Meet Christopher Gerg Christopher Gerg is the CISO and VP of Cyber Risk Management at Gillware. He is a technical lead with 20+ years of information security experience tackling the challenges of cloud-based hosting, DevOps, managed security services, e-commerce, healthcare, financial, and payment card industries. He has worked in mature information security teams as well as building secure technical environments – all while working with the boardroom to promote executive understanding and support. Your company does a lot of work with incident response, what is the most common kind of attack that you're seeing right now? I think probably over 95% of what we're seeing is has to do with ransomware and wire transfer fraud. Wire transfer fraud is more of a human problem than is it is a technical problem and it's really just someone tricking someone else into transferring money where they they shouldn't. A lot of people have in their mind what ransomware is, and I think what a lot of people have in their mind is is wrong, frankly, you don't just get something in your email, double click it and then you have ransomware. Ransomware is the last step and kind of a conventional attack and a conventional hack, where they've been in your environment for four to eight months or longer. And they find where I jokingly say the soft chewy center of your company is and and encrypt that so that you're you're almost forced to pay the ransom or face a huge amount of downtime. So what advice do you offer to help organizations protect themselves from these types of incidents? Use multi factor authentication, the little code generator app on your smartphone is a good start. Locking down services that are available to the public internet. Windows remote desktop protocol RDP it's a way to get a remote desktop on a computer and people use that for remote access to their computers from from like trying to work from home. I think the two other things would maybe be make sure everything's up to date with patches. And I think finally, just kind of awareness. I didn't come up with it, but I'm using it a lot more is the human firewall. The people sitting at the desk are a big and important component to your information security program. And so the people sitting at the desk and checking their email and doing your company's business really need to be aware of what to click on what not to click on. How would you recommend a smaller organization such as my myself, help to educate the other team members and to make sure that they're not clicking on things they shouldn't? There's one that's actually local to me called the InfoSec Institute. They do online information security awareness training, and also phishing testing. They charge by the seat, and so it almost doesn't matter if you're a four person shop or a 3000 person shop. You're paying just a fixed amount, it may be, 10s of dollars a month. But that training is kind of a big deal. And the nice thing too is it's not just information security awareness training there's also kind of the certification training too. Do you see smaller companies or are these larger corporate entities kind of getting the majority of these attacks? I think it's pretty democratic and how it goes after things. Everyone has a chance of getting it. They really do just scan for vulnerable services and if they find one they get in. The other aspect of this that kind of blew my mind when I started doing this kind of work is, these are organized, essentially companies, that are doing these criminal activities. They've got help desks, they've got websites, they have email addresses. And so they have different teams in that there's some teams that just scan in an automated way the entire internet looking for vulnerable services, if they find one, they try to exploit it usually again, in an automated way. And if they get one it shows up on a list and then they they pass that list to the next phase, the other team and...