Unauthorized Opinions 03: Cost of a Data Breach 2026 https://codykretsinger.com/episode?show=unauthorized-opinions&ep=3 Narrator: This is Unauthorized Opinions, part of the Threat Aware Podcast Network, where the Galactic Security Team says exactly what's on their minds. Unfiltered takes on the cybersecurity threats, trends, and stories that matter most to the people defending real organizations. Here's your host, Max Kurek. Max Kurek: Welcome in. We are glad you're here. I am joined as always by Seth Loe, Galactic's President and Chief Security Officer, and Cody Kretsinger, Director of Security Research. Now, you may notice, especially if you're watching us on YouTube today, we've got a missing face on the podcast because our esteemed colleague Aidan Brown is out on paternity leave. He and his wife have just celebrated the birth of their first child, so congratulations to them. We will miss Aidan, but really happy that he's enjoying time with his new family. Seth, you're the only other father on this podcast. So any words of wisdom for Aidan? Seth Loe: Yeah, I will say you've probably never done it before, but trust your instincts. You've got this. We know you to be an incredible, compassionate, intelligent human being. Have you all that you need, young learner? And there are a couple of milestones to keep track of. There is a day coming when you don't need a diaper bag anymore. That is a glorious day. Be ready to s to celebrate that. There is a day coming when I don't know how many kids you plan on having, but one day they will all be able to let themselves in and out of the car unattended. That is amazing day. And then there's this big break in the in your life where the next big milestone is the day they can watch themselves when you go out for date night. So that's a big remember those milestones, my friend. You got plenty of heartache ahead, but there's lots of milestones there too. Max Kurek: I would assume that day that you described of watching themselves might feel like it's far away, but then isn't the whole thing about how it all goes so fast so it'll be like it'll feel like tomorrow and then Seth Loe: Yeah, but that bomb's on a delayed timer. Cody Kretsinger: Trust me. Max Kurek: All right. All right, fair enough. So Aidan, we know you're out there listening, so there's some words of wisdom and yeah, congratulations once again. We'll look forward to having Ba Aidan back in the saddle soon. Speaking of celebrations, guys. Today's episode is a celebration of sorts. It's kind of a cybersecurity holiday in a weird way, if those were real. I don't know if we like If we created one of those calendars, it's like, you know, it's like National Pancake Day or whatever, I don't know if national release of IBM's cost of a data breach report day would be on the calendar. But if you're a data nerd or if you're somebody who has an interest in like empirical trends around cybersecurity, data breaches, AI usage, and you like to crunch numbers and actual data associated with those things. Then this is a pretty big day for you because the IBM's cost of a data breach report just dropped, and there's a ton of stuff to unpack with it. And so that's what we're gonna cover in today's episode. We're gonna do a deep dive on this report. There's a lot of things that relate to AI adoption, that relate to kind of threat landscape trends. It's all packed into this gosh, 70 ish page report. And one of the things I think that's so important about talking about this specifically is we talk all the time about how rapidly security is changing, how rapidly the threat landscape is evolving. And releases like this, reports like this, give us a chance to actually examine the depth of that evolution, right? They it allows us to level set, it allows us to get a picture of what things actually look like with real data and real survey results to back it up. So I think that's why even if holiday is not the right word, there's no gifts being exchanged today, although maybe a an unauthorized opinions white elephant gift exchange is an idea we'll take down for the future of the podcast. Yeah, I think everyone would like that. But that's why we're dedicating an entire show to this. And there's a lot to unpack, year over year trends, some eye popping AI related numbers, and a whole lot more. Cody Kretsinger: Good idea. Max Kurek: So I wanna just dive right into it. And guys, what I want to start with is I just want to go over for everybody a little bit about the methodology and a little bit about how this report works so that everyone understands. And we will include a link if you want to read the full cost of a data breach report. We'll include a link to it in the show description and in the show notes for this episode. So go ahead and take a look. You can go through the full thing. It's gonna be there for you. But Just so everybody understands, this is the 21st edition of this cost of a data breach report. I mentioned this one's 70 pages. The research itself is conducted by a group called the Poneman Institute. And they're a dedicated research organization. And what they do is conduct empirical studies specifically on issues affecting information security, affecting IT infrastructure. And then IBM is kind of the sponsor of the report. They analyze it. They published the findings, but to be clear, they did not conduct the survey and conduct the actual study themselves. That's done by a third party. For this year's report, 602 organizations were analyzed and they conducted over 3,500 interviews of security leaders, C-suite folks, anyone that kind of had a role in dealing with breaches at their organization, they were interviewed as part of this study. The study actually covers breaches. The breaches covered in the study span from March 2025 all the way through February 2026. So it's very contextually relevant, very recent, and it also includes 16 countries and regions and 17 different industries. So the trends that you guys are gonna see in this report and that we're gonna talk about today are very generalized, right? That this is not a Look at one specific vertical or one specific vector. And I think that's what's very powerful about this report is that it looks at a lot of different factors. And the breaches that they actually studied in this report range from just over 2,500 compromised records to over 115,000 compromised records. So it's it it's a very wide range. And just to be clear, the publication year 2026, that refers to when the report is released, not necessarily when the breach has all occurred. So that March 2025 to February 2026 time frame is what you should have in your minds in terms of like where this data is actually coming from. And then the last thing I want to mention, and we're gonna talk a little bit more about this toward the end of today's episode. I think one thing that happens a lot when somebody reads this report is they're kind of taken aback. By the dollar figures, millions and millions of dollars, because they feel very unfamiliar, especially if you are a small business owner, if you are a security professional at a small to mid-size organization, you might look at these numbers and kind of not quite relate to them. And so what I want everyone to understand, and what we're gonna be doing when we unpack this, is looking at trends and looking at what are the things that I can take away from this report, even if the company that was studied in this particular case is much larger. Or their revenue numbers are completely on a different end of the spectrum from mine, there are still very useful insights to glean from this. And we still want to make sure that we give it our due attention. So that's kind of the caveat to all of this, but enough it enough about the methodology. I think you guys can read they cover the entire methodology and the report itself. So just go grab the report if you're curious. But I want to open up with a question. And Cody, I want to come to you first on this because I think the best way to get us started is what is that one thing from the report this year that really landed the hardest? If you had to pick one number or one finding that as you were reading through it that really stood out to you, what was it? Cody Kretsinger: So there's a few of them, but the easiest one for me is gonna be that fishing is the number one vector that they called out. This is the fourth year straight on that particular vector. They specifically call out vishing, that is voice phishing, so giving somebody a phone call or smishing. There's too many ishings, by the way. We should just it should be just a blanket thing, but smishing is the basically the text message or MMS message to phones as well. And then the other thing that they highlighted was help desk and MFA fatigue. And they put that all under one particular percentage. But MFA fatigue was thirteen percent just FYI and the combo vishing and smishing attacks were seventeen percent and obviously those two combined makes about 30. So a third of the way Of the bad guys getting in is still fishing, which is interesting because I'm gonna call out that on the Verizon breach report, the number one way in on that report was vulnerabilities on getting in. So we're seeing this a little bit of a difference between these different reports now, which is fairly interesting. But that was the primary one for me is that okay. Identity phishing, vishing, smishing, ishings, is the way in. But the other big call out that I saw that just captured my eye was not encrypting data at rest or data in motion. And that was over half of all of the findings in this report. That is significant. If you think about these organizations, many of which are in regulated industries are not encrypting either data at rest, which is a which is eye opening for me, or even scarier, data in transit. Those are the things that are just they stand out to me as being kind of number one, number two. Max Kurek: Yeah, if ever we shouldn't consistently need back to basics reminders, but if we do, clearly we do, and findings like those are a real good reason why you'll constantly hear security folks, and if you have these in your own organization or you work with third parties that consult with you on security, it's why you they sound like broken records sometimes when they talk to you about some of these baseline controls and when they talk to you about some of these activities that really help you be more secure is because you see reports like this published where a huge percentage of data is sitting unencrypted at rest or in transit and you're like, okay, that's the reason why. It's also why all of us need to continue to suffer through end user security training, fishing awareness training, because there's a reason why the bad guys keep using it. It's effective. It works. And so next time you're lamenting about the training that you have to complete, remember the findings from this report. That's the reason why. Ahead. Cody Kretsinger: Yeah, there's another thing that recently somebody asked me, I was doing some presentations, doing some talks at some conferences, and I w I did a talk around AI. This was kind of late last year, but somebody brought up Cody, like if you had to focus on one area in security, where would it be? You know, for most or most organizations and Max, you just you essentially took what I said to them, which is cover the basics. Making sure that passwords are actually secure, you know, and that password hygiene is there, that you're not exposing identity where you don't need to, that there's nothing, you know, you're not running RDP to the outside internet, that SMB version one is disabled. Like these super basic stuff. Because as we can see in this report, the bad guys are still bad guying on the stuff that people still are the back to basic stuff. And I think it's so incredibly Important for organizations to make sure that they don't lose sight of the fact that the basics is how you get started and you have to maintain those basics in order to actually get better because the bad guys, the bad guys are gonna bad guy, and some of them are fairly smart, but most of them are looking for the lowest hanging fruit, for the least resistance path in order to get into an organization in order to do the damage. And that is through the basics more times than not. Max Kurek: Yeah, there's a reason you don't build your house on an unstable foundation. It will crumble. Seth, what about you? What was the biggest number, finding, takeaway that stood out to you when you were kind of looking at the report this year? Seth Loe: Well, first of all, teacher, I would just like to point out that Cody was asked for one statistic and he gave like four. So that's the number that stood out to me. No, appreciate. Cody Kretsinger: You gotta bump up your game now, man. Come on I know the only Seth Loe: Only reason I bring that up is that you stole like number one, two, and three from me and now I'm going down to my was that what's what is the fourth? Is it the quaternary tertiary? I think it's quaternary. That was two hundred and forty-seven. That was the number that stood out to me. And that is the number of days it takes us to get these attackers out of the environment. So hundred and eighty three mean days to detect that they're in this organization. Max Kurek: It's after tertiary, yeah. Seth Loe: And 64 days to contain that for a grand total of 247 days. That's like two-thirds of a year between the time the attacker gets a foothold in the organization. He's hanging out, he's drinking a cup of coffee, he's reading your email, he's laughing at your jokes, he's finding out where you stored the keys to the kingdom. He's noticing that 50% of critical data being unencrypted, laying around your organization quietly. Exfiltrating that data, polite enough to use the times of the day when you're using the internet the least, so you can get the most bandwidth out of it. And then once they have that the keys to the kingdom, then they're dropping those ransomware attacks. And that's just really a lot of time to focus on a project. You know, if you got two thirds of a year to very quietly sit around and make your decisions, see what you can see, go loud sometimes, be quiet other times, see what you can get away with. That really sucks because that's actually up year over year. So last year we were six days faster at get the getting the folks out of the environment. And our track record on this is not great. I mean, we're in an arms race here, right? The attackers are getting better at getting in. They're getting better at staying quiet while they're here. And we're getting worse at noticing that they're in the environment and getting them out. So that really stood out to me from this report. Max Kurek: Yeah, there's definitely I think a question of well does that say more about attackers? Does that say more about defenders? And as Cody would say, yes. Probably both. So Cody Kretsinger: Hundred percent so yes the other thing is on Seth on your points that's the I think the mean time to detection has gone up. That's bad to be clear. That's a bad figure. But also I want to highlight the inverse of that which is essentially the time that it takes for organizations to recover after that. Because the so that's essentially two thirds of year or three quarters of a year, right? That the bad guy is inside the network just chilling. Just having fun doing whatever they're doing. And then the organization has to respond to that. And I remember an incident, this is way back when I was running MSSP, an incident that was one of the largest incidents that I've ever had, that I've ever dealt with. And I remember being on site for nearly three and a half months from six in the morning until midnight. Every single day and Saturdays and Sundays included, that included all of the IT staff. That was after the initial first week where nobody actually slept, right? But where I'm headed with this is that organization took just as long to recover as the bad guys were likely in their particular network themselves. And the other thing that I will note is that organization would not be on this report. They would be too small. And be in we talked about a little bit earlier, Max, the figures around this particular report. There's always some incredible statistic, right? It's like thirty-four billion dollars spent on, you know, malware or whatever it may be. Just these ginormous numbers that you know a lot of folks can't really wrap their head around. What I can give some perspective on is that incident. That I dealt with that wouldn't be on here was hundreds of thousands of dollars. That organization wasn't very large. The organization was not large at all. And the significance of that particular incident, luckily they were able to recover and by like the skin of their teeth able to recover. There was like a backup that somebody had on their desk, like on a thumb drive that was like that was the only thing that the bad guys didn't actually get. The point being, there's so much time that the bad guys are sping s like they're spending so much time in the organization and then the recovery time for organizations has also started going up as well. Seth Loe: Well, and I love your point about an organization that would not have been large enough to make this report. And there are good things and bad things about that. I think that if you are a small organization, if you're an SMB and you feel like maybe I'm a little outclassed by some of the research that's been done here, one thing that you can know is that this is a harbinger of things to come. I mean, this is what your report looks like next year, right, as these attacks advance. The other thing to think about is This includes companies that survived long enough to be around, to interview, to get these statistics from them. So when you talk about the Poneman and Poneman Institute doing this research, they researched companies that number one, their breaches were known. Number two, those were willing to actually share information about the breaches. And I think that this is very important because this is all about a community of the willing, right? The bad guys share notes about the attacks, right? They compare tactics, they swap, they brag, they talk about how they got in, they publish their tactics. This is the good guys doing the same thing. We need to get together, we need to huddle together, we need to share notes about what's going on. So these are the companies that we're still around for that institute to do this research on. Ask yourself: does your organization have the backup infrastructure? The backup financing, the backup staffing solutions, the other revenue streams available to be able to stay in business 64 days later so that you can be interviewed about how you actually recovered from the breach. So that's what really scares me on the risk side about people who see themselves as too small to fit on this report. Often they don't have a reasonable expectation of how long it takes to recover from this. Because I know plenty of times, and Cody, and you've mentioned this before too, it's been I it's been my neck on the line to respond to these issues. And I know that none of the clients that I worked with had numbers like sixty-four days in their minds. They were like, we're gonna go to a backup and a couple hours later we're gonna be back in business, right? And often that is not the case. They're not just standing around on the street corner waiting for you to pick up, slap them in cuffs and haul them off. They have gotten into every little corner of your network. They have got backups to their back doors. They've got persistence established so that even after you think you kicked them out, all you do is somebody reboots one computer that you didn't catch and they're back in. And the odds of them being able to get back in are so great that accounts for these 64 days. I would imagine that somewhere along those 64 days, somebody thought they had them out and found out they didn't really. Cody Kretsinger: The thing that I want to highlight, there's like an image that goes around on the internet of a World War II plane. It shows all of the bullet holes that when it lands. And the meme or really what it's trying to show is survivorship bias. Those were all the planes that actually landed after being shot up and you know, survived. W what the statistics here do not show is all of the planes that didn't land. And we can account for all of the things on these surveys on the organizations that wanted to be surveyed and talk about the things. And we'll talk about attribution later because that's gonna be a whole nother topic because I'm I I've got a soapbox ready for that particular thing, because there's some stuff in this report that I genuinely disagree with. But what we are seeing here is the folks who did survive the incident. There are many. Many organizations. And in fact, there's a university here that made headlines in a few years ago that they had an incident so bad that they had to shut down an actual university because of because the bad guys won. And you don't actually get those statistics in the reports like this. So I think it's an incredible call out to say that some of this data is a little bit skewed. In a lot of different ways and some folks really need to be cognizant of what this actually represents. Max Kurek: All right. Well no note for the production team on that one. I'll just mention one thing really, really quickly. It's a little bit more in the weeds than what you guys called out, but we're gonna get into kind of the AI side of this conversation a little bit i in just a minute. One thing I found interesting was half of breached organizations have deployed AI agents in their SOC. And we talk about AI both from the defenders and an attacker's perspective and kind of who's winning the AI arms race when it comes to this. But one of the things I found interesting, and Cody referenced the Verizon report from earlier this year about vulnerability exploitation being the number one way in. And there's obviously some conflicting findings with the this IBM report. I think we can agree that, you know, multiple paths to entry are still on the table and attackers are doing it the way attackers do it. But Half of those breached organizations that deployed AI agents into their SOC, only 18% of them are pointing those agents at vulnerability scanning and management. So is it is that a commentary on the adoption of AI defenses and whether they're being applied correctly? Do we still have a lot to learn there? Are we aiming these things at the wrong place because If the Verizon report is to be believed, we're aiming our AI SOC agents everywhere except where the threat maybe actually is most coming mostly coming from. I think that's probably a little bit a little disingenuous. But what I wanted to what I want to keep an eye on is the overall approach to adopting AI as defenders and what that can really do or From either end, from the positive or the negative side, as security folks, third party security consultants are trying to keep these businesses safe. And we'll get into the AI discussion here in just a moment. But I want to follow up on CES statistics, because this actually it dovetails really well into the first topic I wanted to kind of hit on from the report. And I'll just kind of reiterate. Mean time to identify and contain. So identification and containment rose from 241 days to 247 days. And like Seth mentioned, that reverses five consecutive years of improvement. The same figure was 287 days in 2021. So if you look at like the overall we're still trending upwards, but noticeable that after five consecutive years of improvement, we've kind of gone the opposite direction. But Interestingly, recovery improved for a third straight year. Forty-two percent of organizations fully recovered. And I saw Cody's face. This is why I'm asking this question, because I think there might be something might not quite smell right with some of this. But recovery time technically improved based on the numbers. 42% of organizations fully recovered, up from 35%, and the share needing more than 150 days to recover. Fell to 19% from 26%. Now, here's the caveat to all of that is this is self reported, right? And this relies on surveys. So number question number one is do we really believe that? And question number two, when it comes to detection versus recovery, if we had to pick one of those two areas to fix, Which matters more from a business perspective and why? And obviously the easy answer is both, and you need to, you know, plan accordingly, but everyone's resource constrained. So that's kind of where I wanted to start this conversation of year over year trend, because I thought those were two things were particularly interesting. Cody, I don't know if I'm gonna put you on your soapbox earlier than you expected to jump on it, but what is that, what do those things say to you? Cody Kretsinger: Well, sixty-three days to recover, that's only two months. I mean, there's no way an organization can't respond within two months. That's the there's if you look at it right, so yes, the w by the time you identify everything that's been impacted, you get cyber liability insurance started, you've talked to a lawyer, you've decided exactly which components are going to be running the organization while you Try to do the recovery itself. All of those different things. We're already talking like three or four weeks just based on those conversations. That's halfway through it. And then to this magic wand of just restore for backups and everything is good and golden and the bad guys are out. I don't believe it. I what I do believe is perhaps it's recovered to a point where the business can function. And that makes a lot more sense because 63 days. Is about where that would be. About two months in where, you know, you can start to bring back the majority of your staff in order to do their normal jobs, even if it is at a reduced capacity. But most organizations, the ones that I've dealt with, six it's either a very small incident that is easily can like contained and very easily recovered from, but Again, this report skews heavy into the big boy, big bad type of incidents. So knowing that, I think it's more closely. It the number is closer to the organization actually getting to a point where they can actually start to do business again, not necessarily fully recovered. I think that's a bit pie in the sky numbers because it takes months, months, plural. Maybe half a year, maybe closer to a year to fully recover from a big bad incident. There's just too much work to do. Max Kurek: Yeah, the variable definition of what fully recovered even means is also going to Yeah, right. Is also gonna play a big part here. Seth, what are your thoughts? Seth Loe: Yeah, I want us to attack that hundred and eighty-three days to identification. On this side. I want us and I this is for the people that I'm pulling for, because in that hundred and eighty-three days are people just like you and me on the defense side, on the governance side, on the administrative side, who are gonna have to answer the question, they were in your environment for six years. Months and you didn't notice them. How is that even possible? And I think as you're gonna see that number go down, I think, as those basics that Matt that Max was talking about before start to really be consistent. The basics of authentication, multifactor authentication, tokens MDR seam, all those solutions in place that have the ability to notice attack patterns. You know, I don't know about you guys, but I feel like we are still watching the business community wake up to collecting information from large portions of the network. You know, that would that be traffic, that's ingress, egress, between segments, on devices, between devices, between networks and backup solutions. Actually being able to harvest that information, notice patterns of attack taking place before the first MDR ever kicks off, before the first antivirus solution. And God, we're still talking about antivirus. But for the first antivirus solution ever notices a pattern, you know, a thumbprint-based attack, which I mean, I mean, that's the horse and buggy of malware now, is where you can hit the thumbprint on it. Right. I think when you see the rest of the business community begin to take this the mitre solution into account, being able to watch that entire attack framework, look for those patterns, be able to identify when different phases of the attack are taking place, have the ability to trigger in there, I think that you see that hundred and eighty-three days come down. And also that 183 days to me is all blast radius. The longer it takes to identify that infiltration, the farther they've gotten, the more data they've gotten access to, the more credentials that they've compromised. Whether you are the on the IBM side of the argument or on the Verizon side of the argument, it's whether you've got more passwords have been cracked so that they could get into more systems or more vulnerabilities have been noticed and exploited. And the one thing I can hear, I can bring peace between the two communities. You can. Fish your way into an environment and the attack methodology you use is exploiting a vulnerability. It doesn't have to be cracking a password. It doesn't have to be using a cracked credential to get in. So those two communities can now come together and they can hold hands and sing kumbaya for they are both right. Cody Kretsinger: I mean a bad guy's gonna do a mix of those things anyway, right? They're looking again that we're going back to path of least resistance. And that's where most, you know, that's where most threat actors are gonna look at something. If it's an easily cracked password, they're gonna go there first, right? And if it's an easily exploited vulnerability, they're gonna go there. It the what I love about this is that it doesn't matter if it's identity, meaning anything pertaining to. You know, usernames, passwords, tokens, all that stuff, or the vulnerability itself. What we do is we have two two reports here that are basically saying they're number one and two and they're interchangeable. So these things are really, really, really important. And I think I heard your position, Seth, on which one is more important, detection or recovery. And I if I heard right, it was detection. You think that detection should be more important out of there. And what I realized is I didn't say which one I wanted to be, and that is recovery. Because people it the bad guys will always be very good at being stealthy and finding a new novel way in. But every organization needs to be able to recover as quickly and as normally as possible because It doesn't matter if it's a bad guy. It doesn't matter if it's a, you know, some sort of weather-related event or something else. Something, you know, economic even, all of those things need to be taken into consideration for the actual recovery plan. And I think it's more important to have a recovery plan than it is a detection plan. Seth Loe: Mm. Max Kurek: So there you have it. Th there's the incident responder folks telling you need an incident response plan. So go build one and practice it. Cody Kretsinger: Please. Please go I'm sorry, like I'm just gonna keep doing this. Please go if you do not have an incident response plan, it is like the number one thing you need to do, write this but like pause this, go copy an incident response plan from somewhere, make sure that you understand it and then resume and then tell us in the comments that you did it. Max Kurek: Yeah, exactly. Let us know. Okay, I want to hit this one. Seth Loe: The IBM report. That's what we'll give Max Kurek: Yeah, exactly. You'll get your own free we'll frame it for you. We'll put it in a we'll bind it into a nice book and send it to you. And sign it. Yes, and sign it. Really quickly, I want to spend just a minute kind of rapid fire because it's the IBM report. We have to talk about ransomware a little bit. And I do think that there's a really intriguing finding from the report on the ransomware side of the house. Ransomware hit 39% of breached organizations in this report, which is up from 24% back in 2023. But what really I think stood out to me at least was threatening brand reputation is now the most common pressure tactic at 41%, ahead of encrypting data at twenty three percent. So it's not a, hey, we're gonna lock down all your computers and encrypt them all. It's hey, we're gonna Put this stuff out in the open and kill your reputation. So I guess that's really interesting. And I think is probably in line with all of our experiences and what we've seen, especially since 2023, when the last time kind of the this number really is what we're comparing it to, right? 39% compared to 24% in 2023 of breached organizations experiencing ransomware. But what actually changes about how an organization prepares To deal with the threat of ransomware when the most common way that's going to manifest is data being leaked publicly to harm your reputation, as opposed to encrypting machines to kill your productivity and you know, eventually getting you to pay a super fat ransom that way. Seth, do you have any thoughts on like what this means for organizations as they think about how to mitigate the threat of ransomware? Seth Loe: Well, I think first thing I thought was, is it only thirty-nine percent? You know, because how often I mean, if they're getting in, they're causing people big bucks, one of the best ways, I guess I wouldn't want to say the best way, but one of the easiest ways to do that is through ransomware. So I was really surprised that it's only thirty-nine percent of these incidents. The other thing that I saw was a correlation there when it came to the reputation-based attacks and that being We have to think about this as it's a lever that the attackers are trying to push. Do they really care about the reputation of a local healthcare organization? No, they care about getting paid. And there was a pretty significant representation of healthcare organizations in this breach report. And that's a very big deal for healthcare organizations because now we're not even we attack the reputation of a healthcare organization. You're going to have health and human services pile on, and there's that looming threat of what, ten thousand dollars per patient record hanging over. Even a small health healthcare organization over the span of six to ten years can come up with hundreds of thousands of patient records that blow away the ransom amount. And you better bet they're doing that calculation, going, well, HHS is gonna find them. 3.4 million. So let's bring that ransom in at 2.7. And all of a sudden, this is we've got a value prop that we can talk about. And then when you consider, especially in the United States, and I notice how much the amounts were skewed, right? Worldwide it was 4.99. And I just felt like that's hackers being underachievers. I think they could have pushed a little harder for that other point one to get us to the full five million. But then in the United States. It being 11.5 million. So when we look at what happens in healthcare in the United States, it is required that doctors share ownership of health healthcare organizations. So now they know there is a doctor on the board and it's their name in white letters on the glass out front of the healthcare. Excuse me, out outside the medical office in that practice. Their name is there. It's their name on the website, it's their name. And their face on the advertisements where that doctor walks in the lab coat and talks about how they give the best care ever. It's a human's reputation that's now behind this too. And I think that's why that's such an effective lever. And I not I'm not surprised when I saw how well healthcare was or was represented in this report to see how effective that lever can be and why they're pressing it so often. Max Kurek: Cody, go ahead. Cody Kretsinger: The bad guys have figured out which lever gives them more money. That's all I mean that Seth, to your point, you know, most cyber liability insurance organizations will pay ransoms or at least try to help do some of the things. But what attackers with threat actors have been able to kind of conjure up throughout this process is that man, reputation pays way more because. I in i outside of healthcare, right? Even then you might have to deal with a state that has some sort of regulatory authority over a particular thing or some PCI stuff or whatever it may be. Or it's just executives who don't want that reputation to get out. And I think they've managed to continue to find a lever that actually benefits them, which is really, really, really unfortunate. That goes back now to all of the data at rest, all of the data in transit that needs to be encrypted in order to really stop this from happening. And then obviously secure storage of keys and some stuff along those lines. But what I've found really interesting is that they've realized that the ransom part of it sucks. It's just it's a it's there's a lot of legwork that goes into it. You gotta make sure that the thing gets deployed, you gotta make sure that you the thing can actually decrypt. You've got to provide support, you've got to do all and that's all humans, right? Because the bad guys actually had human tech support for the folks decrypting their data. And if they don't have to invest in people in order to provide that support, and it's purely just the reputation of the organization. It's a matter of whether or not they publish the information to their leak site. That's all it is. And take it a step further. A lot of times what these threat actors are doing is they'll actually go through if it's like a healthcare facility, they'll go through and notify the patients themselves. So that's where like the double extortion is starting to come. And then now they're even they can take it a step further. They start looking at vendors, they start looking at competitors. Things along those lines where they want the reputational damage to be the worst possible way of doing it. So you from their point of view, you better work with them because the reputation is gonna far outspend any kind of ransom that they could have possibly done. And I think organizations need to start considering those things. This is a whole different conversation around being prepared to have holding statements for incidents and making sure that you have. You know, the proper containment things squared away, that lawyers are involved from the very get-go, that you truly know your full blast radius, all of those things are so incredibly important. And that is another reason why recovery, I'm putting another hash in on the side of recovery, because if that data truly is encrypted, if that do or if that data is truly unusable to the threat actors, You can recover it, thank goodness, and not give the leg up to the bad guys. So I've got two hashes in my column, Seth. I don't know how many hashes you've got yours. Seth Loe: I wanna put some synergy between what Max said and what you said. And I wanna get out the crystal ball and let's talk for a moment here about the next level of what this data is saying about the future of attacks. Because I think we get a little prognostication in here. Think about this. Now the attackers. Break into your environment using AI. And we know that if they use AI in one out of four cases, that means they're getting better at it. And they're apt to recover $2 million more if they used AI in the attack. They get into your environment and now they attack the AI that these companies have been using in order to reduce headcount or expand the capabilities of their existing headcount to grow their businesses. Now what I'm exfiltrating is not only your private data, but I'm exfiltrating your AI automations. And then I shut it down. I'm exfiltrating your skills, your projects, all of the agents that you have set up. I am shutting them down and I am taking them away. And if you want them back, now those are held for ransom too. So it all changes because you've got organizations that are actively working to dehumanize their business processes, rely heavily on agentic agen agentic processes in their business. And once those get stolen, what are you gonna do? You're gonna go rebuild it all from scratch? I hope you kept the person who created it. Max Kurek: Right. So that and that actually let's talk about AI a little bit, because there's a lot of there's a lot of meat on the bone from an AI perspective in this report. And I've got a couple of directions I want to take this, but first to kind of speak to follow up on what Seth was saying, this survey found that ninety two percent of the organizations that suffered an AI related breach lacked proper whatever. You consider proper AI access controls. Only 40% use access controls on AI models and data at all. And IBM actually, if you read the conclusions, they root causes, they list compromised APIs, applications, cloud misconfigurations, and they actually cite these all as governance failures rather than model risk. And so A lot to unpack, I think, just from that perspective alone. But one other conclusion here is that there's really no category of AI security. There's only identity and configuration with a new surface area attached to it. Right. Is that oversimplifying it? Or does that we talk about back to basics, right? I mean, that's very much a back to basics way to approach this. Or is that a really good place for defenders to be thinking about and to be starting from in light of what these numbers say? And if you have comments on the numbers themselves, please feel free. But Cody, I'll start with you on that. Oversimplification. Cody Kretsinger: You know what, just given my observations, not only, you know, at Galactic, but also recently at Black Hat and DEF CON, I can say most organizations don't likely have controls or governance around AI. And that could be policy procedure, that could be identity, it could be, you know, monitoring technology, the network, the endpoint like all of those things. And you know, just based on the conversations I've had at work, but also in the number of conversations that I had in the hallways at Black Hat and DEF CON this year, I most organizations are n are finally coming to the realization that, hey, AI is a technology we probably have to manage as an organization, not just as a bolt on to what the IT folks want to do and how they manage it and things like that. So that I think those numbers are probably pretty accurate. The one thing I do take The one thing that I do take some I the one thing that I've got a problem with, I'll be very clear, is the number of attributed attacks to AI based on this report. So we have a saying in the industry that attribution is hard. And that is very true, right? So you have to be def almost definitive in terms of when you attribute a particular threat actor or a particular method or something like that. To a you know a group of people or an individual or a thing. There's different levels of confidence that you have to score it with. And what we have here is a lot of organizations that say definitely was AI related. And to that I will say I don't believe you for a moment. Now AI assisted potentially. We only have a handful of actual examples of AI being used for some like really specific campaigns, handful. But for an organization to say that definitely AI had a hand in some sort of breach or something along those lines, specifically right after Cloud Mythos or sorry, Cloud Mythos and Fable Five came along and there's now a number of organizations that are going, well actually, you know, it could have been AI that actually hacked us. No, no, it was still the standard bad guys, I promise, because that's what it was. Don't cop it out on AI and like, come on now. But that all being said, what we are probably going to see in the future is more AI assisted breaches happening. That is almost certainly going to be a thing. We're definitely going to see AI helping with finding more vulnerabilities that therefore the bad guys are going to leverage in order to get deeper into an organization to bypass. Security controls and things like that. All of those things are either happening or are soon to happen, which means we need to take them into account. And to the very last point, Max, I really think this report should have had a section that was dedicated to AI. It is a technology, much like you guys have heard me talk about this, much like cloud, that needs its own section in order to do in order to really have a good view on what is going on that. So all right, I'm gonna step back off my soapbox. I don't believe this thing, I don't believe those some of those stats for a single second, but I think there is some good takeaways here, including most organizations are not considering how to govern AI. Max Kurek: And really quickly, Seth, before you jump in, I'll just kind of to speak to what Cody said there. I didn't mention the stat originally, but according to the report, and again, this is the attestation component, sixty-eight percent of organizations that were breached say they lacked governance to manage AI or to detect shadow AI usage. So the governance gap is real, and that and what that resulted in is as you would imagine, a steep increase in shadow AI usage and presence in attacks, which isn't a surprise. And I think we'll continue to see that number grow until folks do get a handle on this governance conversation. So Seth, just another kind of thing to chew on there, but any other takeaways from your end on the AI side of this report? Seth Loe: Yeah, I'll take the governance track on this one and I'll say you should yeah, what do they tell you? What Dr. Phil would tell you the best indicator of your boyfriend's future behavior is his past behavior. Like don't expect him to change, right? One for Dr. Phil on their hashtag Dr. Phil. But the thing that you would should expect to see is the same bad behavior that they've employed in. Max Kurek: Yeah. Plus one for Doctor Phil reference. Seth Loe: Places like Microsoft 365 and in their key business applications. If they were slow to adopt secure passwords in those in that infrastructure, they're going to be slow to adopt secure identity practices in their AI solutions. If they were slow to adopt MFA, if they were slow to adopt token-based authentication, I mean, how long is the world going to go before we start getting on pass keys? I'm tired. Of the excuse of, well, they're only fish resistant, which is just a conscious decision to say there is this way to make it harder for my employees to get fished. But because I can say, well, they're only fish resistant. They're not fish proof. I'm not going to do it. And then we look, and how many years later, fishing's still the main way? People are getting into the organization. It's like, because people won't take that next step. I think you're going to see that same bad behavior in AI implementations and AI security too. That same slow adoption of logging, monitoring, and alerting of AI activity. You know, and Max, to a point that you made as you introduced this segment was that the stakes are even higher because when I break into your AI, it's like I just compromised one of your employees. I just got them on my team, like I just bribed them for free to do my bidding. And probably one of your most talented, one of your most integrated and one of your most capable and in intellectual employees. And I've got them doing my bidding now because they trust me in addition to you. So you know, I think we're gonna see the same bad behavior. Cody Kretsinger: Percent. Couldn't agree more. Max Kurek: And so it the question if you have the if you're a security person or a consultant or someone who's has any level of responsibility for pushing these security initiatives forward inside your organization, if you're sitting there thinking, well, you know, how hard should I be pushing on this stuff? How much noise should I be making on this stuff? Well, the answer is obviously a lot, but look at your organization's track record, just like Seth was talking about. And the slower it's been, if you're still fighting legacy security issues that you've been fighting for years and years, which so many of us are, right? Insecure passwords, use of password managers, all of those back to basics things. If you're still fighting those things, you've got an uphill battle ahead of you on the AI conversation, which means it should have started a couple years ago, but you need to get on that megaphone now. And you need to be screaming at the top of your lungs into it, because this is just another cycle repeating itself in a it's a new wolf in sheep's clothing, right? Like just like all of these things were before, like Cody just mentioned. So inwardly at the history of your organization and act a quick hat. Yeah, completely. Seth Loe: Looking Cody Kretsinger: Want to we targeted that towards like IT professionals, security professionals, consultants, stuff like that. I think the onus is just as big on business owners, compliance folks, CFOs, anybody, anybody that actually everybody that is listening to this podcast has some responsibility in order to make sure that it's done right, either from the very top or bringing it to the very top. I don't think that it's one. Individual's responsibility, not to call you out Max or to change how this is kind of laid out, but I think every single individual and organization has an onus in order to make sure that this is done right, done right the first time, because we we've what is going to happen is if not done right, it's going to get much worse. And you might as well just get her over with. Max Kurek: Yeah, I no, I a hundred percent agree with that. And I guess the only follow-up to make is that guys, we're all defenders in some form or another, right? Like we sit we think the term defenders applies to like the guys implementing the technical security controls in the environment, and it does, but ever the human is the weakest layer in your security stack. We're all humans, and so we all have a responsibility as defenders to impact this stuff. So a hundred percent. Okay. I want to ask an ethical question about the report. And I don't know if I'm giving if I'm putting another soapbox down for you guys to jump on, but I think it's an important thing to bring up when reports like this are published. And I like we said out at the beginning, Ponoman conducts the research here. IBM sponsors, analyzes, and publishes it. And if you look at the recommendations section of the report, it points to things like using agentic AI for vulnerability management. Autonomous security tooling, AI sovereignty, expert guidance through migration into a post-quantum world, right? IBM sells into every one of those categories. And the section, the recommendation section in the report actually links out to IBM offerings. If you take a look. And obviously, Verizon's report from earlier in the year occupies a similar position, right? Verizon sells security services. So my question here is does sponsorship compromise a report like this in any way? Does it shape which questions get asked in the first place? The answer to that is probably yes. But can you separate the findings from the recommendations? And maybe that's the right approach to take with something like this, or just how much does that pollute or call into question some of what you read and some of what you see in a report like this, or are do we feel confident that, you know, because of the third party nature of the actual conducting of the survey, we're kind of good with where things land. I I'm just curious about this ethical question because this is a structure that you see a lot in these types of studies. Seth, why don't you unpack that a little bit? Seth Loe: Well, I think that I don't know there's any way we get around this, right? I think this is the best information that we're gonna have available to us. I still call my favorite music venue, Deer Creek, and I'm sure it's had three different corporate sponsors that have renamed that venue since then. James Taylor still sounds great on stage though. I just have to say. So I don't think there's any way around the corporate wrapper that this comes in. I think that you should probably take a little caution. But at the end of the day, I the recommendations here are real recommendations that all industries are running to catch up with. And I don't think it should be your first reaction to say, you know, well The fire departments doesn't have my best interest at heart because they sell fire blankets. Right. You know, I think that the advice is good, the data is valuable. I appreciated the fact that they go to a third-party organization to pull the analysis. I expect the price that you get, the price that you pay for getting the report for free, is that the organization that paid for the report is going to be able to advertise for theirs. Products and services. I didn't see anything in there that read to me as bad advice. I think that other organizations would have liked to have had their names mentioned in there too, but you know what? They didn't pay for the report. So get out there and be the AWS breach report. Get out there and be the, you know, people love. Crowd strike. Get out there and be the CrowdStrike report that everybody celebrates every year right after Arbor Day. We do cost of a data breach day and everybody wears pink underwear and you just know that it's a thing, right? That's my take. Max Kurek: Cody, what about you? Cody Kretsinger: Agreed. I mean there's a couple of specific call outs here around the I've mentioned the unencrypted components and IBM has really leaned into this post quantum making sure things are secure. That's w this you know, there's some marketing silliness going on a little bit, but at the end of the day, these were real surveys, this is real data. It is it narrow in a couple of places and sometimes a little skewed, I think, but it is a accurate representation of what's going on out there. And there's a reason why I can say that is because it doesn't matter if it's CrowdStrike or Google Mandience or Verizon's yearly report. We're seeing about the same figures across the board. This isn't it isn't a magic pie in the sky stuff. This is The narrative of what is going on to organizations. So, yes, there is some recommendations that even if I was IBM, I would absolutely be doing the same thing because as Seth said, I paid for the damn report. I'm gonna use all of it, right? Like I want it to be accessible, I want people to read it, but at the same time, I paid for it. So I need a little bit of advertising space in it, and if you want a different version of it, then go do it yourself. But the data is still the data and it's still accurate. So I be cognizant that it is sponsored, but it is good data. It is actionable data. I think most organizations can use. Max Kurek: And there are a ton of stories worth telling to the decision makers inside of your organization, to your clients, a lot of them that we've covered today, but go unpack this a little bit further. There are stories that can fill your meetings for the rest of the year. And especially if you're a defender who has been pushing your organization or pushing your client to make security decisions, reports like this. And we go back to the Verizon report from earlier this year that we hit on a couple episodes ago, can be your best friend. And it doesn't really matter, like Seth said, the rapper, the corporate rapper that's placed around it. There this has utility for you as you're having those conversations. And so I think the best way for us to wrap up today is what is that one thing when you look at this report, guys? What's that one thing? That folks should do differently, whether you're a business decision maker, whether you're a security person, anybody who is kind of listening and thinking, okay, all this good info, what's the one thing that I should do differently based on what this report found? Cody, is there something in here that stands out to you in terms of like, hey, Tomorrow I am going to go do this or I am going to initiate the process of this because of what this study found. Cody Kretsinger: All this study has really done is just validate a term that we've used several times throughout this episode, and that's get back to basics. And that doesn't mean that we can't do that with new technology like AI or anything along those lines, but there are some basic level things every organization can do. And what I think has been highlighted here for the twenty first year, mind you. Is we still need to go back to basics. We still gotta make sure to check all those boxes because the bad guys are still doing the standard bad guy stuff. Let's make it hard for once. That's it. Max Kurek: Seth. Seth Loe: Yeah, I think Cody nailed it in the basics. That was what I was gonna emphasize as well. I did fall I would fall back on it is time to move up the sophistication ladder on your authentication mechanisms. You know, the name of your puppy with one, two, three exclamation point at the end of it ain't crap ain't cutting it no more, folks. It hasn't been cutting it for probably about twenty two years. But we've got 21 years worth of data from independent organizations along that have come alongside businesses. I until we get the Nabisco Beach breach report. I don't think you're gonna get your favorite cracker involved in this, but it's enough, it's enough information. And I think that a lot of the stuff that we didn't get to cover today, like non-human identities, are gonna sweeten the pot. And if you are if you're behind, it's time to learn. About this. And I and you know, we talked about AI today. One of the easiest things that you can do is you can chat with your favorite language model, tell it where you are, what you understand about cybersecurity, what you understand about hacking and breaches, what you understand about your company, tell it to educate you. Have it just build a course for you that takes you to the next level and to the next level and to the next level. You can do it in tiny little chunks. One of the things this report revealed is that it is time for us to send the machines in to fight the machines. You know, I don't know if does that make this Terminator two judgment day where we're sending the machines to fight the machines? Okay, so that's the phase of this dystopian reality that we find ourselves in. So use the machines, use AI. This is so much a part of this breach report. Use AI to educate yourself. I don't care whether you're a business owner, whether you're an executive, whether you're a chief financial officer, whether you're a senior network engineer. In charge of security, whether you are a basic IT person, educate yourself. Education's never been freer. It's never been more widely available. So yep, that's it, Max. Max Kurek: And spoiler alert, the most significant finding in the Nabisco threat report is that Oreos are the single biggest threat to my wet weight loss journey of anything that there is. Like 92% of my hiccups in my weight loss journey can be attributed to Oreos. So thanks a lot, Nabisco. I would just mention on the back to basics thing, the newest basic, I think, and this speaks to the AI side, is Seth Loe: Me Max Kurek: Just go get an acceptable use of AI policy written. Like start your AI governance journey. Just get going on it. And that is very much a basic control. That is getting back to basics. It's just the newest basic thing because AI governance is kind of the new guy at the party when it comes to this conversation. So just go get an initial acceptable use of AI. Policy on paper for your organization so that you can start that taking those steps toward not being the statistic in this report that says we have no AI governance in place whatsoever. Cody Kretsinger: Super easy policy. Max Kurek: Yeah, yeah, very easy policy. And if yeah, there's lots of places you can go to grab Soupstarter for this, but just think about your approved use cases, think about your approved tools, and bring AI use out of the shadows, and your organization will benefit because of it. For Seth Loe, Cody Kretsinger, I'm Max Kurek reminding you to stay threat aware. We will see you next time.