The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Cyber Work
Cyber Work artwork

Working in ransomware response, investigation and recovery | John Price

Cyber Work · 2025-07-28 · 36 min

0:00--:--

John Price brings a rare combination of military counterintelligence background and private sector cybersecurity expertise to the forensics and incident response space. After starting in UK Ministry of Defence signals and counterintelligence at 17, transitioning through roles at PNC Bank focused on vendor risk management, and founding Sub Rosa, Price now leads a three-person forensics team handling primarily ransomware attacks and business email compromise cases for mid-market organizations. Unlike traditional forensics firms focused on legal evidence preparation, Sub Rosa emphasizes rapid triage, recovery, and remediation - getting companies back online quickly while implementing preventive measures. The team works across email security, backup and recovery procedures, and policy implementation, often coordinating with insurance providers, legal teams, and finance departments. Price highlights that 95% of cases originate from targeted email attacks on individual employees, making email security training and technology the primary focus for preventing recurrence. He also discusses emerging threats in specific verticals, like the car dealership industry's vulnerability to email bombing attacks, and the broader challenge of reactive rather than proactive security adoption across industries.

Key takeaways

  • →Most ransomware cases Sub Rosa handles originate from targeted emails to employees, making email security and awareness training the primary prevention focus rather than paying ransoms.
  • →Sub Rosa's forensics team acts as front-line responders for triage and recovery rather than legal chain-of-custody specialists, typically handing off to legal teams only if law enforcement involvement is anticipated.
  • →Digital forensics hiring should prioritize hands-on experience with relevant toolsets and frameworks over certifications alone, and drawing talent from larger established firms brings valuable expertise.
  • →Email bombing attacks are increasingly targeting car dealerships despite being relatively unsophisticated, exploiting the industry's historically low email security maturity and FTC compliance gaps.
  • →The cybersecurity industry remains fundamentally reactive rather than proactive, with adoption driven primarily by compliance requirements rather than genuine security maturity.

Guests

John Price

Topics in this episode

email securityBusiness email compromiseChain of custodyDigital forensicsRansomware responseSub Rosabackup and recoveryincident response playbookscar dealership industryFTC compliance

Questions this episode answers

What happens after a ransomware attack when you don't pay the ransom?

Sub Rosa leads triage to assess damage, implements backup and recovery procedures to restore systems to the last operational point, coordinates with insurance and legal teams, then focuses on preventive measures like email policy changes and access management improvements to prevent recurrence.

Do digital forensics firms need to maintain legal chain of custody for all breaches?

Not necessarily - Sub Rosa primarily handles operational recovery and mitigation for mid-market clients rather than legal chain of custody, which is typically only necessary when law enforcement involvement or litigation is expected, at which point cases are handed to legal teams.

What are the most common attack vectors Sub Rosa encounters in ransomware cases?

95% of cases originate from targeted emails sent to individual employees, making email the primary entry point for both ransomware and business email compromise attacks.

How does Sub Rosa determine whether to recommend paying a ransomware ransom?

Sub Rosa's principle is not to recommend ransom payment, but decisions involve insurance providers, finance teams, and legal counsel based on the specific business situation and whether insurance covers the attack.

Why are car dealerships becoming targets for email bombing attacks?

Car dealerships have historically not prioritized email security, making them vulnerable to high-volume targeted email attacks, and the industry's FTC compliance requirements haven't yet driven widespread security adoption.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C58%
  • Speaker B32%
  • Speaker A10%

Most-used words

security25cybersecurity23side20forensics17team14industry14attack13usually12email12listeners11start11military11response11writing11john10rosa10

Episode notes

Get your FREE Cybersecurity Salary Guide: John Price of SubRosa joins today's Cyber Work Podcast to share insights from his unique career path spanning UK military counterintelligence, banking cybersecurity and founding his own digital forensics consultancy. John breaks down what really happens when ransomware hits small and medium businesses, why most companies choose recovery over legal action, and how his team helps organizations get back on their feet quickly. He also discusses the growing threats facing industries like automotive dealerships, the critical role of documentation in forensics work, and why AI will reshape both offensive and defensive cybersecurity strategies.

Full transcript

36 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Today on, um, Cyber Work, John Price

Speaker B: of Sub Rosa joins me to talk

Speaker A: about his work in digital forensics, his time with the UK Ministry of Defence in counterintelligence, and how he and his team come in after the ransomware attack has happened. The ransom was not paid and the company must quickly move to prevent further downtime, which can be certain death for small businesses and damaging even to the largest organizations. If forensic analysis, evidence preparation and being able to help a struggling organization get back on its feet and after a cyber attack all sound like interesting jobs to you, then tune in today for

Speaker B: this episode of cyberwork.

Speaker A: The IT and cybersecurity job market is thriving. The Bureau of Labor Statistics predicts 377,500 new IT jobs annually. You need skill and hustle to obtain, uh, these jobs of course, but the good news is that cybersecurity professionals can look forward to extremely competitive salaries. That's why InfoSec has leveraged 20 years of industry experience drawing from multiple sources to give you Cyberwork listeners an analysis of the most popular and top paying industry certifications. You can use it to navigate your way to a good paying cybersecurity career. So to get your free copy of our Cybersecurity Salary Guide ebook, just click the link in the description below. It's right there near the top, just below me.

Speaker B: You can't miss it.

Speaker A: Click the link in the description and download our free Cybersecurity Salary Guide ebook. Your cybersecurity journey starts here. Now let's get the show started. Welcome to this week's episode of the cyberwork podcast. I'm your host, Chris Sanko. My guests are a cross section of cybersecurity industry thought leaders and our goal is to help you learn about cybersecurity trends and how those trends affect the work of InfoSec professionals as well as leave you with some tips and advice for breaking in or moving up the ladder in the cybersecurity industry. My guest today, John Price, is an experienced information security executive with a demonstrated history of working in the public and private sectors. John is skilled in counterintelligence, risk and vendor risk management, information security, program management and project planning. Uh, John is highly business oriented with an affinity towards gaining an understanding of what the client needs and tackling the challenges of meeting those needs in a risk based, cost effective manner.

Speaker B: Uh, so one of the things we are going to discuss today uh, is also uh, John's time working uh, in digital forensics and I'm really looking forward to that because our listeners, uh, pretty frequently Request, uh, forensics episodes. So, uh, John, thank you for joining me today, and welcome to Cyberwork.

Speaker C: Thank you. Thanks for having me on.

Speaker A: My pleasure.

Speaker B: So, John, uh, let's start with, uh, a bit about your sort of early years as a tech fanatic.

Speaker A: Do you remember what the initial spark

Speaker B: was that got you excited about computers and security? Was there an initial draw, maybe a teacher or a family computer or something like that?

Speaker C: Uh, yeah, really, it was in my kind of late teen years, early twenties. Um, that was when I was definitely immersed in the cyber security, intelligence side of things, counterintelligence. And I think the natural draw was just really from transitioning out of that world and, um, always having an affinity towards, uh, computers and enjoying working with computers and exploring that, uh, it was a natural transition from the one to the other, I would say. Yeah.

Speaker B: Did you. So just to make sure I'm understanding, you said you were, you were involved in or reading in counterintelligence, uh, when

Speaker C: you were in your teens, uh, late teens. So I, Yeah, I entered that world and, um, through the military at, uh, 18, and continued on there kind of for six years. Um, so it was, uh, something that we were always immersed in, not always something we were directly involved with. Uh, intelligence kind of spans, um, many different domains. But, uh, I had enough exposure by the time I was kind of in my early to mid-20s to know that this was something I was interested in and kind of enjoyed doing.

Speaker B: So you started, you got involved with the military pretty early then, it sounds like, or this aspect of things, like in your teams then.

Speaker A: Is that right?

Speaker C: Yes, yeah. 17. Uh, I was in signals and then quickly moved to, uh, intelligence after kind of realizing that was more what I wanted to do.

Speaker A: Okay.

Speaker B: And so that was, that was a combination of. You were already interested in that, plus you signed up and then they said, okay, you've got this natural affinity. Uh, is that, is that right?

Speaker C: Yes. Yeah, that's pretty much what it is. That through aptitude testing and everything. It was, uh, something that they, they recognized and, and then they kind of push you down that, down that path from there.

Speaker B: Okay, what aspects of, uh, counterintelligence, uh, were you, were you doing in your, in your early military days then?

Speaker C: Uh, so my focus was on security of all aspects, so security, um, of military bases, security of personnel that included, um, but also included physical and uh, everything else kind of within that realm.

Speaker A: Mhm. Okay. Uh, so, yeah, so like I say,

Speaker B: some of our listeners use, uh, our podcast to look at, uh, the work that various IT and cybersecurity roles entail and so you have a pretty interesting um, career uh, map. As I say you've uh, in the intro you said you uh, have worked both in private and public sector as well as military, uh and so forth.

Speaker A: Can you talk about some of the

Speaker B: key roles and key moments that got you where you are today as the founder of Sub Rosa?

Speaker C: Yeah, absolutely. So um, I would say for anyone looking to get into the industry, definitely don't rule out um, you know the military as an option. It is a very uh, robust and quick way to get into, into the cybersecurity world. Obviously comes with some sacrifices, uh, that you have to make, um, time and lifestyle. But that is really how I started. Um, my second role was in the private sector at PNC bank, um, here in the States. That was kind of after I transitioned from the UK to the us. Um, and again banking is a very good way um, from a cybersecurity perspective to get exposure to uh, you know, what really needs to be done, uh, on both the controls, technical, uh, non technical as well as the compliance side of things, obviously a heavily regulated industry. So um, you get a very good all round exposure to how that world might work. And traditionally banks have very big budgets for stuff like this. So you're going to see um, you're going to have a good opportunity to um, to move around a lot in there. Um, and that was really what led me to Sub Rosa was you know, in banking, in, I say in banking, in the cybersecurity side of banking. Um, right. And understanding what some of the challenges were for these big companies and looking at you know, where they filled gaps with contractors, where they filled gaps with private, with you know, vendors and things like that and kind of thinking that was something I would like to, to do. And that's kind of what led me to, to founding the company. We didn't specifically target banking as an industry, you know on founding, but just in general having that understanding of where the need was um, helped me to uh, start the business.

Speaker B: Yeah, it kind of explained itself to you along the way.

Speaker C: Exactly. Yeah. So with, within banking and finance there's, there's a massive compliance drive. So everything we do, um, the regulators are aware of. And uh, being in Cleveland, you know there is a Federal Reserve here. So we're very, very physically close to them as well as just kind of in touch every day on what we do. So that was something I hadn't experienced before. Um, a lot of the military is doctrine driven, um, ah, in just everything we do. But um, in finance, that, that took some getting used to in terms of the process around regulation, around what we can do, what we can't do. And then just in general, I was surprised at how much the regulators know day to day about what um, what we do in, you know, in cybersecurity in the bank. And just in general across the whole organization. They, they, it felt like they were very in touch and very in tune and that was a bit of a culture shock for me. Um, which might sound weird coming from the military, which is known to be, you know, pretty regimented and uh, disciplined. And um.

Speaker B: So you had this kind of feeling that someone was kind of always looking over your shoulder in terms of the

Speaker A: procedures you were implementing.

Speaker C: Yep. Yeah, and not necessarily in a bad way, but um, you know, especially around my role which was vendor risk, uh, in the bank, um, it was a big, became uh, a big thing after the 2008 crash, um, managing vendors. So um, there was a big drive, it felt like behind that and something that the regulators at least at the time were paying very close attention to. Yeah.

Speaker B: Nice.

Speaker A: Okay. So, uh, can you tell our listeners

Speaker B: about your role as the head of uh, Sub Rosa? You know, like I say, you know, a lot of people want to maybe start their own business eventually. What is, what does the actual uh, job entail of being in charge of this uh, this organization?

Speaker C: Um, so I would say I definitely moved away from the day to day cyber risk, cybersecurity side, um, founding it. And you definitely move more into a sales and marketing role, um, at least in the early days where you have to, you know, really get out there, promote the business network, um, to build that client, the clientele. Um, I think a lot of people who like to go into this want to do both and some are quite successful at that. I had more of an eye to try and scale the business so I hired where I could to actually uh, folks to do the work. Smarter people than me. Um, and then so my focus day to day is on, um, well, number one, our existing customers, making sure they're happy, making sure they're taken care of and then growing the business with new customers, um, and then keeping an eye out for new um, service offerings, new things that we can offer to add value, um, new skills, things like that, um, that maybe our customers haven't thought of or anticipating uh, that demand.

Speaker B: Yeah, it doesn't seem like that that's been uh, much of a frustration. I know some people who go from the hands on side to the managerial side, uh, really don't like it, because that's not kind of what they got into the game for. But it doesn't seem like that bothers you too much.

Speaker C: No, I think I looked at it as a case of um, uh, I guess march or die, for lack of a better phrase. You have to adapt, otherwise you fall by the wayside. Yeah.

Speaker B: Wherever I'm needed as well, I suppose.

Speaker C: Right, Exactly. Yeah, yeah, yeah.

Speaker A: So, yeah, I mean we have a

Speaker B: lot of different directions we can travel, uh, for this episode because your background is so diverse and so varied. But, uh, one particular thing that I really wanted to ask you about that stood out was your experience leading digital forensics and breach response operations, both with sub rosa and with your work in the UK military. Uh, this is something that our listeners are always asking us to talk more about because it is such a fun and sort of cool aspect of cybersecurity.

Speaker A: So for starters, can you tell our

Speaker B: listeners about some of the type of digital forensics operations you've overseen?

Speaker C: Um, so yeah, from a forensics perspective, um, we have dealt mostly with ransomware attacks. Um, I think in our time, um, forensics, and that's in sub rosa. Different in the military, but in sub rosa. Yeah. Most of the um, forensics and investigation type of work that we do would be usually centered around ransomware attacks or um, bec business email compromise. Um, those are the two most common things that we see. Um, we have tools that are deployed in place with most of our customers on the email side. So we're able to catch and kind of mitigate that pretty quickly. Um, and then with the ransomware it can become a little bit more uh, tricky. But I would say in terms of attack types, um, those are the two that we deal the most with. Um, with our customer base.

Speaker B: Yeah, yeah, yeah.

Speaker A: So, um, what is your digital forensics team like?

Speaker B: Are there, do you have multiple people on the team? Do they have certain specialties that they have. I know in past guests have talked about having. You know, if you're going to have a team of forensics people, each should kind of have a specialty that you know, can work across like multiple projects and sort of multiple types of uh, uh, you know, evidence gathering and so forth.

Speaker C: Yeah, absolutely. So we have uh, three people on the team now for um, forensics. Uh, they are multi role, so they uh, they kind of work in a number of different domains. Um, and then the focus really with them is uh, on um, the investigation side and then kind of the chain of custody side of things as well. Um, for us, just with the nature of the sizes of our clients and things like that. We tend not to go down the chain of custody route too often. Um, with breaches, M. We are more focused and the demand on us is more on, um, mitigating, um, and kind of recovering after a breach and figuring out what to do next, um, with our customers. If there then is a need to go down the legal route, um, we, we often will hand it off to, um, to their legal team or whoever they brought in to handle, you know, liaison with law enforcement and things like that. We are definitely acting more in the front line of, uh, triage, helping clean up, managing evidence and then handing it off to, um, to lawyers and folks who kind of handle the rest of that process.

Speaker B: Is there any kind of standardizing of evidence that you need to do to make it sort of usable? Uh, are you kind of basically like translating what you see to the sort of legal team who might take this into a court situation?

Speaker C: Yes, absolutely. Yeah. And we usually know pretty quickly if this is a situation where it's going to end up like that. And again, with the budgets that our clients have and the sizes of them, we tend not to see it go that way. They're usually about, hey, let's recover from this, let's put things in place to prevent it from happening again. Um, but I mean, and unfortunately I think that's just the nature of cyber attacks on mid and small businesses is, um, they're more focused on getting back up and running as quickly as they can. Um, if an attack is in the 6, 7 figures of value, then we start to see interest from the FBI and law enforcement. Um, but in my experience, um, and take it for what it's worth, Law enforcement tend not to be interested on the smaller attacks. They collect data on it, but you're not going to see a lot of proactiveness on these smaller cyber attacks. So most of the customers just tend to be focused on, let's get operations back up and running, um, let's mitigate what we can and let's stop this happening in the future. And that's really where I think we add value to our customers.

Speaker B: Okay, yeah, understandable. So could you kind of walk through a, ah, hypothetical, uh, you get called in on a ransomware attack and you're doing the mitigating and trying to sort of recover, uh, things and get things back running again. What are the steps that you and your team do to make that happen for your client?

Speaker C: Yeah, so, um, first off, with all of our clients who are in this capacity, we would have A, um, if we're doing any kind of incident response or detection work with them, we'd have a playbook in place for that type of cyber attack. So that's going to be unique to the client in terms of who and who does what in a scenario like that. But usually there's some kind of incident response process that's kicked off where we are working with their, um, responsible parties within their organization to figure out what happened, um, triage the damage done and then look at backup and recovery procedures. So again, it depends on what, what technologies they have in place to handle something like this. Um, but usually we would look at, um, restoration and getting us back to the closest point in time that we can from where things were operational on their network. Assuming if it's an endpoint or a network compromise, something like that. Um, as a matter of principle, we don't normally recommend, uh, communication with, uh, ransomware attackers or uh, paying a ransom. But, um, it depends again on the customer. If there's insurance involved, sometimes, you know, they want to take a different course of action. Um, so, um, that's something that we work with as well. And then we're bringing in the insurance folks, the finance folks and the legal folks in on those conversations, um, to kind of hopefully work in harmony and come out with uh, a next steps that is, uh, um, that's what works for the business. Again, usually the priority is let's get back up and running as quickly as we can. Uh, once we do that, then we're circling back. Um, we're looking at lessons learned. How can we improve the process? How can we improve the detection? How can we stop this from happening again? Um, that might involve a procedure change, that might involve a change or an introduction of a different technology to detect or handle things like this. Um, I will say 95% of the cases we deal with it comes in through an email of some kind, um, to an employee. So, uh, we're usually looking at the email side, we're usually looking at the training and awareness side and any vulnerable areas within the organization. Because like I said, it's coming in through an employee. It's usually fairly targeted to an individual. Um, so that's where the focus is going to be for stopping that happening in the future.

Speaker B: So because you're kind of acting as almost more of a consultant rather than being part of the company, I assume any recommendations you make in terms of, you know, changes to be made, that this doesn't happen again are more suggestions than you actually doing the implementation. Right.

Speaker C: So we yeah, we would make the recommendations to the company and then, um, and then if they said, yep, that sounds good. Yeah, yeah, we usually, we would execute on the implementation too. Okay. Yeah.

Speaker B: Okay. That's what I was wondering.

Speaker C: Okay. It's obviously it's their decision whether or not we do it, but most of the time with that far ingrained in the process already, that it's us who would, uh, be helping them with that.

Speaker B: So you're actively getting into their network and saying, okay, we're making all these changes to your email policy, to your access management, all that kind of thing. Uh, you're kind of making all those changes, uh, for them and then sort of showing them what you did, basically. Is that right?

Speaker C: Yeah. So usually if it's a client, especially if we've got detection technologies deployed already, we would have that, um, capability and we would be able to make those changes for them. Yeah.

Speaker A: Okay.

Speaker B: Um, so what kind of, uh, sort of skills or backgrounds were you looking for? You said you have three people on your team who do this sort of thing. Uh, what attracted you to those team members? I guess, like, what was it you saw in their background or their qualification? You said, oh, yeah, this would be a perfect person for my team.

Speaker C: So we hire really based on experience. That's what I like to look for. Have they had experience with certain tool sets potentially or with certain other organizations? There's a few pretty good ones out there that are bigger and better than we are at this. So if we can draw people from there, that's always a bonus for us. Um, and then just yet, in general, looking at experience with working with, um, certain frameworks, depending on the role, or certain tool sets, depending on, um, again, depending on the role, um, is really where we would look. And then after that, degrees, certifications, things like that, um, and that's just our style of hiring that's worked for us, um, so far. So, um, I can't say that about everybody, but, uh, that's definitely kind of how we look, um, when we look for people. Yeah.

Speaker B: Have you had any particularly unusual cases? I mean, it sounds like a lot of what you do is an email got in, ransomware was installed. Uh, we're, you know, we're not going to pay the ransom. We're going to stand firm, and then once the damage is done, we're going to mitigate and sort of, you know, repair it and make sure that doesn't happen again. But have there been any particularly unusual sort of breaches or compromises either in your current roles or in the Military that uh, that you're like oh, people should hear about, about how this happened.

Speaker C: Um, good question. I'm trying to think to one. I think um, what springs to mind is probably um, we serve a lot of car dealers in the car dealer market um, uh, because of the FTC compliance stuff and uh, what we see on the emails quite commonly is um, uh, employees or dealerships getting email bombed. So um, essentially it's a very targeted but high volume uh, email attack. Um and from my perspective from what we see, I don't think it's anything new in terms of an attack style but um, on that specific industry uh, it's been interesting because we've not usually seen that type of attack used before and uh, it's a shotgun approach so they're casting the net wide, see who they can get, uh, and then go from there. And car dealers especially up until recently have really not been paid close attention to email security. So it's one that's very effective. Um, and something new that we haven't seen in that industry before a whole lot but we keep seeing that one pop up uh, which is interesting.

Speaker B: Yeah, yeah. Um, ah, is the auto industry or the car dealership industry in kind of sound the alarm mode in regards to that? Because I know certainly over here we talk about industrial control systems and, and just the sort of like unbelievable swath of, of you know, people that take care of our water supply and our, our sewage and all these things who have absolutely no security, you know, attached to their legacy systems and so forth. Is, is the car dealership industry feeling a similar like hey guys, we need to do something about this right now or is it just going to be uh, you know, one attack after another until you know, a snowball effects, makes people sort of change on a fundamental level.

Speaker C: I think it's going to be more of the latter. Yeah, I think so. Yeah. I think it's so far been pretty slow to adopt. Uh, it m is compliance driven um, which helps but uh, we're still reactive in security across the board. So. Yeah, um, uh, that's I think unfortunately the way it's going to be.

Speaker B: Do you think that point of friction is down more to time, money or lack of knowledge about having to do it? You know, I guess I'm curious if they knew would they do it quicker or is it just oh that's a lot of work, I don't really want to take the time or is it like that costs us too much money, we can't, you know, we'll take our

Speaker C: Chances, I think it's a combination of all three. Yeah. Especially um, and I'm, you know, not to single out that one industry, but you know, car dealers, you have the 30 plus dealership groups who have the budget, they have the resources to do this. But you know, I'm really looking at the one or two dealer groups who um, might not even have full time IT staff and suddenly they're being told, you have to do all this stuff for cybersecurity and you got to do it by this date. Go figure it out. And I understand these guys are like, I just want to sell cars. You know, we want to keep things going. And they're in an industry that is.

Speaker B: I didn't get into this to learn security.

Speaker C: Exactly. Yeah.

Speaker B: Right, right, right.

Speaker C: Yeah. Glim margins, very high turnover of people, you know, um, can't lose a day. Exactly. And now all of a sudden they've got 100 plus hours of work to do every year in IT and in security. It's a lot to ask.

Speaker B: Yeah, yeah. So, you know, again, it sounds like your aspect of sort of breach reporting and forensics is a little different from some of the other guests we've had. But with uh, regards to, obviously you're doing the mitigating, you're doing the recommendation. How much of what you do involves uh, writing and reporting and documentation. I know that past guests talking about digital forensics have said that like, writing skills are really, really important to the job. You have to do the reports and so forth. Is that, is that similar here? Do you still have to kind of document everything you've done? Extensively?

Speaker C: Yes, absolutely. So we have, um, we have folks on the team who are dedicated, um, most of their time to technical writing, I would say, um, and the documentation part of it is uh, critical. And I think the biggest reports that we write are one that involve breaches or incidents of some kind. Um, definitely, because, uh, not only for um, kind of lessons learned, but these reports sometimes need to be admissible, um, as expert opinions or um, as kind of uh, documentation as to what happened. So yeah, that's one of the things I think that um, is fundamental in that process and in everything that we do.

Speaker B: When you're looking for people who are going to be very heavily in that sort of writing space in terms of working for you, uh, do they need to have some kind of background in like court reporting language or tech writing language, or is that something they can kind of learn on the job if they're just a good writer across the board?

Speaker C: Yeah. So we look more on the tech side than we do on the court writing side. Um, and I think the first place we start when looking for people like that is, um, past writing. Right. We all want to look at what have you written before? Can we read it and see? And, um, that's kind of where we start. Um, report writing in any form. I think in cybersecurity is, um, the least favorite thing for anyone to do on the consulting side. So it's often the thing that's avoided

Speaker B: the most and startlingly large percentage of what you do. It sounds like. I know one guest said writing the reports could be like 30% of the overall work in some cases.

Speaker C: Yep, that's about right. Yeah. Uh, so, uh, time management is very important as well, because you have to be able to do your job and document what you're doing while you're doing it. Um, the idea is that, um, we can learn from it or we can in some cases replicate what you're doing. Um, so documentation is very, very important in that. And I've seen all kinds of creative ways that folks have come up with, uh, automating that process or trying to.

Speaker B: And was just going to ask about that.

Speaker C: Yeah, yeah, yeah.

Speaker B: I mean, yeah. What are your thoughts? I know that GRC professionals have been saying that AIs and LLMs and so forth have been incredibly helpful in streamlining the sort of sifting of big data or starting a report, even if you don't let it, like, kick your whole report out, like it's a good sort of beginning point. Has that been a similar thing, uh, with, uh, the forensics rules first?

Speaker C: I think so, yeah. I think, um, used in the right way and used securely, LLMs can be hugely helpful for, um, you know, for helping streamline report writing and taking some of the burden off of that, which in the end helps the customer as well. Because if, you know, they're paying for a report and if we can find a way to streamline the production of that report and make it so that it takes us 50% of the time, I'm all for it as kind of the company leader. So, um, absolutely. As long as they use securely, LLMs have a tendency to make things up and, um, be insecure in how they do it. So we have to be careful with what and how we use it. Yeah.

Speaker B: Not to mention the fact that you're putting all of this sort of like court data, uh, you know, admissible data into, you know, this open system that can be hacked or, you know, sort of sent out into the ether and so forth. So, yeah, that's, that's a lot to worry about. So, um, uh, one thing I keep thinking about, you mentioned that when you're hiring, obviously you have, you have a fairly elite team, but when you're hiring you're looking for, uh, past examples of using certain types of tools, past examples of writing. Uh, for listeners who are trying to break into this type of digital forensics and breach response.

Speaker A: How hard is it to do without

Speaker B: experience if you don't have sort of a portfolio? And do you have any sort of tips for sort of working around, uh, that eternal paradox?

Speaker C: Yeah, um, I think it's one of, it's certainly in my opinion, one of the niche areas of cybersecurity to get into. Uh, it's one of the more in demand areas, but I think it's also one of the harder ones to get to break into. So I would say it's kind of a word of advice, if that's the end goal, have maybe a backup plan or have a path charted out that might not necessarily involve immediately going into that, but security operations is a good place to start really for cybersecurity in general. And that will give exposure to the incident response and recovery side of things. Um, and then being able to kind of specialize from there.

Speaker B: Yeah, I was going to say that was going to be my next question is that it seems like maybe these kind of forensic roles might be the first sort of budget lines that a lot of companies are looking to slash when they're sort of like downsizing their security, uh, you know, security money and so forth. Is that what you're seeing as well?

Speaker C: Um, yeah, I think so. Uh, and if they even invest in it in the first place is something that, um, you know, is a big thing as well. Um, and there's a few really big names out there from consulting who handle this and all they do is incident response. And I think a lot of companies are kind of leaning more towards having it as an outsourced capability rather than, um, something that's in house, um, as well, uh, is kind of what we're seeing. But yeah, I would certainly agree with that.

Speaker B: So in terms of, uh, how to get the role without the experience, and get the experience without the role, it sounds like your recommendation, and you can correct me if I'm wrong, is to instead of look directly to sort of make your mark in the sort of forensics, breach response side of things to start maybe in a SoC, and sort of learn incident response by sort of going up through that and then Seeing if there's kind of like lateral movement uh, from there. Is that right?

Speaker C: Yeah, absolutely. I would say start in something frontline on security operations that's going to give you an exposure to the incident response team or that process and then laterally move from there. And in my experience I've kind of worked in big and small companies, but on the big company side I certainly saw a lot of opportunity for folks to move laterally within cybersecurity, um, and within those teams. So um, yeah, I can't speak for every big company obviously, but I certainly think that um, at least in the banking world was uh, there was a lot of, a lot of opportunity for that lateral movement.

Speaker A: Okay, so as we start to wrap

Speaker B: up today, um, you know, as you were sort of telling me a lot of the uh, types of attack, um, you know, attacks, attack, uh, scenarios that happens, it seems like it's an awful lot of email gets compromised, someone uh, gets access, ransomware is installed. So you know, I mean obviously there's, every attack is subtly different or whatever but like looking five, ten years down the road, do you see this still being the sort of like primary thing that we're fighting against? Do you see any kind of um, um, tech that's happening now that might really like change the nature of the way email is compromised? Security awareness, endpoint protection, anything like that?

Speaker C: Yeah, I think AI integration um, is going to massively change the security landscape I think, um, in a couple of different ways. Um, on the one hand, sorry, my dog is in the background. Um, on the one hand I think

Speaker B: never apologize for a dog in the background.

Speaker C: On the one hand, I think um, in detection and response AI is going to be, is going to potentially change the game and we're already seeing it implemented in the big tools already. Um, but how we interpret that data and the speed at which we can interpret that data I think is going to be, um, is going to be changed by AI. But then on the flip side of it, as, as companies are injecting and wrapping uh, software and product into large language models, um, there is a huge area of exposure there, um, for sensitive data that they're overlooking right now. Um, as a company we've just started kind of paying attention to large language model security and what implications that has for our customers. Um, but that is an exposure area, especially if you're training models on sensitive data and customer data, um, it's an area of exposure that is otherwise has not been looked at. I don't think pre2025 arguably, um, um, so AI on both sides, both on the defense and on the offense is going to uh, change the game I think in the next 10 years.

Speaker A: Are there any particular AI tools happening

Speaker B: right now that you think students really, really need to understand or AI processes, prompts, whatever? Uh, because again we're, we're mostly talking at entry level people and you know, I think there's a lot of tools and a lot of noise on the landscape. What do you, what do you like to cut through that? What, what do you think? Like, here's one thing that you absolutely need to know, uh, really well about AI to sort of future proof your skills.

Speaker C: Uh, the OWASP top 10, uh, LLM vulnerabilities is where I would look. That's a good baseline start. It was only released I think the beginning of this year. So again, yeah, this is like tip of the spear type of stuff, um, and is going to evolve very quickly, um, in the next coming years.

Speaker B: Um, yeah, yeah, absolutely. So as we wrap up today, uh,

Speaker A: tell our listeners more about Sub Rosa

Speaker B: and you've talked a little bit about what you do, but give us the whole deal here.

Speaker C: Yeah, absolutely. We're a full suite professional, um, services firm. So uh, our main focus is on um, is both on the proactive and the reactive side. So we do have a full 247 soccer, um, that we monitor for our customers. And then um, outside of that the services focus is definitely on the penetration testing, um, and uh, governance, risk and compliance side of things. Um, we are, uh, as I just said, I mean we are in a big push right now, um, for AI security. We're seeing AI being adopted across our customer base. We're seeing AI being adopted almost everywhere. Um, so the large language model security is a major focus for us um, now and will be uh, continuing into the future. Yeah.

Speaker A: Okay, one last request here. Tell our listeners where to find out

Speaker B: more about John Price or Sub Rosa or anything else you want to promote online.

Speaker C: Yeah, absolutely. I'm available, um, uh, on LinkedIn, uh, and our website is, uh, I'm sure we can share that but SubrosaCiber.com is the company website. Um, and then yeah, I can, um, I don't know if you want to provide my email address, we can do that as well. I'm always open to questions and communication from folks.

Speaker A: Sure.

Speaker B: Yeah, Our listeners like to use LinkedIn and they'll hit you up with requests and so forth. So. Yeah, so it's subrosacyber.com is that right?

Speaker C: Yep, that's right. Yeah.

Speaker A: Okay, perfect. All right, well, uh, yeah, John Price,

Speaker B: thank you so much for, uh, talking with me today. This is a lot of fun.

Speaker C: Yeah, thanks for having me on, Chris.

Speaker B: Uh, and thank you to everyone who watches and listens and writes into the podcast, uh, with feedback about cyber work. If you have any topics you'd like

Speaker A: us to cover or guests you'd like

Speaker B: to see on the show, uh, just

Speaker A: comment below, make use of our community tab on YouTube, or go over to

Speaker B: our TikTok channel and, and yell at us until we tell we get the guest that you want.

Speaker A: Uh, before we go, don't forget infosecinstitute.com free. That's a page where you can get

Speaker B: a whole bunch of free and exclusive stuff for cyber work listeners, including our

Speaker A: free Cybersecurity Talent Development Playbook, which contains in depth training plans and strategies for the 12 most common security roles, including SOC Analyst, Pen tester, Cloud Security Engineer, Information Risk Analyst, Privacy Manager, Secure Coder, ICS Professional, and more.

Speaker B: Uh, also you can look at our

Speaker A: free Cybersecurity salary guide for the latest data on popular certifications and their related roles. Uh, there's also security awareness posters, ebooks, and you can sign up for 100

Speaker B: plus free courses for a month on our Infosec Skills platform, learn incident response,

Speaker A: forensics, security architecture and more. One more time, that is infosecinstitute.com free and yes, the link is in the description below. One last time, thank you to John Price and Sub Rosa and thank you

Speaker B: for watching and listening.

Speaker A: This is Chris Sanko signing off. Until next time, make sure to learn something new every day. Keep one step ahead of the story and don't forget to have a little

Speaker B: fun along the way.

Speaker A: Bye for now.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The trust paradox: How attackers weaponize legitimate SaaS platformsTalos Takes · on email security94 / 100
  • ACH Rule Changes for 2026: What Treasury Needs to KnowThe Treasury Update Podcast · on Business email compromise85 / 100
  • “An AI-Enabled World.” Why You Can’t Avoid Building AI Into Your Practice | New SoloLegal Talk Network · on Digital forensics82 / 100
  • Practice Makes Progress in Cyber Resilience with Jim Bowie, VP and CISO at Tampa General HospitalHybrid Identity Protection Podcast · on Business email compromise80 / 100
  • Managing IT for Growing Restaurant Chain Jim N' Nick's Barbecue, with Stephen SelfIT Matters · on Ransomware response77 / 100
  • Domain Security Plus BlackHat USA 2026 Interviews from Balance Theory and WiCyS - Ihab Shraim, Greg Baker, Lynn Dohm - BSW #460Business Security Weekly · on Business email compromise75 / 100

More from Cyber Work

All episodes →
  • From stealing servers to saving lives: Working in red teaming | Jim Broome69 / 100
  • Why Hackers Are Stealing Encrypted Data Now To Decrypt Later | David Close
  • From security audits to privacy consulting: Building a GRC practice | Will Sweeney
  • From "dead-end job" to CEO: Building an IT consulting business | John Hansman
  • From FBI Cyber Agent to Police Tech Innovator | Andre McGregor
Explore the best B2B Engineering & DevTools podcasts →
All Cyber Work episodes →