Skip to content
TrackPodcasts
technologyMar 12, 202633:48

Episode 172: The biggest security blind spots in Midsized companies

About this episode

Hey folks! Greetings from the Offensive Security group at SecurIT360. Brad & Spencer are on this episode of The Cyber Threat Perspective to break down The Biggest Security Blind Spots in Mid-Size Companies.

In this episode, we expose the most common (and dangerous) gaps that leave mid-sized organizations wide open: poor asset inventory, flat networks, flat identities, overconfidence in security tools, credential reuse, and the emerging risks with AI.

If any of these hit home, go to offsec.blog/pentesting, fill out the form on our website, and see if we’re a fit for you.

Blog: https://offsec.blog/
Youtube: https://www.youtube.com/@cyberthreatpov
Twitter: https://x.com/cyberthreatpov

Follow Spencer on social ⬇
Spencer's Links: https://spenceralessi.com

Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

Get every episode summarized

Each time The Cyber Threat Perspective publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

351 searchable segments. Every word is indexed and playable.

Episode 172: The biggest security blind spots in Midsized companies

The Cyber Threat Perspective

0:00
33:48

Full transcript

The Cyber Threat PerspectiveEpisode 172: The biggest security blind spots in Midsized companies. Machine-transcribed; use the interactive transcript above to jump the player to any line.

All right, dude. So what are the largest blind spots that you see in mid-sized organizations, man? We got like hundreds of pen tests under our belt over years of experience, probably collectively like two or three decades of work here in the offset group. What are we seeing that's just killing people, man? It's funny because a lot of the things that I see now in internal pen tests are things that I struggled with as an IT admin and things that like mistakes I've done and I think everybody can relate to that probably. But the first one is asset inventory, asset inventory. It's CIS control number one, right? It's like knowing your assets, knowing what you have out there, knowing your tax surface, knowing your footprint, that in many ways, especially now with AI is getting very difficult, right? Because the speed at which IT admins, developers, DevOps teams can spin up resources is incredibly fast. A lot of the stuff that's spun up now

is ephemeral, right? It's temporary. It's meant for a single purpose and then it's spun down or so we think, you know, in many cases. So asset inventory is kind of one of the biggest blind spots I see. And not because people are not paying attention to it really, it's because it's a challenging problem, right? Yeah. It's a challenging problem for small organizations. So imagine how difficult it is for even larger organizations, big enterprises as well. And particularly dangerous is when you, when you're not really sure what's available externally, right? What is exposed externally from an unauthenticated standpoint. If you don't know that, you're in for a world of hurt because if you don't know it, chances are it's not in your patch management system. You're not checking for vulnerabilities. You're not looking at the attack surface there. So asset inventory is like a big one. It's foundational, right? It's like the blocking and tackling, but I think that's a good place to start. Yeah. It is, man. And look, we see this all the time on external

princess where we'll find hosts. They didn't know they had, you know? And my favorite phrase to hear is, oh, I thought we turned that thing off or I thought we decommissioned that server. I'm like, yeah, you probably did in all of your policies and processes, but that thing's still sitting on the internet. It's still not getting patched. It's still getting attacked. And do we see this all the time? I got a great story for you. So just on a recent internal, I was going across their environment and, you know, I found a C.A. server and there were some issues on it, right? Some certificate template abuse and I'm abusing them and, you know, doing the thing. And then in the debrief called the client, they're like, I didn't even know we had a C.A. server. I'm like, how do you not know you don't have a C.A. server? But what happens is, and this is probably relatable to a lot of people, right? Is they hired an MSP. The MSP set up like this radius server for them to do authentication for their devices. And, you know, the IT team, the internal IT team didn't really have expertise. That's

why they hired the MSP to have them do it. Yeah. But they set up all this stuff and, you know, they just relied on the MSP to kind of handle it and set it all up. So they didn't really know what was out there. And turns out, you know, they misconfigured it unintentionally and there was some issues with it. They no longer work with that MSP. So they don't have the documentation for it. So this is very common. I've come across this a number of times where a company outsources something. They set up some stuff and then the IT team doesn't really document it or it's not really well understood what's out there. And then they do a pen test or, you know, having for bid, they have a security incident and then they find out like, oh, yeah, there's this thing sitting over here that we didn't know about. Yeah. Yeah, man. I mean, we see it all the time. We also, and this is, I think, an important, it's in the same vein, but it's not the same thing. A lot of organizations have all of these SaaS assets, right? Third party hosted websites, you know, we're working with somebody this week who's got like a CRM that's SSOed in from M365. And there's this perception that it's not mine.

But it's yours. It is absolutely yours, right? And so the risk that it creates is yours. No one cares that your third party vendor got breached and your data got compromised, right? They only care that your data got compromised. And this is a, it is surprising how many folks that we work with who don't share that view. And it's like, man, if it's branded on, if it's got your brand and it's got your data, it's your risk. It does not matter who hosted. Therefore, it should be folded into your asset inventory. It should be folded into vulnerability scanning, pen testing, all of the things that, all the tools that you use to identify and remediate risk, you can't take these things and just move them outside of that or you're setting yourself up for a real bad day. And like I said, man, we've had people in like the banking world in the payment processing world have that narrative with us. And I'm like, God, you have got to change the way

that you think about these things. Yeah, absolutely. Brand risk is absolutely a risk. And in the age of AI, where information is, you know, available at your fingertips and information is very much commoditized in a lot of services, products are being commoditized. The one thing that you have that you can control is your brand and your reputation. Yep. And if your reputation is tarnished, right, it very much can impact the business. So absolutely. 100% man. And you said it dude, blocking tackling. Yep. So that leads me to the next one, which is flat networks. And I guess this can also be a proxy for flat identities. I don't know if we can use that phraseology, but what I mean, what I mean is like flat networks in the context of, you know, everything can communicate to everything. And then flat identities, I kind of bundle this in, we can talk about it separately, but together, it's like this idea that you don't have tiering in place, right? Your admin account is admin everywhere. Maybe users have local admin or elevated

rights that they don't need. It's kind of like the least amount of effort possible put into identities and least privileged, right? At least privileged. So flat networks, flat identities is very much a big, big issue that we see time and time again. And the impact really is at least from the network side of things is maybe not as understood or it's not as understood how impactful it could be, right? If I'm an attacker and I'm on Suzy's workstation, right? If I can communicate to the server, then I can probe that server. I can check for open ports. I can see if there's any web servers on it. I can communicate with it. If there's any vulnerabilities that I might be able to abuse or exploit there on the web server. If I get access to an account, right? Maybe I want to use that account to pivot in the environment. The more I have access to, the more options that I have. And flat networks is something we've been talking about forever and it was zero trust. It makes it a little bit easier, but this is definitely something that is one of those big

blind spots for a lot of organizations. It is. And I actually like that you have flat identities and flat networks together. And here's why. Identities are absolutely the logical segmentation of the future. Now let's unpack that for a second. Traditional networks, old school, we would have VLANs, we might have firewalled off environments. The DNZ was literally the OG of non-flat networks, right? And so the problem is we're moving everything up into the cloud and we're doing that and all of that is managed by identities. Who you are determines what you're going to have access to. There is no longer this physical appliance that is creating a barrier between the networks. Your identity is what creates your access. And so with that in mind, as we're provisioning these users, and this is a conversation we did a cloud pen test in January with a client. And they only had two roles. It was engineer and developer. And which is cool, fine. But the problem is with only

those two roles, the level of granularity of access is very poor. And meaning that devs can access engineering resources. Engineers can access dev resources. And so, you know, but that is the thing that we rely upon in a non-standard non-traditional network environment, which is where everybody's going, man. The days of physically segmented environments on-prem at an office are going away. And so now we're relying on Azure AD or relying on identities and I am in Amazon. And so you have to understand that. And by the way, pro tip for all of you out there listening, if you're using the default roles in any of these platforms, you are wrong. Full stop. Because those roles are highly over permissioned in all of those environments. Even in active directory, you know, those built-in groups, like backup operators and account operators and server operators, like those are recommended, it's recommended to not use those built-in groups because the added permissions, right? It's better

to delegate permissions exactly what you need. But also to the point of, you know, flat identities is, you know, you have to bring up the conversation about agents, AI agents specifically, right? And these AI platforms, all of the products that we know, all the SaaS products, every product that you use is going to have some form of AI in it. And it's going to have some sort of a agentic capabilities in it, you know, now and for this foreseeable future. And what's interesting about that is those agents have to have access to things, right? They have access to potentially your files that have access to maybe your outlook, right? Your calendar, your emails, right? It has access to maybe your project management system, your ticketing system, your wiki, right? It wouldn't make sense for there to be a single identity access all of those things, right? So it's important to think about how we can design agent identities as well and

make sure that those also follow kind of the zero trust principles, right? Because one mistake that we're going to have is if we carry the old way of doing identities into the future of agents, it's just going to be like agent, you know, a single agent has access to everything. And then one bad thing is just going to create this domino effect and create like a huge, huge issue going, you know, if that identity were to be compromised or even in the case of like some sort of prompt injection thing where it's like, you know, people who are using OpenClaw and they're accidentally connecting it or they're connecting it to their Gmail and then accidentally deleting their entire inbox. Yeah. It's like even just from a mistake standpoint, right? We're still very early, right? These AI systems can make mistakes. If we have singular identities across the board, that creates a lot of risk. And especially now that these agent, uh, agentic platforms are coming into play and being used essentially everywhere, making sure that you understand what this idea of segmentation

for identities mean, least privilege, zero trust, like really wrapping your head around that if you have anything to do with that is going to be really key for securing these AI systems and workloads. Yeah. Yeah. I mean, you know, uh, there was, there's a very, very large organization for those of you that keep track of IT news. And so we're recording this in March of 2026. This month, a very, very large technology company had major incidents downstream of AI. And so they had employees who were heavily reliant on it and it started making production changes at their, you know, maybe not directly at their direction, but in the scope of the work that they were doing, causing major outages, massive problems in their environment, just to illustrate your point, like this is happening. And, and folks, I want to be very clear. There will be more pain points. There, there, you know, we have not kind of reached the critical ledge of AI yet in the workforce. And so what I mean by that is this thing is, is running at a hundred miles an hour. And nobody

seems interested in slowing it down, meaning that it's going to run right off the cliff. And it's going to take somebody with it. There will be a major incident this year at a large organization. It could be at the stock market. It could be, you know, gas processing, critical imprint. We don't know yet. But AI is going to nuke somebody. And when they do, everybody's going to be like, whoa, wait a minute. It's absurd because everything you just described, again, we're taking the fundamentals and we're applying it to this, even though it's a new concept, right? It's a new implementation of technology. It fundamentally is no different than anything else. And therefore, our inability to apply the fundamental basics of like access control, you know, and at least privilege, it's going to hurt a lot of people in the very near future. Yep. So quick side note, admin folks. If you're enjoying the podcast, leave us a comment on whatever platform that you're on. We had somebody mention like, hey, love the podcast on Spotify,

hate the video on Spotify. And we're like, dude, that is great feedback. So those are the kinds of things we want to hear from you guys, right? So keep that stuff coming. You know, criticism is always welcome. It's how we improve. And then, you know, it also kind of helps us in the algorithm if you like and comment, you know, even if it's just to say hello, tell us where you're from, right? Just drop a drop a quick note down at the bottom and be like, yo, listening from, I know like 40% is Europe. And we actually have like an awesome spread in Africa as well. So shout out to those guys and leave us a comment down below and tell us where you're coming from. Shout out to Australia too. Yeah. Yeah. Yeah. Absolutely. And one guy is in specific. He knows who I'm talking about. Yep. So awesome. So overconfidence and security tools. So when I think about blind spots, I think about all the conversations that I've had with clients who are especially in like a kickoff call, right? This is a very common scenario, right? Where we get in a kickoff call,

we're doing a pen test. Clients like, oh, we're super good. We're locked down. We're probably going to see everything like you guys are going to get anything like we're not going to go anywhere. And I'm like, okay, cool. You know, like, you know, I just kind of take it. I'm just calm. But quietly in my head, I'm like, you know, challenge accepted, right? Right. Yeah. And most of the time, those are the clients that are less secure, right? Those are the clients that most of the time see the least amount of our activity when we're pen testing or have the most issues or have the most dysfunction, I would say in their security program, it's this overconfidence, right? It's this idea that, oh, we have EDR, we have a SIM or we have an MSP. We're good. We don't have to do anything else. Like, this is just for compliance. Like, there's nothing to learn here. We're good. We're safe. And that overconfidence is a big contributor, I think, to security incidents, it's a big contributor to poor security culture. And it's a big contributing factor to, you know, quite

honestly, people leaving the organization are getting burnt out from that organization. So overconfidence is a big one. Yeah. And more specifically, what I see people have overconfidence are usually things they don't understand. And so, you know, let's take EDR, for example, EDR is an absolute staple in all environments. I would recommend everybody look into, you know, one of the top three. However, it's not a silver bullet, folks, but we get this, this kind of perception going where it's like, oh, dude, I got crowd strike, Falcon complete, man, I'm good. And I'm like, yeah, you're good until we am see bypass that, right? Or you're good until we land on a machine in your environment that doesn't have EDR because it's a performance hit on a legacy box. And so, you know, or better yet, right? A new attack technique comes out that crowd strike hasn't caught up with yet. Now, that crowd strikes very good about things like that, but there's nothing that's perfect. And so, you know, that's one of the reasons that we do internal princess the way we do is because it's like, guys, I'm going to show you that each individual

component in your environment is not going to answer all of the questions. And so we're looking at the ecosystem as a whole. And, you know, so I agree with you, dude, I think, you know, any level of blind trust is misplaced, especially in the security world because of the speed at which things evolve. And also just, you know, these things are like, you know, they're, they're siloed from a, from a, from a role perspective, right? You can have the best EDR in the world that can't be bypassed and can't be made blind to anything. But if you have no network to imagery, you're still running blind folks. And so, you know, again, don't trust them blind. You have to understand how they work, understand their limitations, and then close that gap with something else. Absolutely. And the other area where I see this crop up is, you know, we might do a pen test, and we don't find any critical vulnerabilities. And maybe we don't have have any high vulnerabilities, or maybe there's just a couple of vulnerabilities. But maybe during the course of that pen test,

we somehow, you know, get access to, you know, the CFO's email account, right? Or something like that. Maybe that didn't result in a critical vulnerability. Maybe they just had a week pass word, or we found a credential somewhere. And you could argue if that's a critical or not. But let's say that's not a critical finding, right? Maybe it's just a single text file or something like that. And we got access to the CFO's account because of that. That might not be a critical vulnerability. But the impact is critical, right? The impact that I am now able to, or the damage that I'm able to inflict as a threat actor with access to a CFO's email account is tremendous, right? I might be able to wire money. I might be able to fish other users in the environment to gain access to other accounts. I can impersonate that CFO to other organizations. X fill data that is very sensitive to that organization. Yeah, dude. Exactly. So the impact of those findings has to be considered as well as the severity, right? And just because it's a critical, right? And we we use this argument all the time. Maybe it's not the best, but like SSL 3, you know, the TLS

flaws and things like that that are listed as high critical vulnerabilities by, you know, the vulnerability databases. They're not necessarily the critical in terms of their impact, right? They're not, they're they're more of an academic kind of vulnerability. It's not going to be typically exploited by most threat actors or any threat actors, really, to any extent that's going to pose with any real harm. So I see this oftentimes, and it's kind of a point of education for us to our clients to say, yes, there are no critical vulnerabilities, but here's some of the impact of these other things that arguably could be just as dangerous as a critical vulnerability by itself. Yeah. Yeah. And I mean, the same can be said for stringing multiple lower severity vulnerabilities together, right? So that's something we see a lot on externals, a lot on web, where, you know, having like LFI combined with a vulnerable file upload, like those individually might be meetings, right? Might be highs. But when they're chained together, they create a

significant amount of risk. And so, you know, first of all, I would encourage you like from a Pinterest perspective, you need your Pinterester needs to be telling you that, right? It shouldn't just be a flat report with a bunch of random stuff in it. If there are things that can be chained together, that should be called out. However, that's not your only source of vulnerability data, right? Not your only source of risk data. So it's going to be up to you and your risk program to identify these overlapping risks that then become elevated into a higher risk issue. That's just part of the maturity of an organization from a risk perspective. And so, you know, I like your show notes over here. It's like, we didn't find anything. We're good. You know, and we've had multiple podcast episodes saying that is absolutely not the case. This is your starting point to move forward and improve your program, become more mature. Yep. For sure. The last one or maybe second to last one, I don't know if we want to talk about AI, because I think AI is also a big blind spot. But credential reuse. So obviously me being me,

doing internals, Windows Active Directory, this is a systemic problem, right, amongst organizations. And it's credential reuse of admin accounts, of service accounts, and even of local admin accounts. Now, that one, I am seeing, you know, anecdotally go downward in trends of seeing that issue. But it's still quite prevalent in many organizations and in many industries, especially industries like legal in particular, because legal is kind of an odd one, right, because they don't necessarily have a lot of regulations that they have to comply with from a cybersecurity standpoint, unlike financial services or other industries, right. So legal is kind of a, it's own beast. But anyways, credential reuse is something that is a big problem. And one example is, you know, and this is something we've seen time and time again on internals is we curb our Austin account. And we crack that password. It's a service account. And maybe that service count doesn't have any admin privileges.

It's like, okay, it's a service account. We can only use it on this one server. It's pretty locked down. It doesn't really give us anything. But then we spray that password in the environment, and sure enough, the admin that created that service account is using that password for his account as well, like his daily use IT account. That happens more often than we can count. And it's just out of a bad habit for IT admins to kind of reuse out of convenience, those credentials. Same with local admin accounts. It's easier just to use the same local admin account. I'm guilty of this too. When I was coming up in IT, it's like, just easier, right. You go to the computer, you always know what the password is going to be. The problem is, if a threat actor gets a hold of that local admin password, and it's the same across the environment, now that threat actor just has admin to everything, right? Bad day, bad day entirely. We see this in web all the time, right? When helpdesk is provisioning new accounts or resetting the password, they might have a temporary

password that they'll set, like welcome one, two, three. And then their expectation is the user's going to reset that password. But if it's not enforced and they don't, or they never log in for the first time, that default password just sitting out there. So we see that a lot on even external and web as well. And so it's a culture thing, but it's also a process thing. And so I agree, man, I think it's a fundamental flaw that is pretty widespread. So let's wrap up with the AI, maybe in terms of a blind spot. Now I've had in our notes for a while now, like the risks of AI agent skills, VS code extensions, and there's some more topics that we're going to dig into that'll have been more technical that are related to AI from a risk perspective and certainly blind spot perspective. But one thing I want to call out is these AI platforms, you know, VS code,

copilot, clawed, all those platforms and IDEs that have AI integrations in them. They're all being used by developers. And this is kind of very much inspired by Zach Korman. He made a video and posted it yesterday or depending on when you're watching this. And in that, he talked a little bit about the risk of developer systems and how that's quite a big risk now because of these AI platforms and AI skills. So I bring this up as I mentioned to IT folks who have developers, who have DevOps teams, developer systems are very much the same level of permissions as domain admin. In other words, getting access to a developer system is just as good as getting domain admin access in 99% of organizations, right? Because you get access to the developer workstation, they have local admin, they have access to database servers, they have access to the Kubernetes cluster and, you know, everything that they need to support the DevOps processes of that organization,

API keys, all those credentials as well. So getting access to those developer workstations is I'm seeing like it's going, I'm seeing the writing on the wall that that's going to be a huge blind spot for organizations. And I want to call that out to talk about that to say, there is a blind spot, we have to figure out how to secure those workloads, those processes that developers are using, those AI platforms. While recognizing that it's still very early on, there's still a lot of mistakes they're going to be made. We're still doing a lot of the mistakes we did before. It's just like, oh, no, you can't use that. And then developers are kind of going around it and getting around those guardrails. So this is a big area that I think is going to be continue to grow in terms of risk for organizations. There's no question, dude. So to me, when we talk about AI, they're kind of two broad categories of conversations. So you just hit on one of them really hard and that's the developer piece, right? Using cursor, using, you know, clawed for dev. And here's a word of caution for everybody that's out there listening.

AI enables non-developers to build software, right? And so as people who are even slightly technical start to get on this bandwagon, what's going to happen is where you might not have previously been a software development shop, you are now, right? So your folks are going to be writing code. They're going to be writing connectors between systems. They're going to be spinning up, you know, consoles to make their job easier. And I think it's a great thing. But it's also going to expand your attack surface significantly. And if we embrace this as we probably will, to your point, there's going to be a lot more blast radius on getting on, you know, some random help desk guys, IT support machine in an environment. Well, now it's going to have a whole bunch of API secrets that he's been using to build software and make connectors that we're going to get access to. And so first of all, 100% agree with that. We need to start thinking about that now, because it hasn't quite hit that level of critical mass yet, but it will. I promise you it will.

And then the other thing is talking about AI just from a chatbot perspective, right? Companies are actually, especially law firms, do law firms so hot and heavy on pushing out these large scale rollouts of AI to support their lawyers because it's a force multiplier. Lawyers can do more in less time, right? And I guarantee you hospitals are facing the same thing with doctors and nurses. They're probably clamoring for AI, right? And so, you know, take that and apply that to whatever industry we're talking about. But again, we're moving too quickly. We are not taking into consideration that AI is a standard piece of software that needs to have guardrails around it, right? Which means, here's what I'm seeing, especially in the flat unstructured data world, which, again, applies almost everywhere, is people are creating MCPs with five lines in it, right? And it's like defining the MCP, giving an access to the root of the share in the entire network, and then

no further restrictions have a good time. And so, you know, this little AI is just accessing everything in the environment. And again, that means everybody all the way down to your lowest level help desk person, all the way up to, you know, the founding partner of your organization, has access to the same data now. All of the controls that you put in place to put barricades between sensitive data, non-sensitive data, you guys are undoing that right now by giving these AI platforms full MCP access to your environment. So word of caution, and I guarantee you, most of you out there listening, especially those that are in like a CISO security manager risk role, are thinking the same thing on thinking. They're like, holy smokes, we're moving too fast, something's going to go wrong. And you're right. So, yeah, and there are, there's tools now, there's companies being created, security companies that are seeking to address this problem by like

scanning the NPM package libraries and checking for, you know, malicious stuff and kind of running in line with the package manager. So, it acts as like a gateway or a firewall. So, when you run like NPM install or whatever, or PIP install, it goes out to that security company's package manager. It does the scanning first to make sure it's okay before it allows it to be installed. So, there's a number of companies like that. So, if you have developers or DevOps, or people that are even not in developer roles like you mentioned, using these things, these are going to be very much necessary products and controls that you need to have in place to address these risks. And it's kind of funny. The last thing I'll say is, I forget who asked me this, but somebody asked me about like, how can we defend against data exfiltration? And I'm like, it was impossible before AI. But now with ChatGPT and all of these

chat platforms and heck, even with your phone, right? Like, you can just, you know, record a video of a document, you know, scrolling through a document and then you can just transcribe it with ChatGPT or something. Like, it's just so impossible now to protect against it. You have to move more upstream. That's the only option. Well, I mean, you move the controls to the data, right? And you leverage identities to Siphon or to Silo data subsets. I mean, that's the only answer, right? But that concept is fundamentally not net new. And so, again, I just, it frustrates me to know in because we are failing as a career field. Maybe I don't know, cyber is failing AI, right? We are, we are, we are fundamentally not applying the basic concepts because it's a new and exciting technique. Now, and I'm sure there's a lot of executive level push. I get that. But, you know, if I were to come to you and be like, yo, you know, I'm going to put a web in a web app in your environment that has access to all of your data and the internet, right? And, and oh, by the way,

you know, we're not going to put any controls around it. You would lose your mind. So why are we not losing our mind right now? Yeah, folks, go ahead. No, finish it up, buddy. No, last thing I'll say is there's real safety implications too, right? Like, this isn't just, you know, we talk a lot about security and privacy and stuff like that. But as these systems get integrated with IOT and critical infrastructure and things like that, if you work in an industry like that, there's real safety implications of this too, right? Like, it's not just, okay, somebody's going to steal the data, right? Like, somebody's going to like turn up the reactor or poison the well kind of thing too, right? Like, that's a very serious thing. Yeah. That many industries and maybe many people watching that will resonate with you is safety is a most important of importance. It is. It is. I was actually having this conversation with somebody yesterday and I don't mean to be like morbid or overly alarmist. But AI is going to kill

some folks at some point, right? It's going to happen. And of course, it's not going to be on purpose. But, you know, and I think I think that will be the pivotal point where we're like, hey, wait a minute, are we doing this right? You know, unfortunately, I think an incident is going to have to happen before we as an industry take this more seriously. You know, but, but yeah, I mean, look, man, it's inevitable. As we start integrating this into, you know, all these different critical systems like hospitals, healthcare, like you said, critical infrastructure. You know, so, so dude, yeah, it's common, man. And we're not managing this the way we know we should. And it's going to create some problems for us. All right, folks, that's all we have time for today. If you enjoyed this episode, like, subscribe. As I mentioned earlier, drop a quick comment. Let us know where you're from and whether you like the episode or season, want to see something else, you know, we love hearing about topic requests and stuff like that. So you guys have a great week. We'll see you next week.

More episodes

More from The Cyber Threat Perspective

View all episodes →