The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/The ShiftShapers Podcast
The ShiftShapers Podcast artwork

EP 551 Cybersecurity Reality Check - with Daniel Metcalf

The ShiftShapers Podcast · 2026-06-02 · 33 min

0:00--:--

Key moments - from our scoring

Substance score

44 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality7 / 20
Guest Caliber11 / 20
Specificity & Evidence10 / 20
Conversational Craft7 / 20

Daniel Metcalfe, co-founder and president of Cyberfin, walks through the cybersecurity landscape for benefits advisors in an era of AI-accelerated threats. The core criminal motivation remains unchanged - attackers want access to sensitive data (medical records, identity information, credit data) that advisors hold - but AI has weaponized social engineering at scale, making phishing emails and impersonation dramatically more convincing. Rather than protecting perimeter castles, advisors must adopt zero-trust models with consistent endpoint, internet, and email protection backed by 24/7 monitoring. The biggest vulnerabilities today aren't technical controls like multi-factor authentication; they're email infrastructure and credentials to carrier platforms like InsureTax, which serve as gateways to larger targets. Metcalfe reveals that 80% of agencies lack regular employee security awareness training, and most still rely on outdated checkbox security (antivirus, MFA, cyber insurance) that leaves them exposed to social engineering attacks up 500%. Benefits brokers, agents, and advisors managing employee data, FMO relationships, and commercial clients will find practical steps: inventory all devices and access, implement password managers with MFA, deploy continuous monitoring, and establish ongoing security training beyond annual compliance boxes.

Key takeaways

  • →Social engineering attacks have increased 500% and are the primary vulnerability for benefits advisors, not technical exploits that MFA or antivirus can prevent.
  • →Advisors should inventory all devices, connections, and data access points, then shift from castle-methodology (protecting everything inside) to zero-trust security with 24/7 endpoint monitoring around each person.
  • →At least 80% of agencies lack regular ongoing employee security awareness training, relying instead on one-time annual training that is insufficient against modern threats.
  • →Email and email credentials represent the biggest exposure because advisors must use email to collect, store, and move sensitive data through carrier systems, quoting tools, and InsurTech platforms.
  • →Password managers with multi-factor authentication and continuous monitoring are essential because they prevent social engineers from extracting credentials through social engineering tactics like impersonation.

In this episode

  1. 1The Cybersecurity Landscape for Benefits Advisors
  2. 2How AI is Changing Cyber Threats and Attacks
  3. 3Current State of Industry Preparedness
  4. 4Major Gaps in Cybersecurity Understanding
  5. 5Where Advisors Are Most Exposed Today
  6. 6Practical Steps to Improve Security Posture
  7. 7Employee Awareness Training and Best Practices

Mentioned

Daniel MetcalfCyberfinDavid SaltzmanShiftShapers PodcastChat GPTMicrosoft 365Google WorkspaceInsureTaxCMS

Guests

Daniel Metcalf

Topics in this episode

Google WorkspaceMulti-Factor AuthenticationSocial engineering attacksPassword managersemail securityCyberfinO365employee security awareness trainingcarrier systemsInsurTech platforms

Questions this episode answers

What are the biggest security gaps in benefits advisor firms today?

Most advisors rely on outdated castle-methodology protections like multi-factor authentication and antivirus, which don't defend against social engineering attacks (up 500%). Eighty percent of agencies do not conduct regular employee security awareness training beyond annual compliance, and many incorrectly assume cyber liability insurance substitutes for actual cybersecurity measures.

Where are benefits advisors most exposed to cyber attacks right now?

Email and email credentials are the primary exposure point, along with connections to carrier tools and platforms like InsureTax. Attackers impersonate colleagues and clients to trick advisors into sharing credentials or session cookies, then use those trusted relationships to access larger targets like carriers, FMOs, and commercial clients.

How has AI changed the nature of cyber threats for the insurance industry?

AI has enabled cybercriminals to conduct mass-scale, highly convincing social engineering attacks that look like real colleagues and carrier communications rather than obvious scams. AI has also introduced data compliance risks when advisors grant agentic AI tools broad access to sensitive data without understanding where that information is stored or who can access it.

What are the first practical steps an advisor should take to improve cybersecurity?

Start by inventorying all devices, connections, and data access rights. Separate personal from business computers, then shift from perimeter protection to a zero-trust model protecting each person with consistent endpoint, internet, and email security backed by 24/7 monitoring. Add password managers with multi-factor authentication and implement ongoing employee security awareness training, not just annual compliance.

Why do cybercriminals keep targeting benefits advisors even when they're not the final target?

Advisors are trusted gateways to larger targets with more data - carriers, FMOs, and commercial clients. By compromising an advisor's email or carrier platform access, criminals can impersonate that trusted resource to attack bigger fish with larger datasets and higher-value information.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode contains a handful of useful, specific points - social engineering bypassing MFA, advisors as stepping-stone vectors to carriers/FMOs, and the 80% training gap stat - but large stretches are basic cybersecurity 101 explanations (what a VPN is, what encryption is) and generic advice that any moderately informed operator would already know.

Social engineering tax are up 500%, right? That has nothing to do with multi-factor authentication or antivirus
they're gonna use you as the trusted resource to that bigger fish with a pH that they can start to go after because now they can act as you

Originality

7 / 20

The framing of zero-trust as 'bubbles around each person' is a useful simplification for a non-technical audience but is a restatement of widely-published zero-trust architecture thinking. There are no contrarian arguments, no first-principles reasoning, and no genuinely surprising claims; the territory covered maps directly onto standard vendor-side cybersecurity messaging.

that castle methodology of where we're going to protect everything inside a building, that model is now being used against our industry
we have adopted what companies like Optimum and some of these other enterprises did, which is this multi-layered user-based protection

Guest Caliber

11 / 20

Daniel Metcalf is a genuine niche practitioner - six years operating a cybersecurity firm specifically serving independent insurance agencies - who draws on real assessment data from his own client base. He is not a career podcast guest, but he is also a vendor-founder with an evident commercial interest rather than a practitioner who has run security at scale inside a major carrier or agency group.

our mission here at Cyberfin is to eliminate cybercrime and regulation fines in the independent insurance agency industry
when we do our um cybersecurity assessments for the agencies um that we perform, we notice at least 80% of the agencies do not incorporate employee security awareness training on a regular basis

Specificity & Evidence

10 / 20

The guest names specific tools (Bitwarden, Keeper, Dashlane, 1Password, Microsoft Copilot), cites a concrete internal finding (80% training gap), and drops plausible dollar figures for attacker cost of entry. However, the headline 500% social engineering stat is entirely unsourced, several dollar figures are hedged ('$200 or whatever'), and no named client breaches or case studies are provided.

Social engineering tax are up 500%
we notice at least 80% of the agencies do not incorporate employee security awareness training on a regular basis, meaning like more than once a year

Conversational Craft

7 / 20

The host keeps the conversation moving but consistently telegraphs answers in his questions, fills in the guest's framework himself ('so it sounds like it's a layered approach'), allows all statistical claims to pass unchallenged, and introduces a meandering tangent about Adobe Acrobat that displaces follow-up on substantive points. No productive disagreement or genuine probing occurs.

It also sounds, you know, to a certain extent, like the bad guys are always a step ahead... Is that a good analogy?
So it sounds like it's kind of a layered approach. Would that be a fairer analogy?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

data33david27speaker25start21cybersecurity18access18industry17already17tools15email15internet14sure13everybody12advisors11password11clients10

Full transcript

33 min

Transcribed and scored by The B2B Podcast Index.

1 - > David: Cyber threats are accelerating, and AI seems to be 2 - > rewriting the rules almost every day. 3 - > So are benefits advisors truly prepared to protect their 4 - > clients, their data, and their businesses in this new 5 - > environment? 6 - > We'll find out on this episode of Shift Shapers. 7 - > Announcer: Change either energizes or paralyzes.

8 - > The choice is yours. 9 - > This is the Shift Shapers Podcast, bringing the employee 10 - > benefits industry interviews with individuals and companies 11 - > who are shaping the industry's shift. 12 - > And now, here's your host, David Saltzman. 13 - > David: And to help us answer and understand all of those 14 - > questions, we've invited Daniel Metcalfe.

15 - > Daniel is co-founder and president of Cyberfin. 16 - > He works kind of at that interesting intersection of 17 - > cybersecurity, AI, and the employee benefit space, helping 18 - > advisors understand emerging risks and more importantly, how 19 - > to navigate them with practical real-world strategies. 20 - > Welcome, Daniel. 21 - > SPEAKER_00: Hey, thanks for having me.

22 - > I'm really honored to be here. 23 - > David: It's our pleasure. 24 - > So let's let's jump right in and start with the big picture. 25 - > Before we get into the actual risks and the technology, set 26 - > the landscape for us.

27 - > How should benefits advisors be thinking about cybersecurity and 28 - > AI today? 29 - > SPEAKER_00: Yeah, absolutely. 30 - > A couple things that come to mind, especially since with 31 - > artificial intelligence, there's something that's coming out 32 - > every single day. 33 - > But the core, the core area around cybercrime and 34 - > cybersecurity still remains the same.

35 - > Their whole infrastructure and what they're trying to do is to 36 - > fool you into giving up something that you know, like, 37 - > and trust that they can go make money from, right? 38 - > So whether that's um keeping you, you know, uh mainly in the 39 - > in the benefit space, they want to get to your data, right? 40 - > So they want to get to your data because the data is gold to 41 - > them. 42 - > And that data is the very sensitive data that you have to 43 - > keep about every employee, about the employer itself, the you 44 - > know, the medical data, because they can in the identity data, 45 - > credit data, because they can use that in order to make money 46 - > in other ways.

47 - > And so what you have to be out in a lookout for is how are the 48 - > bad guys trying to attack my agency in order to get access to 49 - > that data? 50 - > Or the other is how do they get access to you because you have 51 - > access to a bigger fish with a lot more data. 52 - > Think like a carrier, an FMO, uh, you know, a business, you 53 - > know, your clients, your bit, your, you know, uh the 54 - > commercial clients or the clients that you have. 55 - > And so they're gonna use you as the trusted resource to you to 56 - > that um bigger fish with a pH that they can start to go after 57 - > uh because now they can act as you, right?

58 - > And have an engineering attack that way. 59 - > So what artificial intelligence has done is one, they've given 60 - > cybercriminals the ability to do mass-scale attacks at once and 61 - > very, very good attacks and making social engineering look 62 - > even more real than ever before. 63 - > We're not dealing with the Nairobian princes anymore, 64 - > right? 65 - > We're looking like carriers, we're looking like uh clients, 66 - > we're looking like uh tech your tech stack, and specifically 67 - > they even know which ones you are.

68 - > On the and the uh the other area within um AI is what we're 69 - > giving it access to. 70 - > So giving it access to the data, giving it access to our 71 - > proprietary, um, how many people are starting to go down that 72 - > route of you know, creating uh uh agentic AI and giving them 73 - > access to everything and making giving them connectors without 74 - > even thinking about what it really has access to and where 75 - > is that information being stored and going.

76 - > So we're constantly, you know, especially within our 77 - > organization, we're constantly working with the agencies to try 78 - > to let them know both of the here's where the cyber criminal 79 - > risk is coming in, and then here's the here's the data 80 - > compliance and protection that you're putting yourself, that 81 - > risk that you're putting yourself in using these tools 82 - > and utilizing it from that standpoint. 83 - > David: So, honest answer, you talk to an awful lot of agents, 84 - > brokers, advisors, call us what we want to.

85 - > Um, are most advisors ahead of the curve or behind it? 86 - > SPEAKER_00: Um, well, I wouldn't be in business if everybody was 87 - > ahead of the curve. 88 - > Um, I said our mission here at Cyberfin is to eliminate 89 - > cybercrime and regulation fines in the independent insurance 90 - > agency industry. 91 - > Um, and I wish I was here to tell you, oh my gosh, we're so 92 - > far ahead after six years of doing this that, you know, you 93 - > know, it's it's been a great uh reckoning for everyone and we're 94 - > everything's heading in the right direction, but this is not 95 - > true.

96 - > Um so when it comes to cyber cybersecurity, we're still a 97 - > little bit behind the curve in our industry. 98 - > When it comes to artificial intelligence, um, because we do 99 - > help organizations implement AI, implement it safely, um, I 100 - > wouldn't say the industry's behind the curve or the agencies 101 - > are behind the curve. 102 - > I think they're right there with what the other industries are at 103 - > when this dabbling phase, and it's still just a really smart 104 - > assistant, and it's just it's better, it's a better chat bot, 105 - > if you will, or a better chat Google search tool than before.

106 - > But really getting the return on investment that some of the 107 - > other industries are are now starting to gain the benefit of, 108 - > we're far behind from that standpoint of it. 109 - > But part of it is the fact that we're regulated and we have very 110 - > sensitive data, and there's a lot of things that we have to 111 - > think about and we have to consider before we even start 112 - > unleashing some of these tools. 113 - > So I want to give us a good grade in our industry, 114 - > especially since we have to start thinking about at all 115 - > times what's what's happening with that data and who has 116 - > access to it.

117 - > David: Yeah. 118 - > Well, and the first thing that you want to think about is PHI, 119 - > and the last thing you want to think about is a PHI breach. 120 - > SPEAKER_00: Right, 100%. 121 - > David: So when you talk to advisors, where do you see the 122 - > biggest gaps in understanding when it comes to cybersecurity?

123 - > SPEAKER_00: The biggest gaps in understanding is, and I and I 124 - > feel that, you know, other people in my in my industry have 125 - > in technology have kind of led us to this, which is that 126 - > multi-factor authentication and antivirus is enough in order to 127 - > protect yourself. 128 - > Um that that that version and that castle methodology of where 129 - > we're going to protect everything inside a building, 130 - > um, that will that model is now being used against our industry, 131 - > right?

132 - > Just by saying, hey, if I check some boxes, I'm good to go. 133 - > If I have cyber liability insurance, I can use that as a 134 - > cybersecurity measure, right? 135 - > Um that's just not that's just not where cybercrime is at 136 - > today. 137 - > Social engineering tax are up 500%, right?

138 - > That has nothing to do with multi-factor authentication or 139 - > antivirus, right? 140 - > That is them tricking you into, you know, through multiple 141 - > different communication technical, you know, technology 142 - > and digital communication tools, and in some instances analog, in 143 - > which they're tricking you into giving up credentials or giving 144 - > them access or sending them money or whatever that might 145 - > look like, right? 146 - > Um they are they are infiltrating people that you 147 - > already work with on a regular basis and acting as them, right?

148 - > So you're going to hand over your multi-factor 149 - > authentication, you're going to press the button, you're going 150 - > to engage with them. 151 - > They are going to get a session cookie because you're you think 152 - > you're interacting with somebody that you're already working with 153 - > and you're not. 154 - > Um so that's where I'd start at is we just we are using these 155 - > old ways of of trying to protect ourselves and from cybercrimes 156 - > or not really protecting ourselves and just hoping to use 157 - > insurance to cover our downside.

158 - > That is not where we need to be. 159 - > David: It also sounds, you know, to a certain extent, like the 160 - > bad guys are always a step ahead. 161 - > Sure. 162 - > It's like every time we think of some way to thwart them, they 163 - > come up with some new way to get around it.

164 - > And it's like this constant battle up the stairs. 165 - > Is is that a good analogy? 166 - > SPEAKER_00: Yeah, it's a great analogy. 167 - > And and and I had the pleasure of talking to um some people 168 - > within the federal government and some of the in the 169 - > international um space on like how they're protecting from that 170 - > level.

171 - > And they say that they they gave two really good examples. 172 - > One is there are entire skyscrapers in China and Russia 173 - > where people put on suit and ties and and grab a backpack and 174 - > they go up these skyscrapers with finding ways to try to 175 - > steal money and steal identities from and and intellectual 176 - > property from Americans, right? 177 - > That's their whole job. 178 - > Right.

179 - > And there's no way of, you know, there's no extradition. 180 - > There's no, there's no way of taking care of those criminals, 181 - > number one. 182 - > And number two, if we start looking at third world countries 183 - > that have an internet connection and they happen to steal even 184 - > just$25,000, that's generational wealth for, you know, three to 185 - > five years. 186 - > So they're gonna do whatever it takes, right?

187 - > Especially if a Chat GPT account is$20, right? 188 - > Or a ransomware as a service is $200 or whatever. 189 - > They're gonna do whatever it takes for as long as it takes in 190 - > order to, if they've got a if they've got a fish on the line, 191 - > right? 192 - > If they got you hooked.

193 - > So there's that they are gonna continue to change. 194 - > They're continued to think, and we have to be ahead of the game 195 - > instead of just reactionary to what to the new items. 196 - > David: Aaron Powell, which means I think for most of us who are 197 - > just, you know, insurance folks, we need to have a partner that 198 - > we can trust who will be keeping up with that separate from what 199 - > we're doing and and advising us. 200 - > But where would you say advisors are the most exposed as we sit 201 - > here today?

202 - > Not theoretically, but what's actually happening? 203 - > SPEAKER_00: Um the two that we see the most is through their 204 - > email and their email credentials and their 205 - > connections to their carrier tools or uh insure tax. 206 - > That is the place that they're the most vulnerable. 207 - > Um we have to, as an industry, right?

208 - > We have to use email to collect, store, analyze, and move that 209 - > data in order to get paid. 210 - > So we're right in the middle, and email is that that crux 211 - > point of where we have to gather all that information. 212 - > We have to move that data into carrier sites, quoting tools, 213 - > insure tax, client tools, right? 214 - > Third-party tools.

215 - > We have to move that data and store it, right? 216 - > Think of even the phone calls that, you know, if you're doing 217 - > individual health benefits, right? 218 - > And you're part of CMS and you gotta record all your phone 219 - > calls and store them for seven years. 220 - > There's a lot of sensitive data inside there, right?

221 - > And now we're supposed to save it for seven years. 222 - > So now we have to do that. 223 - > So that email and that email infrastructure, your O365 or 224 - > your your workspace, that is now your biggest exposure from that 225 - > standpoint of it. 226 - > Then you look at all those tools that you have to move that data 227 - > into.

228 - > That's where you're going, you know, that that connection. 229 - > And then because you have to interact with them on a on a 230 - > day-to-day basis, if someone just even figures out a way to 231 - > fool you into that they're rule, that, that they're real, that is 232 - > the next and you know, most insecure part of your 233 - > organization. 234 - > David: So let's move into what they what advisors and all of us 235 - > can do about that. 236 - > So you work with firms on broadly being more secure.

237 - > What does being prepared actually look like in practical 238 - > terms? 239 - > What's what's the first couple of steps that any advisor should 240 - > take? 241 - > SPEAKER_00: The first of all is we need to inventory what all of 242 - > your devices, your connections, your access to data. 243 - > You have to really take the time to inventory all of that and 244 - > say, okay, these are all business computers.

245 - > Let's let's get rid of personal computers. 246 - > You know, I know we want to do that. 247 - > Let's get, you know, no using a personal computers, business 248 - > computers, knowing what everybody's internet connections 249 - > are, what are their email boxes, what do they have access to, 250 - > right? 251 - > Is there is their credentials have access into administrative 252 - > tools, whatnot, right?

253 - > So start to get that inventory. 254 - > And then from there, start to think how instead of it being 255 - > how am I going to protect everybody inside a building, 256 - > start thinking about how are we going to start protecting 257 - > everybody from a bubble around each person and their most 258 - > vulnerable parts. 259 - > The endpoint, the device they work on, their internet 260 - > connection, and their email. 261 - > Having those being protected, having that protection all be 262 - > consistent, and taking it to the next level of having a 263 - > cybersecurity guard actually watching it 24 by 7, 365, with 264 - > the ability to fix the problem instantaneously, right, and get 265 - > the bad guy out of there.

266 - > That is how you're going to severely lower your risk of an 267 - > attack. 268 - > Now, that is not the most foolproof, so I got to add a few 269 - > more things that we need to put around that, right? 270 - > Which is password managers with multi-factor authentication. 271 - > Right.

272 - > And you're saying, well, Dan, you just told me multi-factor 273 - > authentication. 274 - > I said don't doesn't mean that we can't use it. 275 - > It means that we should at least have a password manager because 276 - > that allows us the whole deny, deny, deny, right? 277 - > I don't know my password.

278 - > Sits in my password manager, right? 279 - > I can't give you my password. 280 - > I can't type it in, whatever it might be. 281 - > I have to use my password manager to be able to do it, 282 - > right?

283 - > Um, and then you know that's constantly being updated, and 284 - > it's you know, you don't have to think about password manager. 285 - > And then second is employee awareness training. 286 - > I can't stress enough employee security awareness training. 287 - > When we do our um cybersecurity assessments for the agencies um 288 - > that we that we perform, we notice at least 80% of the 289 - > agencies do not incorporate employee security employee 290 - > security awareness training on a regular basis, meaning like more 291 - > than once a year.

292 - > And it's and a lot of them are just doing the, oh, we get some 293 - > training from this association and we just kind of do it 294 - > ourselves. 295 - > Instead of actually signing up for, you know, as as a service, 296 - > right? 297 - > And doing the fish phishing simulation tests and doing some 298 - > vendor risk analysis, doing, you know, that that allows you to 299 - > see what the multi-factor authentication antivirus can't 300 - > protect from you. 301 - > It helps you find out who's falling for social engineering, 302 - > right?

303 - > By let's put our pencils down and have cybersecurity Fridays, 304 - > and let's go look to see what everybody's got on their 305 - > desktops. 306 - > Let's go see what, you know, if they're actually saving things 307 - > to the cloud that's already being backed up. 308 - > Like you'll find where your holes are just by stopping, 309 - > training, and seeing what. 310 - > But if we only do it once a year, man, all those bad habits 311 - > are gonna continue to go on, you know, throughout the year.

312 - > Um and then, and then lastly, really having backups. 313 - > I think that many organizations think that um just because they 314 - > put everything into the cloud, that that makes that data safe, 315 - > right? 316 - > That's not true. 317 - > All you did with the cloud is giving them more access to more 318 - > data.

319 - > You need to make sure it's backuped encrypted. 320 - > And encrypted means like making a complete scrambling of all the 321 - > ones and zeros that turn into words, right? 322 - > Into text uh and images and all those different things. 323 - > It takes whole Bitcoin computers to figure out mining computers 324 - > to go figure out how to unencrypt things.

325 - > And bad guys are just gonna go, ah, go right by it. 326 - > So all those combinations combined. 327 - > And you don't and do those in those order, right? 328 - > Because that is where you're gonna severely lower your risk, 329 - > and then you're just going to continue to harden yourself and 330 - > harden yourself and harden yourself as far as an agency is 331 - > concerned.

332 - > David: So it sounds like it's kind of a layered approach. 333 - > Would that be a fairer analogy? 334 - > SPEAKER_00: Yes. 335 - > And we, and that is where we came up with our philosophy.

336 - > We we used to do the CASA methodology just like everyone 337 - > else did, until we found out that that was out of date and 338 - > the bad guys were actually using that against us. 339 - > And now we have adopted what um companies like Optimum and some 340 - > of these other enterprises did, which is this multi-layered 341 - > user-based protection. 342 - > And it's just a fancy way of saying, let's put bubbles around 343 - > everybody where their most invulnerable parts are.

344 - > And everybody has the same cybersecurity, everyone has the 345 - > same, you know, protocol, no matter where they are, in the 346 - > office, out of the office, in Bermuda, right? 347 - > Um, whatever device they're using, Mac or Windows, doesn't 348 - > matter. 349 - > And it's all being managed by a cybersecurity guard. 350 - > Because if you think of the best analogy I can come up with is, 351 - > you know, we call them cul-de-sacs here in Minnesota or 352 - > circles, wherever you're from, right?

353 - > Which is if you have a house that has the lights off, the 354 - > garage doors open, and bikes are hanging out of the back of it, 355 - > you got the second house that has the ring camera with the 356 - > floodlights that pop on when you get close to the door. 357 - > And then you have the ADT or the cyber or the security system, 358 - > the house with the security system. 359 - > The one with the security system has layers. 360 - > The one with the ring camera and the floodlights, it has kind of 361 - > layers, but they don't talk to each other, right?

362 - > They have to work independently. 363 - > And then the other one has nothing, it is, is the bare 364 - > minimum at all. 365 - > You have a garage or you're not even really closing in, right? 366 - > Which one do you think the bad guy is gonna go after?

367 - > First house, no problem, right? 368 - > Second house, no problem. 369 - > Third house, that's layers. 370 - > Why would I bother?

371 - > Because I can go to the next street and I can find two more 372 - > houses. 373 - > I don't need to bother with this one. 374 - > So even by putting in those layers alone, that just signals 375 - > to the bad guys you're taking it seriously and most likely you're 376 - > gonna be left alone. 377 - > David: So we touched on AI a little bit earlier.

378 - > Let's kind of dive into it a little bit more. 379 - > Sure. 380 - > How is AI already changing the way benefits advisors operate, 381 - > whether they realize it or not? 382 - > SPEAKER_00: Oh wow, it's um well, let's let's start from the 383 - > risk standpoint first.

384 - > I I could go and survey 99 out of 100 agencies and advisories, 385 - > and I'm telling you, you've already adopted AI. 386 - > Someone has taken an email, copied the text, pasted it into 387 - > ChatGPT or Cloud or Gemini or Grok or whatever, got the 388 - > results, copied and pasted the results, put it in an email, and 389 - > sent it out to somebody. 390 - > They've adopted AI. 391 - > unknown: Right?

392 - > SPEAKER_00: Because they're using their business email 393 - > address, right? 394 - > That you own, right? 395 - > That you own the business email address, it's part of the 396 - > entity, right? 397 - > So you as a business have adopted AI.

398 - > Um, that's the risk of you're not, you don't already have the 399 - > policies in place to say, what can we use it for? 400 - > What can we not use it for? 401 - > What are approved tools? 402 - > What is the data it should have access to?

403 - > What you know, how do we review everything? 404 - > That's number one. 405 - > The other way that I've seen it from a pop from now from a uh 406 - > operational efficiency and from an return on investment 407 - > standpoint that they might not even know about is your staff is 408 - > using it as a very powerful assistant in order to help them 409 - > make them make their jobs more efficient, more effective, spend 410 - > more time better time with it. 411 - > Um, just as an assistant when it comes to emails and analysis and 412 - > um training and expertise from that standpoint of it.

413 - > If you want to take it to the next level, now you need to look 414 - > at what are some of the manual tasks that happen in my 415 - > organization that we can automatically do. 416 - > Again, as long as it doesn't have access to sensitive data, 417 - > that's where I would start, right? 418 - > And what are some of those things that we can do from a and 419 - > I break them into three buckets from a revenue generating 420 - > standpoint, like demand generation, marketing, um lead 421 - > lists, follow-up, sentiment, those kind of things, right?

422 - > Looking at from a RevOps, like, hey, are these the right, you 423 - > know, what are our ideal clients? 424 - > How do we know who the um people we should be talking to? 425 - > Can I reach out to them and make them connections, whatever it 426 - > might be? 427 - > Then we've got the service aspect of it.

428 - > What happens after someone agrees to allow us to insure 429 - > them? 430 - > What are all the steps that have to happen afterwards from 431 - > certificates of insurance or any types of other analysis that we 432 - > have to do or whatever that service is to make sure that now 433 - > that they have that we're providing them insurance and 434 - > benefits, what are the next steps have to go after that? 435 - > And then we look at the finance, and not finance the way you 436 - > think of it, but finance like how do we collect money?

437 - > How do we, you know, how do we how do we have to collect money? 438 - > How do we um rectify our QuickBooks? 439 - > How do we um pay commissions? 440 - > Things like that, right?

441 - > All those different types of financial admin type roles. 442 - > Agencies are using this already to make their jobs better. 443 - > Now, back to the risk side of it. 444 - > If your your um accounting team decides that, or your HR team 445 - > decides that they want to look at somebody's commissions and 446 - > they put it into a free Chat GPT account because you haven't 447 - > agreed to let them use ChatGPT from an enterprise perspective 448 - > or a business licensing, right?

449 - > They've just put that out there and then in into the ether that 450 - > anybody can go and pull down a bunch of that information. 451 - > So those are the that's the risk side of it too. 452 - > So someone's doing that to make their their lives better. 453 - > David: And I mean, not to go all HR on you, and I I want to stay 454 - > on the subject, but this is all stuff that should be in your 455 - > employee handbook, isn't it?

456 - > SPEAKER_00: Well, yeah, and everyone has a written 457 - > information security policy, and then it's in a response policy, 458 - > right? 459 - > Um David, right? 460 - > Because they the law says the HIPAA law says I have to have 461 - > it. 462 - > And depending on what state you're in, like you have to have 463 - > that.

464 - > And um, and I know I'm being facetious, but that that is, it 465 - > should be. 466 - > And now that you've adopted AI, you need to make sure that those 467 - > AI protocols should be in the handbook, should be included in 468 - > the WISP and the in the um instant response policy. 469 - > David: So for advisors who maybe want to start using AI, uh, what 470 - > are some responsible practical use cases? 471 - > SPEAKER_00: Um I always look at starting with your strategic 472 - > coach, right?

473 - > So training, you know, getting your AI digital brain, right? 474 - > Uh chief of staff, sort of right. 475 - > Everything about your agency that um makes you unique, makes 476 - > you different, you know, the kind of the products that you 477 - > sell, the carriers, anything that's public information that's 478 - > out there. 479 - > Um maybe want to, you know, give it to a strategic advisor to 480 - > help you make quicker decisions or allow you to um have a 481 - > conversation with somebody that has more experience than you, 482 - > right?

483 - > Um at your fingertips instead of uh and you can even talk into it 484 - > now. 485 - > Um that's where I that's a very safe way to start to integrate 486 - > it. 487 - > And then each role within your agency, do the same thing for 488 - > them. 489 - > What makes your position unique?

490 - > What are your responsibilities? 491 - > What, right, what what are the and and other trainings that 492 - > you'd want to do? 493 - > So think about how many times you have to train a new person 494 - > in, right? 495 - > And your standing operating procedures, put those in there 496 - > so that you can train faster, you can be more efficient.

497 - > They have a question, they don't have to come to you as the as 498 - > the bottleneck, they can go to the digital AI brain and they 499 - > can start you know getting trained from that. 500 - > Um, starting to do policy reviews, you know, start 501 - > thinking about things, you know, policy reviews, other things 502 - > about analysis. 503 - > That need to go faster, where if you're looking at two documents 504 - > with 200 pages at it versus some in artificial intelligence that 505 - > can look at 200 pages in a matter of instance and tell you 506 - > what the differences are, those are ways that you can start to 507 - > use it safely and get a benefit right off the bat.

508 - > I always go back to marketing too. 509 - > Marketing's really easy, you know, a little more simple as 510 - > far as like helping you write copy, uh, understanding what you 511 - > know the next um ad that you want to put out there, 512 - > measurements, right? 513 - > I love the analysis and marketing. 514 - > Figuring out here, you know, here's our SEO scores, here's 515 - > our uh, you know, how many leads we're getting from here, how 516 - > many we're converting, things like that.

517 - > Like that's so many tools that you can or uh use cases without 518 - > it actually touching sensitive data that you could get a 519 - > benefit from. 520 - > David: Well, and it it doesn't have to be one of the LLMs. 521 - > I mean, uh, the example that I I would give you is um not too 522 - > long ago, Adobe Acrobat started having a built-in AI piece. 523 - > And so you could input a set of bylaws and look for a keyword, 524 - > and it would pop up instantly all the instances and it would 525 - > analyze it for you.

526 - > Correct. 527 - > And and and I just heard a couple of days ago that Adobe 528 - > who sells a suite of different products is going to be coming 529 - > out in the very near future, as in the next month or so, with an 530 - > AI front end where you won't have to think about which one of 531 - > their products you need to do to use something. 532 - > You'll just tell it what you want it to do, and it will go 533 - > across the entire suite and do them for you. 534 - > SPEAKER_00: Yep.

535 - > Yeah, similar with with uh Microsoft Copilot or um, and and 536 - > there's gonna be domain-specific tools coming out in droves in 537 - > our industry. 538 - > They're in the property casually and the commercial industry, 539 - > these are already out there quite a bit where they're called 540 - > domain-specific tools. 541 - > And what that means is that they're specific to the 542 - > insurance domain. 543 - > And because they know all the regulations and what are ness 544 - > with sensitive data, they are socked to, they have a place to 545 - > put this data safely, or they don't keep the data, they just 546 - > analyze the data that you've already collected and you've 547 - > already protected.

548 - > These are these are um my recommendation on tools you 549 - > should start to be looking at for your operations, you know, 550 - > that might be touching sensitive data. 551 - > That's where I'd start pointing people in that direction. 552 - > Because, like you said, you don't have to put them in the 553 - > LLMs. 554 - > These are already built and they're already, they've already 555 - > been trained and they've already been up to date and and they 556 - > already know a lot of what's going on in your in the 557 - > industry.

558 - > So you don't have to spend so much time training it, right? 559 - > And they've already have workflows, agentec workflows 560 - > already built out that you can just tell it and prompt it to 561 - > say, yes, I want you to, you know, um, I'll give an example 562 - > in the in the personal line side is like, yeah, send the 563 - > certificate of insurance, right? 564 - > Make sure that that gets created and sent out. 565 - > Um, take these after hour phone calls from us and and find out 566 - > what they what what they want, create a ticket for me.

567 - > And so that when my team gets in there in the morning, they can 568 - > see all the people that called in after hours and what they 569 - > needed, instead of someone listening to a voicemail and 570 - > having to set a ticket up and do all those different pieces of 571 - > it. 572 - > Um have it go through my email and tell me all the different um 573 - > tasks I have to do today that came in from the support box, 574 - > things like that. 575 - > David: Or even, you know, go through all the customer support 576 - > calls that are recorded and tell us in order with the frequency 577 - > of particular questions being asked, so maybe we can get ahead 578 - > of them and ask them you know sooner.

579 - > It it's really, you know, amazing. 580 - > For a while, VPNs were the thing. 581 - > Everybody talked about VPNs, VPNs, VPNs. 582 - > What does a VPN do and why is it important?

583 - > SPEAKER_00: Yeah, so there's there's there are VPNs, virtual 584 - > private networks, that scramble the signals or they make you 585 - > look invisible on the internet. 586 - > So if you think of the internet, right, you got the high internet 587 - > highway, and everybody's driving down the internet, and if you 588 - > use with a VPN, you will just your car will be invisible as 589 - > you're going down the internet, right? 590 - > And um, the next level is it could be scrambling what your 591 - > car looks like, right?

592 - > And everything inside that vehicle. 593 - > Um, and they they have to take a lot of time for it to unscramble 594 - > as it's going through through the internet or through email or 595 - > whatever it might be. 596 - > Then there are secure internet portals that act as firewalls on 597 - > your devices that will give you your own tunnel into the 598 - > internet that's that is both masking and encrypted that allow 599 - > you to, just like having a firewall in a building, would 600 - > allow you to be able to use the internet without somebody 601 - > looking into what you're what you're doing, um, recording all 602 - > the stuff that you're that you're interacting with, um, 603 - > trying to divert your your internet usage to their bad guy 604 - > uh internet tunnel.

605 - > David: It's fun and game. 606 - > So from a client perspective, how are cybersecurity and AI 607 - > changing expectations of advisors? 608 - > SPEAKER_00: Well, it's I think it's the same in um in any 609 - > industry right now. 610 - > They're expecting that you're working longer hours, that 611 - > you're working, that you can do double the amount of clients 612 - > that you're able to manage before, that you're able to get 613 - > them the answers faster than ever before, that you should be 614 - > no reason why you don't have somebody answering the phone uh 615 - > when they want to call when they call in or have an ability to 616 - > talk to you on the uh through text message or through a chat 617 - > bot or whatever it might be, because this all this is just 618 - > standard operating procedure up to this point with artificial 619 - > intelligence, right?

620 - > Everybody should have it at this particular so um from a client 621 - > perspective and from a from a um even from a leadership 622 - > perspective, if you will, you should be able to do more with 623 - > more, right? 624 - > And the whole promise, and I we we just had a long conversation 625 - > with a bunch of other um leaders in the space about how the 626 - > promise was we were gonna have less work, we're gonna have more 627 - > time, we were gonna be more efficient.

628 - > And what happens is we can do so much more, we're just adding 629 - > more. 630 - > David: We're adding more to the more. 631 - > SPEAKER_00: More to the more, right? 632 - > Before where I could shut my brain off at 11 o'clock or 10 633 - > o'clock the next day, I caught myself standing up till three 634 - > o'clock in the morning now because of all the cool things I 635 - > can do with artificial intelligence that I couldn't do 636 - > before.

637 - > And there's a lot of testing and there's a lot of refining, and 638 - > there's a lot of, oh, well, now I got to be able to do this or 639 - > make this connection, or that didn't work, or hey, a lot of 640 - > hallucinations, so I can't send that out, right? 641 - > So yes, I can do more, but it's taking more. 642 - > And on the flip side, clients are thinking that we should be 643 - > able to do more and be faster and and and respond at all, you 644 - > know, 24 by seven, because we have all these these tools.

645 - > David: Yeah, but you know, we all we all have to remember that 646 - > AI can't read the room. 647 - > Right. 648 - > Um, AI doesn't take the place of personal experiences and 649 - > personal connections that you make. 650 - > I guess in one sense, we're lucky because our business has 651 - > always been a business about personal connections.

652 - > SPEAKER_00: Exactly. 653 - > David: And um, I remember talking to some agents when um 654 - > when uh the uh Obamacare, when ACA was first coming out, and 655 - > the navigators, remember them, were gonna be part of the 656 - > government. 657 - > And oh my gosh, the navigators are gonna take away my business, 658 - > they're gonna eat my children, it's gonna be terrible. 659 - > Right.

660 - > And you know, my answer was you you can't think that way because 661 - > if you do, you need to check up from the neck up. 662 - > SPEAKER_00: Right. 663 - > David: The good the government's never gonna have the 664 - > relationships that you have with your clients. 665 - > But that's why it's important to have folks like you safeguarding 666 - > a lot of that stuff, because we all know it takes forever to 667 - > build trust and it takes a nanosecond to lose it.

668 - > SPEAKER_00: To lose it, 100%. 669 - > David: So let's let's close by looking ahead. 670 - > Sure. 671 - > If someone just takes one action after this conversation, besides 672 - > calling you guys it's Cyberfin, to better protect their business 673 - > and their clients, what should it be?

674 - > SPEAKER_00: The first thing that I would do is I would start to 675 - > adopt a password manager with multi-factor authentication and 676 - > make sure everybody's using a password manager and 677 - > multi-factor authentication for their business. 678 - > Um, our favorite's Bitwarden, and again, selfishly because 679 - > that's one that we manage, but there's good ones like keeper 680 - > and dash lane and one password that that's available. 681 - > And you, but you want to centrally control it.

682 - > So, what I mean by that is you got to pick somebody in the 683 - > organization that's gonna be whose whole responsibility it is 684 - > to manage these types of security for you, right? 685 - > Get your password manager, have it multi-factor ticket, have it 686 - > centrally controlled. 687 - > Here are the rules, here's how it needs, you know, set up the 688 - > administration of it so that it's updated every 90 days, 689 - > people only know their master passwords, right?

690 - > Um you have access to those things. 691 - > You're gonna have to manage it from centrally controlled. 692 - > The second thing I do is I would look at your email security and 693 - > make sure that it is locked down and somebody's monitoring it and 694 - > managing it 24 by 7, 365. 695 - > Um, and then lastly, what I would do is I would start to 696 - > look at all my policies and make sure that I have all my policies 697 - > up to up to up to snuff.

698 - > Um, because talked to a few DOIs and and departments of commerce 699 - > recently, and they're all saying the same thing. 700 - > We're not gonna do a witch hunt, but if we find out about a 701 - > breach that you were that you were the one that that gave up 702 - > the credentials or you're the one that gave up the the 703 - > sensitive data, right? 704 - > It came from from your act at all, we're coming down like a 705 - > and the consumer turns you in before you turn yourself in, 706 - > we're coming down like a hammer.

707 - > And so the best thing is to say, hey, let's not have this 708 - > problem, first of all. 709 - > And second of all, hey, we're able to report. 710 - > Here's our root and information security policies. 711 - > So if anything happens, we know exactly what to do, report on 712 - > time, make sure we know exactly what we're collecting, and and 713 - > just be ready for the fire plan, right?

714 - > Remember, I don't know if you remember in your in your school, 715 - > we always did the fire plan, right? 716 - > Same idea. 717 - > You want to be prepared if you have a fire. 718 - > You want to be prepared if and when you get hit with a cyber 719 - > attack.

720 - > David: I I'm I'm so old that we did the in case of nuclear 721 - > attack hide under your desk. 722 - > SPEAKER_00: Sure, sure. 723 - > David: Which was brilliant advice if you think about it. 724 - > SPEAKER_00: The desk would definitely protect us.

725 - > David: One last question. 726 - > What is the next what do you think the next three to five 727 - > years looks like if they get this right or if they get it 728 - > wrong? 729 - > On artificial intelligence? 730 - > No, on on all the cybersecurity that we've talked about.

731 - > What is what does it look like? 732 - > SPEAKER_00: I see a world in which we go passwordless. 733 - > I see a world in which we um have artificial intelligence 734 - > being our cybersecurity guards for 99% of everything that we 735 - > do, and everything's cohesive and controlled, where it's not 736 - > just 9,000 different companies that all have their own flavor 737 - > of cybersecurity, that we all follow a cybersecurity protocol, 738 - > especially in our industry, and that it becomes a requirement if 739 - > you are going to have access to the sense of data.

740 - > It makes a requirement that everybody has one of these three 741 - > flavors of cybersecurity. 742 - > Um, and that artificial intelligence is the 743 - > cybersecurity guard that's going to do it. 744 - > That's what I think is going to be the future here in the next 745 - > five years. 746 - > And that's that would severely lower the risk of an attack.

747 - > Now, does that mean cyber criminals go away? 748 - > No, I think they just go find a different industry. 749 - > But if we can do it in our industry, that, you know, so we 750 - > can go from the number two most attacked industry in the 751 - > country, second only to manufacturing, to, you know, 752 - > hopefully not even on the list. 753 - > David: That would be great.

754 - > And that's a great place to end our conversation for today. 755 - > Daniel Metcalfe, co-founder and president of Cyberfin. 756 - > Daniel, thanks for a really fascinating conversation. 757 - > SPEAKER_00: Yeah, thanks for having me again.

758 - > Honored to be here. 759 - > Announcer: The Shift Shapers podcast is a production of Shift 760 - > Shaper strategies and may not be reproduced or quoted in whole or 761 - > in part without our express written permission. 762 - > Copyright 2020, all rights reserved.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The trust paradox: How attackers weaponize legitimate SaaS platformsTalos Takes · on email security94 / 100
  • The Open Book Problem 1: How Your Public Records Become an Attackers' RoadmapThe Small Business Cyber Security Guy · on Google Workspace90 / 100
  • Secure AI Starts with EducationBuilding Unbreakable Brands · on Google Workspace86 / 100
  • Tax Time 2026: How ATO protects your financial dataWith Interest · on Multi-Factor Authentication85 / 100
  • Stop 90% of Ransomware Attacks with Basic Cyber HygieneThe Backup Wrap-Up · on Password managers82 / 100
  • Beyond the Search Bar: How AI is Redefining Visibility for Small Business | Maria Elena DuronUnlocked Professional: AI and Future of Work · on Google Workspace80 / 100

More from The ShiftShapers Podcast

All episodes →
  • EP 550 Mindset Over Benefits - with Lizzie Benton70 / 100
  • EP 549 Building A Better Provider Network - with Jarred Pierce78 / 100
  • EP 548 All You Can Eat Compliance - with Carol Taylor79 / 100
  • EP 547 New "Captivated Health" Book - with Mark Gaunya82 / 100
  • EP 546 Well-Being That Actually Cuts Costs - with Ashley Rutkowski77 / 100
Explore the best B2B Ops podcasts →
All The ShiftShapers Podcast episodes →