sharp and things like that. Within three months, I managed to fill the course working and I got a distinction star there. So I passed that. I then moved into a company called True Commerce. I worked there for two years doing electronic data interchange. So they work with, for example, you've got B &Q and it's the ordering systems and you can see that kind of the transitions that they're making to make sure they've the lobbies have got the right orders on them and the lobbies arrive and start things in the barcode. Did a lot of coding there. But then where the entrepreneur spirit really came from was during the lockdown, I reached out to my friend who owns a gym locally, name is Warren Dyson, and we built an auction site for buying and selling gym wear and effective gym equipment. And we took advantage of that and effectively made 300,000 pounds in the first month. We sold all the gym equipment, took a load of loans out. And then from there, From the 2019 to 2021, I effectively helped local companies become, well, get digitalized and sell online or sell services online. And then from there, 2021, my father reached out and said, hey, son, we've not worked together. You've outright refused my help as a young adult. I didn't want to think it was nepotism. I wanted to build some income merit and effectively said, do you want to work together on a project? And that's exactly what we've done. And that's where we are today. So effectively that is my journey from finishing school to my quick non-regular route into working in cyber and then building this up. So we've been Martin Hinton (10:49) You Andrew Horkan (10:49) doing this now since 2021. Martin Hinton (10:52) So you going back to fifteen and your experience as a a quite young employee at a company and full time employee at that, you discovered something about the way companies actually see security that sort of informs how you pr sort of navigate the reality we face now. Tell me about what you realized early on about how companies see security. Andrew Horkan (11:13) See, this is when exactly mirrors what I see today is people see security as a cost center. So especially a good 12, 13 years ago, cyber was no one was really interested in it. was a, it's not going to happen to us. There weren't many cases of it happening and it was a nice to have and effectively saw it as a cost and they valued. They valued the speed and efficiency of the tool and I was building effectively to make more sales and that's what they care about. And effectively, even in today's language, that's what we say. So with smaller businesses, they don't care about how secure they are. They care, well, if we get attacked, we insured and can we make a claim? Or alternatively, can we win more business? So in the UK, there's something called the Cybersecurity and Resilience Bill and we've seen lots of small businesses that now care about being compliant purely so they can either stay in big tenders. or win tenders, they aren't really interested in being secure effectively. that's still the same kind of vibes we were getting 10, 20 years ago. People say they're concerned, but it tends to be a lost leader for a certain reason. So we see a lot of larger organizations here locally, the IT providers or managed service providers that have cyber as a lost leader so they can use it for marketing and sales, which is a shame because people should want to be secure. But that's the reality of it. Martin Hinton (12:31) So the the the if I'm understanding you correctly, the the the idea of security, cybersecurity is an afterthought to the fundamentals or what's viewed as the fundamentals of the business's profit center, right? not only is it a cost, but it's also a secondary concern. And and that creates in your opinion, significant vulnerability for companies, right? Andrew Horkan (12:54) Exactly that. So whenever I've seen other pieces with cybersecurity experts, they're talking about, companies really care about their cybernet. It just feels like marketing. When you speak to any of the smaller or medium companies, so you've got like your small logistics companies that got one or two vans. effectively they're thinking about their next paycheck and especially in the West Midlands we see a lot of manufacturers who work on adjusting time principles they don't have the costs to go and put all the effort into cyber so effectively if those policies and procedures aren't put in place from day one five years two years three years two months whatever down the line they can't actually afford to go and make these security well changes and policy changes that they need to effectively it's always an afterthought and I very rarely meet someone who is pro cyber unless they've already been breached. So anyone that I've ever met who is pro cyber, who isn't a sub security expert tends to be someone who is either previously been breached or they've been a part of a community that has been breached or an organization that's been breached in the past. Very rarely do you see companies talking of it as a priority. It's always where's the next book or we've got to survive this next month, especially in today's economy as well. Martin Hinton (14:10) Yeah, mean I I think we're we just did a report this week about security concerns are great, but budgets are flat. And that is almost certainly a representation Andrew Horkan (14:17) I'm Martin Hinton (14:19) of the economy is be more than the demand or need or threat that that's out there. So I I wanna I wanna to talk about Cyber Tzar specifically. And there's this the way you assess companies. Take me through how that works. This sort of outside in without consent analysis that you're able to do that you can then well Tell me about how you how you go about this and and what it provides you and how that f sort of fuels your business. Andrew Horkan (14:48) So effectively, we do non-intrusive assessments first. So what we do is we take your website, which normally people say it's only a website, but we can do as many checks as possible. So what we do, effectively, we will find the website. We'll find all of the subdomains. From finding all of the subdomains, we will then, so you've got your dev.uat.email, all of those subdomains. We will then run the same level of testing on every single subdomain. From there, then we do your in-map testing, but it's just like finding the ports, seeing what's returning. From there then we check your anti-spoofing and your phishing takeover testing. From a sub-component of that, we check your DMARC, SPF and DKIM. Those are the anti-phishing protocols. So for those people who don't understand tech too much, it's to stop people sending you spam emails or pretending to be you to your customers. We check those policies and procedures. From there then we do web application security testing. So we do only the static part, not the dynamic. So we can see vulnerable JavaScript libraries. We can see out of date code. We can see where SQL injections, can see potential like credit card information that's on the site or customer information that might be linked into or password files that might be leaked out. Now from there then as well, we check the HTTPS security headers. We also check the redirects on those. So sometimes people have got the security SSL certificate set up, but then in the links to third parties, they're not on there. So for a moment, some of the data is not encrypted correctly. And it's a security hardening post-it issue. But from there as well, we then check the breaches on whoever has entered the email. So for example, it's Martin Hinton at cyberinsurancenews.com. From there, then it would check your breaches and if there's any data on the dark web where people are selling your passwords or personal information. But then we've got a link into LinkedIn's metadata. We find all of the other employees that work at that organization. We use AI to generate all of those emails and then effectively do the breach checks on those for doing a total data exfiltration. From there. from the tech that we've discovered, we also then do the same scans on those to do sort of a shadow IT you might not have understood. So if we see their websites using certain software or we can see their ports of return in certain software, we then scan those companies as well. From there, we also do marketplace. So we'll automatically see you are a company that is 10 men, well, 10 people in the West Midlands of this manufacturing industry. We will then scan. 10 companies that are similar size in the region to do a benchmark comparison report on exactly the same level of testing. And we also check Amazon S3 buckets and containers. We effectively do as much as physically possible without breaking the computer issue. So it's all open source technology. The only difference is the scans take us an average 20 minutes to a day and we can do up to 6,000 websites per day at our current capacity. So we now have data on 7.5 million organizations. And we, for example, we monitor 17 % of the UK continuously and things like this. Martin Hinton (17:49) So i I I just wanna pause one second to make sure I understand and and perhaps there might be some people listening who who need this moment too. It it sounds to me what you just described is a technical version of someone who's an expert in building construction or design or architecture, looking at a building and being able to see things that most people wouldn't even know that were there. or notice, right? So you're seeing a layer of complexity that may be obvious if you have an internet connection in the software you're talking about, but it allows you to reveal perhaps problems that exist in the way this particular site is operating that create vulnerabilities. Is that i is it's sort of an expert eye, is that like a spy? Andrew Horkan (18:36) But the terminology I like to use, so about 20 years ago in the UK, you could ask the police and they would come and review the security of your house. So the terminology I like to use is effectively, I have stood outside your house, Martin, and I've gone, your alarm is out of date. It's 10 years out of date. We can see that. On top of that, we can see that it's actually switched off. So it's not flashing. Effectively, that is where other vulnerability assessments kind of stop. We like a ligmas test. but we get as close as physically possible without breaking the law. So essentially we've stared right into the window and I can see you've got a safe in the window and you can see what version that safe is and what vulnerabilities that safe has. On top of that, we've seen that you've got multiple doors. So as well as your front door, you've got your back door, you've got a conservatory, you've got a shed. We can see all of the entry points and from there then we can see the security on those entry points and effectively we go, it's a bit of a gray area because we're getting very close to the doors. of being intuitive, but effectively this is everything we can say. On top of that, we can also say, for example, if someone has nicked a key or has took a copy of your key and is monitoring you from external with the breaches as well. The difference is also, no, I was gonna say. Martin Hinton (19:46) So it's a bit like Go ahead. No, no, I was gonna say it's a it's it's a it's a bit like you're watching the house from a public pathway or sidewalk. You're not on their property and that's sort of the line that exists. You you've made reference to the computer misuse act. is is that the right way to think about it? Andrew Horkan (20:04) That's exactly how to think about it. However, then if you give me consent, we then go in, well, we'll kick the door down. So effectively, with that, we then do all of our, we do the dynamic testing, we do the DDoS attacks, we do brute force attacks on all of the findings we find. And essentially that's where we go for the next step once we get consent. Martin Hinton (20:24) So prior to the consent part, you will scan a company theoretically and you will then approach them with their score as a way to generate business. Is that is is that the sort of general sales pitch? Andrew Horkan (20:38) Well, effectively, it depends. So for a smaller business, can, they can apply for a score and we can tell them all of their risks that we can say vulnerabilities and breaches. The difference is unlike traditional rating or scoring that we say in the wider ecosystem at the moment, they do vulnerability assessments. They go, you've got these issues and then they do the threat assessment. So they go, these issues mean this. The difference is that's just right and it doesn't really score or mean anything. So we do the vulnerability assessment, the threat intelligence, and then we do risk assessment as well. So we go, this is the issue, this is the threat, this is the impact, and from that impact, this is how you can fix it yourselves. So essentially, we allow small businesses to go and fix those issues and remediate themselves and become the hero. Effectively, from there, we've gathered enough data now over last four years, we can see trends where we can actually say, if you are below a certain score and have certain issues, you are susceptible to different attacks. From there, we saw if your score is below 400, you're susceptible to automated risks. So effectively, people could purchase data on you. You effectively, anyone with a know-how could do significant damage or purchase data to do significant damage. Whereas anyone between the score of 600 and 400 is susceptible to, say, for example, a organized crime unit or organized cyber, a hacker organization or say for example a hostile country could do significant damage. Recently we've been doing some work with some European and Baltic militaries of defense and effectively in a recent report we did a sample of 8,000 direct suppliers to a Baltic country. Can't really name the country at the moment but I'll do some risks and effectively we did that about a month ago and within 10 days, so we did a assessment on 800 companies and three of them come back as critical risks and 10 days later after we gave them a report, one of the ones on the report got taken down exactly how our realistic attack scenarios, it made the news and effectively our partner in that country has now got a photo of them shaking the hands of the prime minister and they're looking to monitor the entire country and seeing what that'll look like but effectively We have collected that data for four years. So we've got the trends of what's happening, how it happens, what happens when our day JavaScript library is coming to play. Or for example, if someone has got, they haven't got the policies for D market, D Kim, but all of a sudden the ports are open, which mean people can take advantage of that. can see and monitor those scoring. Whereas other people won't have that. It's more of a, we've compared you to 10 other companies and you're the seventh. can go actually effective to the score. It's exactly like a experience credit score for cyber. So that's what we're working on building. Martin Hinton (23:28) So you so let me pause you there because you've mentioned the score, you've said four hundred, but we haven't actually gone through the scale of the score. And if I have it right, it's a zero to one thousand scale for this score that you can potentially achieve on your scan. T take me through what four hundred means or six hundred or eight hundred. What where do we want to be on this zero to one thousand scale if I've got that right? Andrew Horkan (23:49) So I'll break that down. essentially the score works off a matrix of different risk groups. So it's got a risk matrix, which is kind of like a little rectangle. And from there, you've got impact versus likelihood. So you've got five levels. So impact would be negligible to impact significant, which is one to five. And then on the likelihood, you've got not likely to happen to unlikely. and then two pretty, well, pretty likely. Essentially then we change those into little risk groups. So risk group one would be a five likelihood and a five impact, whereas risk group 25 would be a one impact and a one likelihood. So it's more information like, we've got this and you can see this. Effectively, a risk scoring is then generated from the matrix depending on the issues that we can find and broken down from there. The score, best potential score, so we do say a thousand, but the best potential score you can get is 999. That is because we don't know the unknown unknowns. So no one can have a perfect score because there are things that we don't know of or haven't been released yet. From there then we also have the best potential score you can get. So what we've seen is some organizations will, for example, they can't get a score 999 because of who they host for, because the host who have got vulnerabilities that we've monitored. and effectively their score might be capped to like 870, for example. From there, we kind of set the standard as 850 is where you want to be and where you want to aim for. Anything above that is pretty good as far as we can say without doing any intrusive testing. We can see that out of all of the organizations we've monitored over the last five years, so it's 7.5 million organizations, a score of 700 is average. So that's what we've seen is average. Anything between 600 and 400 is susceptible to risks by someone who has the know-how could do significant damage. So for example, that organization I was speaking to earlier, got taken down. Effectively, was via their out-of-date JavaScript libraries, meant there were some weaknesses in the code. It got taken advantage of, and their database was accessed, 1.5, 1.2 million customer data was leaked within a day. And effectively, because of the update JavaScript libraries, they had a score of 575. It was a targeted attack. Whereas anything that is below 400 is susceptible to automated attacks. So for example, our website has 250,000 bots constantly trying to breach in pretty much all the time. And a score below 400 means those bots will be able to effectively take advantage of some of the risks automatically. So that's kind of where we say lower than 400 is anywhere between high and critical. where 600 to 400 is. If you've got any enemies, be careful, effectively. Martin Hinton (26:36) So y y I mean, w one of the things that's interesting and we we discussed prior to to the this moment in planning this is that it an enormous percentage, almost every organization that you scan and you give a report, within a within a month they've improved their stat status and security standing. Do I have that right? Andrew Horkan (26:54) Yeah, so I can give some really nice statistics that I'm quite proud of. traditional Martin Hinton (26:58) Yeah, please. Andrew Horkan (27:00) supply channel third party risk management vendors have a very low engagement rate because it requires consent or issues. However, we switch that on its head and effectively we allow organizations to go, hey, Mr. Supplier or Mrs. Supplier, we've got these issues and you need to remediate those. From that, we have seen 98 % of suppliers that receive a report from us will remediate their issues and improve their risk posture. within a month and that's measurable. So we can see that where say for example, I go Martin, just to let you know, you've got these ports open and you've got this demark lack of protocol. Effectively, you will then give that to your tech team and they will panic and fix it within a month. And we've got that as a measurable impact. From there, our platform also allows people to do procurement and form filling, but instead of going, can you fill the form in first so they can send then the assessment, we do the assessment then ask for them to fill the forms in. And effectively we've seen that 70 % of people who use our platform, so suppliers who utilize the platform, will fill in compliance documents within the first three months, which is a very high amount of engagement I'm quite proud of. So effectively we can see that across the board. Martin Hinton (28:08) You you you mentioned we started off with the anecdote about the defense company, but the aerospace defense and space data set and and space that you operate in. D double click on that part of all this for me, because it's a fairly significant industry, both in the UK and in in the e EU. Where does that stand? Because there's a lot of the reason Andrew Horkan (28:29) So I Martin Hinton (28:30) I ask is so people understand the there's a lot of supply chain reality to this industry, which is where enormous amount of vulnerability can exist. And I wonder whether you could sort of, you know, dive in on that for us. Andrew Horkan (28:44) So if you're very sick, I'll get the actual figures up to an exact. So if you're very one moment. So Martin Hinton (28:47) Sure. Yeah, no, no, please. Andrew Horkan (28:49) we've been monitoring the aerospace aviation, defense and space organizations. We've got some partners and clients that work with the UK space agency and they want us to monitor this data set. So we have took data of 55,630 core aerospace aviation, defense and space organizations worldwide. In the UK, there's 6,310 that we monitor. But from there in the supporting sector of manufacturing, of people that supply to aerospace, we've got data on 462,374 companies and 40,000 in the UK in supporting sectors. Effectively though, is a SME heavy ecosystem. So we've got a lot of data on all the different companies. So effectively on that data set, we can see some trends. Those trends that we can see are smaller companies like the SMEs, the one man bands, they've been trading for like two, three years. Effectively they have, they tend to actually have, and this is empirical evidence we've gathered. They have 90 % of them have lack of DMARC and DKIM protocols set up. So they've not got policy just because they don't know about them. And it's not someone that's set standard. However, a lot of them have paid for a website where it's automatically built on Wix or WordPress and they've got automatic updates. So they've not got a lot of outdated JavaScript libraries. It tends to be little silly holes where policies aren't Then we can see from medium to larger organizations where they've got their own dedicated IT team or they can pay a third party IT team to do a cyber review. What we can see with those is effectively they've got a much larger percentile of outdated JavaScript libraries, SQL injections, effectively where... they've turned automatic updates off to keep the company running. Like we spoke earlier, people care about the paycheck more than the security and effectively they're just missing things. So they've gone, we're secure in January and they've turned automatic updates on so the website stays up and effectively there's a load of breaches and issues that then generate because they don't continuously check those issues. Then for the larger organizations in that sector, what we can see is because they have their own dedicated teams, they're a very large moving beast of an organization. What happens there is the attack surface discovery, attack surface becomes too large for them to monitor. So we work with a aviation company. They've got a website, they work in the States. They've got 1200 sub domains. So nevermind domains in the one domain, the .com domain, had 1200 sub domains. Now it doesn't matter how big your team is affecting the security on every single sub domain is next to impossible. And effectively with that company, we could see half of the sub domains never had MFA on. So they're like development.dev. whatever effectively had no MFA on, could try as many passwords as you like. And that's when it's just overlooked. We now monitor all of the universities in the UK continuously. We monitor a good 20 % of the universities globally. with universities, we tend to say that's the largest issue. They've just got so many. subdomains, different departments, and all the departments have got their own issues on websites through the main site. So effectively with the larger organizations, it tends to be the attack surface discovery is so large, there's bound to be a weakness somewhere. And effectively the team can't monitor that. So we can collect that data in different sectors, effectively, and local and regions. So on that space sector data set, those are the three breakdowns of the different types of issues depending on the size. Martin Hinton (32:20) Just to touch on some numbers before I move on to the next topic. You've scanned seven and a half million organizations. You currently continuously monitor 17% of the organizations in the UK. You just threw out 20% of the universities in the world. In the cyber insurance realm, one of the things that people have talked about not having enough is data before binding policy or whatever it is. Where what are Andrew Horkan (32:44) Thank Martin Hinton (32:46) underwriters actually doing with this information? Is i how how is it informing the process as far as you you've experienced? Andrew Horkan (32:53) So we're working with, well we're now working with three insurance organizations. So one's an underwriter and two are brokers. But with the, I take the broker because we've been working with them for nearly a year now. They've been using us for two reasons. So one was to help them make an informed decision when they're going into a customer. Effectively, if they're too high risk, even if they've got, so in the UK you need cybercentrals, even if they've got the compliance documents. If their score is too low and they've got too many issues, they will go, could you please remediate these before we insure you? But the other way they use them, the flip side, are They are now able to do an assessment on a company before they go and sell them. So say if they already do, they sell insurance to them in general, they can then offer the cyber insurance and they can say, effectively, will go in your company is worth £2 million and effectively being worth £2 million, a medium breach would be worth £50k. So we suggest you insure for £50k worth of cyber insurance. Whereas with our tooling, they can then go and the likelihood of that happening is the next three months based on these findings. So they've been able to close more insurance deals. cyber insurance deals based off our data because it gives the customers real impact that makes them feel like, actually they've got those issues, we should remediate them and it's more of an urgency thing. It also makes the insurance company come across that they care and they're showing how these are the ways you can improve instead of blindly insuring people. So those are the impacts that we've had on brokers and underwriters at the moment. Martin Hinton (34:14) I mean, th you you you touch on something that seems obvious, but some might argue and certainly have to me that it's slow to be adopted. This idea that that there's an enormous need to provide protection from the form of insurance because of things that can happen in the digital realm, the cyber realm. But there's a really difficulty underwriting that because there's so little data available and also the threats are dynamic. As you've noted, continuous monitoring is not something that's generally the case for a lot of types of insurance. But it's becoming more and more popular specifically in cyber. It it seems obvious to me that insurers would want to use this information to be able to go to companies that don't have policies that are, you know, maybe effective or even policy at all, and say, hey, here's how you stand. Let us help you get to the spot where you're much more secure. As a result, your policy is going to be much easier for us to to write. And it's a, I don't know, to use the American expression, win-win. It i i is that am I thinking about Andrew Horkan (35:13) Okay. Martin Hinton (35:14) that? It it just seems like why why isn't everyone rushing to take this tool and make it part of their even if it's just their marketing and sales? I mean, do I have am I am I overlooking something in that analysis? Andrew Horkan (35:25) So effectively, we've seen a real shift this last year, specifically in the UK as well with JLI, Mike's and Spencer's. And we've been working with a guy called Martin Hughes at Source Consulting, London. Martin Hinton (35:36) I well so so have I. So we we we share we sh's a business partner of ours here at Cyber Insurance helping us expand our coverage and our our our reach in the in the UK and the EU as well. So so yes, Martin Hughes. There'll be a link to him in the show notes. So but go on, yeah, tell me about your side of Andrew Horkan (35:51) I was just, I was just going to mention so Martin's had some really interesting conversations because he's obviously been working in insurance market in London a lot more. And effectively thanks to Martin, we've had feedback from LIBB, I was going to pronounce it correctly. I think it's the London Institute of Insurance Brokers and stuff like this where they are starting to request for us to put seminars on for insurance brokers to get them to understand that there's these types of software out there. At the moment, the original writing services that would have been available in the past, they're not good enough. they're just, the data doesn't actually mean anything. Insurers can't make informed decisions from them. And effectively it's because the tooling hasn't been available or if it is available, it's a high cost. Whereas with ourselves, we make it affordable for pretty much everyone. So it makes sense that insurers can do it on a case by case basis without breaking the bank. Effectively, it's just, it's new tech, it's innovative. previously, unless you were like a premium, you've got a lot of money to spend, you wouldn't be able to afford to do these checks externally anyway. So effectively, I think that's what the breach is. So it's a change in the market need, but also the fact that there wasn't these types of toolings available without a big price market. Martin Hinton (37:07) You you touched on the Marks and Spencer's hack and you said JLR. That's Jaguar Land Rover for for those of us who don't know the acronym. These were two enormous hacks. And the Jaguar Land Rover one is the most recent. I think that if you put a dollar number to the the cost, it was two and a half billion dollars. But they had a lot of on time providers and supply chain people in that small and medium sized space who suddenly had no one to sell to because of of a factory shutdown. The Marks and Spencer hack was another one that can can caused a business interruption, to say the least, for months, particularly online sales for collect in person. But going back back further, you've got tons of hacks involving the National Health Service, the NHS in the United Kingdom. One of the things that I've come to observe from my seat here currently in New York City is that a lot of this seems to be forcing the issue of how to improve not just cybersecurity, but how we underwrite cyber insurance in the UK. The cy you've mentioned the Cyber Resilience Act. Do you think because there's so much going on there of such c such significant cost at high profile UK brands, in the case of Marks and Spencer's and Jaguar Land Rover, that there's a real energy there to fix this that would be wise for American companies or those outside of the UK to pay attention to? Andrew Horkan (38:24) Well, effectively, I think the problem is, it's took two years for this policy to come out. So effectively in the UK, by the time the policy is out, we've AI advanced and everything. You've to remember AI works both ways. It's not just protecting people. People are using it to cause destruction and hack. Effectively, policy can't keep up with the modern era. Like effectively, I think since the hacking with Marks and Spencer in 2025, you've got to see the growth of AI as... like completely changed the market, completely changed how people are doing things. We now have, we can see people using deepfakes to actually make calls of people's moms and dads and have the same voices. It is a scary world where the amount of hacking and attempts at such a high rate of increase that policy can't keep up alone. And effectively that's why my proposed solution of monitoring everything in the world and monitoring everyone and effectively going look. We are now all on a level playing field. Cyber is accessible to everyone. Are you a farmer? Are you a, a, a lobby driver and they've got a small logistics company. Instead of these massive costs where you're paying assessors or larger organizations to do assessments, you can effectively go, this is my score. These are the things I need to fix. And if you can't fix them here, the local organizations that can. And on top of that, these are the compliances that I need to adhere to. And you can do the assessment gaps. So essentially. say if you're a company that even wants to trade in the States and you're currently in the UK and you've got cyber essentials, you can upload that evidence and it'll fill in the mapping for SOC 2. Or if you want to do trade in Australia and you need to achieve eight essentials, essential eight, you can then see the mappings between those and it part fills the forms and does the readiness check for you. Effectively, it will mean that this is accessible to everyone worldwide on 11 playing fields. So my... 2028 goal is to effectively do that and monitor everyone and just make it easy for any size of business to go, we're all on 11 playing field and from there, this is how we can improve. And that's my vision in that regard and what people should be doing. I see a lot of things that are, so in the UK from a compliance standpoint, the Cybersecurity Resilience Bill means that if any, you work with national infrastructure, you work with government, you work with defense, or you're an MSP, you have to be adhering to the cyber central standpoint. Now the problem is over the last five years, they put a large amount of money into cyber central and only 5 % of the UK have it. So effectively once this bills out, they want to push it out to everyone, but there's no budget to go out and the people don't have money where effectively this goes, Hey everyone, we've assessed everyone in one go. And effectively this is how you can go and achieve the compliance documentation without the government having to spend a boatload of money. So that's why my solution is it's all great being compliance led, but let's Let's lead with evidence driven first so people are actually secure. Martin Hinton (41:18) So, I mean, i it it not to knock any specific government, but there's a tendency for government to lag the the most demand the demanding of s of problems and and be a bit slow to provide. I mean, it it sounds to me what you're saying here is that the private sector in c in this case you is is is there with a solution that's available now and compliant with the law and doesn't require anything new. I mean, am I am I overstating that t is that too simple? Andrew Horkan (41:43) I know you're exactly right. So a lot of the government led public stuff is very compliance driven. They can't legally monitor many people. And on top of that, resources are just sped to things. So in the UK we have got something called the National Cyber Resilience Centre. So it's UK government paid support and it's police organisations that effectively give SME support for free. However for each sector, for the entire West Midlands there's over like a ridiculous amount of people here, we've got two staff. So it's not a solution effectively that can do anything, they can't do that many assessments and they do some brilliant work. However, it's just an economy of scale problem. You'd have to have so many staff being paid this and the cost to do that is just too hard. So effectively, it's just the rules and then their actual know-how of what they can and can't do. Martin Hinton (42:37) You know, we we've touched on it a couple of times and I'd just like to sort of expand on it because I think that because it's a brand so many people are familiar with globally, it it's worth diving into the scale Andrew Horkan (42:48) Thank Martin Hinton (42:49) and also sprawl of the impact. We we keep saying Jan Jaguar Land Rover or JLR Hack, but because of the way they supply or receive parts supplied for the construction of their vehicles, the number of other companies impacted through their supply chain was significant. Additionally, compounding that impact was the the on point or on demand supply chain where Andrew Horkan (43:11) you. Martin Hinton (43:12) where parts don't arrive until they're needed, which means they're generally not created and ready. So there isn't a warehousing, there's no buffer, there's no there's no safety net, if you will. And we one of the companies that we exchanged notes about was on point logistics and the 400,000 pounds they lost just the first month. And as we know that Jaguar Land Rover has just announced layoffs of four thousand people that some are speculating is tied to the issues they had as a result of their hack. But this supply chain reality as it pertains to Jag Jaguar Land Rover specifically. Talk to me about how bad that was as a way to illustrate why this matters and why the solutions we've been discussing are so important to explore and consider. Andrew Horkan (43:55) I think with Jaguar Land Rover, the reason why it such a massive impact, particularly in the West Midlands, are lots of manufacturers in the UK work off something called just-in-time principles. So effectively that means they will say if you need a load of aluminium, they will fire just enough aluminium and that small business has put all of their things in that aluminium and they will get paid out when JLI gets paid out. And effectively that put a stop on all of it. So loads of moving pieces fell apart. I talk about On Point Logistics because they're both a client and their head of sales is a very close friend of mine and we've been friends for seven years and he's happy to share his story. So that's why we're talking just close to the information about it. But effectively, they had a contract through DHL to JLR. So they've got lorries and they effectively trade with them. Now that company, they do 10 million revenue a year and effectively they lost 390,000 within the first month because just in time principles, their stuff never got paid up because everything got paused. So DHL never got paid, which means Onpoint never got paid. And effectively the total loss of impact was over a million English pounds. And from there, they had to change the location where they shut down one of their locations because it's a 10th of all of their revenue. And I think effectively 30 of their drivers had to close. And recently, which I think is quite sad, it's caused the two brothers that run it to argue and come and change and make two organizations. So a family business that was around for 20 years is effectively liquidated and turned into different organizations. Thanks to what happened in Jaguar Land Rover. And it's having a real impact on the people locally and those small businesses that don't get a payout. So JLR had a 1.3 billion pound release. So leaf from the government backs like a loan kind of thing. And effectively some of the suppliers to Jaguar Land Rover like DHL got a payout, but then the suppliers to those suppliers haven't, so they receive no aid and no support so far. And we've seen that across the ecosystem. So effectively, it was a massive impact to the economy and jobs, which was just devastating. Martin Hinton (45:59) I I I I again I I've said this before, but I think, you know, we it bears repeating and and so I will. If there had been that this was a malicious act, this hack. It wasn't an accident. It wasn't some some tech failure. So if there had been a malicious act that was not digital, but physical in nature, like someone blew up a Jaguar Lagnar River factory, heaven forbid, it would have been on the news. The government reaction would have been extraordinary. Now the government reaction was significant financially, but the urgency that you would generate as a result of a fire or again a you know a a some sort of bombing, if you will, would be monumentally greater than it is even in the wake of the Jaguar Langriver Act. Do do you think that's a fair way to look at it? And I wonder Andrew Horkan (46:44) What? Martin Hinton (46:45) whether that this disconnect we have when we we we can't figure you know, most of us don't know how the ones and zeros make this thing play Netflix and and I'm I s I would struggle to understand it even if it were explained to as as though I were a fifth grader. But that inability for us to sort of imagine the impact this has. Because this hack, it's cost people jobs, it's cost money. I mean the stress. Like th this is a real problem. And it well, so what do you think? I mean I w I mean I I I I I feel very passionate Andrew Horkan (47:13) Effective. Martin Hinton (47:14) about this. So I I I I I'm losing my train of thought. But go on, Andrew, go on. Andrew Horkan (47:17) No, it's okay. effectively what I think it is is business. So we've saw it's not visible from the outside in the real using. So effectively I've seen firsthand that people try and sweep those issues under the carpet quite quickly. I'll use an example. One of our clients four years ago, their front of their website was taken down and it was replaced with a big middle finger and some swear words about the owner's wife. But within an hour, we were able to make sure it was remediated. Now, they didn't announce it to any partners because no one saw it effectively. They didn't tell they didn't disclose it. However, if someone had graffitied that on the front of their building, it would have been seen straight away. So effectively, I think it's because there's no physical visible impact straight off the bat. And it's something that people tend to try and want to resolve and sort out quietly because it is a massive financial impact. So I think the reason why the media doesn't push it too much is effectively the time that it gets out to the news is slightly longer than some of the, boom, massive impact straight away. And I think the jail I did have, Jagger Landry did have a lot of publicity, but it was probably a delayed response to a fire, for example, that would have been the same day, same hour. Martin Hinton (48:30) Well put, well well said. I mean, you know, are there any other events in the UK that that rival that, that that you know, that are that are important for people to know about? I mean, you know, we've mentioned Mark's Spencer's. I mean, w what else is in your on your radar in that sense that maybe doesn't get the news coverage that you'd think it would, or maybe it should. Andrew Horkan (48:47) Well, to be fair, we've got a LinkedIn just called Cyber Tzar Intelligence. post different hacks every day. We post three a day. We've got like a planet which gets all of the news articles globally. But in the UK, I'm sure people have seen with the airports, Manchester airport was taken down again. It was taken down two years ago, pretty much exactly the same way. And effectively, I've seen one or two news articles about it and that's it. And it's just, that's a massive. infrastructure issue like how can the airports be taken down it should be a massive concern but again not many people are as frosty as if a airport had actually set on fire or something like that and we see daily monthly about four or five months ago there was an attack where hackers released loads of data from schools and I think it's just the When I speak to people, so what, who cares? Well, they had to school, who cares? They've got this data and it's just the lack of understanding. Sometimes you really have to put yourself in the body of these people. Effectively with the school data, one of the use cases that I was explaining to a client the other day was, so what, well, hang on, what time do you pick your son up? You pick your son up at five o'clock, right? And the school's got data showing that the child is released at 4.30. Also that data of the photo of who you are. the child's name when they leave, the password that you've got to say. So for example, I have to say a word when I pick my younger sister up, she's five years old, I have to say a word. It's not this way, but I have say, Andy Hawking banana. And then it lets me pick my sister up. But they could sell that data to local paedophiles, kidnappers, anything. So you've got to really put yourself in those minds. And I think some people are just a bit too innocent and like, well, who cares? I've leaked some data and they don't understand the implications of what that data can do. Martin Hinton (50:37) No y you know, we we I have done a podcast specifically on data theft involving minors. And the other side of it is if you know, someone steals a bunch of eight year olds personal information, in the case of America, say your social security number and birth date and all that sort of thing, they could open accounts and and and financial d devices for those people and no one's checking their their credit at twelve years old. You go to become an an adult at eighteen and you go to get a credit card or a loan, say in America for For university and suddenly you realize you've got all these, you know, accounts that you opened in the last decade that weren't you. likewise, there's a lot of confidential information in these files, student files that relate to things like mental health sort of counseling. And if you're nine or ten years old and your parents get divorced and you you have some time with a school therapist or something like that, that's a wise thing to do. You shouldn't have to relive that at forty when maybe you're up for a big job or you're running for office. Andrew Horkan (51:30) Yeah. Martin Hinton (51:33) That's that's just I mean, it's immoral, it's illegal. So th there is this sort of misconception about the the how it involves children and data in generally, what can be d how it can be monetized. and the other interesting thing is, you know, as you as we we haven't touched on, but stealing of encrypted data with the idea that quantum computing is gonna make it easy to code that and thus make it monetizable later in the future. There's there's there's just because you don't understand how it could be worth a lot of money doesn't mean it's not worth a lot of money. It's the only s it's the simplest way I can think about it, you know. Andrew Horkan (52:03) Yeah, exactly. with cyber, some people just don't understand what the implications of that can be. So if you see a school on fire, you understand what the implications are. If you see a terrorist threat, you understand that. However, from a cyber, people just don't know. Who cares? It's just a password. It's just a bit of data. They don't understand the implications in the fall forever. So for example, with Marks and Spencer's, when they got attacked and they went down, there was a company called Peter Green Chill, and they just provide meatballs. So you're to think, well, How can a cyber attack affect a company that delivers meatballs? And effectively, because that company had all barcodes and none of it was physical, it's all electronic barcodes. They lost a hundred thousand pounds worth of meatballs in the first two weeks. And it's just like, that's a massive cost to a small business. And it's just these things where people just don't know what they're going to lose. Like you've got to ask yourself today, if I lost access to my payroll, what would happen? If I lost access to my data, what would happen? And people just... don't see it, they can't empathise with people who aren't in their sector. Martin Hinton (53:06) You know what I I I think I one of the things I say to people is like, Well how well how bad is it if if you get hacked? And I said, Okay, well, on Monday morning in your office, everyone who's there, they have to hold their phone up and they have to put it in a bucket and they just can't use their phone for the rest of the day. How's that gonna impact your business? Now you wanna make it really worse? They're not allowed to use the internet. So you can't turn on any of your computers. So all the stuff you've stored in cloud or wherever Andrew Horkan (53:18) Thank you. Martin Hinton (53:29) it might be, none of it's accessible to you. It's Monday morning at nine o'clock. How much money are you gonna make that day? And when you consider that these outages can often l extend into the weeks before complete restoration occurs, that that's it to your point about small businesses, an extraordinary amount of time to go without being able to generate revenue. Go ahead. Andrew Horkan (53:51) I was going say it goes one scarier than that because you can then ask yourself the question of, well, if the hospital batteries were turned off, how long would the life support last on the backup supplies? So like we've seen, I think 2022, was an American attack in America where a ransomware organization effectively turned the lights off in a hospital and said, look, unless this money is in this account, we turn everything off. And then it's all of a sudden, well, could you work to people are to die. And it's that scary. We've also seen people hacking to satellites to change GPS locations when they're data over to, well, sending supplies to Ukraine, for example. And it gets a lot scarier quite quickly. Effectively, the next wars that we'll be fighting will be driven a lot by technology and cyber is the key part of that. And especially as things have been automated with AI, all of a sudden traditional roles like accounting, that we've got bookkeepers and all that's automated. cyber is the biggest threat to everyone in the modern world. And I think people need to start thinking, it's not just what could I lose? What money am I not going to make to what is the impact to my business? What is the impact to my family? And effectively how I can mitigate that or at least reduce that risk down to a bare minimum. Fun fact, when Marks and Spencer's went down, Co-op went down. And the only reason they recovered is because they've got a legacy system that's pen and paper. So they just turned everything off and did it in paper. Martin Hinton (55:23) I mean, y you know, I mean that's what happens in hospitals, right? They go back to runners running prescriptions and orders around the the the the hospital and that sort of thing. And it's one of the reasons healthcare environments are so susceptible is that they can't turn the lights off, right? It's literally very much day to day a life and death situation, which is sort of the way we need to think about it broadly. And so that kind of brings me to sort of moving toward the close and something that you've got coming up, the universal cyber risk score. Tell me about that. What's what's what's in the works there? Andrew Horkan (55:53) So effectively, my vision, my long term plan is to effectively monitor as many people as possible. Effectively, we've worked out that there's 358 million active domains and effectively scan everyone and then make cyber accessible for everyone. So it doesn't matter how big or small your company is, you can then assess that data. And then from an insurance point of view, instead of having to pay a lot of money to do external assessments or risk assessments, you can just have access to this big part of data. Effectively, by 2028, we should be able to have monitored everyone in the world at least once a quarter. Effectively becoming a credit score, but for cyber. And that's where my vision is going in the next two years. And that's what I want to do. Effectively, by the end of this year, we will be able to do that for the whole of the UK, parts of the Baltics and Europe, and then effectively Saudi Arabia as well. So that's where we're going. Martin Hinton (56:45) So we're we're we're talking about If if an airport has air traffic control and radar, all the planes coming and going and on the taxiways are being observed and monitored by both machines and people twenty four hours a day, seven days a week, you're talking about that for the digital reality of every organization. Andrew Horkan (57:07) So effectively, the external risk posture of every organization. So even though we do look at lot of the web stuff, we can see the infrastructure, can see what infrastructure is effective, and we can go, well, these are the issues in this country's sector, so if the UK. manufacturers, 10 % of manufacturers are at risk of these issues. But you could do that on a global standpoint. Effectively from there then it makes, it makes, well, it makes remediating things a lot easier. It makes people's cyber journey a lot easier. It makes people becoming compliant a lot easier. Effectively, if a company is selling to you and they've got the compliance documents, but we're showing they've got no firewall, it makes it accessible and easy for everyone, depending on the... size of organisations useful for underwriters, banks, financial companies, stockbrokers, anyone really can then use and access that data. Martin Hinton (58:00) Well, you you you make the credit score score analogy and we've touched on the cost associated with a publicly traded company in the in the Jaguar Land Rover and Marks and Spencer's. If you're in an investment environment, the idea that Andrew Horkan (58:05) and I'm to it around and I'm turn it around and I'm turn and going turn it and and I'm going turn turn around and I'm going going to turn and Martin Hinton (58:13) a company is not only secure but also resilient in the case of an attack, which everyone says is a not if but when reality now, that becomes something that you might look at if you're building a portfolio of companies to invest in as like a mutual fund sort of thing. Andrew Horkan (58:30) No, no, no, exactly that. So I was actually talking to an investment banker this morning who wants us to scan all of their hedge funds. So they want to scan all of the companies in the hedge funds because effectively if you drop below a certain score, you've got a high chance that you're going to be in the news with a breach. And effectively that is a high risk investment issue. they're looking to effectively if a score drops below a certain amount, they might short some of the stock. And it's interesting to see how people are changing their mindset. Martin Hinton (58:57) I mean that that becomes a really interesting way. We we you know, we we touched on the idea that that being secure in the cyber sense needs to move from the being just a cost center and a a budget line item and a a a a bill you right, because it is about the resilience of the company. And this is an example of how that can be put to put to paper, right? Like if someone's not gonna invest in something, are they gonna withdraw their investment or short a stock as a result of seeing a vulnerability because of their cyber posture. That's that's something you can take to a C suite or a CFO or a board and say, hey, listen, we're we're seeing a little pressure on our stock price and one of the reasons we're hearing from, you know, investment bankers is because they've scanned us and and we we've got these issues that that that could make us vulnerable to a cyber attack. I mean, am I right about Andrew Horkan (59:44) Well, effectively, we've built a releasing an app as well. So when you it's like a Chrome extension, it will tell you the score and the vulnerabilities that are on the web page you're using. So effectively, if you're a business that's doing e-commerce and you've got really bad, you've got nothing's encrypted, you've got breaches, you might think twice about purchasing with them, for example. So essentially, you then want to fix those issues and it will change it. But the thing is, because we can monitor it for such a nudgeable cost and I want to give it out like a credit score so you validate you who you are and it tells you how to improve yourself you can then spend the money on remediating the issues and building that digital resilience so effectively instead of spending the money on finding the issues you spend the money on fixing it and coming up with policies that can make you secure and we're completely flipping the model at the moment everyone spends a lot of money on the finding and we're going to make the the money on the finding nudgeable effectively Martin Hinton (1:00:39) mean we th i that scenario you just painted is almost like you know when you see a business here in the States with the Better Business Bureau stamp and it's it's supposed to impart something that allows you to trust them as a a legitimate organization. Given every business exists now in the digital space in some way or another, that's that sounds to me like, you know, a a a new benchmark for who you want to work with. I mean, is that what you're saying? Andrew Horkan (1:01:00) But essentially, essentially, that's exactly what we're creating. So effectively, on a compliance level, we can do the mapping. So from the cybercentrals in the UK, can map it to the essentials eight in Australia. We can map it to the NCU policies in Saudi Arabia. We can map it to the SOC two to see effectively where you are compliance wise. But effectively, it will mean that there will be a score globally that everyone can adhere to and everyone is treated the same. And from that there, can go, okay, these companies are doing proper policies, they're doing the proper things versus, that company's got a load of policies on their website and they've got a stamp, but their score is lower. And effectively it holds everyone to a set standard of excellence. that's my vision is to combat it by increasing the risk posture of the world globally. So every time there's a zero day threat, we put that straight into the software and then everyone is then monitored the same and treated the same. So effectively at the moment we look for 19 million different types of vulnerabilities and issues and from there it grows daily, weekly with everything that's released every week, month. Martin Hinton (1:02:05) Got it. Well, listen, Andrew, as promised, we've been talking about an hour and we didn't get Andrew Horkan (1:02:09) you Martin Hinton (1:02:09) to everything. Is is there anything we didn't get to that you'd like to say something about? Andrew Horkan (1:02:14) But I was quite chuffed to be fair. I was having a look at the document and I we managed to cover a fair amount. There were some use cases. Martin Hinton (1:02:18) Yeah, no, we did. No, I I I think so. I mean, I I think that you know, one of the the the there's a coup the couple of really interesting things that that just to sum up from my point of view, and maybe I in case I've got this wrong, you can correct me. But you just touched on this idea that we've been looking at this problem from the same way. And the idea that you move the cost, particularly in a tough economic environment, to fixing a problem you found cheaply versus you know, spending all your time to find a problem and then having no money to fix it. It it's just seems to me like you know, a slightly counterintuitive. And then it also opens up the marketplace for all sorts of you know, business for companies with solutions. so it's just an interesting take on it all. Andrew Horkan (1:03:00) Well, effectively, we allow companies that have got the solutions to fix it to lead users for lead generation. So they can then go hire Mr. Customer, Mrs. Customer. We've got these issues. You need to fix them. And that's why you need our services payers to fix them. But then on the alternative sector, we've seen loads of companies in the UK that I use one, a customer paid 25,000 pounds to have a penetration test with KPMG and then run out of budget to fix any of the issues they found. But they were like, they were really tough. We're compliant, ISO, we've been able to prove that we've got a penetration test schedule. It doesn't mean any of the things are like, you still left the doors open. That's like me saying, I paid for an assessment. They've told me the door's open. I've not closed the door. So effectively, they could then use that budget to mediate the issues, put things to fix them, put things into place to block things, put things to make sure their policies are better and secure, put things into do the training because effectively, once the vulnerabilities and everything are blocked, the largest risk is people and... the training and their awareness as well. And that money can be spent more effectively instead of spending a lot of money with a vendor that's just going to rip you off finding issues. So that's our main position. Martin Hinton (1:04:10) Well, Andrew, I think that's a perfect way to end it unless you've got something else. Andrew Horkan (1:04:14) I don't think I'm quite chuffed with that other than I was hoping to visit New York in the next couple of months. So I should get some photos there. quite excited. Martin Hinton (1:04:19) Well you y s say the w say when we'll we'll we'll get together. Andrew Horkan, who is the CEO of Cyber Tzar out of Birmingham and and North England, the West Midlands specifically. Andrew, thank you so much for your time. we've referenced a few things today and there'll be some links in the show notes, places to find more about some of the things we've discussed and find Andrew and find Cyber Tzar if you're c curious about inquiring about their services. Andrew again, thank you so very much for for your time today. Really, really enjoyed the conversation. Everyone else, thanks for watching and listening. My name's Martin Hinton I'm the executive editor of Cyber Insurance News and Information. Thanks again for your time. Enjoy the rest of your day. Martin Hinton (1:05:00) a request that you take a few minutes and complete the Cyber Insurance News 2026 survey. There's a link in the show notes, and respondents get the results first. Thank you.