Trevor is a solutions engineer for Telarus and has a master of science degree in cybersecurity. In this episode we discuss cybersecurity with a vendor-neutral expert that knows how to simplify some of the complicated aspects of cybersecurity. We focus on small business and how they can affordably implement a cybersecurity plan for their business.
Trevor is a vendor-neutral solutions engineer for Telarus. Trevor has a master of science degree in cybersecurity.
Welcome to another episode of the Technology Matchmaker. I’m very fortunate to have Trevor Burnside with me today to discuss cybersecurity. Trevor is a Solutions Engineer for TLRS and has a Master of Science degree in Cybersecurity. And welcome to the podcast, Trevor.
Speaker 2 (00:25)
Appreciate it, thanks for having me.
Speaker 1 (00:28)
I’m glad to have you. Hey, can we just start off and just give us a brief summary of your professional background?
Speaker 2 (00:34)
Yeah, it’s kind of eclectic, I’d say. I started out, actually, I got my undergrad in criminal justice. So I thought I was going to be, you know, fighting bad guys on the street and went into the military. I actually did, was in military intelligence. And so, you know, I thought I was going to go down the FBI, you know, kind of route that way. Oh, yeah. Appreciate it. Yeah.
Speaker 1 (00:58)
Thank you ⁓
Speaker 2 (01:03)
But, ⁓ actually found, ⁓ technology kind of roundabout way. My, my neighbor, ⁓ was working at Telarus actually. And, and, I was talking to him about what I was kind of doing. He said, well, he should come check out, what I do. And told me about trusted advisors and partners and, know, that whole, whole channel that I I didn’t know existed and, ⁓ ended up, you know, really finding a home here. And I’ve been doing this for over a decade now. So.
Speaker 1 (01:30)
Great, well there’s a common thread there chasing the bad guys.
Speaker 2 (01:34)
Yeah. Yeah. I mean, with the cyber security actually ended up being, you know, it’s not one of those things I went to, you know, growing up. was like, I’m going to, you know, go after cyber. That wasn’t a thing, you know, growing up, you didn’t really think about that kind of stuff. So, but yeah, military, ⁓ criminal justice, and then, you know, just background in technology, ⁓ cybersecurity was just really good nexus of all those interests. And, so got a graduate degree in it and have been kind of consulting in that now for, for a while.
Speaker 1 (02:01)
And actually it’s not going after the bad guys in your situation. It’s keeping them keeping them at bay,
Speaker 2 (02:08)
Yeah, it’s typically a lot more of of education on how to protect yourself. Risk management, understanding threats to organizations and what we do to mitigate those threats and respond when when bad guys do get in.
Speaker 1 (02:23)
Can you explain real quick? I refer to you guys as subject matter experts, solution engineers for Telarus. And as I explained the EOTG model, which is vendor neutral, ⁓ and we don’t really have a horse in the race necessarily. We don’t care what vendors our ⁓ clients pick as long as it’s the best solution for them. And Telarus is an extension of that. Telarus is a big partner of ours and has relationships with most all IT companies.
Describe your role as an independent, non-biased subject matter expert that can help our clients, help them make decisions without necessarily one path or another.
Speaker 2 (03:04)
Yeah, you bring up some good points. So from what I do as a solution engineer is ⁓ I take a look at what clients have from a technology stack, the business outcomes they’re looking to achieve through different transformation or otherwise. And then we can look and see, across the market, who are the best fits based on what they’re looking to do. And that’s, think really the magic of working with trusted advisors in technology and procurement is we don’t have any
Any, like you said, any real horse in the race, right? We want to do what’s right. What makes the most sense? What’s going to give that business outcome they’re actually looking for? don’t, you know, that it’s kind of no overuse frame, you know, with like a square peg and around whole, right? ⁓ We don’t have to do any of that. we can take a look at a specific client, their specific needs and address those. And really in cybersecurity, ⁓ the needs are, there’s not a one-stop shop. There’s not a silver bullet.
⁓ Everyone’s risk is different. Everyone’s assets that they own have different valuations. You shouldn’t be spending the same amount of money for different assets that are worth different things. So we can really take that prescriptive approach and ⁓ help clients with those decisions on procurement.
Speaker 1 (04:20)
Yeah, that’s my favorite part of the business model is that we can truly sit on the side of the desk of the clients ⁓ and we don’t have one product that we have to sell, have a quota to meet ⁓ and can be truly unbiased and be an advocate for the client. ⁓ What would you say are some of the most challenging and also the most rewarding aspects of your position there at Tilleris?
Speaker 2 (04:46)
⁓ I’d say some of the most challenging ⁓ are when we are working with clients that have a definite need. They go through, you know, talk about the threats or some of the risks that they have that they’re not addressing. And we find great solutions for them that are going to be a perfect fit. And sometimes, you know, we’re maybe not working with ⁓ the decision maker from a budget perspective and they say, well, we’ve got other things that we need to work on. And the people we are working with.
Like I see the risk, I see the need for it, but we just can’t get that budget for them. Oftentimes in those situations, I’ll say, well, can we, can we set up a call? Can we discuss with the decision maker, see what we can do in some cases because we’re not single threaded into any technology, right? We can say, let’s find budgets somewhere else. Let’s, let’s economize. Let’s maybe look at your software spend, look at your spend, consolidate, and we can find that budget. ⁓ It’s a harder conversation. That’s really kind of.
where the difficulty is, but in the end, really becomes a relationship basis, right? A relationship of, do we have the relationship with the client and can we escalate to their leadership and the decision makers above them ⁓ when we see a need and when we know we can fulfill it?
Speaker 1 (06:02)
So I think some people out there, you we understand our model, but a lot of people, don’t think necessarily understand the model. And they think maybe we favor certain vendors over others or the certain vendors pay us more than others. And I did a whole episode on the top 10 objections that I hear. And, you know, from our standpoint, the commissions, I mean, everybody has to make a living and these companies have to pay somebody to market and ⁓ advocate for their services.
And they love us because we don’t, know, as a, as a partner agent, we don’t have a salary. They don’t pay us for sick days, vacation days. They don’t pay us if there’s no sales for three, for three months. and so as a subject matter expert with Telarus, do you have vendors that you favor or you come in with an open mind? ⁓ and you really have no vested interest in one particular vendor or another.
Speaker 2 (07:00)
Yeah, it’s a great question. It is something that comes up often, Of, of, um, am I, it really agnostic? We know when they’re the reality is, you know, commissioned changes, uh, there’s different levels with different partners or suppliers, uh, where I sit on our team from a technical advisory perspective, I am only concerned on the technical aspects of solutions. And is it a fit or is it not a technical fit? Um,
We essentially firewall the rest of the politics away from my decision making so that ⁓ when we get in front of a client, ⁓ my recommendations and advice are purely on technology and business outcomes. ⁓ So we make that ⁓ an effort specifically on the engineering side to just be technology focused. I’m sure there’s other people involved when it comes to the other stuff, but we stay away from that just to be an unbiased opinion.
Speaker 1 (07:57)
Great. ⁓ In terms of staying ahead of the curve, because the cybersecurity is changing literally probably every day, how do you stay up to date with the ever evolving cybersecurity landscape out there?
Speaker 2 (08:10)
⁓ It’s a full-time job in itself. It’s just keeping up with everything, especially with the advent of AI. And certainly AI is, agentic AI is prevalent in cybersecurity and cybersecurity solutions. Everyone’s clamoring to add it to their software stacks and solutions. ⁓ Our team, we do quite a bit to stay on top of it. This year, I and some others on our team attended ⁓ RSA Conference, Security Conference in San Francisco.
to talk to vendors face to face on the latest and greatest of what they’re doing, how they’re doing it, ⁓ are they fit for our channel, our model, our clients. ⁓ So we are as invested into the market as we can and as close to the ground as we can be. That being said, things are changing pretty quickly. So we’re always looking to add vendors to our portfolio that maybe there’s gaps being created within the market of capabilities that are being added that we have to.
We have to bring in so that when clients are asking for those things, we have solutions for them.
Speaker 1 (09:12)
That’s great. And then, you the clients don’t have time to keep up with all that and you live and breathe that every day. ⁓ What would you say the most significant cybersecurity threats you’re seeing currently?
Speaker 2 (09:24)
Uh, it depends on, um, the threat landscape in the, in the industry that you’re in, right? If you’re critical infrastructure, that’s a hot topic of, um, you know, nation state actors going after, you know, critical infrastructure for the average every day, you know, small to medium, mid market business, uh, email threat vector is, is, is huge, right? Uh, threats coming through email every single day, the amount of phishing attempts that you get, uh, it’s insane.
from a really with the industry.
Speaker 1 (09:56)
Isn’t
that the weakest link that the employee ⁓ clicking on the wrong link type thing?
Speaker 2 (10:03)
Yep. Yeah. Just, you know, ⁓ the problem with those phishing emails, they used to be able to, you know, see them a mile away and just know, you know, things are spelled wrong. It’s coming from a weird domain with the advent of AI in a lot of these things. You actually, there’s AI engines built to create phishing emails. Now where that to make them look very, very real as far as duplicating actual existing emails from, you know, Home Depot ads and things like that, taking those, duplicating them and sending them out. ⁓
⁓ So it’s getting very, very hard. That’s kind of the conversation in the industry now is AI tools ⁓ meant to create malware or build social engineering attempts like phishing that are just very, very hard to detect, ⁓ you know, ⁓ malicious from benign, ⁓ you know, attempts.
Speaker 1 (10:52)
Yeah and you can create as big offense as you want but if somebody lets somebody in the gate scramble.
Speaker 2 (10:58)
Yeah, it’s one click. Yep.
So we do insecurity. That’s a layered approach, right? You have to plan on someone clicking on something because you know someone who will. It’s about how do I position myself for when that event happens that we can quarantine block and resolve and remediate those issues and then and train those people so they don’t click again, right?
Speaker 1 (11:21)
I
think the training is an important part and I don’t think that’s done that that often. I just read earlier, I think it was this morning that Microsoft crushes Luma, which is cyber crimes favorite malware. Do you know anything about that?
Speaker 2 (11:37)
⁓ There’s been a lot of things recently as far as the Coinbase attack, ⁓ the Ethereum being the largest crypto hack recently, just in the last month or two. It’s only escalating and I think we’re going to continue seeing things every single day of just groundbreaking ⁓ attacks and breaches.
Speaker 1 (12:00)
Yeah, my next question was going to be about the human error role that plays. We kind of talked about that, but let’s go into that a little deeper. What are some of the things that a small business can do or a big business can do large business to keep the human error at a minimum?
Speaker 2 (12:20)
You got to initially have to look at where that human element meets ⁓ the data. You know, how do they access it? What do they have access to and how are they manipulating the data? ⁓ You look at email, for example, right? If I have access to company data and an email address and I’m able to send out company data through an email as an exfiltration point, that’s something to consider, right? If I have, if I, wherever I can access data and make a mistake is somewhere that we want to take a look at and then.
⁓ in security, look at, you know, people processing technology and in that order, ⁓ so you look at who the people are, do the training, coach them on the ways to do it process so that you’re building in good process of that, and policy. So they can’t be doing things that they shouldn’t. And then the technology layer to block those things that where you can and mitigate, ⁓ you know, exfiltration or otherwise.
Speaker 1 (13:17)
And for those that don’t know, we’re talking about social engineering, right? This is that’s what they refer to to this as is you’re reaching out to the individuals to try and let them in.
Speaker 2 (13:28)
Yes, the social engineering attempts of, sometimes you get a call, right? ⁓ Kind of the quintessential one is I get a call on my phone, they say, I’m IT support, I need access to your computer to fix something. this link and give me access to an RDP session and now they have access to the environment, right? You think you’re talking to IT support and ⁓ it could really just be anybody. ⁓ That’s still very common of, hey, this is Microsoft, we need to access your computer.
⁓ That’s social engineering attempts and a lot of the training is telling people, hey, ⁓ what questions are we asking back to make sure they are who they are? Can they call us in a different way, especially from an email? You should be verifying any of type of emails with a phone call to the person that they’re ⁓ pretending to be to make sure it’s coming from them.
Speaker 1 (14:19)
Yeah, and I think you have to have your antenna up a lot because I know since I’m in the business and around it, I’ll catch stuff before my friends do. They’ll send something to me and to me it looks so obvious, but it’s just, when something’s out of context, know, somebody’s probably not going to notice it. But I think because we kind of live it, we’re always kind of in context, if you will. But most people are not. So that’s a weak spot.
Are there any certain demographics or industries that are more vulnerable than others ⁓ to these specific types of attacks?
Speaker 2 (14:56)
Yeah, well, there’s the answer is two-phased, I think. Part of it, and I’ll answer the first way, is there’s a lot of organizations we talk to and clients that say, well, I’m not a healthcare, I’m not a big company, I’m not XYZ, so I’m not going to be targeted. Right. And in some cases, there may be some truth to that, but most of these breaches aren’t from being targeted. They are acts of opportunity where…
Speaker 1 (15:24)
So they’ll do a gut, they’ll do a shotgun approach and whoever bites nibble.
Speaker 2 (15:28)
Correct.
Correct. It’s targeted. It’s you made a mistake and now I’m going to take advantage of your opportunity. You’re a corporation and you have some type of value that I can extort and ⁓ get something for. So just being a company working on the internet and having internet access means that you are vulnerable to certain threats. ⁓ Now, that being said, certainly ⁓ regulated industries, healthcare, ⁓
you know, that have patient data, lots of, you know, social security numbers, very valuable data about people that can then be further extorted and exploited ⁓ in other ways is ⁓ certainly a target. They can sell that data on the dark web, make money off of it, get username passwords and or, you know, do ⁓ identity theft, you know, with enough data that they can get from those types of things. So healthcare.
Speaker 1 (16:24)
Truly
anybody. ⁓
Speaker 2 (16:26)
Really? Yeah. I mean, if you’ve got the data that is valuable, that could be used for other ways in nefarious acts, certainly.
Speaker 1 (16:35)
It may not be valuable to the greater world, but it’s valuable to that company. And if they lose it, ⁓ that’s hugely valuable to them, small or big.
Speaker 2 (16:45)
Yeah, I mean, even just from like reputation and you think about company reputation, if you have a certain breach, you’re a certain size, you have to tell your customers, you have data that is now exposed, go change all your passwords, right? Or are you going to do business with that customer or that company again? Maybe not, right? You can’t really put much of the value to a customer’s reputation is invaluable.
Speaker 1 (17:12)
Let’s talk about small businesses, because I think a lot of the attention gets put on the big businesses that get hacked and ⁓ ransomware, et cetera. What are some of the key cybersecurity considerations for a small business with limited resources ⁓ in order to protect their data and their employees, et cetera?
Speaker 2 (17:32)
It’s a good question. Oftentimes when we talk to SMB clients or even mid market, there’s the conception that cybersecurity is too expensive or that all the tooling is very expensive and the budget, you have to have a high budget to be able to afford it. And the reality is it’s just not the case. ⁓ What it comes down to is those basics of risk management that I kind of mentioned earlier, as far as what are the most critical and most valuable assets? How do we access those assets?
and what are we doing to protect them? And if you focus on those things, a lot of times it’s a email security database, making sure that those things are tightened up, that data is encrypted. And these things can be actually very economical and they can, and what we would say, it’s not just buying an insurance policy. A lot of these things can add value back to the organization. So it’s not wasted money, just trying to protect yourself. ⁓
It improves data integrity, data availability, access to the data in a way.
Speaker 1 (18:35)
than an overhead cost, could be actually an investment.
Speaker 2 (18:38)
Right, right. It provides value back to the organization. And that’s the way that cybersecurity should be built rather than feel like you have to spend money to, know, in ways you don’t want to, it can be a value add.
Speaker 1 (18:51)
How does the small business decide whether they can kind of do this themselves with some malware protection and some things that they can install on, if they have seven or eight employees, 10 employees, and they install some cybersecurity software on their laptops, et cetera. At what point do you think you need to bring professionals in or do you think it needs to be from day one?
Speaker 2 (19:15)
I think everyone should be using a consultant. If you don’t have on staff support that have experience in cybersecurity, you should be using a consultant. And the nice thing about OTG, we can provide that consulting at no cost to a client. Let’s do ⁓ a fairly high overview of their security posture, take a look at risk management and do some of these exercises at no cost and that they can bring someone in.
that can help them make those decisions and say, based on what you’re doing, here are some options that are gonna be within your budget and sized according to your organization. And they don’t have to pay for that consulting. It’s really a value to, there’s no reason not to.
Speaker 1 (19:59)
Yeah, a lot of times it’s just a matter of getting a conversation with people to understand the model because again, they think either you’re gonna bring in, know, favored vendors or that they have to pay more. I think that’s probably the number one question in people’s minds is, well, if I use you and I’m not paying you, ⁓ you got to pay your mortgage and put your kids through college. The vendors, you I must be paying more for the service and that’s when I tell them.
Well, they’ve got to pay somebody direct sales reps or are us. Um, we’re a lot less expensive and et cetera, et cetera. I’ve gone through that.
Speaker 2 (20:33)
The margin exists somewhere built in, right?
Speaker 1 (20:37)
Right.
I use the analogy if they’ve ever bought a car from a auto broker or health insurance from a broker that represents 40, 50 different lines of health insurance or, you you get a car from an auto broker. You tell them what kind of car you want. Maybe they help you decide. They go out there out on their network and find the automobile. They don’t call the salesperson on the floor. They call the fleet manager because they do business all the time and they both know what a good price is and what a good price is not.
And they usually cut to the chase and get a fair price for their client. ⁓ And that’s a lot ⁓ how our business model works. And that’s favorite part of the model. ⁓ In terms of, again, with these small businesses, just kind of discuss antivirus software, firewalls, and any other security things just as a first line of defense or somewhere to start, even if they’re using a consultant.
What should they be focusing on with that consultant?
Speaker 2 (21:38)
Yeah, it’s a good question. What we kind of talked about earlier of, ⁓ you know, people process technologies, you got to plan on someone clicking on a link that they shouldn’t have. You know, something got passed. ⁓ So we have to plan for what happens when that link is clicked. And that’s where that next gen antivirus, those type of platforms come into play, where they can stop executables from executing on a workstation. They can stop.
⁓ malware moving from one computer to another and really moving across the network. So, ⁓ you can’t, there’s no, like I said, no silver bullet, but we have to plan on people getting through our first line of defense, our second line of defense, that next gen antivirus, some ⁓ endpoint detection and response. You get further down to manage detection and response where you can add on of, if something clicks on something or somebody clicks on something and we have an executable, we could quarantine it, but
What do we do now to remediate and make sure it doesn’t happen again? Is that computer now infected? Do we have to reimage the computer? Maybe not. Maybe we can just flash a couple things. That MDR aspect of it is having a security analyst that you don’t have to pay benefits for. You don’t have to pay a salary. They can work on a lot of clients at one time. When they get that alert that something happened, they can jump in right away, parachute in essentially.
and take care of the problem and then you’re back up and running with low impact to the business. those are things that we, from endpoint detection response, bunch of tools in the marketplace. I mean, think last I saw like 1200 MDR vendors in the US. ⁓ So that brings back to your point, how do I know which one to go with, right? Working through a trusted advisor like OTG, clients can find what’s gonna be right size for them.
Speaker 1 (23:35)
Yeah, sometimes it’s just narrowing down the choices. ⁓ One of my favorite books is called the paradox of choice. It basically discusses how in a lot of cases too much choice is not good. A, it’s not good for decision making because one just kind of freezes and paralyzes their decision making. And the other is once they do make a decision, they’re thinking about all the other choices they did not make. Right. So more choices is not always better and having somebody
help you guide you down that path, I think is very valuable. ⁓ It’s kind of like viruses and people too. If somebody comes down with a virus, and we all lived through this five years ago, ⁓ containing that virus, right? Not having it spread from person to person, and it’s the same in cybersecurity. You get an infected laptop, and the first thing you want to do is keep that from spreading to the other laptops, right?
Speaker 2 (24:32)
Yeah. Well, there’s another aspect too of just having the software on your computer or your workstation may not be sufficient. It’s got to be configured correctly. It’s got to be set up appropriately. I worked with a client that actually had a Bitdefender on their workstations, which they had, which is an anti-virus ⁓ type software. There is a configuration setting that requires to be turned on, which is anti-tamper. So I can’t turn it off at random.
They actually had a bad guy get into their system on the computer and they didn’t have that enabled. They went and just turned off Bitdefender. ⁓ And so the software wasn’t enough in some cases. It takes a consultant to know how to configure it, how to deploy it, and if it’s sufficient for that type of threat. There could be other things that are better.
Speaker 1 (25:22)
What are some of the other must do’s for personal cybersecurity? I’ve been kind of focusing the episode here on the smaller businesses. That’s who I happen to deal with mostly and a lot of my colleagues rather than the Fortune 500 companies. What are some of the personal cybersecurity must do’s like strong passwords, MFA, software updates? You just mentioned the software update.
Speaker 2 (25:47)
Yeah, strong passwords ⁓ is something you see ad nauseum. The reason why, and I don’t think it gets explained as well, because people say you gotta change your passwords every 30, 60, 90 days. They all gotta be unique. And people are like, it’s just so hard for me to remember. It’s absolutely hard to remember. But the reason being is if I’ve got the same username password and I’ve used that at 10 different places, even though I might have good hygiene on how I…
how I navigate the internet, I might have done nothing wrong. If I use that username password on the website and that website gets compromised with the database of all their username and passwords, now even though I did nothing wrong, that username and password together in that combination is out on the dark web. And anybody can just try that. If it’s my Netflix, it’s my eBay, it’s my YouTube, it’s my bank maybe, right?
And then now if people use those, that combination, they have access to my whole life. So that’s a major thing is using unique passwords.
Speaker 1 (26:50)
What are some password software programs that you recommend to do it, to manage it for you?
Speaker 2 (26:58)
Yeah, inherently I’m Microsoft and Google Chrome. They’ve got, you know, they can build passwords for you and then they’ve got a password locker. There’s also third party. ⁓ One password yet is last pass is another common one. ⁓ Nord locker is is a Nord has a VPN, but they also have a password locker offering as well. There’s quite a few.
Speaker 1 (27:09)
I use one password.
Speaker 2 (27:22)
Password lockers and those are good products. What I would recommend is people take a look at ones that encrypt the passwords individually rather than just a box that the container you know you can have. ⁓ You want him individually encrypted so if they if a bad guy somehow gets into a password locker they have to unencrypt every single one and that’s just not feasible. So ⁓ there’s some different traders in the market but is a good product ⁓ to look at.
Speaker 1 (27:50)
Great. How about some tips for securing home networks and IoT devices?
Speaker 2 (27:58)
So IOT devices and we’re talking, you know, in a home network that could be your refrigerator now. It could be your microwave, right? It could be your, you know, you can start things remotely from your phone, which is amazing. ⁓ The problem with those is oftentimes IOT devices aren’t the security on those is not as up to date as other things. And they can be vulnerable to attacks, to, you know, people driving by and picking up signals because a lot of those don’t have
most up-to-date encryption, wireless encryption protocols.
Speaker 1 (28:34)
Does some of that have to do with literally the size of the devices or no?
Speaker 2 (28:38)
It could be the size of devices. could be the maker could be are they up to date from a a patching perspective? you know, are they being kept up to date? Are they receiving regular updates? One of the things you can do from a home network perspective is ⁓ which we’ve done in enterprise networks for a long time is segmentation. So if you look at your wireless router or otherwise, oftentimes you can create a secondary network and put all of your IoT devices on a secondary network. So if.
somehow a bad guy hacks into my refrigerator and they go laterally in my network, they’re only going to be able to see my microwave and my dryer, right? They can’t see my phones or my, or my laptop or anything like that.
Speaker 1 (29:20)
So you kind of break the ties between the parts of the network.
Speaker 2 (29:24)
Yep, yeah, to my more critical network is, then my IOT devices that may be more vulnerable, break them off so that they have their own separate, you know, VLAN within my network. We’ve done, we do that with enterprises, but that, that type of methodology is very applicable to home, home and wifi.
Speaker 1 (29:43)
Gotcha. Well, wrapping up here, Trevor, ⁓ what are some of the biggest cybersecurity challenges and opportunities you foresee in the next few years?
Speaker 2 (29:54)
Well, from the discussion we’re having today, really in the cybersecurity space, ⁓ the threat of AI as well as using AI to ⁓ improve defense is paramount. I think we’re still trying to figure out what that looks like. Some of the solutions that are out there right now actually you can take advantage of that excite me are agentic AI SOC agents. So security operations center agents. ⁓
A lot of what we’ve done in the past is looking at ⁓ a security operations center as a service and using a third party security operations center, which is still going to be relevant. But now can we automate and augment those human efforts with AI that can reduce false positives, take a lot of those level one alerts that they just get every single day, reduce burnout, reduce the cost of the security operations.
Speaker 1 (30:53)
It’s
free of time for the more important.
Speaker 2 (30:55)
Absolutely. Let the humans worry about the larger threats and have some of the meaningless stuff weeded out by AI. think that’s what we’re seeing a lot adopted right now and clients can take advantage of.
Speaker 1 (31:10)
Do think
AI is helping the bad guys more right now or helping the good guys more?
Speaker 2 (31:16)
Yeah, there’s actually, you look at, there like chat GPT or llama or Gemini, you know, some of those LLMs we’re familiar with. are ones like worm GPT fraud GPT, that help, you know, bad guys build malware, build exploits, build vulnerabilities. ⁓ so just like you can, Hey, I want, you know, help me with this math problem or, you know, write this email for me that exists and write this malware that does this exploit. So,
You know, those are things to think about. It’s a revolving door or two-way door, I should say.
Speaker 1 (31:49)
Yeah, well, that’s yeah, it may be an obvious one that AI is probably obviously the most emerging technology that’s going to impact both sides, right? And hopefully AI can can help the good guys more than the bad guys.
Speaker 2 (32:03)
That’s a lot that came out of RSA is use AI to fight AI, fight fire with fire. So I think there won’t be a choice coming up.
Speaker 1 (32:12)
I don’t think there is a choice. Well, that’s it for the episode. I hope that was informative, not only for businesses, but for individuals. And I thank you again, Trevor, for your time. All right.
Speaker 2 (32:23)
Yeah, I appreciate it.
Don’t get stuck with overpriced, unreliable technology solutions. Leverage our 30+ years of telecom experience to ensure that you are getting the best, most reliable and cost-effective solution for your business.
Complete the form below and one of our technology consultants will get in touch with you.