
The Incident Report · 2025-01-15 · 21 min
Key moments - from our scoring
Substance score
15 / 100
Five dimensions, 20 points each
Hosted by Allyson Indigo and Aaron Ivey, this episode breaks down essential cybersecurity fundamentals for businesses of any size. The discussion emphasizes that 95% of breaches are linked to human error, making employee awareness training as critical as technical defenses. Key services covered include MDR (Managed Detection and Response) for 24/7 threat monitoring, Incident Response (IR) for breach containment and recovery, Endpoint Protection Services (EPS) for device security including IoT devices, Patch Management Services (PMS) to handle the 2,500+ monthly vulnerabilities, and immutable storage as a ransomware safeguard. The hosts also explore Zero Trust Network Access (ZTNA) as a modern security approach using multi-factor authentication and contextual access controls. A critical insight: the average company takes 280 days to detect a breach. The episode addresses common myths - that cybersecurity is only for large enterprises, too expensive, or just an IT problem - and stresses a holistic, team-based approach where leadership sets the tone and every employee becomes a first line of defense.
Research cited in the episode shows the average company takes 280 days to detect a breach, nearly a year, during which significant damage can occur.
MDR is a 24/7 security service that actively monitors systems for threats, acting like a security team always on the lookout - essential because most companies are reactive rather than proactive.
ZTNA operates on the principle of 'never trust, always verify,' using multi-factor authentication and device posture checks to grant access based on context - seamless for trusted users but more restrictive for suspicious activity.
Small businesses are often easier targets because they have fewer resources and less sophisticated security; attackers seek weak points regardless of company size.
Start with a risk assessment to identify critical assets and compliance needs, then implement basic measures like strong passwords, multi-factor authentication, and software updates - and don't hesitate to seek expert help.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode is almost entirely definitional - explaining what MDR, IR, EPS, PMS, ZTNA, and immutable storage stand for - with no actionable implementation depth. The handful of statistics cited are well-worn industry figures delivered without context, and the final third of the episode is a near-verbatim repeat of the conclusion, adding zero net content.
Start small. Take it one step at a time. Conduct a risk assessment, figure out what's most important to protect. Then implement basic security measures. Strong passwords, multi factor authentication.
there was this study, right? So the average company takes a crazy 280 days just to even notice they've been breached.
Every framework, analogy, and talking point here - zero trust, layered security, 'never trust always verify,' the human element, building a culture of security - is standard industry boilerplate. There is no contrarian argument, no first-principles reasoning, and no perspective a practitioner couldn't find in any vendor whitepaper.
Never trust, always verify sounds like a digital bouncer at every door, checking everyone's id.
It's like building a fortress. Gotta have a solid base.
There are no genuine guests or practitioners. The two 'guest podcast hosts' share no credentials, company affiliation, or practitioner experience, and the scripted back-and-forth with theatrical surprise reactions strongly suggests AI-generated content rather than real operator knowledge.
We have our guest podcast hosts, Allyson Indigo and Aaron Ivey.
Research we looked at is pretty shocking. 95%. A whopping 95% of breaches are linked to human error.
Three statistics are cited (280 days to detect a breach, 2,500 vulnerabilities per month, 95% human error) but all are attributed to anonymous 'research we looked at' with no source, date, or methodology. No specific companies, vendors, case studies, dollar figures, or named incidents appear anywhere in the episode.
there was this study, right? So the average company takes a crazy 280 days just to even notice they've been breached.
Over 2,500 new vulnerabilities every single month. Just think about that.
The host's contributions are almost exclusively affirmations and theatrical reactions rather than real questions, and there is zero pushback on any claim made. The conversation is visibly scripted, with the entire closing segment repeated word-for-word - a structural failure that makes meaningful follow-up impossible.
Wait, hold on. My coffee maker needs protection? Seriously? Hackers could use my morning coffee to get into my business.
280 days, seriously? That's almost a whole year.
Computed from the transcript - who did the talking, and the words that came up most.
Welcome to The Incident Report! We have a couple incredible guest hosts today: Aaron Ivy and Allison Indigo. They take a comprehensive look at cybersecurity strategies and risk assessments. Don’t miss this episode! Articles cited: 7 Essential Cybersecurity Services for Every Business Cybersecurity Best Practices for Businesses How to Perform a Cybersecurity Risk Assessment If you have questions or suggestions for the podcast, you can always email Paul and Adam at theincidentreport@questsys.com . Thanks for listening! The Incident Report is created by Quest Technology Management. With over 40 years of experience, Quest is a leading Technology Integrator, working seamlessly with your staff, and systems to achieve your IT goals. Learn more about everything they do at .
Transcribed and scored by The B2B Podcast Index.
Speaker A: Start small. Take it one step at a time. Conduct a risk assessment, figure out what's most important to protect. Then implement basic security measures. Strong passwords, multi factor authentication. Keep your software updated. Those simple things make a big difference.
Speaker B: Welcome to the incident report presented by Quest Technology Management. This week is a little different. We have our guest podcast hosts, Allyson Indigo and Aaron Ivey. The incident report brings you skills, tactics, and channel news to help you stay productive and agile in a changing technology landscape.
Speaker C: All right, let's dive in. Today we're tackling cybersecurity head on. It's a huge topic, we know, but no worries. We've been digging through research, tons of it. And we're here to break down the essentials you need, you know, to protect your business. The stuff that really matters.
Speaker A: Yeah, you know, it's interesting. There's no like one size fits all solution than cybersecurity, but there are certain services. They're kind of like the foundation. No matter what. Every business needs these big or small.
Speaker C: You got it. It's like building a fortress. Gotta have a solid base. So let's talk about one of those foundational pieces. Mdr. Managed Detection and Response. You know, I know acronyms can be a bit much, but stick with me on this one.
Speaker A: Absolutely. And you know, MDR is like having a 247-security team watching your systems, always on the lookout for anything fishy. And get this, there was this study, right? So the average company takes a crazy 280 days just to even notice they've been breached.
Speaker C: 280 days, seriously? That's almost a whole year. I mean, imagine the damage that could happen in that time. It makes you think. Most companies are just reacting, waiting for something bad to happen, then scrambling. But mdr, that's a different story. It's about being proactive.
Speaker A: Right, Exactly. You got it. It's all about spotting those threats before they become a disaster. Speaking of disasters, that leads us to ir Incident response. That is, even with the best defenses, sometimes those breaches happen. Think of IR like your emergency team. They're ready to swoop in, minimize the damage, you know?
Speaker C: Okay, I like that. The emergency team. So MDR is like the security guard preventing things, and IR is the cleanup crew after the alarm's gone off. But how does IR actually work? I'm curious.
Speaker A: A good IR plan. That's crucial. It lays out the steps, what to do for different incidents. It's about containment, Stopping the problem from spreading.
Speaker B: Mhm.
Speaker A: Eradication. Getting rid of the threat, making things safe again. And really important Learning from it all so you can strengthen your defenses for the future.
Speaker C: Learning, yeah, that's key, isn't it? Turning a bad thing into a way to improve.
Speaker A: Exactly. You got it. And this brings us to another crucial part. You know, protecting all those devices on your network. And let's be honest, probably more than you realize.
Speaker C: Oh, definitely more than I'd like to think about.
Speaker A: Right, so that's where EPS comes in. Endpoint protection is a service. A mouthful, I know. It's not just your laptop and phone anymore. It's your smart coffee maker, security cameras, everything. Anything connected to the Internet needs protection these days.
Speaker C: Wait, hold on. My coffee maker needs protection? Seriously? Hackers could use my morning coffee to get into my business.
Speaker A: It sounds crazy, but yeah. Yeah, it's a possibility. Unsecured IoT devices, they're a huge weak point. So EPS acts like a shield, watching for anything suspicious, blocking malware, keeping all those endpoints safe, no matter what they are. And it's not just about individual devices. It's about protecting your whole network from those threats spreading.
Speaker C: All right, all right, you've convinced me. No more skimping on security, even for the coffee maker. But let's be real. Keeping up with updates and patches, it's a never ending battle. You know those notifications always popping up at the worst times?
Speaker A: Oh, I hear you. It's a pain. That's why PMS is so helpful. Patch management as a service, basically outsourcing those updates. And there's this crazy stat. Over 2,500 new vulnerabilities every single month. Just think about that.
Speaker C: 2500. Wow. That's a lot of potential problems. But wouldn't PMAs slow things down? Waiting for a third party to handle patches, that seems risky.
Speaker A: It's actually the opposite. PMAs can make things faster. It automates everything. Keeps your systems up to date, always protected. Plus your internal team, they can focus on other things.
Speaker C: Okay, that makes sense. Efficiency and security. So we've talked about systems, devices, all that, but what about the core of any business? The data. You know those ransomware horror stories, wiping out databases. It's enough to keep any business owner up at night.
Speaker A: Absolutely. Data, it's the lifeblood of any organization. That's where immutable storage comes in. Think of it like a time capsule for your data. Once it's in, it can't be changed, can't be deleted, even if someone breaks into your systems.
Speaker C: Wow. So it's like an insurance policy for your data. Even against the worst attacks. That's reassuring.
Speaker A: Exactly. Peace. Of mind, knowing your data is safe. And it's not just ransomware, it's accidental deletion, too. Insider threats, compliance requirements, it covers it all.
Speaker C: Okay, I'm seeing the value here, definitely. Now, with so many businesses going remote, using the cloud, our networks, they're getting so complex. It's like trying to secure a city with a million entry points. How do you even start? With something that big, you're hitting on a key point.
Speaker A: The old ways of security, they just don't cut it anymore. We need a new approach. And that's where ZTNA comes in. Zero trust. Network access. It's got a catchy name. And the idea is simple. Never trust, always verify.
Speaker C: I like that. Never trust, always verify sounds like a digital bouncer at every door, checking everyone's id. No sneaking in allowed. But wouldn't that be a nightmare for users? Constantly jumping through hoops just to open a file?
Speaker A: Ztna, it's about finding that balance. Security and usability, they got to work together. So it uses things like multi factor authentication, device posture checks, making sure only the right people and the right devices get access to what they need. And the cool part, it adapts, you know, depending on the situation, the context of the access. So someone logging in from their usual spot on their own device, it's seamless, no problem. But someone on a borrowed laptop in a new place, they're going to face more checks. Got to be sure.
Speaker C: So it's about being smart. Uh, right. Not just blanket security, but adjusting to the situation. Makes sense. Makes sense. But with all this technology talk, aren't we forgetting something? The human factor, the most unpredictable element of all.
Speaker A: You're absolutely right. Even with the best tech, human error is still a big issue. That's why cybersecurity awareness training is so important.
Speaker C: Okay, how big of a problem is human error really? Are we talking a few careless clicks or is it more serious?
Speaker A: Research we looked at is pretty shocking. 95%. A whopping 95% of breaches are linked to human error.
Speaker C: 95%, that's mind blowing. So even, even with all the firewalls, all the fancy systems, it comes down to people making smart choices. Awareness training, it's just as important as any technology.
Speaker A: Absolutely. It's about empowering your employees. They become your first line of defense. You know, teach them to spot those phishing emails, those dodgy links, understand strong passwords, all the basics.
Speaker C: So we're not talking boring lectures and compliance modules, right? It's gotta be engaging, relevant to people's lives.
Speaker A: Exactly. The More engaged they are, the more, the stronger your security becomes.
Speaker C: Makes sense. Engagement is key. All right, we've covered a lot of ground here, but I have a feeling this is just the beginning. There's so much more to building a cybersecurity strategy.
Speaker A: You're right. There's a lot more to explore. It can feel overwhelming, especially for businesses with limited resources. But that's what we're here for. To break it down, we'll start with a few key questions every business leader should ask themselves. What are your critical assets? What compliance rules do you have to follow? What's your current risk level? And what about your budget? How much can you spend? These are all crucial things to think about. It's about prioritizing, figuring out what matters most for your business and finding the right partner, someone with experience to help you navigate all this and give you peace of mind.
Speaker C: A, ah, partner. Yeah. That's key, isn't it? Having someone you can trust who knows their stuff.
Speaker A: Absolutely. Cybersecurity, it's not something you have to do alone.
Speaker C: Alright, so we've got the foundation, we've talked about the key services, the questions to ask. But there's another piece to this puzzle, isn't there? The human element. How do we really get people on board?
Speaker A: You're right, that's a crucial part. Technology is great, but it's only part of the story. We need to create a culture of security where everyone understands the risks.
Speaker C: A culture of security, I like that. So how do we do that? Where do we even begin?
Speaker A: Well, it starts at the top, with leadership. They have to set the tone, make it clear that cybersecurity is a priority.
Speaker C: Leading by example. Right. Not just talking about actually doing it.
Speaker A: Exactly. Walking the walk.
Speaker C: Okay, so leadership is crucial, but what about the rest of the team? How do we get everyone involved?
Speaker A: Communication, that's key. Regular training, making sure everyone understands the risks. And most importantly, creating an environment where people feel comfortable speaking up. If they see something suspicious, they need to feel safe reporting it.
Speaker C: That's so important. Feeling safe to speak up. We don't want people afraid to report potential problems.
Speaker A: Exactly. We need everyone's eyes and ears. Cybersecurity, it's a team effort.
Speaker C: A team effort. I like that. So we've got leadership buy in. We've got communication. We're building that culture of security. But the threat landscape, it's always changing. How do we keep up? How do we stay ahead of the curve?
Speaker A: That's the million dollar question. And honestly, it's a constant challenge. The attackers they're always evolving, always finding new ways. In. One of the biggest trends we're seeing is AI powered attacks.
Speaker C: AI powered attacks? Okay, that sounds straight out of a sci fi movie.
Speaker A: It might sound futuristic, but it's happening now. Attackers are using AI to automate their attacks, making them faster, more efficient, harder to detect.
Speaker C: So it's like they're using our own technology against us.
Speaker A: In a way, yes. But we can use AI to fight back too.
Speaker C: AI versus AI. That's a scary thought.
Speaker A: It can be, but it's also an opportunity. We can use AI to analyze data, spot anomalies, automate tasks. M. It's like having an extra set of eyes constantly watching for threats.
Speaker C: So AI can be both a threat and a tool.
Speaker A: Exactly. It's all about how we use it.
Speaker C: Okay, I'm starting to wrap my head around this AI thing. Let's talk about something a little more down to earth. Finding the right cybersecurity partner. With so many options out there, it's hard to know where to start.
Speaker A: You're right, it can be overwhelming. Choosing a partner is a big decision. You gotta get it right.
Speaker C: So what should businesses be looking for? What are the non negotiables?
Speaker A: First and foremost, they need to understand your business, Your risks, your industry, your goals. It's not about a one size fits all solution. You need a partner who can tailor their approach to your specific needs.
Speaker C: It's like finding a good doctor. Right? Someone who listens, asks the right questions, creates a personalized plan.
Speaker A: Exactly. You need that same level of care and attention.
Speaker C: Okay, so understanding your business is key. What else should we be looking for?
Speaker A: Experience. Definitely. Look for certifications, industry recognition testimonials. You want someone with a proven track
Speaker C: record, so do your research, check their credentials, make sure they're legit.
Speaker A: Exactly. Don't just take their word for it.
Speaker C: And what about responsiveness? If something goes wrong, I need to know they'll be there ready to help.
Speaker A: Absolutely. Responsiveness is crucial, especially when you're dealing with a security incident. Every minute counts. Look for a partner with 247 support, a solid incident response plan, and clear communication. You need to know what's happening every step of the way.
Speaker C: Peace of mind, knowing you've got someone in your corner.
Speaker A: Exactly. That's what a good partner should provide.
Speaker C: Okay, so we've talked about finding a partner, but let's address some common myths about cybersecurity. One I hear all the time is that it's only for big businesses. You know, the ones with tons of sensitive data. If You're a small shop, you're safe. Right.
Speaker A: That's a dangerous myth. Unfortunately, small businesses, they're often more vulnerable. They might have fewer resources, less sophisticated security. And the attackers know that they look for easy targets.
Speaker C: So it's like those nature documentaries. The predators go after the weakest in the herd.
Speaker A: Exactly. They're looking for businesses that haven't invested in protection.
Speaker C: Okay, so size doesn't matter. Everyone's a potential target.
Speaker A: Right. And another myth is that cybersecurity is too expensive or too complicated for small businesses to handle. But there are plenty of affordable solutions out there. User friendly tools that can make a big difference.
Speaker C: So it's about finding the right tools and strategies for your budget.
Speaker A: Exactly. You don't have to break the bank to be secure.
Speaker C: And there are free resources too, right?
Speaker A: Absolutely. The Small Business Administration, they have some great stuff online.
Speaker C: So be resourceful, find the information and support you need.
Speaker A: Exactly. It's out there.
Speaker C: Okay, here's another myth I want to tackle. The idea that cybersecurity is just an IT issue.
Speaker A: That's a big one. Cybersecurity, it's a business issue. A, uh, company wide issue. A breach can impact everything. Operations, finance, customer relationships, your reputation, Everything is at stake.
Speaker C: It's like a ripple effect. One incident can impact the whole organization.
Speaker A: Exactly. That's why a holistic approach is so important. Everyone needs to be involved, from the
Speaker C: CEO down, breaking down silos, making security. Everyone's responsibility.
Speaker A: Right. It's a team effort.
Speaker C: But with all this talk about the human element, I wonder, are we overemphasizing it? Can't technology solve most of our cybersecurity problems?
Speaker A: Technology is crucial, but it's not a magic bullet. We can't just rely on firewalls and antivirus software. We need to be smart, use technology strategically.
Speaker C: So it's about having a plan, using the right tools in the right way.
Speaker A: Exactly. And that plan should include regular assessments, vulnerability testing, incident response planning, being proactive, not just reacting to threats.
Speaker C: And that proactive approach extends to our employees, right? Empowering them to be the first line of defense.
Speaker A: Absolutely. Cybersecurity awareness training is key. Teach employees how to spot phishing emails, suspicious links, all those social engineering tactics that attackers use.
Speaker C: Make security everyone's responsibility.
Speaker A: Exactly. Create a culture where people feel comfortable reporting potential issues.
Speaker C: And speaking of those attackers, they're always coming up with new tricks, aren't they? What trends are you seeing right now? What should businesses be prepared for?
Speaker A: One of the biggest concerns is targeted attacks. We're not just Dealing with random hackers anymore. We're seeing organized cybercrime groups, even nation state actors, targeting specific businesses, specific industries.
Speaker C: So it's not just about protecting yourself from anyone. It's about understanding who might be after you and why.
Speaker A: Exactly. These attackers are using sophisticated techniques. Social engineering, spear phishing, custom made malware. They're also exploiting vulnerabilities in new technologies. Cloud computing, the Internet of things, all that.
Speaker C: It's like they're always one step ahead.
Speaker A: It can feel that way. We can't give up.
Speaker C: So what can businesses do to keep up?
Speaker A: Stay informed. That's crucial. Subscribe to security newsletters, attend conferences, follow experts online. You need to know what the latest threats are so you can take steps to protect yourself.
Speaker C: To be proactive, be curious, keep learning.
Speaker A: Exactly. Cybersecurity is a constantly evolving field.
Speaker C: Okay, so stay informed. What else?
Speaker A: Layered security. That's another important concept. Multiple layers of defense. Firewalls, intrusion detection, endpoint protection, data backups. Make it as hard as possible for attackers to get in.
Speaker C: It's like building a fortress. Multiple walls, multiple moats.
Speaker A: Exactly. Make them work for it.
Speaker C: And of course, we can't forget the human element.
Speaker A: Right. Regular security awareness training for employees.
Speaker B: Mhm.
Speaker A: Teach them to recognize phishing, suspicious links, social engineering.
Speaker C: Make security a part of the company culture.
Speaker A: Exactly. Everyone needs to be involved.
Speaker C: Okay. So stay informed. Layered security, employee training, that's a lot to take in. What advice would you give to someone who's feeling overwhelmed? A business owner who doesn't know where to start.
Speaker A: Don't panic. That's the first thing. Start small. Take it one step at a time. Conduct a risk assessment. Figure out what's most important to protect. Then implement basic security measures. Strong passwords, multi factor authentication. Keep your software updated. Those simple things make a big difference.
Speaker C: So build a solid foundation, then go from there.
Speaker A: Exactly. And don't be afraid to ask for help. There are experts out there who can guide you.
Speaker C: Like having a cybersecurity coach in your corner.
Speaker A: Exactly. Someone to help you navigate the complexities.
Speaker C: Okay, that's reassuring. Before we wrap up this part of our deep dive, I want to touch on something we mentioned earlier. The human side of cybersecurity. It's easy to get caught up in the technical details, but at the end of the day, it's about protecting people, isn't it?
Speaker A: Yeah. You know, it's easy to focus on all the tech stuff, but cybersecurity, it's not just about firewalls and passwords. It's about people. The human factor.
Speaker C: Right, right. It's about protecting people's lives and businesses.
Speaker A: Exactly. Get it. Behind every cyberattack, there's a person, a motive, and on the other side, there are people and businesses being hurt, their lives disrupted, their finances messed up, their privacy invaded.
Speaker C: It's a good point. It's easy to forget that impact. Cybersecurity isn't just about data, it's about protecting people's livelihoods.
Speaker A: Absolutely. You know, it's not just numbers on a spreadsheet, it's real world consequences, real people being affected.
Speaker C: That makes it even more important to get cybersecurity right.
Speaker A: Definitely. And that brings us back to awareness and education. When we understand the human cost of these attacks, we take it more seriously. We make smarter choices.
Speaker C: It's about empathy, realizing our actions online have real world impacts.
Speaker A: That's a great way to put it. Empathy is key.
Speaker C: So as we wrap up this deep dive, I want our listeners to feel empowered. The cyber world can be scary, but we can handle it.
Speaker A: Absolutely. Proactive steps, staying informed, those are the keys. You can reduce your risk. Navigate the digital world with confidence.
Speaker C: So what's one thing our listeners can do today to improve their security?
Speaker A: Have a conversation, talk to your team about cybersecurity risks, their role in protecting the business. Encourage questions, reporting suspicious activity, good security
Speaker C: habits, open communication, shared responsibility. That's what we need.
Speaker A: Exactly. Cybersecurity, it's a team sport.
Speaker C: Well said. On that note, we're wrapping up this episode of the Deep Dive. Thanks for joining us on the cybersecurity journey. We hope you found it insightful, engaging and empowering. Until next time, stay curious, stay safe, and stay ahead of the game.
Speaker A: Yeah. You know, we get caught up in the tech side of things. We gotta remember, behind every cyberattack, there's a person, there's a reason, a motivation.
Speaker C: Right. Real people doing this, not just some abstract threat.
Speaker A: Exactly. And on the other side, there are people being affected by it. Businesses too. Their lives disrupted, finances messed up, privacy invaded.
Speaker C: It's a good reminder that cybersecurity, it's not just about protecting data, it's about protecting people, their livelihoods, their well being.
Speaker A: Absolutely. It's not just about numbers and systems. It's real world consequences, real people being hurt.
Speaker C: That makes it even more crucial to get cybersecurity right?
Speaker A: Definitely. And that brings us back to awareness, to education. You know, when we understand the human impact of these attacks, we're more likely to take it seriously, make those smart choices.
Speaker C: It's about fostering a culture of empathy, realizing that our actions online, they have consequences for ourselves, for others. It's all connected.
Speaker A: That's a powerful way to think about it. Empathy is key.
Speaker C: So as we wrap up this deep dive into cybersecurity, I, uh, want our listeners to walk away feeling empowered. The cyber world can be intimidating, but we don't have to be afraid of it.
Speaker A: Absolutely. Taking those proactive steps, staying informed, that's how you reduce your risk. Navigate the digital world with confidence.
Speaker C: So what's one action our listeners can take today to boost their security?
Speaker A: You know, start with a conversation. Talk to your team, Talk about the risks, their role in protecting the business. Encourage them to ask questions, report anything suspicious. You know, build those good security habits.
Speaker C: Open communication, shared responsibility. That's what it's all about.
Speaker A: Exactly. Cybersecurity is a team sport. Everyone needs to play their part.
Speaker C: Well said. And on that note, we're wrapping up this episode of the Deep Dive. Thanks for joining us on this exploration of cybersecurity essentials. We hope you found it insightful, engaging, and most um, importantly, empowering. Until next time, stay curious, stay safe, and stay ahead of the game.
Speaker B: Thanks so much for listening. The incident report is brought to you by Quest Technology management. With over 40 years of experience experience, Quest is a leading technology integrator, working seamlessly with your staff and systems to achieve your IT goals. Learn more about everything they do at Ah, quests.com and if you have questions or suggestions for the podcast, you can always email Adam and myself at the incident reportues.com we hope you have a great week and we'll see you next time.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.