The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/The Business of Cybersecurity
The Business of Cybersecurity artwork

Index Engines On Why Cyber Resilience Has Become A Boardroom Issue

The Business of Cybersecurity · 2026-05-17 · 30 min

0:00--:--

Key moments - from our scoring

Substance score

57 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality11 / 20
Guest Caliber13 / 20
Specificity & Evidence11 / 20
Conversational Craft10 / 20

As ransomware attacks become more sophisticated through AI and ransomware-as-a-service models, security leaders face a fundamental strategic pivot: prevention alone is insufficient. Jim McGinn of Index Engines reframes the conversation around cyber resilience and recovery speed rather than attack prevention. The episode explores why boards now treat ransomware as a business continuity crisis rather than an IT issue, and introduces the concept of 'return on risk' as a decision-making framework replacing traditional ROI calculations. McGinn discusses Index Engines' CyberSense product, which uses AI-powered detonation labs and byte-level detection to identify data corruption with 99.99% confidence - addressing a critical blind spot where attackers now corrupt data subtly rather than bulk-encrypting it. Real-world examples illustrate the stakes: the MGM Grand breach through social engineering, a city transportation system requiring board-level recovery assurance, and deepfake CFO impersonation. The NIST Cybersecurity Framework provides structure, but the key insight is that organizations should assume compromise and plan recovery around clean data availability rather than prevention alone.

Key takeaways

  • →Organizations must assume compromise will occur and design strategies around rapid recovery with validated clean data rather than focusing solely on attack prevention.
  • →Ransomware-as-a-service and AI-powered variants have lowered the barrier to entry for attackers, making cyber resilience a board-level business continuity issue with measurable financial and reputational consequences.
  • →Return on risk should replace ROI as the decision-making framework for cybersecurity investments, accounting for recovery costs, regulatory penalties, and customer trust damage.
  • →Data integrity validation at 99.99% confidence - detecting byte-level corruption deep within files - is a critical blind spot most organizations lack, requiring AI and continuous testing against new ransomware variants.
  • →Board-level questions about recovery time objectives and clean data availability must drive funding and cross-functional collaboration between storage, backup, and security teams using frameworks like NIST Cybersecurity Framework.

In this episode

  1. 1Introduction to Cyber Resilience and Index Engines
  2. 2Why Ransomware Attacks Are Becoming More Aggressive and Widespread
  3. 3Shifting from Prevention to Recovery: Return on Risk Framework
  4. 4How Boards and Leadership Must Engage with Cyber Resilience
  5. 5Detecting Data Corruption and Validating Data Integrity
  6. 6Real-World War Stories and Business Impact of Cyber Attacks
  7. 7Building a Resilience Strategy and First Steps for Organizations

Mentioned

Index EnginesCyberSenseNord LayerDellDenodoJim McGannNISTRansomware as a ServiceMGM GrandMarks and Spencer

Guests

Jim McGinn

Topics in this episode

NIST Cybersecurity FrameworkCyber resilienceIndex EnginesCyberSenseRansomware-as-a-serviceData integrity validationRansomware variantsAI and machine learning detectionDell Cyber Recovery VaultReturn on risk

Questions this episode answers

How can companies validate that their backup and recovery data is actually clean and not corrupted by ransomware?

Index Engines' CyberSense product uses AI-powered detonation labs that test against thousands of ransomware variants daily, detecting byte-level encryption corruption inside files and databases with 99.99% confidence - far beyond traditional compression-rate or threshold-based detection that attackers now work around.

Why has ransomware become more aggressive and automated in recent years?

Ransomware-as-a-service infrastructure, combined with AI, has lowered the barrier to entry so significantly that non-technical actors can hire formal ransomware organizations to execute sophisticated attacks, and attackers can use AI to generate variants tailored to specific organizations' security tools.

What should a board ask IT and security leadership about cyber resilience?

According to McGinn, boards should ask three critical questions: How quickly can we recover when attacked? How do we know what data was impacted? And where is the clean data we can recover from? Most organizations cannot easily answer these questions.

What is return on risk and how does it differ from ROI in cybersecurity spending?

Return on risk reframes investment decisions by accounting for the total cost of a breach - downtime, recovery costs, regulatory penalties, reputational damage, and lost customer trust - rather than just the upfront cost savings of cheaper infrastructure, justifying investment in resilience-built technology.

What is the first step organizations should take to build a cyber resilience strategy?

Organizations should adopt the NIST Cybersecurity Framework, assume compromise will occur, establish clear recovery time objectives and data validation processes, and ensure cross-functional collaboration between storage, backup, security, and executive leadership to define what recovery looks like.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode covers a clear strategic shift from prevention to resilience and introduces the 'return on risk' framing, which is conceptually useful. However, much of the content relies on high-level observations (ransomware as a service, attackers use AI, backups fail) without deep technical or operational specificity. The guest repeats core messages frequently rather than layering new insights, and several segments devolve into war stories that illustrate but don't explain.

Less about stopping an attack and more about saying, I know where I have clean data, I know where I can recover, and I can do this quickly and efficiently
if you flip that on its head and say, it's less about the return on investment and the return on risk

Originality

11 / 20

The 'assume compromise' and resilience-over-prevention thesis is well-established in security circles by 2024, and the return-on-risk reframing, while practical, is not novel. The NIST framework, ransomware-as-a-service, and AI-enabled attacks are standard talking points. The episode lacks contrarian takes or first-principles interrogation of why boards actually resist this shift or what blinds them structurally.

it's not if, it's when
organizations like healthcare, education, those that really, they've done two things that create a target on their back. They haven't invested enough in cybersecurity

Guest Caliber

13 / 20

Jim McGann is CMO at Index Engines, a vendor in the data integrity and recovery space. He has operational exposure through customer interactions and prior experience but is ultimately a marketing executive selling a specific product, not a practitioner who runs security or IT at scale. His authority derives partly from proximity to real incidents rather than direct operator responsibility.

I've been with the company for quite a few years where we've seen our product evolve
We have a customer that's a very large city in the U.S. and it's their transportation subway system

Specificity & Evidence

11 / 20

The episode includes some concrete examples (MGM Grand attack, Marks and Spencer outage, a Dell Cyber Recovery Vault integration, 99.99% detection confidence) but they are sparse and often anecdotal. Large claims like 'thousands of ransomware variants per day' and AI-turbocharging attacks lack metrics or sources. No financial data on recovery costs beyond 'millions,' no timeline specifics for most incidents, and no quantified business impact comparisons.

they'll find it. They'll know how much they're insured for in terms of cyber, and that's what they're going to ask for in terms of the ransom
99.99% confidence

Conversational Craft

10 / 20

The host asks reasonable setup questions and occasionally probes ('how can companies be confident their recovery data is clean'), but rarely follows up with skeptical pushback or presses the guest on vagueness. When McGann makes sweeping claims (e.g., attackers are 'spending 24-7 building strategies'), the host doesn't challenge or ask for evidence. The dialogue is conversational but lacks the sharpness and friction that would stress-test the guest's assertions.

I was reading how it's built around detecting data corruption with an incredibly high level of accuracy but I'm curious what are the common blind spots
But what changes when boards start viewing it as a business continuity and operational risk?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

data43cyber20recover17organizations17ransomware16recovery15storage13risk12clean12back12security11today11return11center11actors11resiliency10

Episode notes

What happens when ransomware stops being treated as a cybersecurity problem and starts being viewed as a direct threat to business survival? In this episode of Business of Cybersecurity, I sat down with Jim McGann, CMO at Index Engines, to unpack why 2026 is shaping up to be one of the most dangerous years yet for organizations facing increasingly sophisticated cyberattacks. Jim shared how ransomware gangs are evolving into highly organized operations powered by AI, automation, and ransomware-as-a-service models that dramatically lower the barrier to entry for attackers. From healthcare systems and transportation networks to retailers and city infrastructure, no sector appears off limits anymore. We explored why traditional disaster recovery strategies built for floods or hardware failures are no longer enough when attackers actively corrupt backups, manipulate databases, and target recovery systems themselves. A major focus of our conversation centered on the idea of “Return on Risk” or ROR, a shift away from viewing cybersecurity purely through an ROI lens.

Full transcript

30 min

Transcribed and scored by The B2B Podcast Index.

And if you are listening and you're responsible for security or IT, you will know the reality that most of your risk now sits inside SaaS apps and browser activity. That gap is exactly what Nord layer is addressing with its new business browser. So instead of bolting security on from the outside, it builds it directly into the browser itself. This means you can control access, monitor activity, enforce policies and reduce shadow IT all from one single place.

And most importantly, it does it without adding deployment headaches or complex onboarding. You get things like browser -based data loss prevention, SAS access control and zero -trust browsing, but delivered in a way that your team can actually use. So if you've been trying to simplify your stack while improving visibility, please check it out at Nordlayer .com slash browser.

What if the real cyber security question is no longer how do you stop every single attack but how fast you can recover when one gets through. Now as ransomware becomes more and more aggressive more automated and more business driven resilience is now moving from just a technical concern to a leadership priority. So today I'm joined by Jim McGann he's the CMO at Index Engines and we'll talk about why cyber resilience now matters as much as prevention and also why leaders need to think in terms of return on risk and why knowing that you have clean data could be the difference between a bad day and a business ending event but enough from me it's time for me to officially introduce you to Jim now So a massive warm welcome to the show.

Can you tell everyone listening a little about who you are and what you do? Hey, Neil. Thanks for having me today. My name is Jim McGinn.

I'm the chief marketing officer. I'm responsible for obviously marketing as well as strategic partnerships at Index Engines. We have a core product, which is CyberSense, which is in the cybersecurity space, which is front and center and near and dear to many people's hearts these days with the activity that's happening out there. I've been with the company for quite a few years where we've seen our product evolve from really understanding enterprise data.

to really taking action on enterprise data to have confidence that it's good to know that you can recover and keep the business operational. And with bad actors lurking in your data center, and for a lot of organizations, they're probably sitting in there today, to be able to know that you can recover and that you have good data. So I think what we focus on in a nutshell basically is that Less about stopping an attack and more about saying, I know where I have clean data, I know where I can recover, and I can do this quickly and efficiently.

And that's becoming the most critical component of cyber resiliency. It feels this year that cyber attacks or cyber security have gone mainstream. I was watching an episode of The Pit recently and that took down an entire hospital for a shift. We've been talking about ransomware for so many years and even now ransomware attacks are becoming more aggressive, more targeted.

So why do you think that conversation needs to shift from just pure prevention to maybe more resilience and recovery? It's the old adage, it's like, why are they robbing the banks? It's like, that's where the money is, right? So, I mean, unfortunately, organizations like healthcare, education, those that really, they've done two things that create a target on their back.

They haven't invested enough in cybersecurity and security tools. Their budgets and IT are very lean and mean, but they've also embraced internet access and access to their data center. They're opening it up basically to their customers and their patients and so on, partners, but also to the bad actors. There are countries allegedly, Russia, now Iran is in the mix, thanks to what's going on.

North Korea, China, that are really supported by their countries and they make money and it's a successful business for them. It's ramping up because it's not only been successful, but the biggest thing has been ransomware as a service. So, lowering the bar in AI, combination of AI and ransomware as a service is lowering the threshold for anybody to get into the mix here. So, if you're a non -technology person, you could call these organizations which are formal companies that are ransomware as a service organizations and say, hey, I want to execute an attack against this healthcare provider or this retail organization or this manufacturing firm.

and they will do all the heavy lifting for you. But also AI as well. I mean, you can go to AI today. There's a lot of good about AI, but there's also the bad actors are leveraging it, that you could build ransomware variants that are far more sophisticated than they have been in the past.

using these AI tools. So you can go and say, hey, this organization, I'm in their data center. I know they use XYZ for preventative tools. They use this for backup software.

They use this for their production databases. Build me some ransomware variants that will circumvent those tools and have the maximum impact. And that's what they're doing. So to answer your question is they're ramping up because the The infrastructure and the technology is out there allowing them to do that.

And you mentioned there those lean and mean IT budgets and that heavy focus on the return on investment of any tech project now Maybe it's because if you were burnt on those AI projects that didn't make it out of pilot phase But you've introduced this this idea of return on risk So tell me more about that and how businesses should maybe think in practical terms when making those cyber security investment decisions Well, it's reframing the question. You speak to the infrastructure and IT folks and folks that are managing data center environments all the time.

Their purchase decisions are based on ROI. If I buy this storage, what is going to be my return on investment? If I buy these databases, if I buy this infrastructure, what is the return on investment? Those are the conversations you'll have with your leadership when they need to write a check.

But if you flip that on its head and say, it's less about the return on investment and the return on risk. Because if you are a healthcare organization or a financial services firm and they shut you down for a ransomware attack, it's not only the downtime, but it's the recovery cost, the reputational damage. the regulatory penalties, so I know in NMEA and there's DORA and there's other regulatory requirements and penalties that are associated with that, and lost customer trust.

I mean, if you go to your hospital or healthcare organization and they leak all your medical records, you need to think twice about going back there. You're saying, you can't protect my information and my privacy, so I'm not going to go back there. The average cost, and there's tons of different numbers for recovery, can be in the millions. If you're looking at the ROI for buying storage and saying, oh, this is cheaper than brand X, Y, and Z, that's a very tactical decision.

But if you're looking at return on risk saying, hey, I need to buy storage, but I'm going to buy this because it's more expensive, but it has cyber resiliency built in and allow me to recover. That's the way organizations need to think. It's a battle. It's a war out there.

The bad actors are using nuclear ballistic weapons and organizations need to say they need to ramp up and say this is a risk. situation that I need to control and participate with and buy the right technology that's going to help me support that strategy. And we will have many people listening from organizations that maybe still treat ramp somewhere as, hey, that's an IT issue. But what changes when boards start viewing it as a business continuity and operational risk?

There's been a lot of changes over the years. A decade ago, maybe they struggled to see the value in what if kind of scenarios. But I think that's changed. But what do you see here?

Well, back even a few years ago, and it still happens today. When you go into a meeting and if you've got the team that runs storage, the team that runs data protection, the team that runs security, and different aspects of the team that runs the data center. I've been in meetings like that like, well, we don't really do introductions. You all obviously know each other and it's like, no, we've never met.

You know what return on risk or what cyber resiliency strategies and if you look at in the US they've got the NIST framework which is kind of a structure around this is it collaborates and brings different teams together to work and collaborate on cyber resiliency because if you go in and if you talk to someone that's managing the storage or infrastructure and say, well, if we have a ransomware attack, I'm just going to call the backup people, disaster recovery people, and tell them to recover.

It's like, well, how do you know they have a clean copy of data? And if they're recovering a multi -day old Oracle database or SAP database, what's the impact on your business? And it's like, it's not my problem. It's their problem.

It is your problem. I mean, everybody needs to contribute to this. And the companies that you know, have the cyber resiliency strategies where all the stakeholders are brought together and everybody knows what they need to do in case of a ransomware attack and never takes ownership of it. We have a customer that's a very large city in the U .

S. and it's their transportation subway system, you know, and that's a high value target and they're... The person that's in their data center that's responsible for this in terms of cyber resiliency, he speaks to the board. And the board asks those questions.

And we do have customers where the board asks the question. It's a simple question, is how quickly can we recover when we get attacked? And how do we know what data was impacted? And how do we know where the clean data is?

And we constantly talk to customers that when those questions are asked, they don't have an easy answer for that. And they need to go to the board and say, we don't have an easy answer. And they need to be open and honest with the board and say, we don't have an answer, but we need to build one. And it needs to be funded.

And a lot of our customers' funding comes down from that level. And they could throw money at this situation. part of the cyber resiliency strategy is governance issues and regulatory issues. That's the stuff that they're going to care about and reputation issues.

All the stuff that the board cares about is wrapped up in this. We talked to folks and they're like, well, how do I get funding for this? It's like, well, talk to your board. If your board doesn't understand this or care about it, then you're exposed.

Yeah, and I think we're seeing attackers more and more are actively targeting backup systems and even disabled security tools in some ways. But how can companies be confident that their recovery data is actually clean and usable when they need it most? Because when it goes down and nobody can access that data, that's when people take it seriously. It's usually too late.

The organizations that think that they have disaster recovery strategies in place and I've been in place for decades and that's good enough. The fatal flaw there is those were built for something like a fire or a flood or something that's going to physically wipe out a server or the networks in there and to recover from that. A cyber attack is very different. They're specifically attacking data and locking your data down.

If you go and you use backup software to recover and you put a bunch of data back online, That data is going to be fine because no one's really touched with it or manipulated it or modified it. You're like, let's just get that data back online and we're good. The bad actors are going in and they're manipulating the databases files so that they're not usable. Again, a lot of them, as you mentioned earlier, are corrupting or deleting backups totally.

We have one customer that he was at a previous organization and He got a multi -factor authentication message on his cell phone on Saturday morning saying, hey, you need to allow me to log in. He's like, that's weird. No one's in the data center who's doing this. So he got in his car at 7 o 'clock Saturday morning, drove to the data center, and just looked and said, let me see the backups.

OK. They were gone. Gone. And then he's like, let me check servers.

Servers were down. Everything was destroyed. He was almost in tears talking about the situation, but he said the next 33 days were the worst days of my life. I spent the entire time at work rebuilding active directory, rebuilding the network infrastructure, finding the last good copy of clean data.

He moved over to a new organization. They had a resiliency strategy that they put in one of our partners solution, the Dell Cyber Recovery Vault with our CyberSense product. He gets an email every morning that says, hey, the data scan, it's validated, it's clean, it's good for recovery, and he goes about his day and he's like, I have confidence, I have clean data. Backup doesn't do that or the infrastructure that's in place doesn't do that today and validate the integrity of your data.

That's what needs to happen to know that you have confidence that you've got clean content and can recover. Incredibly grateful to the team at Denodo for backing the Tech Talks network and helping us produce over 60 interviews a month. And if you are looking for better ROI from your lake house, this message is going to be worth hearing. Because Denodo helps reduce complexity, control costs and accelerate time to insight.

And it does that by connecting all of your data sources in real time. So make your lake house work harder with Denodo and you can do that by simply visiting denodo .com. Yeah and you mentioned the Cybersense product there.

I was reading a little about this before you drew me on the call today and I was reading how it's built around detecting data corruption with an incredibly high level of accuracy but I'm curious what are the common blind spots organizations typically have when it comes to validating data integrity? Well it's a complex job, we know we've been doing it for a number of years. Back in the day, way back five years ago, the bad actors were using these bulk force, bulk encryption algorithms that would just encrypt data randomly throughout the data center.

It would be very easy to detect. If all your server was encrypted, you would see that. Now what they're doing is they're doing byte level encryption inside files, enough to manipulate it and make it unusable, but not enough to be easily detected. So I mean, some of the tools others use to detect it is looking at changes in compression rates.

So if it's highly encrypted, the compression rates change dramatically. We're looking at threshold changes where there's a... increased number of files that have been deleted or added and so on. The bad actors know that that's what they look for, so they work around that stuff.

What we've done is we've embraced AI for many, many years where we actually have a detonation lab, which is isolated obviously, where we download all the latest ransomware variants that are on the market. there's thousands every day. They're not brand new ones. They're changes of names and changes of encryption algorithms or modifications.

So thousands every day, they're detonated in the lab automatically. And then we test our algorithm to make sure that that type of corruption is detected. So even if it's very stealth, hidden inside of a file or hidden inside a database, and we've had that validated at 99 .99 % confidence.

And I think What we learned early on is the only way to fight the bad actors is to study what they're doing. It's like if you're, you know, if you're looking at, you know, if you're in the finals of a football championship. What you're going to do is you're going to study what the competition is doing and see what they do. That's what we're doing with our tools, is we're studying exactly what the bad actors are doing every day.

If it changes, then we could use AI to update machine learning algorithms and so on, so that customers have that level of confidence. I think if you're making purchases, having SLAs, and there's been SLAs on storage and the four nines, five nines, 10 nines, whatever it is, have SLAs around ransomware recovery is where the industry is changing. And that's why we're doing, you know, costly testing. And I think we should highlight here that there are very real world consequences from what we're talking about, whether it be revenue loss to disruption of critical services, maybe to bring that to life.

Can you share how Cyber resilience directly impacts business outcomes beyond just security metrics. I'm sure you've got a long list of tales or war stories from your time in the field there, but anything you can share. Yeah, I mean, securing data is something that, again, does get to board level and executive levels. It's a risk and it's a liability, especially if you're certain industries, in healthcare, obviously, in financial services, even in manufacturing.

I think organizations really need to understand at the senior executive level how advanced these bad actors have become. And again, the war stories, some of them can't be shared, but they'll make your toes curl, you know? There was an example of what's happening now is with the Deepfakes is, you know, a organization, I won't mention who they are, but the CEO is getting messages from the CFO saying, I need money transferred, which is was normal business practice, but it seemed a little bit strange the way that they were communicating.

So, he said, let's get online on a video chat and discuss this, right? Went online, CFO was there, talking to CFO, voice, face, everything was fine. Wasn't him. It was a deep fake, you know, and that's possible.

I think organizations need to understand that they're already in your data center. I think protection and trying to keep bad actors out is an admirable task, but you have to assume that it's going to fail. The MGM grand attack in Vegas was gotten through a help desk. They manipulated the IT help desk to give them the admin password for the network.

There's no security tools in the world that are going to stop that. That's human behavior. They're smart. Another horrible case study is a customer that was attacked.

The first thing they do is they have a team meeting with their insurance company, with all the recovery people. There was dozens of people on this meeting. There was a Zoom meeting, and they went down and did introductions, and there was a person on there like, who is that? It was the bad actor trying to understand how they're going to recover.

On the meeting about recovery and they're like, yeah. Honestly, it is a war zone out there. It's not getting any better. Ransomware is a service.

AI is turbocharging this whole industry and customers aren't prepared. They're running old software. They're not patching it correctly. They're having open access through open networks.

I'm not saying it's easy for them, but they're not making it difficult to get in. I think not giving up on the preventative stuff, but focusing on the data and the integrity of the data is something that boards understand and senior executives understand. When you ask those questions is like, how quickly can you recover? We have backup software.

It's like, how do you know that data is good? I assume it's good. It's like, that's not a great strategy here. You need to validate integrity and make sure you have a clean copy so you can get back in production as quickly as possible.

Wow, so many great examples there. I think it's so important to share because I think very often we see stories like this on our newsfeed or an item on the news and you think, oh, wow, that's scary, but hey, it wouldn't happen in my organization. But that very real situation of a CEO thinking he's talking to his CFO and can see him looking at his eyes, but it is a deep fake. It's very real, isn't it?

Very real. And I think if you're in an organization where they say it won't happen to us, Hope is not a strategy, as you know. So I mean, it will. And I think these folks are rummaging around looking for entry points.

And if you provide them access, they're going to go. And they're not going to ignore the small players. I mean, we see attacks at small educational, small school systems, small regional governments. the folks that haven't invested in the technology that they need to.

These folks know it's an easy win for them, whether it be a $50 million ransom or whether it be a $50 million ransom. Another story is that when they're in there, they find cyber insurance policies. They'll find it. They'll know how much they're insured for in terms of cyber, and that's what they're going to ask for in terms of the ransom.

They're not stupid. They're very well -educated. They spend 24 -7 just building strategies to do this. And if organizations aren't spending that same amount of time and using the same types of technology that they are, they can continue to be vulnerable, right?

Wow. And for organizations that are still focused on just keeping the bad guys out, keeping those attackers off the network, what is the first step that they should take today, maybe to... Create a strategy that assumes compromise and then ensures that they can recover quickly because as you said, just hoping or just we will keep the bad guys out is not enough anymore, is it? Yeah, there's a number of organizations that have just lots of information on that.

I mentioned in the U .S. there's the NIST, the Cybersecurity NIST framework. It talks about the different, you know, five, now six with governance added.

phases and workbooks and strategies. So there's a lot of great information out there that organizations can provide that will help them build a strategy. But I think if you're not getting enough support at the senior levels and having conversations like you mentioned at board levels or CXO levels, about this, about recovery and what's gonna happen, then you're gonna struggle. And when you do get attacked, and people say it's not if, it's when, right?

When you do get attacked, just be prepared to live and breathe a recovery process. I mean, ask the question, what will it take to recover Active Directory? It will take to recover the network infrastructure. We have customers that...

just are in such fear of this that if they get attacked, they'll just wipe out every server, every desktop, every laptop, and buy new ones because they're just worried that they're infected. It's a multi -week or multi -month. Marks and Spencer, retail organization was attacked. They couldn't take orders and that shuts their business down.

They were down for months. They were not fully back for months. If you ask a simple question, what happens if we're down for five days or 10 days or a month? What does that mean to the business?

I've heard from organizations, Fortune 500 organizations saying that if they're down for five days, they're out of business. Nobody wants to have those conversations, but those are the ones that need to happen. Yeah, I think it's a powerful moment to finish on. And for anyone listening that wants to continue the conversation with you, learn more about Index Engines, the CyberSense product that we mentioned there, or just keep up to speed with some of the announcements that are coming out there from the work you're doing.

Where would you like me to point everyone listening? Sure, yeah. I mean, our website is indexengines .com.

Our product, CyberSense, We integrate with the enterprise storage environment Dell in both their cyber recovery vault, which is linked to their data protection products, as well as their production storage, which will be being launched soon at the Dell technology world coming up in May this year. We're partnered with IBM on their flash storage. So the idea is when customers acquire storage platforms, CyberSense is built in. So it's kind of an insurance policy that's built in.

We're partnered with Hitachi and partnered with Infinidat, which was just acquired by Lenovo. So all the major storage players out there. you can buy storage from them that has CyberShenz built in. And again, it's kind of like the Intel inside of knowing that your data has integrity and that you can recover.

And a lot of our partners have these cyber resiliency guarantees built in. And that's the decision we started talking about return on risk to circle back is that's the questions they need to ask is what's your guarantees or resiliency strategies here when you buy these storage platforms. So indexedengine .com is where you find us.

There's links to our partner sites on there as well. Well, I think the message there is clear. Boards and executives who treat ransomware as almost a core business continuity risk, focus on return on risk, not a one -off IT project. They're the ones that will come out ahead.

I'll include links to everything that you mentioned now. I encourage people listening to check you guys out and see if you're at the events as well. It'd be great to get some face -to -face time. But just a big thank you for shining a light on this today.

Really appreciate your time. I appreciate the time, Neil. It was a good conversation. If today's conversation proved anything, I think it's that backup alone is no longer enough.

And in a world of ransomware as a service, deepfakes and attackers who actively target recovery systems, confidence in clean data has become a business survival issue. And please, if you remember one thing from this episode, remember that story of the CEO talking to his CFO or assuming he was, but it was a deepfake. He sounded the same, he looked the same, it was a video. These are very real threats that we're seeing out there now, not just a rare story on our newsfeed.

And a big thank you to Jim McGann from Index Engines for joining me on the Business of Cyber Security podcast. And for everyone listening, ask yourself, if your organisation was hit tomorrow, they are in the system, they are on the network, could you say with confidence exactly where your clean data lives? And how quickly? Could you recover?

Have a think about that and let me know what you've got in place too. I'd love to hear from you all. TechTalksNetwork .com You can leave me an audio message there or send me a DM.

Plus this 4 ,000 interviews. There's plenty of insights from experts all around the world. So that is it for today. I'll be back again real soon waiting in your podcast feeds with another episode.

But until then, thank you for listening and I'll speak to you soon. Bye for now.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • How Zalando Deployed GenAI Without Handing Attackers the Keys with Florence MottayCyber Leaders · on Cyber resilience87 / 100
  • Palo Alto's CSO: Your Security Strategy Is Outdated. Here's How to Build One That's AI-ProofCXO Spotlight · on Cyber resilience86 / 100
  • AI Governance Essentials: Navigating Security and Compliance in Enterprise AI with Walter HaydockCyber Sentries: AI Insight to Cloud Security · on NIST Cybersecurity Framework85 / 100
  • Pursuing strategic partnerships to tackle Cobalt Strike abuseHealthcare Strategies · on Ransomware-as-a-service85 / 100
  • Secret Service Agent Reveals Undercover Cyber OpsThe Audit · on Ransomware-as-a-service76 / 100
  • The Illusion of Control: Cybersecurity, AI and the Risks Beneath the SurfaceThe Financial Executives Edge · on NIST Cybersecurity Framework72 / 100

More from The Business of Cybersecurity

All episodes →
  • Closing the AI Vulnerability Remediation Gap With Cobalt74 / 100
  • Mimecast CISO On Why AI Has Become A Cybersecurity Risk60 / 100
  • Orange Cyberdefense On The New FCA Cyber Reporting Rules76 / 100
  • Deepfakes, AI Agents, and the Collapse of Traditional Identity Security66 / 100
  • When Identity Becomes The Front Line Of Cybersecurity71 / 100
All The Business of Cybersecurity episodes →