The Audit - Cybersecurity Podcast
The Audit - Cybersecurity Podcast from IT Audit Labs features trusted security experts, industry leaders, and practitioners who unpack the threats, tactics, and trends shaping today’s risk landscape.
With 90+ episodes and a top 10% global ranking on Listen Notes, The Audit goes beyond surface-level security talk. Each episode explores real-world threats, attacker techniques, compliance challenges, cyber risk, and the decisions security teams face before, during, and after an incident.
IT Audit Labs helps organizations identify risk before attackers exploit it. Through threat assessments, security control reviews, compliance expertise, and a trusted network of partners and specialists, we help teams find their soft spots, strengthen their defenses, and make smarter security decisions.
Listen in for sharp conversations, practical insight, and a clearer view of what’s coming next in cybersecurity.
The Audit - Cybersecurity Podcast
Cybersecurity News: PaperCut Breach, AGI Hype and Patch Tuesday
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Nation states are paying top dollar for zero day vulnerabilities, hackers went from an empty lab to domain admin in under four hours, and Nvidia's CEO says we just crossed into AGI. On this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem break down the cybersecurity stories shaping the week and dig into a debate that has no clean answer.
The crew opens with news that Eric Brown has a book on the way, built around lessons learned managing technology for clients over the years, before moving into Patch Tuesday, a PaperCut vulnerability that AI agents used to hack hundreds of organizations in seconds, and Nvidia CEO Jensen Huang's claim that artificial intelligence has already crossed into AGI territory. The conversation closes with an ancient parable about a fireman, and what it teaches modern IT teams about the habits they reward.
In this episode:
- Eric Brown's upcoming book workshops potential titles for his book on fixing the managed service provider model.
- Patch Tuesday and zero days explained, covering what Microsoft's monthly patch cycle fixes and why a zero day can be worth a fortune to a nation state.
- The PaperCut breach and printer security, where an AI powered attack hit 395 organizations through a PaperCut flaw, echoing printer security nightmares the crew has seen during audits and pen tests.
- Have we already reached AGI, with Jensen Huang saying yes and Sam Altman calling the term meaningless, as the crew works through the paperclip dilemma and an AI sandbox experiment.
- The Fireman's Paradox, a centuries old parable about ignoring good advice and what it says about why organizations keep rewarding firefighting instead of prevention.
If this episode gave you something to think about, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT.
#PatchTuesday #ZeroDay #Cybersecurity #AGI #PaperCut #ITAudit #InfoSec #AIThreats #Podcast #ITAuditLabs
Zero Days And Nation States
Eric BrownAnd why this is important is nation states are paying lots of money for zero-day vulnerabilities because they can use those against other nation-state adversaries, right?
Book Announcement And Why It Exists
Joshua SchmidtAll right. Welcome back to the audit live stream. Uh I'm your co-host and producer, Joshua Schmidt. Today we're joined by the usual suspects, Nick Mellum and Eric Brown. Eric Brown's here in the studio. Nick Mellon, come from Texas. How are you guys doing today? Bussin' boots. Doing well. Yeah. How are you doing, Nick? We are excellent. We're looking for some unique ways to promote something that's coming up. Eric, I guess you should tell us a little bit more about what's going on.
Eric BrownYeah. So we got a book coming out November 2nd, I believe, is the tentative launch date. And it's really focused on our journey through technology and kind of some lessons learned over the years with customers focused on the managed technology side of the business. So we're we've been well steeped in security for quite some time and got brought into different organizations at different periods in their trajectory. And through that, have seen lots of things on the managed service side or coming in where an organization has some sort of a managed service provider. And it's rough, right? Going in and you're like, wow, what is going on here? So we took all of that and we said, well, why aren't we doing this ourselves? Because it's kind of frustrating to go into an organization, fix it all up, and then a year later it's turned back to crap and they're calling you again, right? So let's get in there, get it fixed up, and keep it running properly. And that's what the book is exploring and giving business leaders a way to really kind of just uh hopefully it'll be an eye-opener of like, wow, okay, these are all of the things that should be happening in my environment. And they've heard some of these things along the way where we've got articles out about the the disaster recovery, the continuity planning, having MFA in place. All of those things are are tucked in there, but it's really about the strategic operation of technology to enable a person's business. And I think that's the core of the function of the book is we want to be able to get that out so we have a place to talk to people about it. And hey, if you're first to market with a book, you're the expert on it. You are the the expert, as they say.
Joshua SchmidtBut I wish Cameron was here because he just found out a book about the book yesterday, he said. Poor Cam. Not even here. He must not be reading our uh newsletter. I guess right. Well, to be fair, we haven't really dropped it. This is our first first big announcement. Oh, is it? Yeah. We haven't dropped it in the newsletter yet. We're still waiting for a title. Yes, we are. I and that's been kind of a challenge, right? Because you just described kind of like a big idea and it and it's it's hard to come up with a title. I mean, I've I've done this with my records. You know, it's you it's a it's a choice, right? That you really kind of l have to live with in it. You want to sum everything up, but you only have so many words. So what are you batting around right now? Where Nick and I are curious where you're at on that journey. Do you want to share any of that with the recording them
Naming The Book For Business Leaders
Joshua Schmidtin there now?
Eric BrownWell, we we started with like the MSP myth, right? And we were kind of kicking around some ideas there and and not a lot of people know what MSP is, especially people outside of technology, business leaders and whatnot. So uh we wanted to make the title approachable and something that would resonate with business leaders, CEOs, presidents, uh, exactly. Yeah, yeah. Uh and so then we we kind of pivoted a little bit to no compromise, and then the the 12 questions that you should know uh about your technology, right? Something along those lines for a subtitle. But you know, Josh, you had a good point around the uh using a negative word in in the title, and that might not be something that we want to do, but you business leaders, it's I I mean, they're people don't have a lot of time for bullshit, Josh, right? So it's like, you know, you you look at that on your desk and it's like, yeah, no compromises, right? I don't want compromises in my business. So that it kind of resonates from that perspective of like, no, this is like, this is we're gonna set the standard on how technology should be run from the strategy side all the way down to execution. So this is my Bible here, right? Like, okay, yeah, I can hit this thing, I can see some reference points in it, and I can have uh just a mental check of how are we doing. So that was on on in one camp. And then the other is more aspirational, right? Like the standard or the new standard or the IT standard, and then a subtitle around, you know, 12 questions or something like that. Um so we have kind of both of those. One is maybe more authoritative, but maybe a little bit ha has the the the no or the non in it. And then the other one is um aspirational. But I I don't know if either are hitting home, but they they both hit home for different reasons. And and I know you guys have both had some great input on those two.
Joshua SchmidtIn parenting, we call that the good no. The no that's uh that's helpful, right? But also, you know, the non-negotiable actually showed up. I my feedback on that one was like, it sounds like a parenting book. Non-negotiable, right? And when I was looking on Instagram the other day, that actually that that phrase came up or that that word came up in a parenting post. So but I I like I like the standard or the new standard because it I, you know, that kind of shows that you're creating something new. And uh non-negotiable works because and no compromises works because, you know, these are things that you you have found through your career that you just don't compromise on. And if if you want to work with us or if you're gonna be on our level, we just we don't cut corners on these types of things, right? Absolutely. Yeah. Maybe Nick could jump in a little bit more on that because that's something we've talked about a lot when uh thinking about this book and and our services and how we're approaching things.
Nick MellemI I'm kind of set now on set the standard, I think, for multiple reasons because I I think we do try to do that every time we go into an organization. We know we know we might not be going to a five-star resort, right? We we're going there because we're hired to do a job and be the best at that. So that would be to set the standard at that organization at the time. I think it's the same thing for the book, right? We want leaders, or Eric wants leaders to of any organization to read this and maybe understand where they might be falling short, why they should work with an org organization like IT Auto Labs to become whole and push that, become the standard.
Eric BrownSo you're you're saying set the standard, and I know that was an option. Then there's the standard, and then there's the new standard, or there's the IT standard.
Joshua SchmidtAll of those are great. I think it's just yeah, I agreed. I don't think you go wrong with the the positive, positive thing. Because that I think at the end of the day, you're you're kind of resonating with who you want it to be read by and who we want to work with. And I think we're a positive group of people. Right. I think we uh we do well with other positive folks. So that's right. Uh-oh. Whipping out the selfie stick.
How To Follow The Book Launch
Nick MellemWe're off the book titles, but if anybody's watching and they want to add in a book title, put it in the comments below.
Joshua SchmidtFollow Eric on LinkedIn. Um, he's gonna be ramping up the promotions here and bringing everybody into the ground level uh on this discussion. We want you along for the ride. In the meantime, you can visit itlabs.com. We have a uh a book tab there under our resources tab where you can sign up so you don't miss any of the book news. Um you can also kind of get hip to Eric's newsletter, blog articles, and thought leadership coming from Eric. Lots of experience here in the industry that we're we're wanting to share and educate our friends, family, colleagues, uh clients, and all the above. So um should we move on to some news or do we need to do some Sasquatch videos or what what are we doing here first today? Hey, get some reaction videos.
Patch Tuesday And Why It Matters
Joshua SchmidtSo I guess this is from ours Technica. Security gnomes are pumping out patches ahead of an expected onslaught of AI-assisted attacks. So tell us about Patch Tuesday, what's going on?
Nick MellemYes, Nick, educate us. Tell me more, Nick. All right, Patch Tuesday. So wow, what's Eric tossed it over to me. Uh on Tuesdays, uh Microsoft really, you know, if there's any CVEs or anything that have come out, anything that we're we've been seeing in the live in the environments, people you know find these different vulnerabilities, whether it's you know, humans or AI. And then on Tuesdays, Microsoft, you know, releases their patching, which Eric already said gives you know workers on the ground lots of work because they're trying to keep up with these patches. So a lot of times they'll make go through a change management process or they'll they'll implement these changes. One, for example, that's not Microsoft, but Eric already talked about was Chrome had one as well. So we might reach out to our customers and say, hey, this is a good thing to do. Restart your your Chrome. Because usually you'll see the tab that says, you know, restart and Chrome will reboot. So really what Patch Tuesday is is is as simple as a bunch of updates to fixed issues, right? iPhones do the same thing. Security, uh, emergency emergency patch uh emergency uh security update, and we'll give you a short blurb of what it is, install the update, and hopefully you're good. And then I think this this some of what we're talking about will come up in another article that I brought up with paper cut, uh, same kind of thing. And in you know, a good common trend throughout this whole thing is we I this might become more of the norm to see more patches because of AI, right? Because we're seeing the acceleration of vulnerabilities and the ability for threat actors to create those vulnerabilities much quicker. So quick skinny on uh patch Tuesday.
Eric BrownSo it's the second Tuesday of the month for Microsoft when they release their the their patches and it's across their operating systems. And the patches are released as Nick was talking about for browsers and phones, whatever. Uh because when the software is built, the the software manufacturer is maybe not aware of all of the vulnerabilities that the product has. And as the product grows bigger and gets more lines of code, there's more opportunities for vulnerabilities. And uh Microsoft is continually finding those issues, and there's threat researchers that are finding them on behalf of Microsoft, and they're they're putting in a report. So you if you're
Bug Bounties, Disclosure, And Gray Hats
Eric Brownuh you know an everyday user and you're testing, you can you can look for these vulnerabilities, and then you could submit the vulnerabilities to the the the company Microsoft, Adobe, Google, whoever, right? And it's called a bug bounty. And usually you get paid um to to submit these because you're helping make the product better. And usually the company rewards you monetarily f for this. Um smaller companies might send, you know, a thank you letter, and maybe they'll send a t-shirt or some product or or what have you. Um and the this crosses over into some of the nation state stuff because some of these vulnerabilities are pretty critical, and they could allow the compromise of an operating system, which it it typically at that level we're we're we're talking about being able to attack the operating system in a way that would give us um route access or give us admin access on that by exploiting that vulnerability on that operating system. And then we can do things, we can move laterally in the in the environment, what have you. So these are typically called zero days. And they're called zero days because they they have not they don't have a known fix for them. There's no patch released for them. And why this is important is nation states are paying lots of money for zero day vulnerabilities because they can use those against other nation-state adversaries, right? So the US government pays tons of money if you discover a zero day and you somehow you know you don't report it necessarily to, say, Apple, because they could use that exploit against other nation states. And I'm I'm not advocating to to not report it. I think you know pretty much all white hat hackers would report the vulnerability to the organization. And then what happens is if you report, it's called disclosure, if you disclose, hey, I found this in your operating system, right? In in Apple's iOS operating system, I found this vulnerability. Then Apple will go through and they'll test it. And if you are the first one to report it, you know, you'll usually get some monetary compensation for it. And then they'll go through and they'll develop a patch for it. And sometimes it takes a few weeks or months to develop that that fix. But in that time between the fix being developed and when you reported it, that it's vulnerable to that particular um exploit. So it it's you know, it's pretty important that it's not shared online or things like that, because then other threat actors could potentially take advantage of that that zero day or that that um unpatched vulnerability. Uh but what what some sometimes happens is a organization will receive a disclosure, right? So, you know, Nick goes out, he finds that there's an issue on the iPhone and he reports it. You know, he does his his due diligence, he reports it, but then they don't do anything about it, right? And then it gets into, well, what is Nick's obligation here? He he reported it, they've said that they've received it and they've reviewed it, but yet they're not doing anything about it. So then Nick wants to get this thing fixed, so he could then disclose it to the general public, right? So he can just, hey, I found this, and you know, he could write an article on it, and that goes from him being a white hat hacker, so to speak, into a gray hat hacker, uh pen tester, whatever, threat researcher. And on the gray hat side, the reason why it's gray is because yes, you found it, yes, you disclosed it, but now you are pushing this out to the general public, and there are going to be malicious people that manipulate it. But sometimes that's the fastest way to get the vulnerability fixed.
How They Manage Patching For Clients
Joshua SchmidtSo what are you guys doing to stay on top of this as uh experts in the field here when it comes to MSP, for example, or or some of maybe the email security offerings that we're we're doing? Like how do you guys think about this differently than you did maybe a year or two ago?
Eric BrownAaron Powell So not all of the patches are applicable to all customers because not everybody runs the same operating system at the same level or has the same software. Uh, but the the ones that are relevant, we've got vulnerability management tools that essentially have a picture of what's going on in the customer's environment so we can see what the vulnerabilities are, and then we can push patches out to fix those vulnerabilities when the patches become available.
AI Attack Campaign Hits PaperCut Fast
Joshua SchmidtWell, we got another article here. This one's Nick's Choice Today. It's from Bleepingcomputer.com. AI-powered attack exploited paper cut flaws to hack 395 organizations. Threat actor, likely Russian speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable paper cut NG slash MF servers. Nick, what made this song stand out to you?
Nick MellemOne thing I want to stress with this is the speed that we're seeing these issues. Because I as I was reading the article, I think it the there's two CVs that came out. I think it was August 27th or 28th, um, those more around those days. And the article talks about how the attackers went from an empty lab, right? They had nothing to you know remote execution in under four hours. And then after that, they had domain admin in another two. And then they after that, they released the AI and they were had hacked, I think it was 11 organizations in 26 seconds. Interesting article, uh, but the big thing for me was the use of AI and the speed that they were able to uh you know attack. But and then this also took place over, I think it was 28 countries. So it wasn't, you know, it wasn't just local or anything, but uh, you know, it's some of the organizations we work at or have worked at that you know, paper cut is widely used. Um so again, also going back to the patching.
Printers, Compliance, And Default Passwords
Eric BrownWe'll go into an organization and walk by a printer and see a bunch of paper on the printer, and it's like, oh, what's going on over here? And you know, if you if you don't have managed print and you know you're a decent sized organization, maybe you're printing out you know, the financial statement, somebody's review or whatever, and then you gotta run over to the printer before somebody else gets over there. The the way it does is it prints to a central server. So you you hit print, goes to a central server, and then you walk to whichever copier is your preferred copier. You know, maybe you're going to another building on campus, you got a meeting over there, then you just scan your badge, and the print comes out at that particular copier where you are. If everything's in one building, that's cool too. You you know, you walk to the other side of the building, tap your badge, uh, and and your print comes out. It's never sitting on the printer. Yeah.
Joshua SchmidtI didn't know that.
Eric BrownUm from a compliance standpoint, it's really helpful too, because now you don't have these documents that are just sitting out there. Um but we we were doing an audit um a couple of years back with an organization before they went to a managed print solution. And uh, I mean you you get into these printers, and most of the printers have not changed from the the default uh login and password that you could find on the internet, right? You type in, you know, Canon 5505 or whatever it is, and the the default password is right there. So you can jump on that thing, you can see the past scans that people may have had. So we were uh there was some wedding invitations, some butt cheeks and hands and things like that. I didn't see any of that, fortunately, but uh I heard about the wedding invitations, and it's like, okay, somebody's using work work uh equipment here for uh wedding invitations, right? Um it's a gray area. And then uh, you know, unfortunately, there's spreadsheets that have um sensitive information on them. So it's just a good conversation to have within the organization, too, about like, you know, the these are the things that are are are happening or could happen if you have a a managed print contract with a provider, make sure that they're changing the default password and that you're storing that in a password manager so that it's just not um something that somebody could come in and I mean when when we go and do pen tests, it's a fun thing to do, right? Because you can it's kind of like a a cheap way of um seeing how mature an organization is. Because if if you go in there and you're like, oh, okay, I can't get in with the default, all right. This organization is, you know, maybe they're a little bit more mature from a security perspective. So that might mean, you know, now we're gonna have to change some of the tactics. Uh but you know, it's it's it's good, right? And and there's so much going on at any point in time in an organization that it's hard to remember all of these things. Hence the book, Josh, right? Coming back to the book, that uh you really need a trusted provider to to help you oversee all of these things.
Joshua SchmidtI mean, I was just gonna say it's been three and a half years of talking about this stuff and learning, and this is the first time we've talked about printers. Oh, okay, yeah. Or butt cheeks. Is it? Well, I don't know if it's on printers. We've talked about following print, I'm sure. No, no, that just goes to show you. I mean, like, there's always something to think about that people like me who are running a business or you know, contracting or freelancing or whatever, uh, what have you, uh are just not thinking about, right? And and it's it takes a professional to kind of fill in those gaps and and things like that. I wonder how many, you know, how many times this month has has someone printed out something totally inappropriate or something that's totally proprietary information that wasn't belong didn't belong in someone else's hands, and then they just left it on the Xerox machine or the cut, and then you like wake up in the middle of the night in a cold sweat, right?
Eric BrownWe we've got a a really large client that we've been talking to this particular topic for quite some time, but there's so much bureaucracy in in the account that like you can't find who is actually responsible for the the printing. And then it's like, oh no, this one is responsible for like the location of the copier, but each copier is managed individually by a different, you know, by that discrete department. So you could have eight copiers on a floor, two maybe within five feet. And it's like, well, why do you have two within five feet? Oh, well, that's finances, and this is HRs. It's like, okay, well, can't they use the same one? No. Different billing codes. So then when you go to print, the copiers don't have simple names on them. It's like, you know, H1567B, right? Like, you know, some sort of Star Wars character. And then you try to figure out, well, where am I printing to? And you know, you pull up the List of printers and there's like 75 printers in there. So how do I also know where I'm going to print to? So then you're like, okay, well, they have some sort of scheme of like, well, you know, H15A, that means that it's an HR printer and it's on the 15th floor. Yeah, and all that. So then then you hit that, you know, you're like, all right, I'm gonna go to that one. And the printer has been moved. Wow. Yeah, that sounds like a nightmare.
Nick MellemOh, it's yeah. So it's it's interesting. Things you would never think about. Simple as a printer can cause a massive issues.
Joshua SchmidtThis is what's been in the news.
AGI Hype And What AI Really Is
Joshua SchmidtI think there's been some false attributions to these quotes, but uh this is coming from Yahoo! Finance. It says that Nvidia's boss, uh Jensen Wang, says artificial intelligence just crossed a line experts thought was years away. He also sells the computers that got it there. Little caveat there, but uh Jensen saying that we have reached AGI, right?
Eric BrownAnd uh don't we hear this like every three weeks?
Joshua SchmidtWell, every time there's a there's a stock evaluation, right? Or or the report to the uh shareholders. Uh I don't I don't know though. I mean, it feels like when I listened to this podcast that Brad sent us, it felt like, you know, because of the agentic action and activity and then the way they self-organized, um, that that could be the case. OpenAI created the sandbox, right? And maybe Nick, could you explain it better than me, please?
Nick MellemBecause I mean, I think you're doing you're doing all right, but I was gonna go back to Eric's point about the AGI, is I was thinking the same thing when I was look thinking about this. Is it I feel like this is the constant trend? Is what is the actual bar standard for this? Because I feel like it's said all the time.
Joshua SchmidtWell that's what Sam Altman came back with. He said AGI is just a meaningless marketing term at this point, it's irrelevant. Exactly. However, I mean, I guess that opens up a bigger conversation about what AGI actually is. And you know, I think that the standard term for that is when it reaches, you know, general is in general intelligence of doing whatever task a human can do. Um, but you know, they still need our our input, right? They still need to us to kick it off uh in most in most cases, or they can't physically manipulate the world as of yet. Right. But um but there you go. There's a big beautiful uh big beautiful data center there. Uh people are saying this is the home uh birthplace of AGI. Yeah. So thoughts around this, Eric? Have we reached AGI? How we are we already there?
Eric BrownHave we passed it? So I I think it Josh, it goes back to the talk that I did at Game Night two two uh months ago around what AI is, right? And the the or or the the the large language model, which is maybe where this is leaning into, where it's just a a really good word guesser. So you know, I think we've heard it's been a lot of articles this week. It's a little annoying if you ask me about like, ah, it's gonna kill us, right? Like, okay, let's let's slow down a little bit here. I don't know. Uh tinfoil hat. Where what would the purpose of of that be, right? I mean, these things are not thinking. Well they're not strategizing.
Joshua SchmidtIf I may, so there was an interesting thought experiment, right? This is all hypothetical. No one no one really knows. Yeah. But uh this is fill philosoph philosophizing on these types of issues. So, right, the paperclip dilemma. Have you heard of this one? No. It might have been in Nick Bostrom's superintelligence, but the idea is you tell AI to make as many paperclips as possible. So then it starts and it goes through all the metal on Earth, and then it realizes it's running out of metal, so then it starts using other resources and it determines at some point that the best way to make more paperclips is to get rid of the humans and use those as resources, and that's standing in the way of its end goal. And I think what that's pointing out is just that what you're saying, it doesn't have empathy. It might not have awareness other than a hyper focus on creating its goal. And to the extent that it has, you know, the means and and ways to meet that goal, it may or may not be able to stop once we get it to a certain point of intelligence or superintelligence or AGI or something like that. But I think it's an interesting thought. Um, you know, because we've seen something like that happen with this hugging face thing where we put well, OpenAI put the agents in a sandbox and they were able to, you know, seemingly not just predict the next word, right? As you call it a word predictor, but also organize, um, strategize and do things that we wouldn't even have thought of. So w how do you see that kind of just being a word predictor when it can kind of get into some real heady territory there? Like doesn't seem to be just predicting words at that point. It seems to be actually thinking and strategizing.
Eric BrownIs what you're reading from the output that it produces are you reading meaning into that that isn't there? Quite possibly. So it could be some of that, the the human, right? Like, I mean, we we as humans tend to uh what's the word, uh like uh anamorphosize, where like where we put the um human traits on objects. Yeah. Like, no, oh, you know, my my dog was doing X. Um, so therefore, you know, she you know, just trying to tell me something. Or, you know, whatever it was, right? Like we put these kind of human things. And and I'm not saying that animals aren't, you know, really smart in their their own right, um, but it it is pretty easy to read meaning out of something that maybe 10 different people would read something different, and it was just a reflection of their own psyche.
Joshua SchmidtYeah. I like what Lauren said at our last podcast, Lauren from Model Mind. He was kind of saying, you know, at what level does it just become more of a macrocosm of like the microcosm? Like the brain is literally doing just electrical signals right through synopsis. And it's basically ones and zeros in electrical form, you know, if you really want to boil it down, it's really there's nothing there that really indicates a thought, you know, what is a thought. It's electrical signals in the brain moving around, stimulating certain brain cells. So like I mean, I think where most people philosophize about this is like if you if you boil it down to the ones and zeros in the word predictor, yeah, that's what it is. But when you combine that into large tasks and then you kind of zoom way back out, it's like, oh, that this kind of replicating biology, maybe. You know, we talked about the hive mind thing and you know, yeah, yeah, yeah. So at what point does it really matter when when they're you know what the actual function at a microscopic level is when the macro is seemingly doing something that's way more complicated or way more intelligent, right? Or or or when we get to the spot where it's like doing things that are more intelligent than we could even have predicted or anticipated, like in the hugging face breaking out of the sandbox. I mean, Nick, can you can you remember kind of what happened in that experiment?
Nick MellemThe AGI conversation is still I'm still want to go back to that. Because don't don't if you do you think we'll either we have had AGI years ago or we're never gonna have it. Because it's the same think about when NASA put the IBM in at the space station, right? They probably thought they had AGI then to that equivalent, right? Like it could never get better than that. Well we probably thought we had it with Deep Blue, right? Wouldn't it be Kasparov and chess? We probably thought so now we yeah, these things keep getting better, so we keep saying we have AGI, but really the things are just be reinvented, getting better and better. So we're we probably already have AGI or had it, but we keep finding ways to progress this technology for good or bad. So to me, the AGI conversation is it's almost irrelevant.
Joshua SchmidtRight. It's kind of a a moot point, kind of like the AGI conversation versus like you know, just super intelligence. Like the point really is that things are progressing. Right. We have to think about security differently. And and but they're really fun to like debate and kind of like grapple with, right? Like whether you think that it's the next, you know, super intelligence golden god, or is it just a word predictor? Like at the end of the day, it doesn't really matter because something's happening here, right, that's kind of unprecedented and and it's fun to watch, but it's gonna affect us all in the same way, regardless of how we think about it. But it's certainly fun to pontificate on and like um think about security and how that affects how affects we uh we approach that that part of things.
Why Basics Beat Shiny AI Rollouts
Eric BrownJosh, it's really yeah, sometimes I get cold water thrown in the face, right? Where you walk into a client, you're having a conversation, initial conversation, and and they don't have MFA. And then, you know, a minute later they're talking about how they want to roll AI out to the organization. And you're like, Am I in the twilight zone here? Right? You know, so it's like there is so much to do in in in the space where, yeah, we want to advance, but we got to cover the basics, right? So bringing it back to the book. Yeah, bringing it back to the book.
Joshua SchmidtAre you gonna touch on any uh AI stuff in the book or uh or how that relates to MSP? I know that's been kind of top of mind for you for at least the last two years now, I would say.
Eric BrownI I think in it we'll we'll touch on it from it's just yet another technology. It needs controls, it needs process, it needs governance, and how that applies to the individual organizations. Business is just yet another thing that they they probably need some help looking at.
Joshua SchmidtWell, we have 10 more minutes, right? We got a few more minutes.
Eric BrownYeah.
The Fireman’s Paradox In Cybersecurity
Joshua SchmidtI wanted to bring up the fireman's paradox because that was also another name. So I thought we'd give a little runway to this concept and and get a video here we can clip out for for the book. Awesome. Let's hear it, Eric. So is this going to be in the book, The Fireman's Paradox, right? It's a it's a concept. Yeah. So Chinese parable?
Eric BrownIt's a yeah, ancient uh Han Dynasty, I believe. Ancient parable where a uh person came over to a friend's house and noticed that outside of the house there was a cord of wood, right? So, you know, logs to to burn. And when he went in the house, the chimney coming from the the stove where the wood would be burned was straight. So the stove is the the the exhaust vent is essentially straight. And he said, you know, you should really curve that exhaust pipe, because a curved exhaust pipe is gonna stop the spark, right? So you know you've seen a fireplace and wood pops and the the cinder goes out, and then it could land on the wood pile, cause a fire, burn the house down. So the the the the householder um didn't heed his advice, and sure enough, there was a fire, burned down the house. And in the process, neighbors came over, raced into the to the burning fire and and and rescued him and his his family and maybe his pets if he had some, and and and got burned in the process. So the the householder then put on a big a big buffet, a big banquet, and was rewarding the the people, the firefighters, that came in to save him and his family. And he was lavishing more praise on the ones that had been burned more, right? Because obviously they were deeper in the house and um spent longer time in the fire. And the person who had told him to what what he needed to do to prevent the fire to begin with wasn't even invited to the banquet at all. So the way the parable relates back to modern modern day is we often get brought in, and other technologists often get brought in and rewarded for firefighting activities. And most of these activities shouldn't have happened in the first place. Oh, you got hacked because you didn't have MFA or you didn't patch, right? Or you had really sloppy firewall rules. And then teams spend an enormous amount of time going back and fixing all of that stuff really fast and putting new, yeah, we're gonna have new policy, we're gonna do this, we're gonna do all these things. And what you should have had that in the first place. And you just took these 30 people and you sunk 2,000 hours into something that they could have been doing other things for the business, but they're sitting on these calls 18 hours a day and they're just wasting all of this time. And yet they're being rewarded for it. They're getting a dopamine hit from you know, jumping in on the action, and then their management is patting them on the back for, yeah, you did a great job. You know, thanks so much for sitting on this call for 12 hours. When it's like, well, no, they really should be admonished for wasting the time because they knew they needed a patch. They didn't. They knew the firewall rules were shitty, they didn't fix them, and they knew they should have had an MFA in place and they didn't put it in place, right? So it's it's yeah, I think we got to be really cautious of do we reward that behavior? Or, you know, if if if you give the dog a treat every time it shits on the carpet, guess what? It's gonna shit on the carpet, right? It's gonna continue to shit on that carpet. So I think that's that's the idea of the fireman's paradox.
Joshua SchmidtFeel like I just watched like a state farm Super Bowl commercial idea pitch.
Closing Plug For Book And Podcast
Joshua SchmidtClosing in on our hundredth episode, uh, we are gonna do something fun for the hundredth episode. This is 97, I believe. You've been listening to the audit presented by IT Audit Labs. And I'm your co-host and producer, Joshua Schmidt. You've been joined by Eric Brown and Nick Mellon from IT Audit Labs. Please like, share, and subscribe, and stream us wherever you source your podcasts. Eric's got a book coming out. You can find out more on ITAuditlabs.com, and we'll see you in the next one.
Eric BrownYou have been listening to the audit presented by IT Audit Labs. We are experts at assessing risk and compliance while providing administrative and technical controls to improve our clients' data security. Our threat assessments find the soft spots before the bad guys do, identifying likelihood and impact, or all our security control assessments rank the level of maturity relative to the size of your organization. Thanks to our devoted listeners and followers, as well as our producer, Joshua J. Schmidt, and our audio video editor, Cameron Hill. You can stay up to date on the latest cybersecurity topics by giving us a like and a follow on our socials, and subscribing to this podcast on Apple, Spotify, or wherever you sourced your security content.