Why Most Companies Can’t Afford Cybersecurity | Gaurav Keerthi
Gaurav Keerthi · July 21, 2026 · 46:50
Back to Episodecybersecurity has become a luxury good. It is something that big rich enterprises can afford and small, poor companies cannot. And that just doesn't sit right with me. Like no other form of security is that much of a luxury good. I mean, your police, your military don't just protect and guard the rich parts of the country, they protect all parts of the country.
And that's how they should be set up and designed and funded, in theory and hopefully in practice as well.
if you extrapolate even from from security into other domains, you take a look at something as simple as like water sanitation. You know, in the eighteen hundreds, water sanitation was like cybersecurity. the kings and queens would have boiled water to drink and it would be filtered and cleaned and then they would be able to drink it. And then the the villagers, you know, those who lived out in the f the the meadows, would have to dig from a well and sometimes they died from, you know, all sorts of weird diseases that live in well water.
And the whole philosophy was, you are all responsible for your own wells. Please don't drink dirty water. And eventually that worked for a little while, and then the kings and queens started getting sick too, because their cooks lived in the villages and their tailors lived in the villages, and the supply chain of running a castle lived in villages. And so they realized that the only way to keep themselves safe is to build what we now call modern water water sanitation.
Piping systems where everybody gets clean drinking water. We're still in that 1800s era of cybersecurity where like the enterprises believe that they can protect themselves and all of the people who are doing their gardening and cooking need to figure out a way to keep themselves clean and not pollute their enterprise environment. But it can't be done unless we build essentially what the utility system for the country. So that's the space that I think needs to be built and it's a problem that needs to be solved.
It yeah.
the problem is is that from a cybersecurity standpoint, the small businesses these days, are the target of nation states and threat actors. So meanwhile you have this bohemoth you know countries with unlimited budgets now targeting
small businesses that can't protect themselves and now and and since they became a target the question I think was brought up does the government and we're not just talking about the US or Singapore, we're talking about many governments. Do they have their responsibility ethically to help the small businesses to defend themselves to protect the greater good? So your story, your your your your analogy is perfect in this.
Because it's not just the small businesses that are gonna get hurt. It's the surrounding organizations, the other businesses, the other people, because they become ultimately targets through lateral movements and stuff. So perfect story to that.
Yeah. And it's the same example. So even if you take it out of water sanitation and you go to something like vaccination, in economics we have this concept of a public good and a private good. And public goods are basically things that governments should be providing. There's a whole economic definition about non-rivalrous consumption, et cetera, et cetera. But the whole idea is it there are enough positive externalities, there's enough positive side effects from consuming this thing that it should be given to everybody. Vaccination is one of those examples.
If vaccination remains only something that very wealthy people can afford, you never get herd immunity. And the disease continues to circulate around and getting stronger and stronger and eventually break through your vaccine. But if you have herd immunity, essentially classes of diseases just disappear. And the only way you can do that is having a wide enough level of protection. And that's the same concept for cybersecurity. You can't protect just this group.
You have to set a baseline and then everything else gets better. And it's not that you're gonna provide enterprise great cybersecurity to everybody. It's like drinking water. You turn on the tap, some people can drink from it, it's doesn't taste great. If you want filtered water, you want, you know, fizzy water. You there's a bunch of places you can buy expensive water from. And there's a whole bunch of branding and marketing around selling people expensive bottled water. And if you run a factory, you need a different kind of water. But if you're an ordinary person and you turn on the tap, it shouldn't kill you. That's that should be the basic assumption.
Yeah, it's that's it. It's
safe. Yeah.
die from connecting
to it. But that's the internet. Like if you you could literally die from just connecting to the internet, which is not a great philosophy.
Yeah, well it's interesting how you put that because, you know, in looking at IT and the way security is done, it is done in a very isolated way. And you know, most security places are like, you know, we need to protect ourselves. This is our stuff. We don't want the government in here. We don't want and in the US we d you know, they don't want the liability of sharing information or letting them in or anything. But yeah, it is very, you know, isolated. Almost the idea of sovereignty ownership to it. Except
Now we're so interconnected that if you're an enterprise, you are invariably connected to some much smaller organizations, and it doesn't matter how much third party risk you do. They don't they're not protecting themselves and you like you really want them to be.
That's the irony, Joe,
right? The irony is that less government is what we talk about. However, the government the US government, let me s qualify. The US government's first responsibility is to protect the people. So it's almost contradictory, but it's aligned. So it's a c it's a quandary, right? We need to protect the people, we need to protect their livelihood, we need to protect their organization.
Always, yeah.
But we also want to have herd immunity. We don't want somebody going from that small business to that other small business that's connected to them to maybe an upstream provider. But we want less government, some people believe. So what do we do?
It's a it's a so I don't think it's that much of a dilemma. I mean the the basic premise of even the US government is we want to let everybody seek their own opportunities. So we're not gonna cap you on the upside. I mean go and build whatever enterprise you want and profit maximize. That's great. But we need to provide a basic level of security and safety for the country so that you are free to find that enterprise. And if if the United States was constantly in domestic like violence, if there's riots, there's civil war.
You wouldn't be able to build an enterprise. So the government makes sure that that doesn't happen. And that's the basic starting point. The same thing for communicable diseases. There is a basic starting point and a floor of hygiene that they set. After which, if you want to go and you know health maximize and do, you know, biohacking and do all sorts of stuff, go for it. That's up to you. That's that's for you to go and seek out on your own opportunities. But the base level of kind of healthcare, at least there's something there. You can opt into it. And you don't have to do it.
you can opt into it as well. So I I liken it to telcos. You can get a telephone anywhere in America. You don't have to, but nobody's excluded from getting a phone plan depending on where they live.
Well
And I can tell you right now, go off, that there are people right now that when they're gonna listen to this, they're gonna say, Yeah, I get it, communicable diseases and we're worried about, you know, herd immunity, but people are gonna start throwing around analogies about COVID. So, yeah. And but I I but from a cybersecurity standpoint, that we do need to ensure that these small businesses if I understand correctly and I'm just guessing
I believe I've heard it multiple times. Small businesses is is what America is mostly about. And these small yeah, most small it's mostly small businesses. We see these box stores, but you know, small businesses is what builds America, but they're the ones that can't afford some of the insurances, the cybersecurity insurance is the the enterprise software, right?
Yeah, most are small. Yeah.
I think we shouldn't just talk about America. I mean, Guarav is a true you have a little more of an international bent than than I do, I know. i I I'm assuming that's true throughout the world, perhaps even more that it's really small business that it's the bulk of the economy.
We of course.
Yeah, so the World Economic Forum has this concept of cyber inequity, and there's this great video that they or not a talk that they had about two years ago. and basically I think the Indian Minister for Digitalization, I can't remember the full title, but he basically said less than one percent of the companies in the world have a person whose job title includes the word cybersecurity. And if you think about that, that that sounds about right, even in the US.
Wow.
Defining it as small, medium, or large is irrelevant. It's is there somebody in your company whose job title has the word cybersecurity? And if it doesn't, then you're not a smart buyer. You don't know what you're doing, you don't know what you're getting, you don't know how to buy it, because nobody knows what an endpoint detection and response tool is versus a firewall versus a d like they don't know these things. And so they're stuck.
it's even worse because in the US since some of the regulations have come down come out where they've said, you have to have someone who is responsible for security. And they'll say like, IT guy, you're now network and security manager. Congratulations. And you know
Yeah.
But but you but
you but that's not even true. That's not even true. It's worse than that. It's I've seen so I'm sure you know this. You you you you you I mean you're you're you're more global than we are, but like the cybersecurity market is horrible. People can't find jobs. Meanwhile there's a lack of people in the jobs. And I would argue that there's medium sized businesses
I think that's the only thing.
that barely have cyber security people there. But but the truth is it's like you don't want to hire somebody who's who's practicing law that's not a lawyer. And I know it's not the same equivalent, but you don't want someone practicing cybersecurity that's really never done that a day in their life for for for even small businesses because I've seen people that turn off like firewalls and
NAT
yeah.
stuff to the outside so that you can come in from any source IP and if you look at I don't want to say certain products, certain firewalls, certain products right now, I mean there's vulnerabilities that you can't even patch.
Yeah. No, and the biggest dilemma of double hatting somebody who's the IT guy and the cybersecurity guy is that he's forced to make that trade-off between opportunity and risk by himself. And he's being held accountable to a hundred angry staff who cannot get access to their frontier model. And they're like, Well, I want to use my AI and you're the one who's blocking me from it because you can't figure out how to secure it.
And this guy doesn't know how to secure it, so he then is pressured to let everybody use it. And then you have all of these attendant risks of AI and whatever else happens. So a single person balancing the risk and opportunity doesn't work, especially if the guy's being paid and his primary job is to unleash the opportunity of technology for whatever that company is, the construction company, a law firm, whatever it is.
yeah.
Yeah.
well you're right. Especially if you've got an organization of that size and with that attitude, you know, that one person balancing everything, I'm sure the company has no concept of risk management or that balance and all those kind of things. It's not happening. It's it's management by whoever's the loudest. Yeah, fear. Yeah.
Fear. yeah. But
And
what we've seen is that any
but you but you made a point, Garf. You made a really good point when Joe and I worked for a law firm and the way a law firm works, for those who don't know, is that everybody in that law firm is a CEO. So if you have two hundred attorneys, a a partner okay. So so so in our law firm we had over two hundred partners and that was two hundred CEOs, even though there was only one
That's the partners are the CEOs, not everybody. Yeah.
you know, managing partner, at the end of the day, every single one of them had a lot of power because they brought in certain customers and they ran with certain customers. And each one has a varying idea of what they want to do. And sometimes they give conflicting commands, not through the managing partner, but directly to people. One time Joe had me do something, I basically got to pose for a partner for enabling security. I was spent thirty minutes on a witness stand basically on a phone talking about
When I knew something was happening, why I knew it was happening, did I know it was happening? Why am I blocking him? The software should already know he's legitimate. I goes that's the that's the opposite. Just because you normalize something doesn't mean it should work. So the point I'm making is it it's not just about small companies, even medium sized companies had their big issues too.
I think that tends to be the case and it's largely because if cybersecurity becomes bespoke to every enterprise, the expectations and demands become very bespoke. I want it to work exactly in this way. Nobody makes that demand of their telco provider. I want 5G reception in my bedroom, but not in my bathroom. Like you d you don't get to do that. Like whatever the telco provides is what you get to consume. Whatever the water that comes out of your tap, it's the same water that comes out of every tap. You don't get the demand for filtered water in this tap and not non-filtered water in that tap.
So it it becomes a different conversation, firstly when it's outsourced, and secondly when it's provided as a utility. You can always opt into more services, and I think what we've seen is companies below 200 headcount. So if you have less than 200 staff, there is nobody in your team that does anything to do cybersecurity. If you're lucky, you have a single IT manager, sometimes an IT vendor. Above 200 is where they start to grow an IT team.
And they start to have some level of outsourced cybersecurity. But below 200, and that's the vast majority of companies that we see out in US and in the world, they have nothing. And interestingly enough, so I'm in this space now. My biggest competitor is not another company or another product. It's hopes and prayers. We literally went into one of our Yeah, it's doing nothing. We literally went into so we're based in Asia and we went into one of our customers' offices and then he was like,
Yeah, it's doing nothing. Yeah.
This is the first security product I'm ever installing. And I was like, how did you keep yourself safe before this? And he points us at a prayer altar and he's like, This has kept us safe for the last ten years. In my head I'm like, Well, it's clear you worked. You didn't you're still here after ten years. But that's not a great strategy. Like that doesn't work on the internet. But that's how most companies think. Like, we're just too small. It's not gonna happen.
Yeah, well they're the they're the targets. I mean I'll tell you one of the, you know, the idea of the soft target. one of the reasons I ended up going to work at a law firm and doing cyber there was I was originally in banking and I had been in financial services for a long time And the hackers, this is around twenty fifteen, twenty sixteen or so, they figured that, you know, the banks were getting they were tough to crack.
They were they were getting tough. They they were getting good. but they said, you know, well guess who else has all their data? the lawyers. And they're not a big company, so yeah, there was a real I don't think it's not a renaissance, but a real I don't know, awareness, getting religion in the legal field, in cyber. And I think that happened has happened in a lot of other fields too, because you're right, it's an
It's an ecosystem. It's not only the idea of I suppose, collateral damage, but also these other places have your data. They're they're they've got your stuff. They're doing it and and so many are small or tiny, you know.
So I can Yeah. absolutely
So I can share this great story which happened in Singapore and it's it's public. So essentially the hackers were trying to get into one of our largest banks in Singapore and in Asia and they were unsuccessful. They wanted to find out who all the rich people were who were their clientele for many obvious reasons. But they couldn't. The bank was well defended. But they realized that the banks need to send their, you know, their black platinum diamond credit cards by mail to these rich people.
So they hacked the printing company that prints the mails that sends it out. Because that printing company knows what's in the letter, they know the address, they know the name. They have all the same details that they're trying to get to. And it's just a printing company. And true enough, they were able to. And so they they wiped out the entire database or they they sucked up the entire database of high net worth individuals who are getting these fancy credit cards, and the bank never got touched. The bank never got hacked. So that's one kind of great case study. The other one that we've seen, and
like specifically the law firms, is that there's this whole concept of client confidentiality in the legal service, which is a concept not backed by technology. So it's like we have client confidentiality, except all our client data is on Gmail and it's, you know, unencrypted, free text. So they they claim that it's client confidentiality, but they don't put that technical layer on top to actually protect the data in law in smaller law firms. And that's becoming something that the attackers are realizing that yeah.
You're telling your lawyer all of these great sensitive things which I wanna suck up, and you're not protecting it. So it's great.
I can also tell you it's only within the past seven or eight years that even the big law firms have done it. And it's been incredibly expensive and and disruptive to them.
yeah.
I it's more expensive to not. So we had a law firm in Singapore that's medium sized, about two, three hundred lawyers. and they went famous because they paid a ransom of like almost two million US, I think. and they did they came out and said that they paid the ransom. And I was like, that is a terrible strategy on so many levels. Firstly paying, secondly telling people that you've paid now. but that's that's the ex that's how much it costs if you don't protect yourself.
So the pr the problem that we have found with w with and it's not just law firms, but because Joe and I worked at a law firm, first you have to worry about how the copier is going to get decommissioned because all that data is on that hard drive and never leaves. Then you have and and don't get me wrong, I'm not saying they didn't combat that. I'm just saying people don't think about that. And then the other issue is that every attorney decides they're gonna send their data to their personal email addresses
Once it goes and traverses that email, it's going through other servers. Yeah, I know there's encryption between servers, blah blah blah. But if it's a sort of trusted server, but now it's a plant, now that data is sitting in that location. Then these people take their data and put it on USB drives. You don't even want to know what I had to deal with to encrypt and non-encrypt these drives with end with endpoint encryption on the drives because before they even had Microsoft
You know, we had to do things with checkpoint and then the trials and tribu the trial the tri the whatever they call it, the tribulation yeah, they would turn around and say, You cannot give us an encrypted drive. So these drives that got lost sometimes were unencrypted. So I it it's it's so ridiculous. And then some of these servers that people have are end of life but they have proprietary software on there, so you can't patch them anymore.
Tribunals, not the trials and tribulations, the tribunals.
So you have to micro segment them and it gets to so we've learned so many tricks. But the problem is and w and we had a deep pocket. Can you imagine the law firms that were smaller than ours that didn't have deep pockets and they sat there as like you know, open targets?
Yeah.
Yeah. No, I mean the good thing though is that a lot of technology is commoditized away from that direction. So if you set up a law firm anytime in the last ten years, you probably don't have a server rack in your office. Yeah, so it's it's moved in a different direction. It's on cloud, which is a different problem, but yeah.
Correct.
But the problem with that is a lot of law firms don't want to put their data in there for government reasons. So have your own key versus bring your own key, making sure the encryption is not in the cloud, you don't get a blind subpoena. These are s we Joe Joe and I Joe put me through the ringer and back, and then when I got back, he put me through the ringer again. We were doing so many meetings about how to protect organizations' cloud versus localization.
Yeah, but well
and and on site and can we we have this on site but this in the cloud and the c crazy stuff. And even the phones, the PBXs that are outsourced, that data, people know who's calling in, who's calling out. So if that's a hosted PBX, you also have problems.
Yeah. Well you're right, Gor Garav, you know, more and more companies, including law firms, financials, etcetera, are moving into the cloud. or have. but you know, the cloud also securing it is not easy either. it can be very, very complex and very costly. even if you say we're gonna get the Microsoft stuff, you know, you gotta get those you need that one thing that means you gotta buy the E five license or whatever and
Yeah, yeah.
And you're into it for a lot of money. So I mean, getting over to the solution side of things, I mean, where do you see things going in terms of trying to get some real and some realistic improved protection for the smaller organizations?
Yeah.
I so I will say a couple of things that are s they sound a little controversial, but I think it's the direction we're moving towards. It's commoditized rather than bespoke. And if you think about another analogy, furniture. If you have a bunch of money and you want to get a dining table for your house, hire a carpenter. He will come, he'll measure your dining room, he'll check all the angles, he'll cut down a beautiful American walnut tree, polish it, and use high-quality skills, high-quality tools, high-quality wood, and build you a beautiful dining table. And other carpenters will come and admire the
quality of this dining table. If you don't have that budget, where do you go? You walk into an IKEA and it's 30 bucks. And that table has never met a tree or a carpenter in its life. Like it does not know what a tree. Yeah but here's the thing. But here's the thing it may not have four legs because Ikea doesn't care about it looking like a table. Ikea cares about it being a flat surface that you can work on.
Yeah.
Yeah.
That's right, like it. And and you're
That's right. And you hope it has four legs. So
It's actually pretty good c furniture if you really think about it.
And so how cheap can they make it? Is it possible for them to make a single circular table with one leg? Yeah, it's possible. It's engineeringly possible. Let's build that and cut the price down by half. So if you build the quality and build the features, you end up on this trajectory of hiring carpenters, which are skilled professionals bespoke. But no amount of carpentry training will ever teach you how to build IKEA. Like it's a completely divergent skill set. Building a factory that church out flat-packed round or flat surfaces with legs on them.
Is a different engineering skill set and choices from learning how to be a carpenter. Today we're trying to figure out how do carpenters make cheaper tables? And it's fundamentally not possible. Because all of the choices they make are like: should I get a cheaper tree? Should I outsource to like Vietnamese carpenters? Like, where do I get cheaper carpenters and cheaper trees from? Because that's their skill set. But if you were to step back and say, look, I just want to make sure that everybody has a flat surface to eat dinner on, that doesn't need carpentry. That needs a factory.
That church out flat surfaces that people can take home and assemble themselves and have a table. That's what I think needs to be built. That's so that's what I'm building. It's that factory that churns out commoditized, basic, bundled, affordable, simple solutions. And it doesn't come and meet it doesn't impress any carpenter. No carpenter walks into a kid and be like, wow, that's that's a gorgeous table. And it also doesn't meet the needs of people who are like, I want it in purple and I want it with three legs in green. It's like that
That does not care. You want it in white or black. Those are two options. Please do.
Mm-hmm.
I have the hard question.
so how do you do that? How does a a company like yours who concentrates on small businesses, how do you provide them that endpoint detection or and response type of app without having to pay that license in that enterprise?
So it starts with basically understanding what cybersecurity at the baseline is. So Singapore has a thing called cyberessentials. UK Australia have something very similar. It's kind of a baseline SMB standard. It's there's no quite equivalent in the US. Europe has Sci Fun Cyber Fundamentals or NIST2, which is kind of in that same space. But it's basically premised around four things. there are only four philosophical things that can go wrong on a computer. You download something bad, you click on something that bad.
Your conf credentials get stolen or lost, and your systems are poorly configured. Those are the four things that can go wrong. And any actual attack is a combination or selection of one of those four things. If you can bundle together something that does all four, actually you're sorted. And every other industry has done this. So you think about finance. finance used to be a very complicated business. You'd have to have an accounting team, an invoicing team, and reconciliation team. You'd have to have all these things, or you'd outsource it.
in Asia, I don't know if they have it in the US, but there's a software called Xero X-E-R-O. It's accounting for small businesses. And it bundles together all of those things. product management used to be a very complicated field. You'd have, you know, I have Jiro and Trello and Slack and my Kanban tool and all of these things. And then Notion and Monday and Asana all came out. They're like, yep, we bundled it together and it's 10 bucks a month. And none of those things are as good as actually having a real product manager in your team or having the best in class tools to use.
But for an average business that's just running a general project, it's good enough. Cyber is the only field that hasn't done that yet.
Do you wanna laugh? Do you know most people don't I don't sh I shouldn't say most people, I'll be lying. A lot of people don't know that if you have like Optimum, which is our cable company, or if you have Spectrum or I think even Verizon, but don't hold me to it, they all give you free security software in the US and most people don't know that. And that's besides the fact that you have Microsoft Defender.
And that's a great starting point.
Well yeah.
Well, you know, I find it really interesting when you say about these basics and some of the packages that they have. You know, I know that here in the US we w it it would help if we would drop some of our issues or whatever and and look at some other some other places. we tend to overcomplicate things and we do tend to to make things expensive. I I saw this really interesting video just within the past week or so.
Where you know, I'm I'm a car guy, so I've known for a long time, you know, cars in America, the cheapest ones are expensive. The cheapest car you bu can buy is like, you know, twenty thousand bucks, which you know, still has air conditioning and power windows and all these crazy things. And you go around the world and you can buy cars that are way simpler, that are way cheaper, that are way more basic, and there are markets where they nobody even buys a car. It's all scooters.
You know, if you got a scooter that can hold you and your significant other or or a kid or two, that's it. You're done. And w we just don't think like that. We think of you're I think you're absolutely right, not how do we do something that that simply and easily performs the task. We think of how do we take this complicated thing and make a version that is is maybe simpler or easier. I th think that's a good insight.
I mean there's an industry incentive. No,
there's an industry incentive behind it. If the cybersecurity market becomes something that is cheap and commoditized, or there's a cheap and commoditized version of it, then actually the luxury version starts to lose a little bit of its market share. And so there's an industry incentive to make it more exclusive. You think about it, nobody is a Python certified engineer or a React certified engineer. Like you just you are a full stack, you you're a dev, you go and build stuff. But
For cybersecurity, show me the list of your 18 certifications before you could even qualify for this job interview. It is only cybersecurity that's made it so exclusive and so hard to break into. And then we complain that there's a talent shortage, because we've defined talent as having these 18 certificates that are so hard to get. That's not how the software engineering works. That's not how other industries work. And so even in the product space, we've made the cyber industry has made it very exclusive and expensive.
And if this commoditized cheap version exists, that's a threat to them. And if you look at what's happening in every other field, like the legal sector is under threat from AI legal, the finance sector is under threat from AI trading tools. Like every sector is being challenged. The incumbent way of doing things is being challenged by this new upstart. And that's a great world to be living in because it does democratize access. If you think about how it you it would be to get a lawyer, if you were in US, there's law firms everywhere.
yeah.
If you're in a country in Africa, you now have access to high quality law like legal advice online. And that's an access they never had before, medical advice. Like all these things are now democratized globally.
So the thing is, is that you see these LinkedIn posts, and I know you see them. We want an entry level cybersecurity person for seven years in the industry that has sans certs, this cert, that cert, and we want to pay them fifty fifty dollars an hour. and they have to be CISO hands on. Some crazy crap.
Become a joke.
I I I need a I need a stronger cocktail for this conversation because that irritates me to no point. Like that doesn't firstly that doesn't exist and that should not be the way the industry is moving towards. Like you should not have to be so pre qualified to start working. Like every other job the qualification is base level and then you build up the skills as you move along. But cyber's just been the other direction. And I think that's not you know.
But I'm not making that up, right? You've seen
even even
those, I'm sorry.
at the even at the senior levels, it's ridiculous. I mean I'll tell you about my own experience in the past couple of years. I've never been a certification guy, only because I've interviewed and hired so many people who had certifications that it meant nothing. So I never bothered getting any of my own. I just never bothered. you know, or the truth is after all my years I could teach these classes and everything. But I finally had to break down and get one.
Because when looking for a job it was the only way to not get instantly rejected, even at like my level of experience. And I and I even said I would even tell people, this is preposterous. This is ridiculous. But you know what?
I have plenty
of them, Joe, and I got instantly rejected anyway.
that's right.
No, but
and that's not helpful to everybody. Like I can understand why an HR person who doesn't understand the field will say, I don't understand your experience, but I know a qualification when I see it, because that's just a string of alphabets that I can look for and screen for. So I can understand why the dynamic has moved that way for cyber, but it's not been like that for every other industry. And that's the part that I don't understand. We have created this problem for ourselves and there's an economic incentive behind it. These certification industries make a ton of money off of all of us as well.
But it's perpetuating and creating a talent problem and creating this gap where we have unemployed cyber people and then we have shortages in the actual enterprises, which will never get reconciled because of all of these weird rules we've set for ourselves. It doesn't exist in every other field. And all I'm trying to say is that cyber should not be treated like a different discipline from every other discipline. Legal service has this AI alternative, this cheaper, more affordable, more democratized version. They have
Qualifications at the starting point, you need to have a law degree, you need to be called to the bar. But after that, nobody looks for the seventeen certifications you earned as a lawyer to allow you to go into court for this particular case. They just look at your experience and expertise and then I think you're the best person for the job. Let's go. That's how should this this should be. And it's gonna be hard shifting, but I think that's the direction we have to move.
So how does it work with you, right? You go into a small business, you pitch your software and and they realise it's value.
Do the people like so let's it's a small firm and they don't have a cybersecurity person, how is that handled? Do you think are you training these people to become cyber or they could do it easily?
So the whole thing is how do we I so if I'm building IKEA, how do I build my software to be so easy that a sales manager in a pest control company can do it themselves? So right now our record setting customer paid us on Stripe, had all of their devices protected in seven minutes, and she was a nurse in a clinic on her lunch break. That's how simple it is. Like she's a non-technical person in a small clinic.
huh.
And all of us have seen these clinics where it's like the doctor and the nurse, and that's it. There's nobody else on staff. And in her lunch break, she needs to be able to pay, check out, install, have all the devices protected against those four things that I mentioned. And the kicker is that it's 39 bucks a month. So she paid on her personal credit card and claimed it from her boss. And so if you have something that's this frictionless, it becomes like, hey, I just want to sign up for you know Figma or Canva or whatever it is. I want to sign up for this SaaS.
It's about like thirty, forty bucks a month. It's not a big deal. And it's easy to install and easy to use and I don't have to think about it. That makes the buying process frictionless. And we have customers that we've never met before. And that should be the way that works. Like I don't need to actually meet you and persuade you. It should just be self explanatory and like nobody comes from Ikea and be like, let me explain to you how this table works. It's like it's a table and it has four legs and you take it home and there's a small sheet of paper that says, Screw these four legs in and you're done. That's how we have to
Mm-hmm.
I'm ready to
buy from you right now.
Really?
Okay, but let me ask you this. I'll play the bad customer. a lot of those people, I'm sure, or at least if you sold it here, a lot of people here would be familiar with the crap bar they get when they buy a PC, Norton some of these other things. in the past, and probably still today, but very often there's a bit of a stigma with very cheap security products because they've been of
Yeah. Please do.
Extremely low quality and some of them even scams. do you get pushback or get any of that when you go on?
yeah. The VPN.
Yeah,
I mean so I think the companies that have been around long enough have seen that. but I think there's also a recognition that AI has changed everything. there were scammy websites that sold AI I mean, digital versions of software before, but today AI has made it much easier to build better things faster and AI has also made it easier to operate better things at scale. So those two unlocks have been quite fundamental and
I mean, we do kind of blind pilots as well. So some of our customers are more sophisticated. They have an IT manager on staff. The guy doesn't understand cybersecurity, but he understands how to run a pilot. And he's like, look, I have an existing kind of anti-malware software on my laptop. Let's run it on this other laptop and we do a blind taste test. Let me run these two systems and we see what happens. and inevitably, so almost all my customers after running that have switched over to us fully. and the reason is not because we're fundamentally better.
All of the things that you get on an individual laptop protection are only for the individual. So a simple example. Any sort of antivirus solution that you install on a laptop does not tell your IT manager that you had a malware.
I was gonna ask do you have a command a control console? An an alerting, yeah.
And that
that's when it gets expensive though, when you need that stuff. But
Yeah, but is
that expensive to build fundamentally? So essentially all I need to have is a signal from all the devices in your company that comes back to a central dashboard and says, Eric had, you know, two alerts, Adam had one alert, Joe had five alerts, Gorov has zero alerts. So but now if you think about it, I'm bundling that EDR, I'm bundling that credential manager, I'm bundling a DNS firewall to protect you against that click, and I'm bundling in scanners.
I can now show you not just at the company level but at the individual level who that person is gonna be that's gonna get your company into trouble. I'm gonna show you like Joe has downloaded two things that I had to block. My EDR had to like contain it. He clicked on five links that I had to prevent him from getting to because there were scams, and his passwords are all reused. Joe is the risk in your company. Everybody else is fine. But but that visibility wasn't there before.
Well we knew that already, but but yeah.
But you know what's funny? Here's what's really ironily or scarily similar. We just had this conversation with somebody else that Joe and I are friends with, but not about your specifics, but about the ability to do vulnerability scanning. This guy, Michael Simmons, and he we just had this whole c same conversation. I don't want to compete against the big companies that are doing this. I want to help small businesses find am I right, Joe?
Isn't that funny?
yeah. Well
yeah. Well there is look, it's an underserved market, really. And you're absolutely right, Garav. That's something else that our friend Mike is looking at. there are so many people who don't have the level of protection that they really should have and that their businesses really need because it's too expensive, can't find the people. It's just if you can make it realistic for them, I think that's a huge a huge benefit and a huge opportunity.
We should put you two together, but go ahead.
I'll add one thing that I don't know how this changes kind of your friend Mike's business perspective, but one of the things that we've seen from talking to smaller businesses is that again, they don't have anybody in their company with the title cybersecurity or the word cybersecurity in their job title. They don't know that vulnerability assessment or scanning is a thing. They know the word cybersecurity. And they know that they don't have cybersecurity. What is in cybersecurity, that's your thing to figure out, not my problem to solve. And so
If if you're selling them a bespoke vertical within cybersecurity, and even if it's good, even if it's cheap, they don't know that they need that. And it goes to that whole bundling philosophy. You want to buy product management as a service. And I don't know what product management is. That's for Notion to tell me, I need to do task management. I don't know what that is, but okay, cool. I assign somebody a job and it gets sent to them by some sort of ticketing system. Great. So it runs the process for you.
Most of the company's buying behavior is just I've been told by my boss, by my board, by my customer, by my regulator, I need to do cybersecurity. I don't know what all this is. So he needs to find a way to get into the headspace first. and what we do is we just sell cybersecurity. An actual professional that comes into my company, like a carpenter that looks at an IKEA table will be like, that's not you're not gonna stop the Russians with that. I was like, Yes. But if the Russians are going after my bakeries, the Russians are lost. Like they should be
They should not be using zero days on small targets. And that's generally what we've seen. We've seen appetite. Exactly.
It's true, it's risk versus reward. It's risk versus
reward. But what you're saying is exactly my perception as well. cybersecurity is like if you're going to a doctor, that's cybersecurity. But if you're going to an endocrinologist,
Fala.
then you might
be doing you might be doing endpoint EDR, endpoint detection response. Or you might be doing vulnerability scanning, or you might be doing risk or you might be doing micro segmentation.
What you're saying is I am your general doctor, I will get the the checkup. Should you need a specialist, we get that's something else you can do. But we can get you in the door to do exactly what you need to do, 'cause most likely you don't need an endocrinologist, a hematologist, and oncologist. You just need a general practitioner and that's what we do for you. If you need something more, we can help you, but we'll get you set up.
Exactly.
I'm gonna steal that 'cause
Adam, you're you're starting to learn all of random parallel analogies, but it it's exactly right.
I'm
I'm available for consulting. You can hire a security mixologist at Parent Company, let us know.
Yeah.
Guarav well this has been this has been great. I've really learned quite a bit. It it does help to shake up your perspective a little bit and how we're doing things. I mean, for someone who is a a small business, either the the owner of a small firm or even that IT guy who's expected to deal with security, I mean what would your best tip for them be to get them off the ground in in terms of some protection?
I obviously I would
love it if they all tried out Strong Keep. that that's the easiest
Well, other than
call you, I know obviously, but
No, I mean
I think the there's enough information and advice out there already for them to get started with something. Again, I go back to my biggest competitor is apathy. My biggest competitor is a company saying that I don't know what I need and so I'm not gonna do anything. That's not great. Like do something even if it's not enough because that at least reduces your risk in some areas. Like have an have some endpoint protection. Even if you don't have a password manager, you don't have training, all those things.
You can get to it eventually, but start with something. And I think most of the people in IT are actually scared of cybersecurity because they see it as such a different deep domain. It's like I don't wanna touch that. Like that's not my job. I'm just gonna set up the three six five and leave it at that. I just recommend start with something. Even if it is the cheapest possible antivirus you can find, it's better than nothing.
the two things I'll add to that is the worst decision made is not making decision at all. And then the second part is people cry, they say, I have nothing to protect. Nobody's coming after me. They don't realize the drive by ransomware that you get in the email and just on the list. They they they think that that there's no why would I be targeted? No one's coming after me. They just don't understand that. And I I'll I'll tell you this, I know you come into the you come into New York for the UN
We're probably gonna have to do a follow up either episode or short at a bar, all three of us together. Cause I cause this is this is interesting. This is really interesting. I and I think there's a lot of value in this conversation. I hope people listen to it and understand that you need security. Do you do you do you do anything in the United States at all or you don't do anything yet?
Yeah. No.
Yeah, well we can all all drink when we're all in the same time zone. That'd be helpful.
Yeah.
I do, I do. So I I I come down quite a bit, both for work and for pleasure. and so the stuff that I do with the United Nations and a couple of other think tanks in the US brings me there once in a while. But I think that my my conversation and this is maybe a a chance for me to share just a little bit about what I see at the global governance level. The world is moving towards a direction of regulating technologies over time. I don't think there's a country in the world that's gonna deregulate
cybersecurity in the next five years. There's it's just a matter of how much tighter they're gonna add regulations, and maybe that's a good thing. I know from a cybersecurity professional perspective, all of us hate regulators because they're, you know, always coming with bad ideas on how to contain risks. But actually compliance is the floor. And if not for compliance, I'm willing to bet that most CSOs wouldn't get budget. So compliance actually drives baseline behavior. And I'm seeing more and more countries start to impose compliance on smaller companies.
In Singapore, we just made it mandatory for every clinic, including the one with just one doctor and one nurse, to have baseline cyber and data protections. So we're gonna see that happen in UK, in Australia, in Korea, in Europe, eventually in US as well, because bigger companies are gonna start lobbying their government to get their small companies to play ball. And so yeah.
Yeah.
It's not yeah.
No, they say it's not only government compliance, it's third party compliance. And what I mean by that is, for those who who might not understand, and I I get Joe and I work for a larger firm, but in order for us to get customers, we had to be within compliance for them in order for them to be our customer. And they would actually always come in I Joe, you what you take it away 'cause you can give a better story than I can about this.
Exactly because
No, it is well, it's the whole third party risk thing. where you know, if your firm, whatever business you're in, your clients want to see that you're providing sufficient security when you have their data, regardless especially if you're a law firm or a fine payment processor or something. And by the same token, they also they also expect you to be you know, monitoring your vendors there. And, you know, I think it's very interesting and
Sure.
Yeah.
I guess this is why I don't have a business mind, but it just occurred to me that with some of these small companies I can see them saying if they get a client like, Do you have cybersecurity? Are you meeting this thing? I'm sure they'd say, Where do I buy that? Where do I get that? And the answer now is not easy. It's complicated.
Exactly.
Yep.
And so that's exactly the direction I see the world moving in. So either the government's gonna tell them or their customers gonna tell them through this whole third party chain. And it's a cascading chain. It becomes a contagion where at some point pretty much the entire economy is gonna be working with a company that has some compliance requirement to somebody else. And they're gonna have to do something. And that's a good thing. So yeah.
And what I was asking before was not like do you come here for business or pleasure, but if customers are listening to us and they're interested in the US and purchasing your product, they can still come to you, right, in the US. Great.
yeah. We have we have American cut.
We have American customers, yeah. we
have a bunch of yeah, yeah.
I
I thought you were trying to get Garav to buy drinks when he's in New York. I thought that's why you were asking that too.
That too. But but but but but Joe Joe
That's right.
make Joe
make no mistake. If I can get him some clients, we'll get some drinks and a steak out of this.
Everybody wins. There we go.
Everybody
wins. Everybody wins. But it's been fun. It's been fun.
No, so much for joining us. It it has been fun and really learned a life. Given me a lot to think about. Gotta get out of that big enterprise mindset. The world's bigger than that. All as always. And thank you to everyone for listening. Take care.
