The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/eWeek eSpeaks
eWeek eSpeaks artwork

Packetlabs CEO Richard Rogerson on Avoiding Ransomware

eWeek eSpeaks · 2024-01-31 · 16 min

0:00--:--

Key moments - from our scoring

Substance score

38 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality7 / 20
Guest Caliber10 / 20
Specificity & Evidence8 / 20
Conversational Craft5 / 20

Packet Labs delivers penetration testing services that simulate cyber attacks to help organizations understand their security gaps from an attacker's perspective. Rogerson explains the company's rigorous 24-hour evaluation process for hiring staff, designed to find vulnerabilities that standard vulnerability scans miss - the kind that end up in data breaches and headlines. He emphasizes that technical tools alone are insufficient; processes, human training, and verification matter equally. Regarding ransomware specifically, Rogerson describes how cyber insurance providers have inadvertently fueled the ransomware epidemic by preferring to pay ransoms rather than fund full network restoration, creating a perverse economic incentive for attackers. Rogerson details how modern ransomware operators employ sophisticated extortion tactics - threatening to leak data, filing SEC breach notifications themselves, or even offering bounties to insiders for credentials. Packet Labs' ransomware pen test simulates the full attack chain: phishing, lateral movement, and encryption attempts - showing clients exactly where detection controls should have triggered. Rogerson predicts ransomware will continue rising and stresses that companies must adopt continuous testing, tabletop exercises, and red team simulations rather than relying on any single security silver bullet. He uses MGM's breach and the Lapsus group as examples of how even well-resourced companies remain vulnerable due to the persistent human element.

Key takeaways

  • →Packet Labs' 24-hour penetration testing evaluation identifies critical vulnerabilities that standard scans miss by attracting staff with the passion and tenacity to grind through extended security challenges.
  • →Cyber insurance has inadvertently fueled ransomware by incentivizing payouts over restoration, causing attackers to price ransoms based on insurer cost-benefit calculations rather than actual victim harm.
  • →Ransomware operators now employ multi-layered extortion tactics including data theft threats, SEC breach filing, and insider bounty programs when traditional ransom demands fail.
  • →Ransomware pen tests simulate the full attack lifecycle - phishing, lateral movement, and encryption - to reveal detection gaps and measure how quickly security teams would respond to a real breach.
  • →No single security tool or insurance product eliminates ransomware risk; companies must continuously test, train personnel, verify controls, and run simulated breach exercises like fire drills.

Guests

Richard Rogerson

Topics in this episode

Cyber insurancePenetration testingRansomware attacksLateral movementPhishingData exfiltrationPacket Labsransomware insuranceencryption malwareSEC breach notification requirements

Questions this episode answers

What does Packet Labs do and how does their hiring process work?

Packet Labs delivers penetration testing services where they attempt to break into client networks to identify vulnerabilities. They hire staff through a rigorous 24-hour lab evaluation where candidates must demonstrate their ability to break into systems, designed to find the deep vulnerabilities that standard scans miss.

Why has ransomware insurance made the ransomware problem worse?

Cyber insurers often pay ransoms because it's cheaper than full network restoration, and attackers know this. Ransomware operators price their demands based on what insurers will pay rather than actual damage, creating a financial incentive that fuels more attacks.

What tactics do modern ransomware operators use beyond just encrypting files?

They employ multi-layered extortion: threatening to leak stolen data, filing SEC breach notifications themselves to trigger regulatory investigations and fines, and offering insiders bounties (10k-30k) for VPN credentials or passwords.

How does Packet Labs' ransomware pen test work?

They break into a client network, simulate phishing and lateral movement like real attackers would, then demonstrate encryption on test files to show where detection controls should have triggered and what the security team would have missed.

Will companies ever be secure enough that ransomware becomes obsolete?

No - even well-resourced companies like MGM with large security budgets get breached through the human element (social engineering, insider threats). Continuous testing, training, and simulated exercises are required to reduce but never eliminate the risk.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

There are a handful of genuinely interesting operational points - insurance carriers preferring to pay ransom over restoration costs, and attackers filing SEC breach notifications themselves - but these are surrounded by a lot of generic advice ('think like an attacker,' 'people are the weakest link,' 'test and verify') and extended product-pitch content. Insight-per-minute ratio is low.

the insurance providers, not all of them, but some of them, were actually preferring to pay out the ransom than to restore from backup or to restore otherwise. because it's more expensive to do the full rebuild from the ground up than it would be to pay out the ransom
the attackers have actually filed a submission to the SEC, notifying them of a data breach, sharing the breached clients information, and figuring the process for the SEC to do the investigation

Originality

7 / 20

The SEC self-reporting angle from attackers is a genuinely novel and underreported tactic worth highlighting, and the 'appraisal' framing for ransom pricing is a useful lens. Everything else - human element, layered security, fire-drill analogy - is recycled industry boilerplate with no contrarian or first-principles thinking.

the ransomware operators know this. So they're setting their prices almost like an appraisal when they get into a client network
One of the operators called Lapsus, what they were doing is actually offering a significant bounty to anybody who would give them keys to the kingdom

Guest Caliber

10 / 20

Rogerson is a working CEO of an actual penetration testing firm with apparent hands-on operational experience, which is more credible than a pure thought leader. However, the conversation skews heavily promotional for Packetlabs' services, limiting how much genuine practitioner depth surfaces.

we've had several clients that we've been in their networks for weeks before they've detected us
we put our staff through a rigorous 24-hour evaluation... they're given 24 hours to demonstrate, can they break into systems

Specificity & Evidence

8 / 20

A handful of real-world specifics - MGM's call-center breach, Lapsus's credential bounties with dollar figures, the SEC mandatory notification rule - add credibility, but quantitative data is almost entirely absent. Claims like 'enormous ramp of ransomware' and 'remarkable uptick' are asserted without numbers or sources.

if you look back at MGM MGM has a tremendous security budget and they they were breached through someone calling into the call center
Here's 10, 20, $30,000 if you just give me your password

Conversational Craft

5 / 20

The host asks broad, leading questions and consistently validates rather than probes ('That is nasty business, no doubt,' 'Important stuff to be sure'). There are no follow-up challenges, no pushback on vague claims, and the interview functions largely as a PR vehicle for Packetlabs rather than an interrogation of ideas.

I'm sure obviously there's a huge market for that
That is nasty business, no doubt. We need to protect ourselves from those folks, no doubt about it

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

ransomware23sure13insurance12network11vulnerabilities8demonstrate8client8breach8continue8test7understand6certain6data6clients6question6security6

Episode notes

The cybersecurity executive stressed the importance of constantly training company staff to help prevent ransomware.

Full transcript

16 min

Transcribed and scored by The B2B Podcast Index.

Hi, I'm James McGuire, and on today's eSpeaks, we're talking about ransomware and ransomware attacks, how to handle them, how to not handle them. And what about ransomware insurance? What's the deal with that? To discuss all that, I'm joined by a major industry expert.

With me is Richard Rogerson, Chief Executive Officer of Packet Labs. Richard, very good to head with us today. Thanks for having me. Really appreciate the opportunity.

Sure. So I know a lot of people know what Packet Labs does. Can you explain to us, what does your company do briefly? Sure.

So I head up a company called Packet Labs. And what we do is we deliver on penetration testing. And what that is, is we get hired by companies to attempt to break into them and understand where they're weak. What we'll do is we'll actually launch cyber attacks against the companies who hire us to help outline where they're weak and what vulnerabilities are in their networks.

and of course the priority which they should remediate them. That's really interesting. I'm sure obviously there's a huge market for that. And I thought it was interesting when you and I talked before, you talk about hiring personnel and you put them through quite a rigorous hiring process.

Can you talk a little about that and why that's important? Absolutely. So the hiring process that we have, we actually put our staff through a rigorous 24-hour evaluation. And what that is, is it's a lab environment where they connect into over a VPN.

and they're given 24 hours to demonstrate, can they break into systems? And this is really the rubber meeting the road of what can you do and how far can you get? A lot of times what happens in pen testing is you can find certain, discover certain vulnerabilities, but to actually drill deeper into them, you need to have the passion. And those who are willing and excited by the concept of a 24-hour challenge, they are the ones who are finding those vulnerabilities that may have gone unnoticed, the ones that keep us up at night or land in the newspaper.

They're the vulnerabilities that cause the critical data breaches. And we find that having a certain threshold of caliber of staff, having a designation that is the 24-hour exam, it really helps us stay up with the attackers and the motivations they have. As well, it helps us vet and make sure that the people we have on staff are incredibly passionate about what they do. Because it's so easy to throw in the towel and say, I ran whatever vulnerability scan.

And here's the results. But it's the folks that are willing to grind through a 24-hour challenge from 7 a.m. to 7 a.

m. in which sleep is completely optional to be able to demonstrate what vulnerabilities they can find in client networks. And that really has a tremendous differentiator from a reporting perspective. We find things and we ask these questions all the time from our clients.

How in the world did you find us? We've had other firms that have come in and done assessments, but they miss that finding. Why did you find it and they didn't? And it comes down to the passion and making sure that we're evaluating staff at that level.

And one of the other pieces that is very critical is we have this core value on our team. It's no egos ever. And it's very hard in our industry because you can get very far with having an inflated value of what you think you can find. but what it comes down to is the people who are willing to ask the questions to learn more and dig deeper they find way more vulnerabilities versus the ones that come to the door and say there's nothing more to find i know what i know they're not gonna learn anymore they're not going to be able to keep up you can't rest on your laurels especially in this type of an industry ever-changing every single day there's a new vulnerability that comes up and we need to constantly be looking and exploring and learning more about those things because they're constantly really changing and you just can't stay with them if you don't sure I mean totally understand that because there's so much at stake and some of the you know confidential information and the Cybersecurity you know wall so to speak that's it's it's really sacred to many companies of course because they're protecting their really the the corporate the corporate jewels what about the issue of of ransomware and obviously we hear so much about ransomware these these few years so many headlines What do you advise companies in particular And what about the idea of insurance Because I know that providers will offer ransomware insurance, but it's a very difficult thing.

What are your advice here? Yeah, so the question of insurance or non-insurance is always a difficult one. But I think it all comes down to understanding that security is really made up of layers. And it's really looking at things from different perspectives and making sure you have coverage.

So having insurance coverage, it used to be the simple question of, have you been breached and how many employees do you have? And that's how the cyber insurance providers were kind of doing that check. Well, now it's a five-page, double-sided question and answer, multiple choice, and it just keeps going. There's a lot of controls they're looking at.

And the problem with it is that in cyber, they don't have actuarial data as if they were an auto insurance. In the auto insurance industry, they know a Honda Civic will get a collision in a certain amount of frequency. The passengers will have a certain frequency of injury and all these things. Decades of data and some of that stuff.

Absolutely. Whereas in cyber, it was almost like they were writing the blank check. How many employees do you have and have you ever been breached? And we've kind of gotten to the sticky situation where the insurance providers, not all of them, but some of them, were actually preferring to pay out the ransom than to restore from backup or to restore otherwise.

because it's more expensive to do the full rebuild from the ground up than it would be to pay out the ransom. The ransomware operators know this. So they're setting their prices almost like an appraisal when they get into a client network. This is how much it's worth to restore versus this is how much we can get off this particular individual.

So they kind of do that check. And the insurance providers, they used to do that check to say what's more affordable. Are we going to pay out the ransom or are we going to pay to restore? and this this question is obviously it's fueled a wave of ransomware we've had an enormous ramp of ransomware where you pay out a ransom you're basically allowing or funding the next wave the next attacker that's targeting the next business and i think a lot of companies they struggle with how do you solve this problem do you wait to get hit or do you buy insurance and it's always a tricky thing but what it comes down to is you have to drill into your network and understand your network from an attacker's perspective.

You have to think like an attacker in order to understand what they'll be doing in your network to know what controls you should have in place back to the kind of the onion concept. What about, you also mentioned something about sometimes the attackers themselves will threaten to tell the SEC about a breach. And it's really a very exploitive, very cynical strategy. But what are the details on that one?

Yeah. So basically, there's been some evolution over the last little while where, you know, there used to be this concept of to pay the ransom or to not now the fbi has come out and said don't pay the ransom and if you do let us know now this keeps going and the ransomware operators saying well if i don't have a guaranteed payout how do i how can i ensure that they're going to pay well now they're getting to the next level of extortion in the initial stages what they were doing is they would get into a client network and they would say these are your crown jewels so they send them back to the company that was compromised and say, I have a copy of this.

I'm going to leak it on the web. And you get the timer that ticks down that really induces stress and anxiety and a whole bunch of other things. Now, if that doesn't work, the other angle is now the SEC has imposed this mandatory breach obligation. So within a short period of time, you have to notify the SEC that a breach has occurred.

And if you don't do it, well, obviously it opens the window for the attackers. And what we've seen recently in the news is the attackers have actually filed a submission to the SEC, notifying them of a data breach, sharing the breached clients information, and figuring the process for the SEC to do the investigation. And that comes with fines of its own So they almost playing this game of you know cat and mouse you know what are the things that I can do to get money out of you And there obviously different approaches they can take and this is just one of them That is nasty business, no doubt.

We need to protect ourselves from those folks, no doubt about it. Well, all right, so regarding ransomware, Packet Labs does offer a ransomware protection product, right? How does that serve customers? Yeah, absolutely.

So what we offer is called a ransomware pen test. And what that is, is we're actually trying to break into the client network who hires us, not just random on the internet. And once we get into that client, we're going to then follow the same steps that a ransomware operator would follow. So it's not to say that we would go in and encrypt the client's network.

That's not the case. But what we want to do is demonstrate phishing email into the company, getting onto an end user device, laptop, workstation, server, what have you. And then how do you move laterally to the other systems to get to what we would call the crown jewels? at that point what we'll actually do is demonstrate on on the desktop we'll create a folder put a bunch of fake files because there's files on there and demonstrate that we can encrypt those with our own malware so the purpose of this is to demonstrate that we're hooking an encryption routine to encrypt the drive or the folder the antivirus itself the actual controls that are on that server should be catching some of those things so what we're doing along the way is we're trying to trip all of the little alarm bells along the way to get to the final trigger where you would pull and deploy ransomware.

And what we're doing is we're showing them all of the different opportunities that they could have detected us. Moreover, we're actually drilling in to say, these are the different types of ransomware and how they move laterally throughout your network and the different tactics they would employ. How do you measure up against those? Do you have the right controls?

Are there gaps? What are the things that you should be considering? Because a lot of IT professionals and security professionals, they love tools. And we deploy all these tools and they're great and they have their purpose.

But it's the processes that we really need to drive home. We need to make sure that we're doing the right things and we have the technologies configured the right way. But it's not just technology silver bullets anymore. Like we don't have that.

That's not in our back pocket. We definitely have to do a whole lot of things at once. And when you go through and test yourself with a pen test, you get to demonstrate whether or not someone could break in and you get to learn what they did and how they did it and as well compared to your security operations team what should we have seen that would have detected this type of a breach what were the alarm bells along the way that should have been triggered and how quick was our response and that definitely helped the client understand how vulnerable are we to an attack what is the impact of a breach and what should we do be doing in the next couple of years to really shore up in our defenses.

Well, so that really means that when you start to work with a client, they may be pretty surprised because you, in essence, are saying, here's how an anonymous hacker could get into your network, could penetrate your perimeter. So I would imagine some of the clients are pretty surprised. Oh, we had no idea we were that vulnerable to attack. Absolutely.

And we've had several clients that we've been in their networks for weeks before they've detected us. And then we have it where we'll actually escalate our actions to make So we get noisy enough to get caught. And then what we'll do is we'll share backwards all of the things that we did and as well, the detection opportunities that they would have had to be able to catch us much quicker. So we do want to get caught eventually in our assessments because we're doing this to help improve security.

And as well, we're trying to outline all of the potential gaps that may exist because we all go and deploy technologies. But again, we don't know if they're enough unless we get breached or we bring in someone to simulate a breach. which is what a pent-up delivers on. Right.

Well, I think the big question is the future of cybersecurity and ransomware, because many companies want to be doing what they can now to get ready for that in the future. So as close as you are to the market, what do you see? What do you predict for the future of ransomware and cybersecurity? A couple years out two three four years out what going to be going on and how can companies get ready for that now Yeah great question So the future of ransomware I think it definitely going to be on the rise I know we already seeing a remarkable uptick in ransomware and the amount of attacks that we seeing as well as amount of clients who are being impacted by ransomware.

And I think that trend is going to continue. The whole cash for data kind of thing, it's going to continue to persist. but what clients need or which customers really need to be looking at is how do we make sure that our network is secure how do we test but verify that we have the right controls in place and a lot of that comes down to you know going through a simulated exercise to understand what you would do in a breach sometimes it ends up being a tabletop exercise sometimes it ends up being like a red team style exercise to demonstrate hands on keyboard how far could you get could you get to the crown jewels how would that happen what should we have done answering a lot of those questions and I think that's going to continue to build and we're still going to have this cat and mouse game of is our antivirus capable of detecting but you always need to test and verify and I think a lot of the attacks what we've seen over the past few years as well to forecast the future they all pry on the human element we're all humans by nature we all have the desire to do the right thing, to help the urgent case that comes up over email, the boss that needs the gift cards and all these sorts of things.

But what it comes down to, we have to train our people. That's going to continue to be a common theme is the people end up being the weakest link. Isn't that the truth? I mean, the people who put their password on a sticky and tape it to their PC, they might be part of the problem.

But at any rate, I mean, do you think they'll come a time where ransomware is is largely obsolete because companies of a certain stature companies that can really afford it can at least really get to a level of cybersecurity where ransomware is a thing of the past or or not necessarily I don't know like I kind of look at some of the the data breaches that we've seen you know if you look back at MGM MGM has a tremendous security budget and they they were breached through someone calling into the call center so it comes down to the human element, you have a number of security controls, but if you're not testing and verifying and having all of these other processes in place, it's very easy to continue to have those mistakes happen.

Even with the most secure companies, the human element is still there. One of the operators called Lapsus, what they were doing is actually offering a significant bounty to anybody who would give them keys to the kingdom, right? Like if anybody can give them VPN access or credentials into a network, you know, pay to play. You think about, you know, the opportunities they may have there.

Well, here's 10, 20, $30,000 if you just give me your password. Who knows how you got it. So it ends up being quite brutal from that perspective. But, you know, we're going to continue to have the human element as far as the vulnerabilities go and as well as in the technical landscape.

There's going to continue to be vulnerabilities that are there. So I don't know that there's anything outside of like going through an exercise consistently to really prepare your team for this type of an incident it's going to continue to be a common theme that everybody needs to always test but verify sort of like the whole fire drill thing like in the early days when we didn't have a run a fire drill to make sure that everybody gathers in the right place of the parking lot it was chaos we didn't know what doors to go out we didn't know what to do but when you go through the process and you go through the structure of making sure that everybody does know and running simulated drills to see what they do and make sure they're doing the right thing.

Then you have an opportunity to help reduce the potential for anything like this happening. And that's what, you know, a pen test would do as well. Important stuff to be sure. Richard, I think you said it, a lot of good material.

I definitely learned quite a bit. Thank you so much for sharing expertise and please come back and talk with us again sometime. Thank you. It'd be my pleasure.

Thank you.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Why “Cyber Is Broken”, And Building Trust in an AI World - Karl Van den Bergh CMO IllumioCyber Go-To-Market Talk · on Lateral movement87 / 100
  • Secure AI Starts with EducationBuilding Unbreakable Brands · on Phishing86 / 100
  • Tax Time 2026: How ATO protects your financial dataWith Interest · on Phishing85 / 100
  • Pursuing strategic partnerships to tackle Cobalt Strike abuseHealthcare Strategies · on Penetration testing85 / 100
  • The Internet Will Never Be This Secure Again, IEEE's Kevin Curran on AI and CybersecurityThe Business of Cybersecurity · on Penetration testing81 / 100
  • Insurance Without the BS - What Founders Actually Need to KnowThe Fractional CFO Show with Adam Cooper · on Cyber insurance81 / 100

More from eWeek eSpeaks

All episodes →
  • Chronosphere’s Ian Smith on Cloud-Native Observability
  • Zoho’s Vijaykumar Rajendran on Workplace Collaboration Trends
  • DataRobot’s Venky Veeraraghavan on Building Enterprise AI
  • Persistent Systems CTO Pandurang Kamat on Generative AI in the Enterprise
  • Portal26’s Neil Cohen on the State of Generative AI 2023 Survey
Explore the best B2B AI & Data podcasts →
All eWeek eSpeaks episodes →