
LevelUp Cyber · 2024-11-12 · 34 min
Key moments - from our scoring
Substance score
57 / 100
Five dimensions, 20 points each
Small businesses often believe they're too insignificant to target, but James Bierly challenges this misconception, emphasizing that any internet-connected entity is vulnerable to attacks like phishing emails. The discussion centers on practical, budget-friendly security fundamentals that don't require extensive resources. Bierly advocates for starting with a trusted technical advisor who understands hardware and security - someone like a lawyer or accountant but for IT decisions. Multi-factor authentication emerges as the single most important control, though SMS-based methods suffice for small operations. Beyond MFA, layered endpoint protection (antivirus plus additional security controls) provides defense-in-depth similar to car safety features. Password management can range from written notebooks kept securely to tools like LastPass or 1Password, depending on technical maturity. Security awareness training works best through conversational facilitation and peer-to-peer learning rather than punitive phishing simulations. Finally, cyber insurance protects against catastrophic financial impact from breaches, though honest questionnaire completion and understanding terms like EDR (endpoint detection and response) and BCDR (business continuity/disaster recovery) are critical for proper coverage.
Multi-factor authentication requires multiple forms of proof beyond just username and password - such as a code texted to your phone, a fingerprint, or a hardware token. It prevents attacks because even if attackers steal your password through phishing, they cannot access your phone or biometric data, making unauthorized login extremely difficult.
Layered protection provides multiple barriers; if one security tool is bypassed or fails, other layers detect and block threats. This is like having brakes, airbags, and seatbelts in a car - each adds redundancy that increases your chances of stopping an attack.
Password managers like LastPass or 1Password are ideal if the business is technically mature enough to adopt them, but even a handwritten notebook stored securely off-site beats storing passwords on your desktop. Attackers routinely search computers for 'password' files, so written records in a safe location are preferable to digital shortcuts.
Avoid punitive phishing simulations that embarrass employees; instead, facilitate conversations where peers share how they spot suspicious emails and explain red flags like urgency tactics or authority impersonation. This builds security culture through positive peer influence rather than fear.
Businesses must honestly answer questionnaires about security controls like EDR, BCDR, MFA, and endpoint protection, and ensure these are actually implemented. Insurers will deny claims if stated controls don't exist or weren't documented, so verification and accurate reporting are essential.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode covers five practical cybersecurity practices (MFA, asset management/endpoint protection, password management, security awareness, and cyber insurance) with reasonable specificity and actionable advice. However, much of the content is introductory-level best practices that B2B operators would likely have encountered before. The password notebook suggestion and phishing culture approach offer some freshness, but substantial portions involve explaining basics (what is MFA?) rather than introducing novel frameworks or counterintuitive insights.
multi fact authentication is really just that blanket term. So you already have you know, in most scenarios, you already have you know, a couple factors of authentication your username, your password
I would add a tech person, and I won't I won't disparage you know, like a developer or anything like any particular area of tech. But find somebody that understands some hardware, understand some security
The guest reframes employees as the 'largest attack surface' rather than the 'weakest link' and advocates for conversational security awareness over gotcha-based training - these represent thoughtful departures from conventional practice. The password notebook suggestion for small businesses is pragmatic and somewhat contrarian. However, the core five practices (MFA, endpoint protection, password management, training, insurance) are well-established industry standards. The thinking is sound but not particularly fresh or counterintuitive.
They're not the weakest link. They are instead the largest attack surface
trying to have conversations about uh security awareness. In the past, I've I have done a phishing on a on a customer, and I keep the results to myself, and then I invite, you know, half the half the company to come have coffee
James Bierly is the founder of Secure Point Solutions and has 10+ years in IT/security work including MSP risk assessments and managed security. He is a practitioner with hands-on experience at small-to-mid market scale, which is relevant to the episode's stated audience. However, he is not a recognizable industry figure, has not scaled to enterprise level, and his background lacks the kind of visible proof points (notable clients, published research, speaking circuit presence) that would mark him as genuinely top-tier. He is solid and relevant but not exceptional.
a little over five years ago I formed Secure Point Solutions, and our idea is to help the smallest of businesses
Worked you know, CIS admin type things. And then a little over ten years ago I got hired on to a managed service provider to do kind of risk assessments, network assessments
The episode lacks concrete numbers, named companies (Target is mentioned generically), specific dollar figures for insurance costs, or detailed metrics. Examples are mostly illustrative rather than evidential: a walnut fudge brownie recipe, a coffee shop owner, an elderly lady, and generic references to 'enterprise' breaches. While the advice is practical, the absence of named tools (except vague references to LastPass, 1Password), specific breach case studies, real customer outcomes, or quantified security metrics significantly limits specificity and credibility.
You know, could this be the end of your business if you don't have that sort of insurance there to make you hole Again. As we were talking here, you know, even the reference you you gave the example of Target, right, a Target had a breach
if you can, working with your your trusted technical advisor, you know, whoever, you know, start looking at insurance companies start working with companies that can provide platforms as maybe to simplify the process
The host asks competent, often softball questions that allow the guest to deliver prepared talking points with minimal push-back or deeper probing. Few genuine follow-ups challenge the guest's claims or explore nuance; instead, the host frequently affirms and transitions to the next topic. Questions like "what is multi factor authentication?" are accommodating rather than pressing. The host does add some texture with personal reflections but rarely uses questioning to test assumptions or expose gaps in reasoning.
I'm gonna I'm going to change it up. We had five. I'm going to change our sixth to the fifth, and we'll put a little bow on. At the end
So I really like the advice, and my only piece I would add is, you know, make sure to James point answer the questions properly
Computed from the transcript - who did the talking, and the words that came up most.
In this special episode, host Tony Bryan sits down with cybersecurity expert James Bierly to discuss the top 5 best practices every organization needs to adopt to stay secure in today's digital landscape. From proactive threat detection to strengthening data protection, Tony and James break down actionable strategies that can protect businesses from costly breaches and cyber threats. Don’t miss this deep dive into essential practices that could make all the difference for your organization’s security.
Transcribed and scored by The B2B Podcast Index.
Good afternoon, and welcome to this week's episode of Level Up cyber My name is Tony Bryant, host and executive director over at Cyber Up. We're gonna have a really fun discussion today. I just had an opportunity to reconnect with James today and we're going to jump into something I think that is relevant to a lot of things, and I know something very near and dear to my heart, which is, you know some best practices of how we help small to mid sized businesses look at their security best practices and how they can do things.
Sometimes even on a shoestring budget, which is hard. Right when you're trying to prioritize your growth of your organization and some of the security stuff. So we today's guest, James Byerley, founder over at Secure Points Solution, is a small business expert and has a lot of passion towards a subject. So excited to dive into it with you today, James, So thank.
You, so yeah, thanks for the opportunity. So you and I had a chance to catch up and get going for the show. But I'd love for you to tell everybody a little bit about yourself, a little bit about your company and how you got to where you're at in your career. Yeah, absolutely so I was.
I was in the Navy for ten years and really no marketable skills that I could bring here. So I actually found some IT work overseas, which eventually enabled me to come home and find a job that didn't require me to be somewhere hot and sandy or out on a boat and. Worked you know, CIS admin type things. And then a little over ten years ago I got hired on to a managed service provider to do kind of risk assessments, network assessments.
From that point I really started to kind of dig into how you assess risk for small businesses, security testing, things like that. And then a little over five years ago I formed Secure Point Solutions, and our idea is to help the smallest of businesses. A lot of MSPs have minimums and there are a certain subset of small businesses that kind of get left in the cold. So at the very least, we can provide them a managed security solution to better protect them from the outside mayhem and then provide them a little bit of technical advice on when their computers are acting funny things like that.
That's a great, great information, So I'm excited about today because I think we had a really kind of cool agenda ahead of us, right, And I'm a fan of keeping things simple, and I know that there are a lot there's i would say misinformation, but there's a lot of ways in which you could crack this stuff right to really look in to build it out of security department or program or even just some policies right for your So we're going to spend a little bit of time talking about the top five things or ways that small business can work to protect themselves, right.
And so with that in mind, the first question up is when when should I start looking at these things? Right? You know, like I know I've heard it and right before we hopped on you heard it right, Like I'm too small, I don't have any. Risk, nobody wants my information.
I'm not that important. But you know, in your opinion and through the years of work of supporting a small businesses, you know what what have you seen and what would you advise is when to start looking at building a security department. So really, if you've started business, if you are going to start a business, they always say, you know, find a lawyer or find an accountant that you can at least go to with the problems. I would add a tech person, and I won't I won't disparage you know, like a developer or anything like any particular area of tech.
But find somebody that understands some hardware, understand some security, somebody that could help steer you in the right directions. That way, you don't go to the big box stores and you buy the worst possible laptop ever, or you buy products that are just known not to be great. So really getting getting somebody to kind of help be a trusted advisor is that first step. And then kind of in conjunction with that is knowing that no, you are not too small to be you know, attacked or targeted.
You have email email. I mean I could be in Antarctica and I could send you a phishing email if I so choose to. So the globalness of the internet makes pretty much anybody connected a target. It's a great answer.
So next thing up, you know, what is the single thing that you think is a pretty solid place to start for any small to midside businesses that that is a non negotiable you should at least at a minimum start to do these types of things. Oh Man M f A all the things, you know, if you can, if you can put multi factor authentication on UH, you know, all of your business, web apps, your you know, even your computers if if you're feeling a little froggy, you know, yes, UH, passwords are important, and we'll talk about that, but the m f A part really is.
The big thing. And and don't people shouldn't get hung up on the method. Yes, we know that SMS based UH two factor is not all that great, but if you're trying to help, you know, your favorite barista at their coffee shop, understand a little bit about security risk, it's it's perfect start right there. You know, Hey, you don't want to install an app, you don't want to use your fingerprint or anything cool?
Can you you know, can you let the phone get a text message with a code and then following that up with a little bit of training to understand that if you didn't try to log in that code or that thing should never fire. You know, we see a lot of. The the m FA fatigue where they'll spam the alert and hopes that the user just says screw it and you know, accepts it. Know that, you know, unless you are trying to log in that's not going to go off, and that's a that's a big piece to it.
Yeah, just for for a point of just a think clarity, will you drive dive in a little deeper to the what is multi fact or authentication? And oh and like just the in. And outs of how it works, right, because I think I think a lot of people understand or have a similar concept. But I know for me, just through other instances, I've like, oh crap, I recognized why it is so important and why it does prevent some of those things or how more importantly.
How it does. Yeah, so multi fact authentication is really just that blanket term. So you already have you know, in most scenarios, you already have a couple factors of authentication your username, your password. But then other steps that will go beyond that are, you know, providing additional information so something you know, something you have, and maybe the form of a physical token, a set of codes that are on your phone that you type in.
You know, even even as far as maybe a fingerprint MFA can even be kind of set up to be geospecific. So I know a lot of time card systems kind of do that where you can't necessarily try to clock in from the from the parking lot because you're not close enough, or you're not on the right network, things like that. So really it's just an extra step that somebody should be able to get because it's actually in your possession, that phone, that code and whatnot. It's something that shouldn't be able to be stolen by by an outside threat.
They can maybe get your password because you've used it in a variety of places, or you got phished and didn't realize it. They can probably get your email or your user name. Those are not difficult things to get that often. But the you know, getting physical access to your phone or a fingerprint, you know, unless somebody's going to steal your thumb or something, you're you're probably safe there.
I have been reading books lately that that's as a way to get into phones, right, But that's another there. Don't steal thumbs is probably a moral to some story of there. Right, So we moved to the second aspect of this, Right, what is another you know, non negotiable kind of step that you would. Recommend for a small business to to.
Embrace having having good asset management? Uh, and kind of with that, you know, some endpoint protection. Uh. We we see a lot of times, you know, a company will go out and they they buy a five pack of you know, whatever av popped up in their search, and they kind of leave it at that.
And so we will talk with them and say, all right, you if we compare this to like a car and two car safety will say, great, you now have a car that has brakes and you don't have an airbag or seat belt. We can all agree. You know, I know people who don't like seat belts. I know people who don't like air bags.
Everyone's got an anecdote if somebody, you know, not making it because of one of those failing. But by and large, the more layers of safety you have, the better outcome you have in an event of an accident. Same thing with security within reason. If the attacker bypasses your antivirus and there's something else else there to protect it, that is awesome.
And that's something that we do with our own clients. But we we even do talk to businesses that you know, if they maybe for whatever reason, do not want to work with us, and we just say, hey, not a problem. We can give you a couple of suggestions on things that you can implement and if one gets bypassed or stops working all of a sudden, the other one can pick up the slack, even if it's just an email to the owner of the company saying, hey, something something wonky has happened.
So I think I think that is a piece that it's not it's not super hard to enable, but nine nine percent of your business owners are probably not going to make that leap. You know, They're like, well, I just left the store with the license pack of AV what else do I need? And it's like, well, you need a lot more? Yeah, good I Another part we have talked about a little bit is aligned with that two factor authentication is you know, what are tools or you know what, how are we making sure that when our employees do log in with the credentials, that we're providing the some tools Because I don't know about you, I have nine million passwords that I've got a store at this point, you know, for all the different technologies and software, which they're great, but at the same time, you know, we we want to use different passwords.
We want to be secure, so you know what are you know, we talked a little b about pastor management. What would what advice would you give for those small businesses to create some policies or maybe tools for that. Yeah, I mean, find a find a password management solution that works for you. If you're if you're just a solopreneur and you maybe don't really want to get burdened down with, you know, buying a software solution and all this.
I some people are going to get really upset with this, but I'll also contend that those people are not security mature enough to. Think it through. Just get just get a notebook. You know, the password notebooks that you see at Walgreens and other stores, and you see them every so often on social media where people trying to make fun of it.
Well, first off, there is not a big label that says password notebook. That's a sleeve that removes. The book just looks very nondescript from the outside you open it up. Some of them have kind of pre filled fields for you to add stuff.
Do it that way. If if you're a small business or you know, and it's one or two people and you have credentials that are important, just just write them down and put them in kind of an out of the way place. Most of us, you know, if you have a brick and mortar office and somebody breaks in, They're not going to hunt down your little black book. They're going to grab whatever that they can carry and run out of the store, whether that's your computer tower, that's whatever widget that you make.
You know, I said resta's earlier. You know, if they've run off with a with your coffee machine, you know that, Uh, that's what they're gonna target. And same thing even if you're working from home. Somebody breaks into my house, they're not going to make their way into my office and grab a notebook that I have, because the alternative of trying to do password management in sort of a written form like that usually ends up being the passwords that are on the computer desktop.
And then when you know, if that user gets compromised, a good a good attacker is going to start trying to find creds for other stuff. I know when we do security assessments any computer that we touch, the first thing I do is I search you know, wild card, password wild card and see if anything shows up in there, anything that's useful. So if I'm doing it, I'm. Going to guess a lot of attackers you're doing it.
And now that gets you, you know, access to a cloud, password, access to banks, access to probably everything else for that business. If you're a little more advanced, Yeah, like you know, talk to your tech friend that you should have gotten when we talked about the first step, you know, say hey, can you show me how to use or set up last pass, one pass, whatever the case may be, and and and start implementing that as well. Uh So, you. Know, we've we've tried to make these technologies easy, but we also recognize that there's gonna be people that are still not going to adopt it.
And don't be afraid, you know, if you are that technical practitioner and you're giving somebody advice, don't be afraid if you know them well enough to say, hey, you know what, I'd love to put one password or something like that on your on your phone and your computer and all this, but I think this is gonna throw you off. Uh, let's go get you a notebook and and we talk about creating passwords. Uh. So I've helped the number of you know, elderly people in our in our own areas, you know, in our own communities.
And I had this sweet little lady who she. Was talking about you and she says, well, do I need to just write down a bunch of scrambled things I said you could do that. Or do you have a favorite cookbook? Do you have like ten favorite recipes?
Write down? Use those Your walnut fudge brownie recipe that you love is now your password to your Facebook so you can keep in touch with grandkids. It's probably going to be strong enough to keep most people who want to break into a little old lady's Facebook account. You know, it's going to keep them.
Out walnut brown I like it. I like it so so so far we've gotten right, have a good IT friend, you know that you can lean into or trust it in sigly error. Right, We've got a little multi factor two factor authentication and some password management, so kind of moving forward into that now, you know, I'm going to tee this one up with. A softball if I can really well.
Right, So, you know, now we've got a couple of tools, and so we really want to be, you know, create this culture of security. Right, so there's really only one good way to start kind of getting people involved in understanding you know what, what's your hot take on kind of security. Awareness for for orgs? And you know, what what's some good best practices you would recommend for those?
So I think security awareness when it's done right, is amazing. I think the you know, send a phishing email and then it becomes a gotcha moment and the person gets signed up for twenty minutes of video. That's not the way you build a security culture. And also a lot of the security training itself is dry and terrible.
So how I've approached it in the past is trying to and obviously smaller businesses it's maybe a little bit easier, but I've also seen this work at the at the enterprise level, but trying to have conversations about uh security wareness. In the past, I've I have done a phishing on a on a customer, and I keep the results to myself, and then I invite, you know, half the half the company to come have coffee and we sit down, you know, we we swap some stories, bs around a little bit, uh.
And then at some point I will pull out the email and maybe I've enlarged it, and I don't ask the person that I know click the link or typed in their creds. Not knowing better, I asked the person that actually like reported it or or you know something that caught it And I say, you know, hey, Brian, where did you where. On this email? Did you know that it was jacked up?
And they'll say, oh, well, you know the grammar was or I noticed the email address didn't actually come from the CEO and uh, things like that. And so instead of. Meat teaching or lecturing, it's now Brian from marketing who is sort of telling his peers how he saw it, and I'm just there to facilitate the conversation. And what we find when we can do those at more of a personal level is that now Brian from marketing is almost are like tears zero responder to phishing.
The person that sits next to him will say, hey, Brian, this. One looks weird. Did you see it? And Brian can say, yeah, that's that thing is crap.
You should send that to Secure Point Solutions and let them, you know, do some hunting or something. And so having more of a conversation and asking a person what they know about fishing, explaining to them, you know, the two real big things that you know, especially when we talk fishing, you know, is that that sense of urgency that a lot of phishing emails creates you know, you your account is going to get cancer old, you, you're going to get billed eight hundred dollars, all of those to try to get you off balance.
But then also that sort of false sense of authority. You know, where the where the I R s? Where the where your IT shop? Helping people understand that hey, those are you know, those are the things that are there that are trying to trip you up.
Because we as human beings, we are naturally helpful. So when we get that email or a phone call, we want to we want to help the person on the other end because that's kind of our natural tendency. It doesn't make us weak. Please don't, please don't refer to the humans in a business as the company's weakest link.
They're borrowing from a bryce and board with sythe He once said that they're not the weakest link. They are instead the largest attack surface. And I think that that's a much better way of messaging it, to say, hey, your your employees, there's so many ways to get to the phone, chat, email, all of those things that they're bombarded with risk and you know they they have to make those decisions, but it doesn't make them weak and but yeah, training them and talking to them as human beings and not just throwing a bunch of jargon at them.
That's that's kind of how you build a good security culture. Well, I think you know, you alluded to it a second ago. You know, if you're making it have a negative connotation where it's a you know, no, you mess up, you're. In trouble, there's some form of remediation, right.
I think there's most security teams. In a lot of companies already have that, like, oh my gosh, here comes James down the hall. We got to go to the other side because these we're going to get in trouble for doing something right, there's this stugument. Now you're you know, to your point by reinforcing that with negative reactions or making it as a no tolerance type of thing, and you're really not creating a culture of security.
You're creating a culture of fear, and people are bound to make more mistakes with that fear other than just you know, well I don't I don't want to get in trouble for bringing this to James attention, So I should probably go somewhere else and just ignore it, and I'll somebody else will take care of it, and then somebody else doesn't and then bad things happen. So really really good advice. I'm gonna I'm going to change it up. We had five.
I'm going to change our sixth to the fifth, and we'll put a little bow on. At the end. So we talked a little bit around the idea of insurance. Right.
You know, companies have lots of insurance requirements, whether it's errors. And omissions or general liability. Right, but there's now this new, fancy product of cybersecurity insurance, and there's a lot of newness and uncertainty, and I think fear of just the cost because it can be expensive, right, But there's also some goodness to it that it protects businesses and it really helps. But there's some parameters I think that are important that I'll go in line with number one through four we just talked about in these top five, Right, So you know, what's your recommendations for businesses that are looking you know they've done some of these one through four steps.
You know they want that actual air of protection insurance is there. You know, what are some things they should start doing to prepare to get to prepare themselves to be ready for insurance. Who to reach out to for insurance, like, I don't know ballpark cost is of you know, what they should expect to pay. Yeah, when you're when you're dealing with you know, cyber risk insurance, you know, because of that newness, and also because it's an area that even the insurance companies aren't fully aware of what these terms are.
You know, we we hear EDR endpoint detection response, you know, the insurance Uh, the insurance company, they may have some people who can explain that and what that actually means. But then at the same time you have to then look at a product is like is this an eder or is this something else? And so when we talked about you know, car safety and seat belts and everything, anyone, anyone that's ever really sat in a car would understand what a seat belt is and they would understand what a seat belts expected to do.
Same with all the other safety features. Of a car. But it's kind of the wild West of insurance. So advice for getting yourself, you know, into that spot.
You know, if if you can, working with your your trusted technical advisor, you know, whoever, you know, start looking at insurance companies start working with companies that can provide platforms as maybe to simplify the process. It's something that we do with our customers, is you know, instead of just like taking the questionnaire and either answering it for them or making them have to slog it out, we have we have something that we can kind of a middle ground there to make it a little easier.
But go through it, Go through and answer the questions and be honest and and you know, don't be afraid to ask your your tech friend, you know, hey, this is asking if I have a B C d R, what the heck does that even stand for? And then building off of those things, because the one thing is like, especially with the insurance industry, is I'm I'm old enough to remember when I bought a car, I had to not only did I have to give my insurance person a my VEN number, but I actually had to tell them, you know, like the color of the car, how many doors it had, because we didn't have like that kind of database thing.
Businesses are pretty much just in that same space there where everything is very different. But if you if you're concerned about a slip and fall inside your office or store, you probably should also be concerned about, you know, what could happen in the event of a cyber attack. You know, could this be the end of your business if you don't have that sort of insurance there to make you hole Again. As we were talking here, you know, even the reference you you gave the example of Target, right, a Target had a breach.
You know, there were lots of layers to that, but you know it's Target. They didn't there there was no downtime, the store stayed open. You know, they're they're worth a few billion dollars. But you know mom and pop, you know, coffee shop or you know, restaurant down the street.
You know that's a oftentimes could be an insurmountable kind of recovery process for them that that's going to put them out. So I really like the advice, and my only piece I would add is, you know, make sure to James point answer the questions properly, because of an intent of any insurance company, health or any type of product is to not pay. And so if you're not following the rule, is it not putting in the information in the right way. They're going to use any reason they can to make sure they're not paying.
So you know, it's a great segue to kind of the final question here outside. Of the repeatable question, is you. Know, how do I know we've done all these things where we're going okay, you know, when I got this like nagging thought on the back of my mind, am I doing enough? Right?
So? When would I know I need to go to somebody, whether managed service or managed security service like secure point solutions? Like when do I know when I need that next layer of help and to bring in a professional to give me that assistance. I would say, just from an overall standpoint, is when you maybe find yourself having to help the rest of your business, the rest of your team with issues, or you're having to start pinging your friend, your advisor, and it's not things that can be handled you know, after your tech person gets off from their their day job.
You know, I've seen a lot of companies try to drag that out and they say, well, our tech guys not available from eight to five because they have a regular job and you know, we can't be broke that long. If there's a problem, that's probably a good sign of when you need to, uh look at those things. You know, since we work with companies, you know, as small as one user and all the way up. You know, I'll tell I'll tell a business anytimes the perfect time to like come to us.
But if you're if you're at if you're worried about like at your size, at your you know, whatever the case may be. You know, I think when you start being pulled away from you trying to do the job, especially if you've already like pushed off bookkeeping. If you're the owner of the company and you're not doing bookkeeping, uh, consider yourself lucky. And that's probably a good sign that maybe you could look at not having to worry about your tech and start outsourcing those things to other other companies.
Like it working? Well, what is the adage it's better to work, especially if you're lead on the business, not in the business. And that's a great example of you know, ways to defer expertise to somebody else. Uh.
Absolutely, this was an unscripted question here, but it's I think it's going to be okay. You know, like not all of these organizations are company to created equally, So you know, what what should we look for, you know, when we're trying to find a partner to come help us with their I, T and technique. There's some kind of simple guiding principles here and maybe not, but you know. We can make them up as we go, right.
Yeah, if you're you know, asking asking that provider, you know, if they have experience working with other businesses in your industry, that's a good a good start understand and provide them your expectations. I'm actually offboarding a customer because there's some you know, expectations that just through no fault of our own, we're not able to uh satisfy, and maybe we didn't understand that going into the situation. So those are a couple things that I always always suggest when they're looking for some sort of provider, be honest with your pain points, if or even your concerns.
Those are the those are how you can maybe find the right fit for you. It's great advice. So everybody gets the last question. It gets the same last question.
What advice would you give to somebody looking to level up their cybersecurity career? Okay, so whatever you're doing, if you're if you're aspiring Blue team or Red team er, uh, if you are trying to break into your first job, if you're trying to make that leap to you know, a senior engineer type role. Write about what you're learning, work on your work on your writing and communication skills. We we do things for the companies and you know, and for our whether it's our own company or other companies, whether you're pen testing or you're defending a network, and the cool stuff that we do, like hey, I you know I got I got a shell on this customer and I didn't think I was going to.
You're going to get a high five for that, but you're not going to get paid until you have actually written the report and you've written it to a level that explains what you did, what the impact was, and it's it's something that's understandable by whoever you're hating it to, whether that's your the CSO of a company, or it's the office manager of a dental office that wanted you to do some testing. Write things, get yourself into doing a little blogging. It doesn't have to just be walk through after walk through of like try hack me or hack the box.
But. Just show that you can communicate things to people, because you know, I can train somebody on using our tooling, but if they can't communicate to the rest of the team or they can't communicate to our customers. That's that's something that I don't really have the ability to train you for. I have this.
I've asked that question precisely one hundred and fifteen times. That was the first time I got to answer. But I really like the idea of just the writing because I do know it's one of the most complicated things, is to be able to explain the top a complicated subject to somebody who may not understand it. And the more muscle memory you're able to create for that is a really good example.
So that's that was fantastic. It might be one of my top three answers. By the way, about question, I really like it because it is hard, right, especially you're trying to break in to show understanding or show your work, and you know, blogging and writing is a pretty simple thing to do. And if you know, we're gonna I'm gonna SA a bad word.
But chat GPT is a great way if you feel like your grammar stinks, right, like, write what you know how to write and then put it into a chat GPT to help make it a little better. And the more muscle memory you do for those things that they're off, you're going to be and your consistency and formatting is. Going to get better. So I really like that answer, Man.
You made my day on that one. Good good It's it's one of those that I am, you know, a big fan of because you know, as I was leveling up myself, I always knew him like, I'm maybe not going to be the smartest person doing whatever task, but if I can explain the task and it's impact and everything else, whether it's to a CSO or an office manager at a small business, then I'm probably going to be able to continue to have a job. Yeah, absolutely well, James, Man. One, I appreciated the conversation and the advice.
I mean, so it is a great list of five things that I think will resonate with folks. And you know, I think that the footstoff for me is none of this stuff that you described is easy or hard difficult to do. And there's a lot of cost effective tools out there for that small to mid sized business that works right that you know you can tap into for some of this stuff. And if you you need help right reach out to the James of the world, and I'm sure that they're happy to help.
You with secure point solutions. But at the end of the day, you know, make sure you're you know, doing the best that you can. Always try to learn and grow and do some writing. I like it, so James, thanks so much for joining us today.
I mean, I you know, we're winding down the calendar year. We're winding down shows. It's exciting to see, you know, as we look ahead to the next year of all these opportunities. But what a better time to start looking at this stuff is you know.
Things get slower of the holidays and you know really tap into you know, looking. At these best practices. So thanks for sharing them with us, and also I appreciate you for tuning in. Until next time, everybody, have a great week.
Thank you so much. Fine out MHM.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.