Ep 22: Tackling Tech Troubles: Inside the DFW Airport Cyber Incident and Wider Industry Challenges with Evan Morgan | PrOTect IT All
HomeEpisodes › Episode 22
Episode 22
Episode 22 Interview

Tackling Tech Troubles: Inside the DFW Airport Cyber Incident and Wider Industry Challenges with Evan Morgan

Aug 19, 2024 00:51:29 with Evan Morgan
AIRisk ManagementLeadership

Watch This Episode

In this episode of Protect It All, titled "Tackling Tech Troubles: Inside the DFW Airport Cyber Incident and Wider Industry Challenges with Evan Morgan," host Aaron Crow explore the complexities of widespread tech issues, focusing on a recent cybersecurity incident at DFW Airport that affected over 1,000 machines. Guest Evan Morgan, founder of Cyber Defense Army, discusses the challenges of resolving such large-scale incidents and the importance of standardization and AI in cybersecurity.

 

Evan shares his journey from an Air Force aircraft mechanic to a cybersecurity expert, highlighting the benefits and challenges of running a small consultancy versus a large firm. The episode also covers recent cybersecurity incidents involving CrowdStrike and Microsoft 365, emphasizing the need for preventive measures and trust in business and technology. 

 

Practical tips for everyday cybersecurity and insights into industry-wide challenges make this episode a valuable resource for listeners across all sectors.

 

Key Moments: 

00:10 Entrepreneurship brings freedom and awesome transformations.

03:54 Recent tech outages are gaining mainstream media attention.

07:52 Adapting existing tech for enhanced security measures.

10:48 Over-the-air car updates are complex and uncertain.

14:01 DFW airport machines, recovery time, and problem.

18:39 How do we improve efficiency and learning?

21:26 Customers validate goods, test, streamline, feedback.

25:10 Cyber enables business growth and protection.

28:52 Cyberattack halted gas sales, risking pipeline operations.

32:55 Challenges in the multi-faceted role, regulatory changes.

35:35 Commonalities in cybersecurity, despite differences in industry.

39:33 Robotics and AI revolutionize future human roles.

40:42 AI would bring trust, speed, and efficiency.

44:38 Defense technology, both funny and scary.

47:59 Distance tech carries risk, needs personal vigilance.

 

About the guest : 

 

Evan Morgan is the Founder of Cyber Defense Army, a cybersecurity consultancy and services firm that incorporates geopolitical risk in their cybersecurity practices.  He is a service-disabled Veteran of the United States Air Force and served in the post-9/11 campaigns, as well as remote tours to the Republic of Korea.  He holds a Master's degree in Information Systems (Computer Security Management specialization) and a Master of Business Administration (Information Systems Management specialization), both with honors from Strayer University. Post his military service, he has led cybersecurity functions for Fortune 100 organizations, was a global leader for a worldwide consultancy, and has been honored with multiple cybersecurity awards for his efforts in protecting the organization he was a part of previously.

 

Connect with Evan via LinkedIn:  https://www.linkedin.com/in/evanmorgan/

Cyber Defense Army's website:  https://www.cyberdefensearmy.com/

 

Connect With Aaron Crow:

 

Learn more about PrOTect IT All:

 

To be a guest or suggest a guest/episode, please email us at [email protected]

Chapters

00:10Entrepreneurship brings freedom and awesome transformations.
03:54Recent tech outages are gaining mainstream media attention.
07:52Adapting existing tech for enhanced security measures.
10:48Over-the-air car updates are complex and uncertain.
14:01DFW airport machines, recovery time, and problem.
18:39How do we improve efficiency and learning?
21:26Customers validate goods, test, streamline, feedback.
25:10Cyber enables business growth and protection.
28:52Cyberattack halted gas sales, risking pipeline operations.
32:55Challenges in the multi-faceted role, regulatory changes.
35:35Commonalities in cybersecurity, despite differences in industry.
39:33Robotics and AI revolutionize future human roles.
40:42AI would bring trust, speed, and efficiency.
44:38Defense technology, both funny and scary.
47:59Distance tech carries risk, needs personal vigilance.
Read the full transcript

Aaron Crow (0:1.570): Hey, welcome to the show. Evan, why don't you introduce yourself? Tell us who you are. Tell the audience, like, what is your background? All that kind of

Evan Morgan (0:7.668): Thanks, Aaron. So Evan Morgan, I founded Cyber Defense Army about a year ago. We're a cybersecurity consultancy and services firm. My background, started in the Air Force. Section aircraft mechanic wasn't in cyber back in those days, worked on hydraulics, C -130s, A -10s, F -16s and U -2s. Joined right after 9 -11, so kind of just took the first thing going versus waiting a year for cyber. And then got out and ultimately have had a few different roles in different industries, retail, financial services, apartment home and security.

Evan Morgan (0:38.213): into consulting where we first met back at EY. But yeah, my background has pretty much been technology, engineering, cyber since then, and that's what I do today.

Aaron Crow (0:48.620): That's awesome. How just really quick side note, how is it launching a cyber firm and doing something going out on your own and kind of launching this new

Evan Morgan (0:57.920): It's awesome and scary and all the different emotions. When you get into that moment of wanting to do something different, it's just like you're there. I've been inside of corporate America for almost two decades at this point. Nothing wrong with that type of role, but I just wanted to be the of my own ship, so to speak, and just go off and do my own thing and then grow from there.

Evan Morgan (1:26.494): So we're about eight folks now within Cyber Defense Army. So we're continuing to grow, have a couple of really, really good clients that have been really supportive and ultimately have had awesome transformations that we've been doing. from a day -to -day type thing that you would do inside of a corporation, I'm lucky enough to able to do that across multiple clients, multiple organizations, and have a lot more freedom to do things like this. You don't have as many barriers when you're...

Evan Morgan (1:53.746): running your own company versus being inside another company. But yeah, I mean, there's definitely the moments of, wow, like, this is all on me, right? Like, know, the things that inside of the big organizations, you you complain about the processes or lack of processes and all this other stuff. And it's like, wait, all this is on me now. Like, I don't have any of these partners to potentially work with and, you know, complain about waiting for this, that, and the other thing, like, it's on me. It's either happens with me or it doesn't happen.

Evan Morgan (2:22.888): So it ebbs and flows, take the good with the bad. I've really, really enjoyed it, to be honest.

Aaron Crow (2:28.982): Yeah, I mean, obviously we work for one of the largest firms in the world and there's a lot of pros and cons to that, right? It's just like with anything, like I love that firm. I still have a lot of friends there and I still refer them a lot and get referrals from them a lot. But there's definitely a difference between the things that we could do inside that bubble from a, SEC audit restriction and just that kind of thing. But even beyond that, just a big company versus a small company and the things that you can do.

Aaron Crow (2:57.249): from a liability perspective and just the size of, you it takes a long time to steer a large ship versus a smaller one. You can be more nimble and you can do a lot more and be intentional about the things that you do. So that's exciting. Yeah, you know, I've got a lot going on as well. And, you know, the difference between working for a small firm and a big firm, you know, doing things on my own and all those things, it's definitely a different perspective depending on which seat you're sitting in. But all those are valuable ads to our customers.

Aaron Crow (3:26.859): because they all benefit from all of those perspectives that we've seen through all those different seats that we've sat in, right?

Evan Morgan (3:34.622): Totally, lots of learning.

Aaron Crow (3:36.398): So there's so much going on in the world these days. Obviously the latest being the CrowdStrike thing and actually just saw another thing come up today on Microsoft 365 and Xbox and all that being down. Let's talk a little bit about, cause I know you've got some firsthand experience in this, with all this CrowdStrike stuff and it's amazing how we're starting to

Aaron Crow (4:1.994): more and more things in the mainstream media, right? All these things have happened for years and you and I have seen it firsthand and we've dealt with outages that have probably been as large or larger, maybe not as large or larger, but still really large, right? But they weren't public, right? They weren't as forward -facing the normal, know, normies, people that are not in technology and cybersecurity and consulting, they never heard of it, right? It didn't impact them in the same way.

Aaron Crow (4:29.518): So why is this one so much bigger and

Evan Morgan (4:33.448): Yeah, I think that as an industry, when I really think back over my career, a lot of teams have always focused on detecting and responding to things. And then as the threats continue to evolve and became more advanced, that really wasn't enough anymore, right? Things were faster, especially when we talk about leveraging AI in the more modern day. Ultimately, you need more preventative protections versus just ultimately knowing something happened and then responding after the

Evan Morgan (5:2.392): I think that that is a little bit of a dead -bledge sort. You want that, you want to be able to put in the protections immediately as fast as you possibly can. CrowdStrike definitely does have a level of testing and validation in their release management processes that I've seen firsthand as a customer multiple times over in multiple other firms. I actually held them in high regard as far as their effectiveness there. But everybody does make mistakes and accidents do happen,

Evan Morgan (5:32.512): but CrowdStrike definitely became a, became a household name after that, talking about folks that ultimately have never seen or heard of some of these things, right? I had some friends that, that texted me and they're like, Hey, what's, what's this CrowdStrike thing? I can't get on my flight. so yeah, that was, that was interesting to see all that kind of unfold. But, know, when you see how, how tools that hook into such a deep aspect of, of our systems, right? When you hook into the kernel.

Evan Morgan (6:0.218): I mean, that's the power, right? But that's the double -edged sword that comes with it. So one misstep in that scenario, we have all these systems that ultimately go down and we don't realize how interconnected, or most folks don't realize how interconnected we are these days compared to what you see in the movies. Like we truly are at the point where minor things like that can bring down full industries, full regions of the world. I broaden this a little bit. Like I think

Evan Morgan (6:27.848): how adversaries can ultimately use that against us from a nation state perspective, right? Like, even if there was no, you know, think about the SolarWinds hook in and Russia and everything there, this is kind of similar in the sense that granted there's no attribution to any actors outside of CrowdStrike, I'm not trying to imply that, I'm just simply saying that if you look at how the dominoes fell, ultimately others are watching that too. They're looking at this going, how do I leverage that? How do I leverage that from not just CrowdStrike, but also...

Evan Morgan (6:55.600): others that play in the same space where I can hook in and ultimately send out some malformed updates and take everybody out that I want to in a certain region. That's interesting times for me at least.

Aaron Crow (7:6.710): Yeah, I mean it ultimately is and as we start bringing all of this technology and we expand it and I've said this a million times, but you know, the reason we're in these places is because of the technology that we brought. We brought the commercially off the shelf stuff and brought it into OT, right? We're using it in our kiosk in our airports. We're using it to do booking. And why are we doing that? Because it's so expensive. It doesn't make sense to build these custom systems

Aaron Crow (7:33.396): isolate them the way that we used to, it's way cheaper to just take something off the shelf and convert it and make the code, the application run on top of it, which means we're bringing all of those technology concerns into these spaces, right? So why do we have a product like CrowdStrike that's dealing with the kernel? Most people may not even understand what that means, but that's like the lowest level of the operating system in everything it has to touch every other part of

Aaron Crow (8:2.240): of the applications and the user experience like as a user, you're not really getting into the kernel itself. The operating system does that in the background, but CrowdStrike has to do that because it has to be able to detect if a bad actor or malware or a virus is in there and doing things that are weird. So CrowdStrike has to be able to at that level, but by having that capability, it causes all these problems. And we've brought those needs to be able to detect malware and be able to tech anomalies.

Aaron Crow (8:32.238): in these O .T. spaces because of the technology gap and how we want more data and we want to be faster. We want to have all these new capabilities and all those things are good. I'm not I've never been a component to just, you know, go back to 1950, do a, you know, completely isolated air gapped, you know, a system that, you know, we took to the moon and just stay there like we're good. Right. Because it's not the same. Yes, it can work. You look at a nuclear power plant and a lot of the the technology in

Aaron Crow (9:1.550): at least one of the triple redundant systems is that. But even on those systems, they're putting in newer capable systems in one of those tertiary systems because they need more data. We need more efficiency. Like we want to run these things more efficiently. And by bringing these tools in, it's not just a matter of, you know, I get blinky lights and pretty things like I have behind me, but it's also about I can run these things 10, 15, 20 % more efficient, which means better costs, better recovery.

Aaron Crow (9:30.092): better for the environment. Like all the things are better, but there's also risks that we have to bring in and understand what those risks mean.

Evan Morgan (9:37.640): Yep, yep, exactly. Did you hear any impacts within the nuclear space from your ICS IoT kind of connections? I've heard more airlines like

Aaron Crow (9:46.968): have not, I mean, I've seen some, most of the folks that I've reached out to, they aren't using it in the space. And the ones that I have that are using it, did not have auto updates on. So they did not have those updates done. And that really leads to, you know, the bigger piece of what the issue was with the crowd strike, right? And to your point, nobody is beating up on crush. I know I'm not like, I think it's a great product. I think it's a great company.

Aaron Crow (10:15.106): Things happen though. Like we've seen this, you know, go back to take the company away, but just look at Microsoft, like the OS, like we get patches on windows every patch Tuesday, right? How many of those break a system? Every week it breaks a system. Like it just does, it inherently does. It's going to happen. you, it's, there's too many variables to change, which is why for me, like when Tesla started over the air updating their cars, to me, it was just like, I can't even imagine.

Aaron Crow (10:42.978): the complexity of that because I'm not sure I want auto updates on my car when I'm driving it down the road. There's just too many things that can happen, but that's a side note. But ultimately, I think the big issue with these is that update process, right? And how do we do this? And that's not a CrowdStrike problem. We have to assume that even if CrowdStrike did everything that they possibly could to test these patch releases and updates,

Aaron Crow (11:10.146): There's no way you can know if that will impact your system because you have different software installed. It's configured a different way. It's got different hardware. You know, everything about it is different. And again, this is not a new problem. We've been dealing with this problem my entire career. I've been doing desktop support and systems administration and deployments and architecture and all these things. I never deploy like when I when I ran when I was an asset owner at a power company, a power plant in Texas, right? I had a team and I always told him we don't patch unless we're sitting in front of the computer.

Aaron Crow (11:40.194): and you don't patch on Friday. Like those are my rules. It's like, you're gonna go patch at this power plant that's three hours away, get in your car and drive over there because ultimately it's gonna break and then it's down for three hours waiting for you to get there. And then I'm getting the call because you sent something remotely cause you didn't wanna get over there. So if it's really that important, then we need to be in person. And that's just the difference when OT and IT really in these spaces.

Evan Morgan (11:43.097): Friday afternoon.

Evan Morgan (12:5.384): Yeah, yeah, totally. And you mentioned Patch Tuesday and you're like, there's so many systems that go down. I mean, immediately my thought was, yeah, if Patch Tuesday doesn't get them, Exploit Wednesday does, right? Like that's the about the whole process. like, really appreciate Microsoft with the focus on trying to make sure we get vulnerabilities out. But at the same time, just the approach kind of makes it kind of predictable on, all right, well, I know what the latest ones are and I know I'm going to be able to pop a few folks with some of these along the way that aren't going to patch immediately.

Aaron Crow (12:15.904): Exactly.

Evan Morgan (12:34.296): because of the concern on resiliency. So it's always like this kind of double -edged sword where you got to weigh out the particular risk in your organization, your particular operations. And to your point, certain aspects of, we need people locally that can support these when things do go down. You need to be there when you ultimately try to push these patches versus just, hey, we're in a big corporate environment. Everything's kind of the same from a laptop perspective. Push it out. You solve a few things remotely. You're in an IoT and ICS -heavy environment. It's definitely different. Definitely different risk posture.

Aaron Crow (13:4.130): Well, and that's what we saw with this CrowdStrike issue, right? Is it wasn't that it was that hard to recover from. It's that there were so many systems and they were spread out at every airport in the country, right? How do I get a person and the, the, the most part, the recovery meant I had to be at the computer to get it out of, say, you know, boot into safe mode and go through this process. The process wasn't that complex. It wasn't that hard to recover. You know, CrowdStrike came out really quickly and said, here's how you recover. But the biggest problem was how do I do

Aaron Crow (13:31.948): Right? If you don't have a way to get into safe mode remotely, which a lot of these desktops probably don't have the capability, or at least it wasn't configured, then you have to have a person in front of that machine. And how many machines are at DFW airport that had that problem? Thousands? I mean, I don't know the answer. It's more than five and it's less than a million. It's somewhere in there.

Evan Morgan (13:50.760): Yeah, it's definitely a computer. Totally.

Aaron Crow (13:56.878): And then, you know, and it's just a domino effect. Like how long does it take to recover each one of those things? Let's say that it's 15 minutes, right? You know, but then I have to finish up, test it, make sure it's all up and running, do all that kind of stuff. So maybe it's 30 minutes and then I have to walk to the next station. Maybe it's the one right next door. So maybe I can bundle five of them together, but then I have to walk, you know, so again, it's just a time problem of, how many people do I have to throw out the

Aaron Crow (14:22.498): You know, I know a lot of a lot of customers were reaching out to consultancies like me and you saying, hey, I need bodies like I need people that I could throw with this problem because again, we know the solution. We know how to fix it, but I don't have enough people to get to it in the time frame that I want to be able to do it. I can't throw enough people at it I don't have enough people to do it. Did you experience some of that as well? Yeah.

Evan Morgan (14:43.622): A little bit. So thankfully, the clients that I'm supporting, most of them do not have CrowdStrike. And the ones that did ultimately weren't impacted. So there was a little bit of a saving grace there. But yeah, mean, when you're talking about having people to throw at the problem, to your point, it wasn't a difficult change. But it's not like every person that's available can go solve some of these problems. Even with step -by -step instructions, the average person may not even understand how to access some of these things to remove that file.

Evan Morgan (15:14.385): So it is interesting that it's been, what, two weeks now, a week and a half now at this point. I'm wondering if there's still some systems that are down, that are still in the kind of blue screen of death right now. I wouldn't be surprised if there are. Folks are probably gonna focus on the revenue generating systems first, but I'm not doubting that there's some that are still out there that they have to resolve, various

Aaron Crow (15:38.902): Yeah, and you know, so we talked a little bit about the deployment. I've seen it. I've seen some conversations through from CISOs and such as well around diversification. You know, having a one thing across and you know, and I've fought this battle for a long time and I can argue both sides. You know, let's look at a firewall, right? Should I use vendor A in these places and use vendor B over here? Because you know if vendor A has a vulnerability,

Aaron Crow (16:8.578): then that vulnerability is spread across my entire organization. Whereas if I split it and kind of, you know, hodgepodge it across, then you know, that vulnerabilities and all the place, which is true. But then you have to have a support team that supports two different types of hardware and two different products and licensing is different. And like there's, there's all these other problems that go with that as well. So I was never, I didn't really like that, especially in a larger organization, because I felt that yes, it was a, you're reducing one risk vector or one attack vector.

Aaron Crow (16:37.824): and you're gaining way more that you're less efficient in so many other ways. I didn't feel it was as beneficial, but I hear that talked about a lot and maybe it's an overcorrection because of how big the problem was and how painful it was for them. But I could see people pushing that in their architecture or their budgets in these next coming years.

Evan Morgan (17:0.476): Yeah, I think that's an interesting perspective there. I definitely still see people that still do that, where they look to have some variety within their product sets for the same capability. I've mostly been in very large organizations throughout my career and typically run the security engineering function. architecture engineering, blending those two together, my job has always been like,

Evan Morgan (17:27.304): We've got a ton of tools. We're getting very little value for these things. Help me unscrew this situation, you know, for lack of a better phrase there. And that's what I've always done is really transforming organizations, like laying out what are the capabilities we need, not just from a regulatory standpoint, but really to protect our organization. Like what do we need? And then start mapping tools to those and then going, all right, we've got one of the prior companies that I used to work at. I'll, I'll forget the name now,

Evan Morgan (17:55.560): They had seven different laughs when I got there. And when I mean different, I mean different vendors and products, seven different. Four of them weren't even really being used at all, and they were just continuing to pay the bill. And the other three were very, very light usage. We got them down to the point where we only had a few, right? And we had some ones that were focused specifically on cloud, and then one that was on -prem that really did everything, you know, was the full toolbox, so to speak. But that

Evan Morgan (18:22.622): That was really our focus was how do we get more efficient out of these tools? How do we increase the fidelity of our actual alerting? Right? Cause even in the scenario of just firewalls, you have two different firewall vendors. That's, that's pretty good to just have two. Some companies have three or four, but then you're going, how do I actually respond to these in an effective and consistent way? Right? Like that's, there's a lot of work that goes into just the data engineering of plumbing all of those, all those logs into a central SIM or at least data lakes, something along those lines where you can review them from a ops perspective.

Aaron Crow (18:47.810): Mm -hmm.

Evan Morgan (18:52.702): And then you have different telemetry that you're getting. Then you have this mashup. From this one means this versus this. Let's these actually mean the same thing. And then you start doing all this other magic, data magic on the top of that to try to figure all that out. That's when you hire data scientists and all this other things. To your point, all of that additional legwork, just so I can have two different vendors versus one and basically unify my platform. I do think that there's a lot of value in standardizing your tool sets, like a lot of value.

Evan Morgan (19:22.632): But I do see that there's some value and hey, we have some level of belt and suspender approach, so to speak, if we put into two different product sets. But I really don't think that outweighs the benefits or the losses that you get, so to speak, from having multiple for the same product.

Aaron Crow (19:39.870): With all that we see coming up in the news, like I said, with CrowdStrike and all the Microsoft things and we're constantly seeing vendors with releases and again, the fact that it's more forward facing. Do you see any change in customer conversations, etc. of their willingness, their budget lines opening, their desire to do more, their understanding? Like what are you seeing from

Aaron Crow (20:6.520): from a customer understanding as these things continue to come

Evan Morgan (20:10.868): So like, this is the big new event, right? But I think that a lot of these are kind of very similar. They kind of come up in the same way. Really the reactions from folks are very similar in my opinion, right? Which is, hey, I want to be as secure as possible, but I don't want to impact my business, right? So you're constantly doing that scale of like, all right, well, how much can we put over here versus over here to kind of balance this out? So I definitely have folks that are talking to us

Evan Morgan (20:37.084): I don't want to be in that situation where my systems are down like other folks are in my industry. How do I avoid that? So we're talking about how do we pull back some of the posture that they have to make it so that they do have some level of internal validation versus just relying on their third parties. Because that is a pretty common thing too, where folks go, hey, I have a contract with you. I'm expecting this thing. And ultimately, it's going to be perfect every

Evan Morgan (21:1.144): Well, there are accidents that do happen just like we saw with CrowdStrike. And now you have folks that are going, wait, like this shouldn't happen. You're right. But also it's on you as a customer to still validate that you want the things that you're getting and that it's a good bill of goods, right? And if it's not, don't apply that update. And that's where testing and isolation and all those other types of things happen. But there's a cost to that, right? You're have to add additional people, most likely. And then once you get to a good point where you really start to fine tune that, then you can start automating some of those things.

Evan Morgan (21:29.310): but there still needs to be some level of feedback loop with a human where you go, hey, is this past the sniff test or not? Should we let this out into all of production or not? And then you start talking about smaller environments where test and production is kind of the same thing. So then you even have one less environment for them to even try to test stuff out in the sandbox versus larger organizations that have multiple, if not up to a dozen, potential different test environments for different scenarios.

Aaron Crow (21:43.917): Right.

Evan Morgan (21:57.812): So yeah, it's definitely woken folks up, I think, as far as the impact and the importance. if you've been in this field for a long time, you know that the news cycle is pretty short. And the next thing is going to happen where folks are going go up, go from here to over here, which is totally normal human nature. But I'm hoping that we'll see a positive change as an industry where just in general, folks take resiliency and testing and make that more of their day to day. But I

Evan Morgan (22:26.810): know, time will tell on that one.

Aaron Crow (22:29.102): What are some of the more difficult conversations that you have on the cyberspace? You know, whether it be, you know, convincing a customer convincing is not the right word, but, you know, helping them justify the need or really understanding the risks to their business and how to how to remediate that instead of, know, because I know 10 years ago or so everybody was like, well, I've got cyber insurance. I don't need to, you know, have cyber security. Right. But I think we've seen cyber insurance changed in

Aaron Crow (22:59.009): that's not good enough. Like, yeah, you can have insurance. It's like insurance on your car. But, you know, if you, if you run it into a poll, your insurance is going to be like, yeah, that was your fault, buddy. You know, they're going to be hesitant to, you know, pay you for things that are outside of their scope. So they're, they're stringing down, you know, budgets are hard. Cybersecurity is a cost. That's, that's a difficult thing that we consistently fight. So what are some of those hard conversations that you're having with customers and, you

Aaron Crow (23:27.904): again, validating a justify or justifying the cost and the implementation and the time and the people and it's not just technology, it's people process and technology that it really goes

Evan Morgan (23:40.660): Yeah, great question. So like when I think about the CrowdStrike event in particular, was like 5 .4 billion lost in a single day, right? So like that's what I'm seeing in the news as far as the latest. know, in cyber insurance from everything I've seen, it's only between like 10 and 20 % of what you actually, you your impact was is what they'll pay you back for. So to your point, it really isn't enough. It's more of like, hey, this gives me a little bit of cherry on top, but where's the rest, right?

Evan Morgan (24:9.796): So some of the more difficult conversations are more around the business value, right? So everything costs, right? Whether it's talking about software, hardware, people, professional services, all the different things, there's always a cost associated with some of that. So the harder conversations are, how do get value out of cyber? Like, I invest money, how am I getting it back, right? And when we think about it in purely financial terms, I think it becomes really difficult.

Evan Morgan (24:39.208): because ultimately you're trying to calculate out risk and there's so many different variables and there's so many different ways and perspectives to measure it too. Some are great, some maybe not so great, but I think there's a different flavor for everybody. But I think it's more important to think about the enablement of what cyber can bring to your business. So when you look at modern organizations or actually more modern countries, I should say, the ones that have more of a digital infrastructure.

Evan Morgan (25:4.712): the amount of revenue that these companies are able to generate now because of even just like you and I right now, I didn't have to fly to where you are and sit and sit in your room and have this like I'm in my house. You're in your house. We're having a podcast. We're chatting. But ultimately without digital, without the ability to have technology to support this and ultimately the cybersecurity that protects this without that, sorry, I got my doorbell. So it'll be a cut that cut that cut that cut that.

Aaron Crow (25:17.938): Yep.

Evan Morgan (25:32.828): for the editors. If you're an Always Sunny fan, love that line, cut that, cut that, cut that, cut that. But yeah, so when I think about the amount of revenue that we generate, that these businesses generate by having all this digital infrastructure, that's when you start to help people understand like, hey, it's part of the cost of doing business. Like you don't want to invest in something that doesn't make you money, right? But you also want to protect the things that do make you money. And that's really what cyber is about. It's just like, you know, when you have traditional banks, brick and mortar banks.

Evan Morgan (26:2.098): you have security guards there. Now granted, like this isn't the maybe the best analogy or ultimately the best way to spend your money, but you definitely have a lot more bank robberies back in the day. If you didn't have security guards at least trying to mitigate some of the attempts to rob those banks, right? And it's very much the same thing. If you don't have basic cyber controls, basic technology hygiene and cyber hygiene, you're just leaving yourself out on the wire to easily get popped and easily get exposed, have a breach. mean, especially if you're talking about small and medium business.

Evan Morgan (26:31.294): breaches really can bring them down to the point where they are out of business. So I mean, the big headlines where it's like, X number of millions, tens of millions, hundreds of millions in fines for lack of cyber protections for the big organizations, small ones don't have that even remotely throughout the problem. They just close up shop, which is really detrimental for so many folks, their customers, their employees, the owners, everybody. So cyber is really, really, truly important. It's just whether or not folks can.

Evan Morgan (26:57.926): understand that and that's where I think you have to start talking about the risk to the business, the operational risk, the business risk, all those things versus just, hey, cyber, hey, firewalls, hey, know, IDS IPS, stuff like that, that we talk about and it really truly understand at a deeper level. The average person is like, I don't understand what that means. Help me understand it in my terms. Come meet me where I'm at, which is I'm owning a business, I'm running a business. Help me understand why do I need that, right? You talk about it a different set of terms and they

Aaron Crow (27:25.922): Well, and it's, you know, one of the things Idaho National Labs is working with this concept of cyber informed engineering, right? And really designing from the ground up and adding on, you know, from a cyber perspective, when I'm designing a process, should aim, I should, cyber should inform that engineering, right? It's a lot easier to do that design in the beginning, just like with anything, right? If I'm designing a car, it's a lot easier to.

Aaron Crow (27:50.412): design it with seats from the beginning, then build a car without seats and then come back and figure out how to put seats in it after the fact, right? It's a lot more expensive. It's a lot more difficult, right? It's the same thing with this, right? And it's cyber, you we talk about these small companies, we talk about these startups and a lot of times I see and some of the conversations I'm having is around that, right? It's around these startups get going, they're building a product, they don't have a lot of money to allocate towards cyber.

Evan Morgan (27:53.758): we're going to come

Evan Morgan (27:57.288): We have more stuff to do for life.

Aaron Crow (28:20.578): And it's always a, I'm going to kick the can down the road and I'm just going to, I'm going to, I'm going to take the risk right now and accept that risk. I think too long, too many organizations are accepting that risk. And they don't necessarily understand the risk that they're accepting. And part of that is I don't think it's malice. A lot of that is just because I don't think enough people really understand truly.

Aaron Crow (28:44.524): what can happen. And I think that goes back to this CrowdStrike issue. I think it goes back to so many issues that we've seen over the years where, you know, something happens and they didn't, you you look at Colonial Pipeline and you look at the Target attack and you look at all these different things and it's not like these companies are doing bad things. They just, or not doing anything. They were trying to do all the right things. Like Target had all of their security and their system done, but it came in from a vendor.

Aaron Crow (29:10.658): Right? And they had a back door and they just basically went around all of those cyber controls, know, colonial pipeline, like it didn't impact their OT environment, but it stopped them from being able to sell gas and sell their product in those pipelines. Cause I couldn't determine how much money, know, how much they were sending down the pipe. And it's the same thing with a lot of these things, right? It's, know, another analogy I always give is, it's like you buy a new car, you never change the oil.

Aaron Crow (29:39.406): because it's expensive to change the oil and you drive that car for 10 years and you've never changed the oil and you're every day that you drive it, right? You know, it's, but it's a risk. You know, you're tearing your engine up. Eventually it's going to bite you and it's going to be way more expensive than it would have been if you'd just changed the oil along the way like you're supposed to instead of, you know, at five years or whatever, the engine just ceases and you've got to replace an engine. That's an expensive day, right? You're throwing a car away. You're throwing an engine away.

Evan Morgan (29:44.424): That's very cool.

Aaron Crow (30:8.162): depending on the vehicle. And that's a really expensive day. And a lot of these companies, in my experience, are doing that. Like they are just avoiding it. They're putting it off and they'll say, I'll accept that risk without understanding how much it's gonna cost them on that day. And it's not just a technology perspective, it's loss of business. The product line goes, how much did Delta and American and all the airlines lose on that day because of this CrowdStrike issue?

Aaron Crow (30:34.254): Millions you are talking about 5 billion, right? It's a huge number. A smaller company. They wouldn't. They just close up shop like they couldn't pay their payroll. Those are really, really large companies, but still the impact of these is huge. We're playing with big numbers. We're playing with big impacts. It's also reason why there's a difference between pushing a patch to a Windows machine that that my my emails running on. If that goes

Aaron Crow (31:0.558): I can find a workaround, I've got my phone. Like there's other ways that I can check my email. Whereas, you they couldn't book people on airlines. you saw the graphic with all the planes in the air that day and how it went down. think they were like, there was almost like no airplanes in the air, which is like, I think it's the lowest amount of airplanes in the air since like 9 -11. It was crazy. And that just shows the level of impact.

Evan Morgan (31:16.092): nothing yeah

Aaron Crow (31:31.943): It's insane. So I mean, again, how do we continue to have these conversations? I struggle with the fear selling that a lot of vendors do where they're just going out, you know, firing brimstone like the, Baptist preachers of the, you know, nineties or whatever, you know, the sky is falling, you know, you've got to buy my thing or else it can't be that, but also it can't just be, you're fine. You know, you don't have to do anything. It can't be either of

Aaron Crow (32:0.310): Maybe the SEC ruling on actually holding the C -suite and the CISOs specifically accountable can help. But I think in my experience, most of our CISOs don't even have the authority to make decisions that they need to change anything anyway. So what do you think on those?

Evan Morgan (32:18.652): Yeah. Well, I think the SEC comment at the end there, I'm hopeful to see the positive change because I agree, like, you know, going through this with multiple large organizations, multiple different industries, it's not an industry specific problem. It is an organizational problem, right? Unfortunately, some organizations even like kind of pigeonholed to see so to be ultimately the fall guy or gal, right? And it's really nothing more than that, which is really unfortunate. And thankfully, there's not too many of those that I've seen.

Evan Morgan (32:48.633): But yeah, it's ultimately these impacts that I think folks are going to start seeing firsthand from ultimately the SEC change is ultimately going to drive broader conversation and broader change as an industry. If the CISO is going to be a C -level role, then it needs to be able to have the same responsibilities and same accountability and ultimately the same purview to be able to drive change like other C -levels. Because today it's been more of like taskmaster extraordinaire across the board.

Evan Morgan (33:17.862): a negotiator, like engineer, ops person, risk person, compliance person, a little bit of legal in there. It's just, it's a mixed bag of all different types of operations, which has made it extremely difficult for folks to be successful in that role and ultimately sets the organization up for failure on top of it. So I'm hoping that the CSO role will get elevated for a lot of organizations, at least ones that are in scope for the SEC. But I think time will tell on that one.

Evan Morgan (33:46.878): But yeah, mean, we're already starting to see some activity in the news related to some of the changes. And I've definitely heard that, you AKs and some of the other disclosures have increased, which is a good sign, right? I do think there is a level of secrecy and kind of cloak and dagger in our industry that shouldn't be there. You know, ultimately you've got to have some level of privacy with the organization. But at the same time, like we are all interconnected. And now with the CrowdStrike example, it couldn't even be more blatant in people's faces that we are very interconnected.

Evan Morgan (34:16.882): So when you talk about like, know, threat Intel from my industry versus your industry, we talk about the ISACs and things like that. I love that we have those, but I also think it's really short -sighted to go, well, hey, it's only relevant to my industry, not your industry, right? Like we're all in the same region. We're all on the same planet. We all have the same exposures. Whether or not, you know, attackers are really going after you versus me, sure. But we should still be all aware, we should still have all the same Intel, we should still have all the same protections we're sharing with each other. Because it's really, it's about protecting, you know.

Evan Morgan (34:45.958): us as a species and all of our digital infrastructure that supports us day in and day out of how we operate, right?

Aaron Crow (34:52.238): Yeah. And if you, if you look at the difference between organizations and the same, and you look at, know, a power utility versus a cell phone manufacturer or a, you know, just a bank. when you look at the tech stack, you have to get pretty low in the tech sack before the real changes happen, right? They're going to have stuff in the cloud. They're going to have windows -based machines. They're going to have printers. They're going to have it. Microsoft exchange. You're to have office 365. Like all of those things are the same.

Aaron Crow (35:20.948): at any of those. It's not until you get down to like the OT product level that really the things start changing. Are they making, you know, widgets in a warehouse? Are they are they just a financial company? And obviously there's some regulations on top of that. But but ultimately we have it's just like in general, like the difference between you and I, like I have no idea how you vote or you know what religion you are or any of that stuff. But we have way more in common than we

Aaron Crow (35:48.322): right? Because we're both humans. We both live in America. Like we both have jobs. We're both in cybersecurity. There's a lot of commonalities that we have, you know, more than we don't. And it's really easy to focus on, you know, just like with politics and religion and race and all the things, it's easy to focus on the things that we have different and think that's the biggest thing in the world. And I'm not saying those aren't important, but we all have a lot more in common in this space.

Aaron Crow (36:17.015): from the top down, you got to get pretty low in that tech stack before things really start changing between a power company and a bank, right? We still have to make money. We still have officers. We still have employees. Like what's our biggest risk to environment? It's people, right? People are always the thing is going to bring somebody in. I have people at a power plant. I have people at a bank, right? I'm still dealing with people.

Evan Morgan (36:38.012): Yep, totally. Yeah, and you, you know, talking about people like you said something earlier, I I forgot to touch on which was like the approach to kind of selling and fear monitoring and stuff like that. Like, you know, being in this industry for like two decades now at this point, and being an executive, you know, over engineering for a long period of that time, constantly getting sold, like my phone was ringing left and right constantly, email just deluge all day long with with, you you got to buy this, you to buy

Evan Morgan (37:6.972): I mean, there were some that were extremely aggressive, the one where we had plans and then didn't loop them in and they're like, we're going to call your ethics hotline. It's like, have at it. Like we're allowed to buy whatever we want. Like there's some crazy folks out in the world, but ultimately that fear mongering approach, like I just, I can't, I can't move somebody away from me faster when I get sold, when I try to get sold that way. Like I, I just don't like that. I don't do that myself. Right? Like there's gotta be to your point, like a healthy level of understanding of the risk. And ultimately, what does this

Evan Morgan (37:36.808): So there's some level of awareness raising for folks, but you gotta do it in a way where you're not trying to be like, you gotta buy my product or ultimately you're gonna get popped, right? Cause that's just BS. And there are companies that do that. when something happens, you'll see like the stock emails that come out from all the companies in that space that are like, boom, boom, this happened, you gotta buy my product. We'll save the world for you. It's like, yeah, if you've been through some of these implementations, you know that that's not true.

Evan Morgan (38:3.432): Be more realistic, be more transparent, be more genuine with your customers and your prospects. And I think you'll get a better return than trying to do the short -term fear -mongering approach of, buy it, and then ultimately next renewal, you're out. All like that's the end result for that type of salesperson.

Aaron Crow (38:20.728): So if, and I'm gonna swing this on you, I didn't prep you for this. If you could solve one problem in cybersecurity, like you were God for a day or you had three wishes or one, well, let's just go with one, and you could solve one cybersecurity issue that you see, what's the one that you think would be the most impactful that you'd

Evan Morgan (38:31.870): Thank

Evan Morgan (38:41.869): That's a great question.

Evan Morgan (38:48.596): I think actually kind of ties into what we've been talking about with CrowdStrike there with the resiliency aspect, right? Like the ability to actually have like some level of guaranteed high fidelity on all of our kind of changes, our implementations, our rollouts, all that type of stuff. I think that I've seen a lot of, you know, things over the years where, you know, you do one step forward, three steps back. If ultimately things get rolled out in a, you know, a too aggressive state and ultimately you cause impact to the business.

Evan Morgan (39:18.588): And ultimately, not only go back, but you ultimately go further back than you were before you even started. So I think as we, you know, this has become a buzzword, it's also like, put this in your mouth almost, but like AI, right? So we've had AI in our space for, in a lot of spaces, for over a decade, two decades to a degree, when you start talking about scripting and some other things. Generative AI is what made it really interesting for folks.

Evan Morgan (39:43.442): Sorry, they really are ringing my doorbell like crazy today. Cut that, cut that, cut that. So, know, gener of AI is what people really talk about and, and, and, you know, they're like, the buzzword of the day. But I see a lot of things with robotics these days that are just like amazing, you know, not to, you know, give props to anybody in particular, but you know, Boston dynamics is, an amazing company. I see a lot of stuff come out of there. A couple others, competitors are similar to them. When you start looking at their ability to ingest so much information,

Evan Morgan (40:11.398): and leverage AI in that space to perform so many actions that are literally changing by the millisecond, that's pretty astounding. Like, when you start thinking about where we're going, when you start talking about, know, androids and other robotics in the future and how they can help us as a human race, basically distance ourselves from having to be in the grind every day and actually kind of more orchestrate all of those actions, that's, think, really, really interesting. But really, how long -winded way to go back to

Evan Morgan (40:41.236): leveraging that same type of capability and our ability to protect our organizations with our controls, with being able to have extremely high fidelity with all of our releases, as far as their ability to be sound versus not so sound is really kind of my point. I think that would be astounding. I think that we would have so much more trust in being able to go fast and we wouldn't have 30 meetings to try to have a conversation about

Evan Morgan (41:8.444): Are we going to maybe do this thing possibly at some point this year? It would just be, let's go. It makes sense. We understand the why, the how and the what really are we're totally on board with because we know guaranteed it's going to work. And by say guaranteed, I mean, you have so many different aspects of AI hooked in from the standpoint of truly ensuring soundness of those releases, thoroughly testing them in so many different perspectives.

Evan Morgan (41:35.152): all of those different permutations of the stack you were talking about earlier. It could potentially test against all of those and validate that they all work the way that they should. And you wouldn't have kind of that blue screen of death scenario. There's a lot that goes into making that happen, but if I had one wish, I think that would be amazing, right? Because you could just have so much guaranteed return on your investment when it comes to your time, your effort, and really your assets that you're investing

Aaron Crow (42:0.194): Yeah, absolutely. And it's funny to me as I say this a lot now and you said something there and we really move at the speed of trust, right? What is the biggest problem that we overcome? not, you know, it's getting a product, it's understanding that we need it, it's understanding that it's gonna work, it's building, connects trust between me and you, me and the customer, me and the asset owner.

Aaron Crow (42:26.904): Like as soon as we build that trust, then it's easier for us to move on to the next thing. Like I trust you, now can I trust the technology? Okay, now I trust the technology, now let's do that. Like we have to move down those things that I trust that this thing is accurate, it's true, it's gonna work, it's gonna break things. Like, you know, your cost is accurate, you're not lying to me, like all those types of things in all the different scenarios, whatever that trust environment is. But as soon as we check that trust box, then we can move on to the next one. But until we

Aaron Crow (42:55.098): until we check that chest box, you can say anything in the world and I don't take it as, as fact. And you can tell me your product is great. You know, we've all seen demos of product and then we've gotten it in hand and been like, what did you show me? Cause this is not that.

Evan Morgan (43:7.656): Lipstick on a pig.

Aaron Crow (43:14.019): Whatever your demo world is like, that's like a video game and this is not that. I don't know what happened. We've all been there. Like it's the test drive of the car. Like it looks, you you look at a car on carzilla or whatever online and then you go look at the car in person. You're like, where did all these scratches and dents and you know, the dirt, this ha what did you do? Like, or, the, the filters.

Aaron Crow (43:41.794): The filters people put on Instagram and stuff. It's just like, just take a picture. I'm old, I've got wrinkles. It is what it is.

Evan Morgan (43:52.110): I still need to get one for this all this gray, right? But.

Aaron Crow (43:54.248): Exactly. I've got great coming in too. Yeah, it just, it just is what it is.

Evan Morgan (43:58.362): Yup, Ben, it's serious.

Aaron Crow (44:0.622): Well, so that leads me into, it's our wrap up question, but on that same line, like, you know, the next five to 10 years, what's one thing that you see coming up over the rise and that maybe you're excited about, and maybe it kind of goes along with some of the things you've already said, but maybe what's one thing that also is concerning that we definitely need to make or adjust or see that can cause an impact if we don't do

Evan Morgan (44:27.336): Great question. Yeah, so I would piggyback off of kind of where I was going with kind of leveraging AI and more the robotic side, less of kind of the cyber side. Like I just see so much potential in that space with some of the more leading firms. I see the ability to really truly change kind of how we operate as a species on the planet, right? When you're talking about our systems, but also like all the things that support us, our support infrastructure, our scaffolding around how we operate. But also

Evan Morgan (44:56.996): Double -edged sword again, sorry to use that term one more time. But man, like some of the things that you see from a more defense industry perspective with some of that, right? Even like some of the robotic dogs, like it's just kind of, it's funny, but it's also kind of scary. You know, you see some of the ones that are coming out from other nations and they just hop a, know, pop a M16 right on the back of it and they're just running around. And ultimately it's like, that's our usage of some of this amazing technology we just built really to strap a M16 to the back.

Evan Morgan (45:27.324): Now I've read that there's a lot of really cool like law enforcement kind of leveraging or use cases for that and things like that, know, sweeping buildings and whatnot. But there's a lot of change coming to our world, I think, in the next few years. Definitely the next, you know, five, 10, 15 years. I think that we're going to see it just at least in the more developed parts of the world. We're going to see a drastic change where, you know, robotics become more of a day to day.

Evan Morgan (45:55.711): It's not going to be your Roombas anymore. It's going to be, you know, live -in house assistance types of stuff, which really starts to transform into, hey, this is like movies that we kind of live in, which is crazy, right? So, I mean, it's exciting. It's amazing. Also, it's kind of scary to some degree, right? Because, you know, robots don't have feelings. They process logic, and that's it. And, you know, the person that's behind the scenes developing that brain for them has, you know, different intentions or

Aaron Crow (45:57.826): Right.

Evan Morgan (46:24.469): misunderstands the situation by what it's processing with its sensors, you can put somebody in a really bad spot in a lot of ways. yeah, it's awesome. It's amazing. It's also kind of That is cyber, think, as well, though.

Aaron Crow (46:39.598): It is, I agree 100 % and it's so exciting to be, I don't know how old you are, but I grew up, I was born in the seventies and went, I started out before the internet and I got my first computer and then I remember the start of AOL and online and dial up and all the things. And now I have gigabit speed to my house and we're streaming this and my kids are playing video games and my wife's streaming YouTube and like all the things are happening all at the same time and we're not even.

Aaron Crow (47:7.768): you know, having an issue or buffering on this thing. I remember it'd take hours and maybe even days to download a picture from early, early internet. Yeah, I mean, you'd hit download and go to eat and then come back and see if it, and it may be done when you get back, it may not be, right? Depending on the size of the file. But you know, so much has changed in such a small amount of time when you really think about it. And it's just happening faster. Like that hockey stick of...

Evan Morgan (47:14.376): I think, line by

Aaron Crow (47:34.036): of the amount of things that are happening and how quickly it's happening is just is I mean our cell phones like again, I remember the first iPhone I had and I remember now like we can FaceTime like we can have video calls with people as we're walking around and we just take it for granted like everybody has this. I sent my friend a video message earlier today. I just did a video real quick and send it to him like it's it's before it had to call or send a text message. Maybe I could send an audio but I can send a full 4K.

Aaron Crow (48:3.266): video across the internet across the air and he gets it on his little computer in his phone in his hand and he can play it like it's in. It's amazing. My my family lives in Dallas. I live in Austin. They can FaceTime with my kids like it's it's a big difference between distance and all these technologies are great, but we have to be careful about him because there's also people that take advantage. You know my I've had family members that have been, you know.

Aaron Crow (48:29.144): had phishing attacks and have given money away because they thought it was an investment or this or that, and they've gotten access to bank accounts. So all these things come with risks, but that doesn't mean we throw the baby out with the bathwater. It just means we have to start being intelligent about it. And it's not just enough. It comes naturally to you and I and folks like us, because this is what we do for a living. But the normal people, everyday people have to be thinking about cybersecurity more, again, not as much as we do, but they can't

Aaron Crow (48:55.874): They can't just assume that somebody else is gonna take care of it for them, right? You've got to take personal responsibility. You gotta have different passwords. You gotta do some of those basic hygiene type things so that you're not impacted in your personal life because of all the things that's coming up. Because it's cool, but it can also impact you.

Evan Morgan (49:11.924): Totally agree. Couldn't agree more, actually.

Aaron Crow (49:13.186): Yeah. So so called action who why don't you tell people how to get a hold of you like a little bit about what you guys do and the services you guys provided all that kind of stuff and anything you want people to

Evan Morgan (49:25.726): Sure, thanks Aaron. Yeah, so Cyber Defense Army, we are a cybersecurity consultancy. My background is very much engineering architecture, so a lot of the customers I help are helping them look at their entire stack end to end, figure out what worked, what doesn't work, and then kind of help them work through that transformation. I also have a VCSO service that I have with a few different clients, where I ultimately help them from a lot of different kind of compliance framework perspective, right? So not just things like SCC, but ultimately FINRA.

Evan Morgan (49:56.944): Ultimately, GDPR, ISO, SOC 2, all those types of things. We have an AI enabled platform that ultimately takes it. So you select the compliance frameworks you want to align to, and then we run through all the assessments, technical and kind of risk -based. And then it basically generates all of the tailored policies for that organization based off their industry, as well as their remediation plan. They'll comply with all of those to get their certifications. So that's

Evan Morgan (50:24.222): kind of our newest piece where I've tied up a product in with a service versus just being a peer services organization. But yeah, so my organization, we're about eight of us, about to go to nine, still growing. So things are good. As far as how you wanna get ahold of me, feel free to check out my website, cyberdefensearmy .com. We're going through a little bit of a revamp, so you'll probably see a little bit of change over the next few days, next few weeks.

Evan Morgan (50:49.534): but all the things are still the same. It's just more of a better window dressing versus what I wrote originally. And then also I'm pretty active on LinkedIn. can check me out on LinkedIn. Evan Morgan, you'll find me on there.

Aaron Crow (51:3.616): Awesome. And I'll put all those in the show notes here. So people, can definitely click on that, find his LinkedIn, find the website, all that kind of stuff. So Evan, thank you so much for your time today, man. I appreciate it. It's good catching up. I'm sure we'll cross paths many times again. but, definitely thanks for your time and, until next time,

Evan Morgan (51:20.146): Awesome, you, see you man.

Transcript lightly edited for readability.

Want your brand in front of OT, IT, AI, and cloud security decision-makers?
PrOTect IT All listeners are the practitioners and leaders making security buying decisions across critical infrastructure.
See Sponsorship Packages →

Never Miss an Episode

Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.