The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Simplifying Cyber
Simplifying Cyber artwork

Part 2: Swords, Subpoenas, & Software

Simplifying Cyber · 2026-06-23 · 29 min

0:00--:--

Key moments - from our scoring

Substance score

36 / 100

Five dimensions, 20 points each

Insight Density7 / 20
Originality6 / 20
Guest Caliber9 / 20
Specificity & Evidence7 / 20
Conversational Craft7 / 20

Drew Tharp brings a unique perspective to cybersecurity by drawing parallels between fencing strategy and cyber defense. As an attorney who has worked with Fortune 500s, multinationals, and startups on contract management systems, he identifies three critical concerns in biotech and pharma: protecting intellectual property from corporate espionage (not just data theft), navigating problematic Business Associate Agreements (BAAs) that slip onerous legal terms into ostensibly low-risk data sharing agreements, and applying strategic thinking from fencing to cybersecurity. The episode introduces the four-quadrant fencing model - distinguishing between passive/active and defensive/offensive strategies - arguing that most organizations focus only on aggressive offense and passive defense while missing opportunities in aggressive defense (called "second intention" in fencing) and passive offense (the "press"). Drawing on examples like champagne sabrage and contract negotiation, Tharp illustrates how understanding opponent patterns, reducing internal pressure, and applying fencing principles can improve both cybersecurity posture and legal outcomes. Healthcare organizations, facing intensified ransomware and business email compromise (BEC) attacks since COVID, are particularly relevant case studies for these principles.

Key takeaways

  • →Business Associate Agreements often embed onerous legal terms (limits of liability, indemnification, subrogation) into ostensibly low-risk data sharing agreements, exploiting IT personnel's unfamiliarity with legal language to extract significant rights.
  • →The four-quadrant fencing strategy (passive/active combined with defensive/offensive) reveals underutilized approaches in cybersecurity: aggressive defense (second intention) and passive offense (the press) offer alternatives to the typical aggressive offense and passive defense focus.
  • →Breaches typically exploit a seam (vulnerability) combined with internal pressure (urgency, social engineering, business panic) - reducing organizational pressure and identifying seams mirrors the champagne sabrage analogy of pressure, seam, and one clean strike.
  • →In biotech and pharma, many breaches target intellectual property through corporate espionage rather than simple data theft, requiring different protective strategies than traditional healthcare data breach prevention.
  • →Understanding your counterparty's past behavior, negotiating patterns, and pain points - whether in contract negotiations or cyber incidents - allows anticipatory, more effective responses similar to reading an opponent across multiple fencing bouts.

Guests

Drew TharpTodd Wilkinson

Topics in this episode

Four-quadrant fencing strategyBusiness Associate Agreements (BAAs)Corporate espionageIntellectual property theftChampagne sabrage (sabering)Second intention (fencing)Healthcare cybersecurity threatsRansomware and BEC attacksContract negotiation strategyHIPAA compliance and healthcare pressure

Questions this episode answers

What are the main contractual risks in Business Associate Agreements for healthcare companies?

BAAs often contain onerous terms like liability limits, subrogation, and indemnification clauses designed for sophisticated legal agreements, but these are slipped into ostensibly simple data-sharing agreements where IT personnel lack legal expertise to negotiate them away, resulting in organizations signing away critical legal rights.

How does the four-quadrant fencing model apply to cybersecurity strategy?

The model divides strategy into four quadrants (passive/active combined with defensive/offensive), revealing that most organizations focus only on aggressive offense and passive defense, while missing aggressive defense ("second intention" in fencing) and passive offense ("the press") as viable and often more effective approaches.

What is the primary threat to biotech and pharma companies from breaches?

Rather than simple data theft for social engineering or identity theft, many breaches in biotech and pharma target intellectual property through corporate espionage, requiring different protective and contractual strategies.

How does internal business pressure increase breach risk?

Organizations under high internal pressure (from HIPAA compliance, lives on the line, urgent business demands) are more vulnerable to breaches because employees may bypass security controls or fall for social engineering when stressed - similar to how warm champagne bottles build excessive pressure and become unstable.

What is 'second intention' in fencing and how does it relate to cybersecurity?

Second intention is an aggressive defensive strategy where you appear to defend, then counter-attack when the opponent commits - this principle applies to cybersecurity by being proactive within a defensive posture rather than passively waiting for attacks.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

7 / 20

A handful of genuinely useful points appear - BAAs containing shoehorned liability terms signed by non-legal staff, and the second-intention social engineering analogy - but they are buried under extended sword-collecting anecdotes, champagne-sabering banter, and personal storytelling that produces very little actionable content per minute for a B2B operator.

basically they're trying to shoehorn real legal issues into what's effectively a data sharing agreement, right? And when you try to shoehorn those in, then you have somebody who's not accustomed to looking at those issues, an IT person uh um uh looking at that agreement and going, okay, whatever, and signing, signing away some very important rights on that BAA.
Does anybody know what happened to Cody? Did he get cut with a sword? I I don't understand.

Originality

6 / 20

The four-quadrant fencing model (passive/active × offensive/defensive) is a modestly fresh framing for cybersecurity posture, and the 'second intention' = social engineering lure analogy is decent, but neither is developed into genuinely novel insight; the rest of the episode recycles standard CISO/risk-appetite language and Sun Tzu comparisons the host explicitly jokes about avoiding.

where most people aren't looking and aren't working is in the passive offense and the aggressive defense
it's called second intention. And um I want to talk about that uh in a minute and how that might relate to cybersecurity.

Guest Caliber

9 / 20

Drew Tharp is a legitimate practitioner - 12 years across Fortune 500s, multinationals, and startups on cyber/SaaS contracting - but he is a contracted attorney for the host's own firm, not an independent senior leader, and his depth of insight in the episode is proportionate to a solid mid-career specialist rather than a standout practitioner.

I've worked for Fortune 500s, multinationals, and also uh smaller startups helping them uh try to get their contract management systems up and running
I've been involved in cybersecurity and uh SaaS contracting and things like that for about 12 years.

Specificity & Evidence

7 / 20

The Disney Plus/Disney World arbitration example is a real, named case that illustrates the BAA risk well, and rapier blade-length laws in Vienna, Paris, and London add colour; however, the Disney detail is immediately hedged ('I don't remember what it was, probably slip and fall or something'), and cybersecurity claims throughout carry no breach figures, client names, dollar amounts, or timelines.

Disney World actually put some terms and conditions about their physical locations into the Disney Plus terms and conditions, which resulted in some people having issues at Disney
there were laws put in place in places like Vienna and Paris and London that limited the length of rapiers because people were getting 50, 60 inch rapier blades

Conversational Craft

7 / 20

The host makes a few genuine connective follow-ups - linking champagne pressure to business urgency, and second-intention fencing to social engineering payloads - but no claim is challenged, the conversation frequently derails into personal anecdotes, and the closing 'if your career were a sword' question is pure entertainment with no analytical value.

Is there a connection into the Muhammad Ali rope dope?
The first action is getting you to do something benign, and then the second one, once you've had a little bit of trust or an interaction, the second one is really where the payload is delivered.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

speaker49pressure18fencing16harvey15cybersecurity13champagne11defense10drew9strategy9passive9swords8sword8disney8model8aggressive8cyber7

Episode notes

Send us Fan Mail A champagne bottle, a blade, and a clean strike turns into one of the clearest cybersecurity conversations we’ve had. We’re joined by attorney and cyber contracting veteran Drew Tharp, with Todd Wilkinson stepping in as guest host, and we use swords and fencing to unpack why breaches happen and why “just add more tools” rarely fixes the root problem. Drew walks us through the four quadrant fencing model (active vs passive, offense vs defense) and how most security programs camp out in the obvious corners. We connect the overlooked zones to modern cybersecurity strategy: applying steady pressure that limits attacker options, building aggressive defensive moves that anticipate human behavior, and spotting the “seam” where urgency and confusion let a threat actor land one clean strike. If you work in healthcare cybersecurity, we also dig into why ransomware and business email compromise keep hitting so hard and how internal business pressure makes incidents worse.

Full transcript

29 min

Transcribed and scored by The B2B Podcast Index.

1 - > SPEAKER_01: Thanks for tuning in to Simplifying Cyber. 2 - > I'm Aaron Pritz, and we're here today with special guest host 3 - > Todd Wilkinson and Drew Tharp. 4 - > And I'm gonna give a little summary of what we're gonna talk 5 - > about because you probably saw in the opener we were cutting 6 - > shit with swords and um fruits and champagne that we're now 7 - > drinking. 8 - > Um but Drew has been an avid sword collector over 120 since 9 - > high school.

10 - > Um you saw as we champagne the um as we sabrage the champagne 11 - > that uh it was it was actually easier than I thought. 12 - > Um, but I would say um we're gonna talk about how we got into 13 - > swords fencing and uh really how some of these things connect to 14 - > cybersecurity. 15 - > So, Drew, welcome to the show. 16 - > Thank you.

17 - > Thank you. 18 - > Glad to be here. 19 - > Give us a little intro about you and how you've been in and 20 - > around cyber and legal and kind of where did you where did you 21 - > come from? 22 - > Where are you today?

23 - > SPEAKER_02: Yeah, yeah. 24 - > The boring stuff. 25 - > Got it. 26 - > Um yeah, so I am uh I'm an attorney.

27 - > I work for um uh several different companies and and also 28 - > uh help out here at Reveal Risk with some uh some contracting um 29 - > things. 30 - > And so I've been involved in cybersecurity and uh SaaS 31 - > contracting and things like that for about 12 years. 32 - > Um and I've worked for Fortune 500s, multinationals, and also 33 - > uh smaller startups helping them uh try to get their contract 34 - > management systems up and running and and that sort of 35 - > thing.

36 - > SPEAKER_01: Awesome. 37 - > Yeah, and in with in the contracts, obviously, a lot of 38 - > times companies are upping their game of what they're requiring, 39 - > cyber insurance, unlimited liability, lots of things that 40 - > are a tough dance, especially for a boutique and a Fortune 200 41 - > to work out like where do you land in the middle somewhere? 42 - > SPEAKER_02: Yeah, they the the risk is especially outsized for 43 - > for um cyber issues, because obviously if you if you have a 44 - > breach, that can be you know that can cost millions and 45 - > millions and millions of dollars.

46 - > And um uh unfortunately they're they're fairly common. 47 - > So we have to so the the insurance requirements can be 48 - > difficult, uh especially for uh smaller boutiques to meet those 49 - > challenges. 50 - > But yeah. 51 - > SPEAKER_01: And within Pharma Med Device, you've spent a lot 52 - > of time there.

53 - > What are the what are the emerging things that are on your 54 - > mind of concerns, both contractual as well as cyber 55 - > program, as limit as you limited are involved in that? 56 - > SPEAKER_02: Yeah, absolutely. 57 - > I mean, I I I think three things come to mind when it comes to 58 - > the uh biotech pharma space. 59 - > One is is obviously protecting your data, your um and and your 60 - > intellectual property.

61 - > Uh I I think a lot of the breaches that we see uh in the 62 - > biotech space uh sometimes aimed at actually stealing 63 - > intellectual property, not just getting some some data so that 64 - > we can go, you know, find some emails to send people and that 65 - > kind of stuff, um, steal some social security numbers. 66 - > A lot of it is is focused around actual corporate espionage. 67 - > And so um, so I think that's something that uh we have to 68 - > keep in mind. 69 - > Another issue that I see coming up more and more often is on 70 - > BAAs, business associate agreements, where um a lot of 71 - > times the the business associate who's trying to contract will 72 - > send a pretty onerous agreement that includes uh limits of 73 - > liability, includes um sometimes even subrogation or um or 74 - > indemnity.

75 - > And basically they're trying to shoehorn real legal issues into 76 - > what's effectively a data sharing agreement, right? 77 - > And when you try to shoehorn those in, then you have somebody 78 - > who's not accustomed to looking at those issues, an IT person uh 79 - > um uh looking at that agreement and going, okay, whatever, and 80 - > signing, signing away some very important rights on that BAA. 81 - > Um we actually talked before, um, it kind of reminds me of the 82 - > Disney World uh thing where Disney World actually put some 83 - > terms and conditions about their physical locations into the 84 - > Disney Plus terms and conditions, which resulted in 85 - > some people having issues at Disney.

86 - > I don't remember what it was, probably slip and fall or 87 - > something. 88 - > But then they have these issues and they couldn't sue Disney 89 - > because they'd agreed to arbitration in the Disney Plus 90 - > agreement, and that bound them to Disney World as well, which 91 - > is which is at best disingenuous, uh at worst 92 - > unconscionable. 93 - > So I think that a lot of people, or I think a lot of companies 94 - > are or a lot of places are trying to kind of slip some of 95 - > those past the radar by having um a quote unquote lower level 96 - > person sign a low-risk agreement like a BAA or a CDA with some 97 - > with some onerous terms.

98 - > All they were trying to do is watch Star Trek online. 99 - > Exactly, exactly. 100 - > Exactly. 101 - > Star Wars, I believe.

102 - > I think Disney hasn't acquired it. 103 - > Not yet. 104 - > SPEAKER_01: Yeah, I mixed up my genres. 105 - > SPEAKER_02: Paramount's next, I'm sure it's on there.

106 - > SPEAKER_01: Does anybody know what happened to Cody? 107 - > Did he get cut with a sword? 108 - > I I don't understand. 109 - > Well, yeah, we took him out.

110 - > All right, or the the body cut in half. 111 - > Take one for the team. 112 - > Exactly. 113 - > Anyway, thanks Todd for joining.

114 - > I'm here now. 115 - > I think let's go back to swords because I think that's what we 116 - > came for. 117 - > That you know, we make some connections here. 118 - > But Drew, I think when we were prepping before the show here, 119 - > you were talking about fencing was kind of your path into sword 120 - > collection.

121 - > Yes. 122 - > So what we got into was the four quadrant fencing model, which I 123 - > think has a lot of applicability. 124 - > And we're not gonna do with the classic RSA conference at least 125 - > three to five topics on Sun Tzu art of war. 126 - > But let's at least talk about fencing strategy and things that 127 - > we might be able to learn from that.

128 - > SPEAKER_02: Yeah, absolutely. 129 - > Well, and and I think um I I think that it ties in really 130 - > well to cybersecurity today, because when I learned the four 131 - > quadrant strategy, which I'll explain here in a moment, um, I 132 - > was um it really changed the way that I fenced, and that also I 133 - > think can really change the way that we think about 134 - > cybersecurity. 135 - > So the four quadrant strategy says that there are that uh a 136 - > strategy can either be passive or active, and it can be 137 - > defensive or offensive, right?

138 - > So that gives you four quadrants. 139 - > And uh if you ask most people, they'll say, yep, it's a it's an 140 - > aggressive offensive strategy. 141 - > That's the norm, right? 142 - > I'm I'm gonna go get them, I'm gonna chase them to threat 143 - > actors, that's all they got, right?

144 - > SPEAKER_01: Right. 145 - > On the defensive, yeah. 146 - > SPEAKER_02: Right. 147 - > And then there's and then most people think of defense 148 - > passivity.

149 - > We're gonna set up firewalls, we're gonna set up things that 150 - > people keep people from getting in, that sort of thing. 151 - > So you've got uh you've got aggressive offense and you've 152 - > got passive defense. 153 - > But where most people aren't looking and aren't working is in 154 - > the passive offense and the aggressive defense. 155 - > And you can actually have aggressive defensive strategies 156 - > and you can have passive offensive strategies.

157 - > So in fencing, uh a an aggressive defensive strategy is 158 - > actually called second intention. 159 - > And um I want to talk about that uh in a minute and how that 160 - > might relate to cybersecurity. 161 - > And then in fencing, an a passive offensive strategy is a 162 - > press. 163 - > It's a it's an attempt to gain space to push them towards the 164 - > other end of the strip, but not necessarily attacking them the 165 - > whole time, right?

166 - > It's just that that pressure, that push on them. 167 - > And uh I think that can be applicable as well. 168 - > SPEAKER_01: Nice. 169 - > Is there a connection into the Muhammad Ali rope dope?

170 - > SPEAKER_02: Yeah, yeah, certainly passive defense. 171 - > Yeah, yeah. 172 - > That would definitely be, well, I I think that'd be an active 173 - > defense, probably, right? 174 - > But well, no, it's a it's a passive defense, yeah.

175 - > Yeah, yeah. 176 - > Uh it's it's um yeah, that that can definitely be a passive 177 - > defense, I and I think that uh yeah. 178 - > SPEAKER_01: We'll get into more of those connections as we 179 - > progress, but as we were champagne the uh or champagne, 180 - > sabering the champagne earlier. 181 - > By the way, cheers, fellas.

182 - > Yeah, cheers. 183 - > There's no clink because these are plastic, but they look 184 - > classy on the on the camera. 185 - > So yeah, Drew, you taught us pressure, applying pressure, a 186 - > seam, and one clean strike, which is kind of what a breach 187 - > looks like, right? 188 - > Like there's a weakness, there, uh, you know, the seam, and 189 - > there's some sort of pressure, whether it's social engineering 190 - > or urgency, sense of urgency, and you know, panic, and then 191 - > that one clean strike you're in.

192 - > So um it definitely feels like, especially in healthcare with 193 - > some of our healthcare clients, have heavily been a target in 194 - > both ransomware and BEC since COVID, really. 195 - > There's kind of a pass on healthcare before that, and then 196 - > really during COVID, the threat actors went all in. 197 - > And it's a shame, but it's the reality now. 198 - > Right.

199 - > But what else can we learn from kind of the four quadrant model 200 - > and ways that individuals could um both reduce the seams uh as 201 - > well as um be more maybe maybe we can talk about um active 202 - > offense or really I think we said aggressive defense. 203 - > It sounds like the best option on the other end of the table, 204 - > right? 205 - > SPEAKER_02: Yes, yes. 206 - > So um, you know, I really like your analogy with the opening 207 - > the champagne bottle because you're exactly right.

208 - > It's about pressure, it's about uh, and it's the pressure that's 209 - > inside the bottle too, right? 210 - > And so um you can reduce that pressure. 211 - > And actually, we talked before the show, you said, hey, I I 212 - > want to set up these champagne bottles. 213 - > And I said, make sure you cool them before we come in.

214 - > I they need to be chilled champagne bottles. 215 - > And the reason why that is, is because the pressure inside the 216 - > champagne bottle will rise if it's warmer, because gases 217 - > expand in more spray, so there will be right, and and it can 218 - > actually completely destroy the bottle, just just blow up the 219 - > bottle when you try to do the sabrage. 220 - > So that really makes me think of are you working when when you're 221 - > a cybersecurity professional or a CISO, are you working with the 222 - > business to reduce the internal pressure to make sure that 223 - > things that aren't necessarily uh cybersecurity related, when I 224 - > think of that pressure building inside the bottle, I think of it 225 - > in the healthcare space, right?

226 - > SPEAKER_01: Business urgency. 227 - > SPEAKER_02: The the pressure is there because you've got PHI, 228 - > you've got HIPAA requirements, you've got you've got lives on 229 - > the line. 230 - > Right. 231 - > That creates that pressure.

232 - > And obviously in healthcare, it's easy to think about how 233 - > that pressure is built up. 234 - > But in uh, as people are listening to this, in your 235 - > business, where is the pressure building and how can you um and 236 - > and how can you release the pressure, relieve the pressure 237 - > that's not necessarily cybersecurity, so that when the 238 - > breach does happen, you're not all running for the door trying 239 - > to get out. 240 - > SPEAKER_01: No, that's good.

241 - > Let's go back to your story. 242 - > I think in my Intel report here, I think uh maybe we found out 243 - > that you in middle school you were into Dungeons and Dragons 244 - > and then not get into real fencing, fencing lessons, 245 - > fencing teams. 246 - > Um, what has that, and then obviously your story collection 247 - > hobby, um what what have some of those skills have you applied 248 - > into your legal profession? 249 - > SPEAKER_02: Yeah, absolutely.

250 - > I I actually remember when I was um in law school, the NCAA 251 - > released a commercial that was a fencer, a collegiate fencer, um 252 - > fencing, uh, and then it kept juxtaposing and and cutting into 253 - > the courtroom, showing them fencing and then um doing 254 - > litigation uh activities. 255 - > And um and I was like, oh, that's really cool. 256 - > That's that's my life. 257 - > That's awesome.

258 - > Um, and so I I think that there absolutely are connections uh 259 - > between uh fencing and legal. 260 - > Um, you know, it's it's kind it's competitive, it's uh it's 261 - > adversarial. 262 - > Um at the end of the day, in both legal uh aspects and 263 - > fencing, there's only going to be one winner. 264 - > You have to uh and you have to be strategic about uh who you're 265 - > talking to.

266 - > And a lot of times it's about the other person more than you. 267 - > Uh a lot of times the other person, um, if you know them, if 268 - > you've fenced them before, if you've worked with them before, 269 - > if you've uh competed against them before, you can know what 270 - > kinds of things they're gonna do while they're in details. 271 - > Exactly, exactly. 272 - > And so um so I think that that is true in law too.

273 - > You know, as as I become more experienced, I know more of the 274 - > players and more of the the places. 275 - > Um, I think actually it's funny, even um you, Aaron, have sent me 276 - > some things to review, and I've been like, oh yeah, I know what 277 - > they're gonna do. 278 - > They're gonna be, they're gonna push on this, this, and this, 279 - > because I've signed contracts with this company before, and I 280 - > know what they're going to request. 281 - > Um, and so I I think that that's uh that's a big uh connection 282 - > there.

283 - > SPEAKER_00: I I was gonna say I see that in Cyber all the time. 284 - > There might be a laundry list of things they're worried about, 285 - > but when you really get down to it, there's two or three things 286 - > that really matter to them in the business, and the ones 287 - > they're gonna come back with and make sure are right. 288 - > So knowing knowing those pinch points are their own pain points 289 - > and why they why it matters to them, usually that helps lower 290 - > that pressure a bit.

291 - > Awesome. 292 - > Absolutely. 293 - > SPEAKER_01: Uh Todd, any questions that you want to ask 294 - > from Drew? 295 - > SPEAKER_00: Well, I I was the the the the offensive pressure 296 - > you apply in there, like what is your strategy when you're going 297 - > into it?

298 - > Are you are you a type of person that leads on the offense? 299 - > Do you kind of test with your defenses? 300 - > What's uh share some of your secrets? 301 - > SPEAKER_02: Yeah, right.

302 - > When it comes to like a contract negotiation, I is that what 303 - > you're asking about, or more on the cybersecurity side? 304 - > SPEAKER_00: Well, I was gonna say on the fencing side. 305 - > What's your uh what's your fighting style? 306 - > SPEAKER_02: What's what's my personal fighting style?

307 - > Um I I was taught um when I was on IU's fencing team to be a 308 - > Swiss Army knife, and that has become my style. 309 - > Um I'm not great at any one particular thing, but I'm pretty 310 - > good at a bunch of things, and I use that as a strategy. 311 - > So I wouldn't say that I stay in one quadrant. 312 - > My whole goal is to score a point in each of the quadrants 313 - > or in each of the kind of ideas um in the first few points of 314 - > the bout.

315 - > Because if I push you, then you decide, oh, I I can't be 316 - > defensive. 317 - > Uh he's he's going to be aggressive. 318 - > And and then if you come and you be aggressive to me and I defeat 319 - > you defensively, then you go, Oh, what can I do? 320 - > And you you I try to whittle down your choices until you're 321 - > at a point where you're just like, I don't know what to do, 322 - > and then I just hit you until yeah, exactly.

323 - > SPEAKER_00: The follow-on to that, if we pivot that to cyber 324 - > and some of the own contracts that we have to deal with, how 325 - > how does that approach carry over? 326 - > Do we do we kind of let the let the other side lead? 327 - > What what are your thoughts there? 328 - > SPEAKER_02: Well, I I think that um, you know, I'm not I'm 329 - > definitely not as the I'm not an expert on cybersecurity like you 330 - > guys are, but I think that uh a lot of times the uh you're going 331 - > to be in a defensive uh posture no matter what, because unless 332 - > you are literally a cybersecurity company, you're 333 - > not going to be able to stay on top of what's going on, what 334 - > every single person is doing, right?

335 - > And and uh it's it's always the attackers, um, whether this is 336 - > uh going to Sun Tzu or or Fensec, it's always the 337 - > attackers who are going to have the the opening move because 338 - > they they have to. 339 - > Um by by nature, if you're defending your you're waiting. 340 - > Um and so I think that when we think about that though, I I 341 - > think that we think about how the um how threat actors can use 342 - > that their um use these tactics against us.

343 - > So one example is um they actually can be aggressively 344 - > defensive um because you may think, well, you know, we're on 345 - > defense, we're waiting for them to come try to attack us, and 346 - > that's true. 347 - > But what they may do is bait you. 348 - > Um and this is called a second intention action and fencing. 349 - > It's when I try to get you to do something, knowing what you're 350 - > going to do, and then take advantage of that.

351 - > So it feels very much to you like I'm giving you open, like 352 - > I'm saying, here, come attack me here. 353 - > SPEAKER_01: I think in social engineering and efficient, I 354 - > think that's the lure, right? 355 - > The first action is getting you to do something benign, and then 356 - > the second one, once you've had a little bit of trust or an 357 - > interaction, the second one is really where the payload is 358 - > delivered. 359 - > Exactly.

360 - > SPEAKER_02: Yeah, and uh in order to pull that off, you have 361 - > to kind of know what's gonna make the person move, right? 362 - > Um yeah, if you if you send me an email and it comes from you 363 - > know a bunch of random letters at um, you know, hotmail.au.co, 364 - > I'm gonna go, well, that's stupid.

365 - > That's that's somebody attacking me. 366 - > But if you send me an email that has the that's masked so that it 367 - > appears as though it's one of my friends and family, then that's 368 - > obviously gonna work better. 369 - > And so I I think that's the bait. 370 - > That's the uh yeah.

371 - > Yeah, that's awesome. 372 - > SPEAKER_01: Uh well, that's not awesome, but that's that's what 373 - > it's real world, that's what happens. 374 - > Um, so when we were chatting the other day, we we discussed kind 375 - > of AI and the trends that you're seeing. 376 - > And obviously, uh we can talk about some of the uh the lawyers 377 - > that have kind of uh not been prepared as they used it and 378 - > didn't make it their own and it hallucinated.

379 - > Uh but we also talked about Harvey AI. 380 - > So maybe cover both those topics, tell us what Harvey AI 381 - > is and go from there. 382 - > SPEAKER_02: Yeah, sure. 383 - > So Harvey AI, um, I think, and and I I don't want to be a 384 - > promoter here.

385 - > I'm not uh I'm not a filiated with Harvey at all. 386 - > I just have a client who uses Harvey and I've um and they've 387 - > requested me to use their instance to to do some things. 388 - > And um frankly, I've been really impressed with it, um, what it 389 - > can produce, what it can do, um, how it can streamline work. 390 - > SPEAKER_01: Um I think Harvey was named after the suits 391 - > character, Harvey.

392 - > SPEAKER_02: Is that yeah, I I think that I think that's right. 393 - > I think that's right, which I I pointed out, I find kind of 394 - > funny because they tell us the they tell the lawyers that 395 - > they're selling it to, use it like an associate, but but 396 - > Harvey's not the associate. 397 - > Harvey, it's the partner, but Mike probably wouldn't have been 398 - > as uh quick as a name, right? 399 - > So um, so I I have used Harvey and really think that it has a 400 - > lot of advantages.

401 - > I think that it has some major issues still, too. 402 - > And of course, anybody who's in job preservation mode right now, 403 - > AI isn't perfect. 404 - > I, you know, you obviously need to hire me. 405 - > But why why do you still need a lawyer when you've got Harvey AI 406 - > that can do a lot of the things that you may hire a lawyer to 407 - > do?

408 - > And to me, it's really about threat assessment, which ties 409 - > back to cybersecurity as well, right? 410 - > It's about um it's about looking and and deciding where certain 411 - > risks are. 412 - > What I've noticed with Harvey, for instance, is it saves me a 413 - > lot of time because I can plug a contract in and I can say, hey, 414 - > can you review this for me? 415 - > And Harvey will determine what uh what particular clauses are 416 - > are important, what particular clauses are uh outside of 417 - > industry norms, things like that.

418 - > But at the end of the day, it's not Harvey doesn't know is this 419 - > an important customer that's going to make or break our year? 420 - > Is this something that we're willing to take a risk on? 421 - > Harvey doesn't know the risk context, which is something we 422 - > talk about all the time. 423 - > When you bring a contract to me, I go, you know, I don't like 424 - > this term, but if you want their business, it's probably 425 - > something we're gonna have to accept.

426 - > And that's that's your choice. 427 - > And and I I totally understand what you said. 428 - > SPEAKER_01: Right more back and forth parrying and 18 month MSAs 429 - > and things like that. 430 - > SPEAKER_00: There's this concept in cybersecurity of what's your 431 - > risk appetite, how much risk are you willing to take on?

432 - > And that is that is a hard thing to quantify. 433 - > And it's a lot of personal intuition. 434 - > It's a lot of knowing who to talk to and the context of 435 - > what's happening in that moment. 436 - > And that that one is hard to put down into like an algorithmic 437 - > process that AI can take on.

438 - > SPEAKER_02: Absolutely. 439 - > And that's exactly the same in legal too, right? 440 - > It's it's I I think we actually have a very similar I think that 441 - > we have a very similar profile to the business when we're 442 - > partnering with the business because I don't think they want 443 - > to spend money on either of us. 444 - > We're not fun.

445 - > We don't produce, you know, we're the return on investment 446 - > is not instantly identifiable and and something that you can 447 - > uh that you can write to the state to the shareholders about. 448 - > But you'll find out real quick if you don't have quality there. 449 - > You'll find out real quick, oh, uh we have gaps. 450 - > And um yeah, it's it's it's hard to convince people of your 451 - > value.

452 - > SPEAKER_01: So two last questions, and one question Cody 453 - > usually asks all of our guests. 454 - > And we you've already given us a bunch of Drew fun facts and 455 - > personal stories, but what is one fun fact that most people 456 - > don't know about Drew Tharp that we've not already covered? 457 - > SPEAKER_02: Um I I I think the fun facts that I'll give you 458 - > guys, um, and this this may make it harder for me to win at two 459 - > truths in a while in the future, but um uh and it ties into the 460 - > swords.

461 - > Fun fact about me, I was a professional model. 462 - > And I know those of you looking at the video right now are 463 - > going, man, I mean, I obviously assumed that you were a 464 - > professional model. 465 - > And it was not a professional model for uh for you know ales. 466 - > Um it was uh I was a professional model um because I 467 - > worked at a company that makes swords.

468 - > Uh it was actually an importer of swords called Cass Iberia. 469 - > And this was in college. 470 - > It was um uh it was fun. 471 - > There was this girl I liked who lived in Tennessee, and so uh I 472 - > went and followed her and went and worked at a sword company, 473 - > and now I'm married to her, but I it was it was a fun place to 474 - > work.

475 - > And one day they said, Hey, you actually sort of know how to use 476 - > swords, and I said, Yeah, sorta. 477 - > And they said, Okay, can we dress you up in armor and go 478 - > take pictures of you out in the field? 479 - > And I was like, Sure, why not? 480 - > So I put on this full suit of samurai armor and I went out 481 - > into the field across the the road and you know just did some 482 - > did some uh movements with the swords.

483 - > SPEAKER_01: Crouching tiger, hidden dragon. 484 - > SPEAKER_02: Exactly, exactly. 485 - > And pictures came out, crouching tiger, crouching tiger, hidden 486 - > dragon. 487 - > There you go.

488 - > Um the uh the pictures came out awesome. 489 - > It was this uh it was this field of of uh wild grass and there 490 - > were the mountains of Tennessee behind us, and it just looked 491 - > and they were kind of foggy, it just looked awesome. 492 - > Very nice. 493 - > Um, but then a a couple weeks later, um my boss there at the 494 - > time came to me and he goes, Hey, I need you to sign this and 495 - > uh we're gonna add 40 bucks to your check this week.

496 - > And of course I was in like college. 497 - > I was like, I don't know, okay, whatever. 498 - > And he handed it to me and I signed it and I said, It was 499 - > before I was a lawyer. 500 - > And I signed it and I said, What am I doing?

501 - > And he said, Well, you've got to be in the model guild, you've 502 - > got to be in the model union because we want to put your your 503 - > the pictures that we took on Blade Magazine, which is uh you 504 - > know a uh magazine, uh knife magazine. 505 - > And I said, Okay, and so there we go. 506 - > I am a I was a dues-paying member of the modeling union. 507 - > SPEAKER_01: Very nice.

508 - > All right, and then last question if you or your career 509 - > were a sword, which one and why? 510 - > SPEAKER_02: That's a good question. 511 - > And one that you did not prepare me for. 512 - > So I have to.

513 - > Yeah, yeah, I know. 514 - > SPEAKER_01: There's a lot of AI generated notes. 515 - > There were a lot of notes. 516 - > I'm doing offense.

517 - > You are, you are, you are. 518 - > SPEAKER_02: I I I think I'm I'm uh I think I have to use passive 519 - > defense because I think I was caught off guard here. 520 - > Um but when I think about it, um, you know, I think that I 521 - > would say a rapier. 522 - > A rapier is the sword that you'd normally think of as the three 523 - > musketeers.

524 - > Um it's a it's a it's a longer, skinnier sword that's used for 525 - > um for dueling uh in particular. 526 - > And um the the rapier was was a big um change in technology when 527 - > it came around. 528 - > Uh because what people were discovering is people were 529 - > wearing less and less armor because firearms were becoming 530 - > more and more common, and armor doesn't stop bullets, and so why 531 - > why wear big heavy pieces of armor when you don't need to? 532 - > Um and so the rapier came around as uh you know, firearms didn't 533 - > start being great.

534 - > You had one shot and then you then you needed a sword. 535 - > And the whole idea was the rapier is if I can poke you from 536 - > all the way over here and you're all the way over there, then 537 - > then I win. 538 - > And so actually, uh it's funny, over time there we see uh there 539 - > were laws put in place in places like Vienna and Paris and London 540 - > that limited the length of rapiers because people were 541 - > getting 50, 60 inch rapier blades. 542 - > Long range, the very long range, and then of course knocking over 543 - > people when they're walking through the streets and doing 544 - > all this kind of stuff.

545 - > And so, but to me, the reason why I say I, you know, my 546 - > career, my my philosophy as is a rapier is because um it's all 547 - > about setting up the right strategic decision point and 548 - > then acting on that with uh with uh decisiveness. 549 - > SPEAKER_01: So that makes sense. 550 - > And all three of us desire to be skinny, and we're all working on 551 - > that. 552 - > Exactly, exactly, exactly.

553 - > I think Todd, you said suck it in right before we went on. 554 - > SPEAKER_00: That's that was the plan. 555 - > SPEAKER_02: No, I mean if you asked me what I'd actually use 556 - > in real life, it'd definitely be a Scottish bronze. 557 - > Why is that?

558 - > Uh, because I'm a big guy and I like to hit things hard. 559 - > Okay, all right. 560 - > SPEAKER_01: Awesome. 561 - > Well, Drew, thanks for coming on the show.

562 - > Really enjoyed this. 563 - > Is probably my favorite episode, and we've destroyed the most 564 - > fruit and uh champagne. 565 - > And uh yeah, I appreciate it. 566 - > Yeah, absolutely.

567 - > Thank you guys for having me. 568 - > It's been great. 569 - > Awesome. 570 - > Cool.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • S7 Episode 7: Trevor Davis on The AI Revolution in Creative IndustriesDigitally Curious · on Intellectual property theft86 / 100
  • Episode 20: Guardrails for the AI Frontier - Innovating Without Betting Your License with Travis GarlandThe Root Cause · on Business Associate Agreements (BAAs)82 / 100
  • Employment Agreements and Non-Competes: What HR Needs to KnowThe Generous Benefits Podcast · on Contract negotiation strategy78 / 100
  • Ep 112: Understanding Security Awareness with Tom KirkhamLevelUp Cyber · on Intellectual property theft73 / 100

More from Simplifying Cyber

All episodes →
  • Part 1: Saberage and Cyber31 / 100
  • The Vulnerability Playbook76 / 100
  • Spot That Vish!90 / 100
  • The Evolution of Human Risk83 / 100
  • From NIL Dollars to Data: New High Stakes in College Sports77 / 100
Explore the best B2B Ops podcasts →
All Simplifying Cyber episodes →