In this High-Intensity Tech Training, Sumera Riaz and Chad Muckenfuss discuss the critical intersection of cybersecurity, cloud infrastructure, and business growth. The presenters argue that a lack of trust in an organization’s IT stack directly inhibits scaling and production. They highlight how the rapid evolution of AI has changed the threat landscape, noting that attackers are now using AI to scale attacks, necessitating AI-driven defenses. The discussion covers the inefficiency of excessive security tools—noting that a typical small business may run 83 different tool sets from 29 vendors—and emphasizes the need for platform and vendor consolidation. The session provides advisors with discovery questions to help clients identify security gaps in cloud data, device visibility, and endpoint protection, ultimately positioning security as a way to enable faster, more confident business growth.
Video Transcript
Transcript is auto-generated.
Excited to welcome Sumera Riaz, our VP of cybersecurity at Telarus, and, of course, Chad, VP of cloud. Guys, thanks so much for being on the call. I’m gonna go ahead and pass it over to you.
Thank you so much, Cass. It’s a two for today. So you’ve got Chad and I both, which is very exciting for us, obviously. So today, we’re gonna talk about trust issues. Chad, how do you feel about that?
Well, I think it’s it’s a poignant time to talk about it because of what happened end of last week with with Anthropic and and all the changes happening with security and whether or not we should move forward with AI or not and whether we trust it. So I think it’s a poignant time to talk about it.
Great. Agreed. So let’s start off with a poll. And so if you let’s say, Chad, you know, if you’re a CTO of a company today and your architecture was built before AI, let’s say, two years ago because it hasn’t been out very long. So your architecture is built before AI. Given the current lit given the current threat landscape, do you add or change your security solutions, or do you keep them the same?
So for those of you on in on the webinar, throw up one if you wanna add or change it, or throw up two if you wanna keep it the same.
Chad, what do you would you, as a CTO, add or change it, or would you just ride out the storm?
Have to have to have to change it. Yeah. There is no way around it. The it’s it’s an absolute necessity to try and keep things the same because it’s the technology is changing so quickly on both sides, both for the good guys and the bad guys or the white hats and the black hats, however you wanna look at that.
So true. It is. It’s it’s it’s the way we did security 12 ago is not the same we do it anymore.
There it’s just, like you said, twelve months even six months ago.
You know? It it it changes, you know, so quickly that you have to be on, you know, we we always refer to it as the cutting edge and bleeding edge of technology. I think for security, you have to lean towards the bleeding edge of technology to really try and stay on top of what’s changing.
Exactly. And almost every call we are in, almost every client we talk to on the security side, if it’s true for you too, they’re always catching up to whatever the business is doing. Yes. And yeah. Right? And that holds them back from growth, I feel, because, again, it goes back to having trust in the tool sets that you have deployed to help you withstand on that day of battle. Because today, they’re not.
Agreed. Agreed. They, you know, it’s it’s always a a catch up, unfortunately.
And I think what we’re seeing now is is AI is is being used to fight AI. The good is is being used to fight the bad or at least, reduce impact of the bad.
That’s so true. So true. So today, as you can see on your screen, we’re gonna talk about trust issues. When confidence and security breaks, obviously, it slows down growth.
And I would even venture out to say the confidence in your IT stack changes and breaks. So if you don’t have the right right infrastructure to support your growth, you don’t have the right if whether you’re on in a data center today and not able to scale into cloud, that’s gonna slow your growth because your competitors are already there. Right? Their production to market is a lot faster than if you are on prem a 100%.
So it’s either way that security is so needed that trust is so needed whether it’s security or IT.
So two things we want you to take away today. One is, of course, lack of trust slows your growth. And second is finding clients who’ve spent money on security and they still don’t sleep at night. And I, you know, I could tell you this probably every single one of your clients today just because how the landscape has changed in the last six to twelve months.
So your takeaway companies without trust in the IT stack, their growth slows, and you’re the person, the right adviser to help them move fast again.
So, Chandler, can we get take it to the next slide, please?
So what is trust? Trust is the confidence. It’s to move in a consistently verified state. So, Chad, when you see this on cloud do you see this, first of all, on the cloud side every week? When the client stops trusting their environment, what is the first thing that slows down when it comes to cloud?
Production. Production overall at that organization, regardless of whether it’s a sales organization or manufacturing, doesn’t matter what vertical they in they are in, but the reality is everything slows down because there’s a lack of trust of what’s happening. Is is my input, whatever that input may be, into my network really generating what I’m looking for from an output side of things, whether it’s, again, production from manufacturing, if it’s sales information, if it’s reports that I’m pulling, all of that slows to a crawl when when the network is is not trusted.
Yeah. So true. So true. We go to the next slide, Taylor.
Thanks. So more tools, as we know, it didn’t fix the problem. Right? And we saw it in our tech trends report that recently was published as well that the the vendor loyalty from clients is dropping, and over 500 client space were surveyed for this report, and over 450 advisers were surveyed.
And from that, we saw that vendor loyalty isn’t at all at an all time low. People don’t want the same things now that they had before because it’s not working. They’re getting breached or they’re getting, you know, their their production is slowing down because their competitors have already deployed the new and upcoming technology. They’ve beat they’ve been beaten to the market.
So you see a vendor loyalty at an all time low. The security toolings that have been there for years and years and years for most companies, when you merge or acquire companies, you kinda combine all the all the security line items. I mean, I’ve done that personally when I was a CISO. At one point, I had 278 line items of software for some double and triple.
Like, I had three email security solutions at one time. Did I need them? No. I didn’t need them.
Two of them weren’t even in use, but I’m paying for them. And that is such a perfect time for an adviser to step in and say, hey, let’s right size your environment. Let’s take the funds that you’re spending on two email security solutions you’re not even using and add a pen test and, you know, reallocate those funds and give you a better security posture. It’s that that perfect time for that, and most clients are in that bucket today.
So let’s yeah.
I would just wanted to, you know, just to chime in on this. We see this again from the cloud side because our two our two, practice areas overlap so much. And I think, you know, seeing this, there’s so many tools because exactly what you said, a lot of times, it’s it’s someone that is just buying an EDR, an MDR, an XDR type of tool and throwing it on there to check a box, not really utilizing it for what it can do or bring to the table. So when you get a cohesive look at the overall perspective, it makes it so much easier to manage and so much easier for the the end customer to understand what’s happening in within their their network.
A 100%. That’s such a good point, Chad.
Such a good point. And it’s let’s do a a real another poll question real quick. So in your opinion, you guys use you’re in client accounts every day. So what what do you think is how many tools today, let’s say, does an average organization run on average?
So in your client space, how many security tools do your clients on average run? Under 25 or over 75? Throw in one if you think it’s under 25 or two if you think it’s over 25. What do you think it is, Chad?
I I think it’s gonna be as far as overall tool set, I think it’s gonna be two. Yeah.
Over two. Right? Over 75. So the right answer is, yeah, 83 on average. That’s that’s a small business company, 500 people. They’re running 83 different tool sets from 29 vendors.
Yeah.
That’s crazy. That’s a lot of tools. Yeah. And they have maybe two and a half guy who manages it with four thousand three hundred and thirty thirty alerts coming in on average per day.
Like, how do you that’s nonmanageable. And it’s because it’s, you know, it’s you’ve got AI that is that is scaling these alerts and scaling these attacks, and then you have humans on the other side of the of the table trying to stop them. And it’s I was talking to a client yesterday, and it’s not because humans are less intellectual. We are we’re smart.
We created AI. It’s not about intellect. It’s about speed. It’s about outrunning a car. You know?
You need AI to fight AI.
Yep.
Absolutely. That’s something that you can’t get around these days. And, you know, the the the one stat and I bring it up every time, Sumera, you and I present together. But the one stat that astounded me is the number of of AI bots per live human out there is just unbelievable when you look at that on a on a global scale, let alone a national scale for us here in The US.
It is unbelievable. I think last year, we we were looking at the numbers, Chad. It was Microsoft did. It was 84 nonhuman identities to one human identity. Yeah. And but that was early last year.
Exactly. And a year later, it’s probably double or triple that.
Yes. Yeah. I mean, our our attack vectors have tripled. They went from, I think, 700 per day to they’re in the thousands now per day, actual attacks. And it’s it’s it’s scaling, but we need solutions to withstand that. Right?
Yeah. And from the bad guy side of things, to to give some more perspective, it’s $12 to get millions of bots to do a DDoS attack on on someone. It’s $12. I I could do it, you know, and and have it happen, and it’s the cost is minimal. The the havoc that is wreaked on on customers is is unbelievable when that happens. But, thankfully, we do have suppliers that can step in and and help in those both in in the midst of an active attack as well as help prevent them, more importantly.
Exactly. And I we’ve got some beautiful disaster recovery solutions too that can, you know, be leveraged in time of an attack. So I think Chad and I will do more and more of these for you so we can show you the entire end to end of security and infrastructure and how it bleeds together, how to sell it, how to talk about it, and how to position it. So you’re at the end of the day, you know, the our motto for security and cloud is we wanna leave people and companies better than when we found them.
Tim Bossa, I love how he’s he says it the best. He said, at Telarus, we’re always thinking of the end client first and then we reverse engineer into content, into our talk tracks, into our suppliers go to markets because that’s who we’re here to serve is that client through our advisors. So our equipping and our our supply demand, it all goes to serve your clients and to serve you. And we wanna make sure you have the best and the most up to date information so that you can be that irreplaceable tech adviser for for your folks, for your clients.
And I’ll provide a shameless plug real quick before we move on to the next topic here is my most recent inside the win is is an example of a d of a DDoS attack or DDoS attack. So take a listen. Jump on the, on the Telarus website. You can see it there or, or any of our social media feeds too.
You did a great job on that, by way. I loved it. Thanks. Yeah. That was really good.
That was really good. So the question now is if buying more buying more tools didn’t fix the problem, what does an IT IT leader do instead? So if, you know, when you add on continue to add on more tools, that’s not fixing the problem.
There’s a lack of trust, growth slows, what happens? Right? So I’m gonna give you a a a live example, a practical example from my life. As you know, I love to use Ethan in in my analogies because I just feel like it makes it more practical.
So, Chandler, if you go to the next slide for me. Slide four. Okay. This here is a picture of Universal Studios in Hollywood.
So when Ethan was little, this is back in 2023, he didn’t trust escalators or elevators. Not a little. Not at all.
Malls, we take the stairs. Hotels, we take the stairs. Airports, we take the stairs. And y’all, DFW has the most longest staircases ever. Like, it’s it’s it’s ridiculous.
So and I tried everything with this kid. I YouTubed how an escalator works. I we drew it. We you know, I rode one by myself, actually, waved from him at the top, and he’s looking up at me like, mom, you just made a really bad life decision.
I don’t know how to help you. So he was he was scared of escalators. He wouldn’t he wouldn’t get on one. So then one summer, you know, I took him to Universal Studios Hollywood, and this blasted park, it sits on a hill.
And the top and bottom, you guessed it, are connected with these escalators. So you’re seeing one set. There’s, like, four of these godforsaken things. You have to go, like, four times up of up it to get to your hotel.
Four times, you know, four steps down is it’s the most stairs ever. So, of course, all the families are getting on the escalators. They’re eating their churros. They’re not sweating.
They’re getting to the ride, getting in line on time. And here’s Ethan and I. You know, we’re up and down these these godforsaken staircases five days, up and down, families passing us by and you know it took, I had a moment of reflection obviously as I’m going up and down these stairs I started to think about my work, about life, it was a great time for me to reflect cause I had nothing else to do obviously than stay, you know, walk up and down in pain. So I was a CIO at this time and as I was walking up and down these stairs and it was taking forever cause I don’t know how you guys are when you go to Universal or Disney or any theme parks, I have a plan.
Like, I have a map and we have a plan of which rides we’re gonna hit first, which rides we’re gonna hit last, where are we gonna eat, what’s this, where are our break times. So I’m pretty down down to a tee, I’ve got it all done. But this staircase kinda threw a wrench in my plan, so I wasn’t too happy about that.
So as I was reflecting on all of this and I I was our numbers that year for the company I was working for, they were coming in kinda low. The way our speed to market was slower, our DevOps team was, you know, not producing as fast as we would have liked. And so I was thinking about all this and it dawned on me that, wait a minute, it’s it could be that our IT and our security stack is stale today. It could be that with Edge had that had just come out, with AI that was just budding, that we’re actually kind of apprehensive in moving to moving too fast because what if we get hit?
So it was during these staircase times that I realized that that trust in my IT and security stack has actually slowed our growth. I didn’t put I didn’t put my finger on it until this until I was actually running up and down these stairs and that, you know, the escalators were never broken, it worked all day, it was carrying people, it wasn’t the problem of technology, it was a trust problem and that lack of trust cost us the most important thing was time. For Ethan and I was time in that part because then we had a hundred and twenty minute waits but it was it was costing us time and money in my professional life for for my company.
So, and your clients, I guarantee you, are doing this right now. They bought the security tools and but the landscape changed. Like Chad mentioned, with edge, with, cloud compute getting decentralized at the edge, with that has created a whole new set of problems that IT and security leaders never saw coming. So securing that, having AI now as, of course, our ally, but also as an attacker, that’s changed the entire landscape for us.
So when they don’t trust this when your IT leader doesn’t trust trust their stacks, the budget stays frozen and nobody calls it a security problem, it’s slow it shows it shows up as slowed growth. But that’s your opportunity to have that conversation with them and say, hey. Let’s look at, your stacks today. Let’s see if they’re they would stand the test of time in where we are today in today’s threat landscape.
So how it ended for us just to close this escalator story is, he didn’t he Ethan didn’t start riding the escalator because he took the bribe from me because I did bribe him every day or I gave a better speech. He he took it. One day, we stood at the bottom, we were counting steps.
He all of a sudden got on, we counted all the way to the top, he became confident, we verified the steps over and over and then there was no stopping the kid and now like he runs up the escalators and I have to tell him to slow down. But that’s how it is with your advisors too. You grab their hand, you’re counting it, you’re going through line by line on that Excel spreadsheet on their expenses, you show them a better way than what they’re doing today to help them grow like my friend Graeme, he says companies have two objectives, how to save money, how to make money. You can help you can help them to do that with the technology sets and the solutions that are available for them today. So the Yeah.
I think I think you hit the nail on the head there. You know, the the two things that like you said, Graeme Graeme says all the time is save money, make money. And if you’re showing them, again, an overarching solution that will take those tools and actually utilize them, save time on your IT team, be able to take information and and utilize it properly, get rid of all the false positives, get rid of all of that, and and leverage the technology that’s out there to be able to remove some of the tools that are either useless for that customer specifically or useless now because they’re older and be able to leverage newer, faster, better tools under an umbrella that handles all of it alongside of them or for them completely is really, really good.
So true. So true.
Yep. So side five kinda goes right along in that. Three reasons that trust breaks, and we can, you know, go through this real quick.
Reason one is, and this is actually from CISO, so you’re hearing actually from the from the client space and I know you’re hearing this from your clients as well because I’m on calls with you guys, with your clients every day and I know Chad is too and we’re we’re hearing this together with you. So 74% of the clients space, they think the threat outran the tools which is good news for us, that’s what we’ve been saying all along. They need better solutions for today. And secondly is, I love this 60% of clients today are saying there’s nobody left to run the tools. So for the first time, CSOs are seeing it’s not empty headcount. It’s not adding another person that’s gonna fix this problem.
It is adding AI to their SOC that’s gonna fix this problem. And a great opportunity for outsourcing it because that’s where our MRR comes in. So selfishly, yes, we want them to outsource, but it’s also better for them to outsource because they need that extension of their bench. Three and a half people can’t stand up to AI today. I mean, that’s just logic. And then 98%, the reason the trust is broken is they don’t know where their data is going. They can’t see their data.
So, great question, Wes. On average, what is the longevity of an average tool in the stack? Used to be five years, but in last year, we’ve seen it’s, it’s changed within a year. So it really depends on the world, what’s going on, how the technology is evolving. That depends that is a big, big, predicator in the longevity of the stack.
And I know that’s probably clear as mud, so can go to the next slide, landscape. This slide this slide shows you the attacker. So last slide last slide was on the market. That’s kinda what the market looks like.
This is what the attacker looks like. And we’ll, you know, just to just to kinda skim this real quick because I wanna get you into the elements of what a new security architecture looks like. So real quick here, it’s the architecture, you know, the attacker changed. Attacker went from human to AI, but the architecture didn’t change with it.
So what what happened is our security solutions today were built in the last thirty five years around one thing was human psyche. So every security solution out there is to stop a human from either attacking in into an environment or internal threat going out of the environment. It’s built around humans. It was never built around AI anomalies.
AI who can AI as a worker who can come in, switch their credentials in all in the guise of accomplishing a task, for example. That’s not gonna throw up a flag. That’s not an alert. That’s AI doing its job, but that is creating a lot of nervousness, obviously, in, you know, in a lot of different companies.
The perimeter moved. We talked about that. Chad, you know, would you agree centralization of cloud kinda got decentralized when Edge came into the scene that created a whole new attack surface.
And then exploited timelines collapse. So right now, it takes twenty seven seconds on average to hack into a company. No joke. Twenty seven seconds. It’s less than a minute.
Yep.
Yeah. It’s it’s unbelievable in in my standpoint, like, how quickly something can happen. And it’s and it’s not the big, large enterprise companies that are being hacked. Consistently, it’s the SMB space because most hackers understand that they have minimal tools.
They have minimal security protocols in place to protect those networks, and they’re more apt to pay the 5 or $10,000 for ransomware than than millions and millions of dollars that it it’s gonna be fought for from an enterprise level. So every day, SMBs from your local mechanic’s repair shop for cars to the pizza shop down the street, they’re the ones that get hit more and more often than than the giant enterprises. The giant enterprise ones are big logo, ones that that are gone after just to say they got just to say that they were hacked. The other ones, that that are really in jeopardy are your friends and neighbors that have small businesses that don’t pay attention to the cybersecurity because they think that it’s a small business.
Why why is somebody gonna wanna hack me? I don’t have anything except pizza receipts or, you know, tire receipts. And that’s that’s the key reason why is because they don’t think they are a target.
Yep. Exactly. Anything making money today is a target. Anything at all. Yep. Absolutely. Yeah.
Yep. So we’ve got we’ve got five minutes left, and we’re gonna kinda bring this to a close here, I think. Right?
We are. So if we go to slide, if you go to the next slide, Chandler, I just want you guys to see where what we’re leading with, at Telarus for cybersecurity. These are the elements of a modern security architecture. So Gartner hasn’t adopted it yet, and I think they will.
It it pretty soon, I think. So if you were at Telarus Partner Summit, you heard our boss, Dan Foster, on the stage. He talked about modern enterprise architecture. Right?
I would go as far as to say that’s a modern digital architecture. What he’s talking about is platform consolidation, vendor consolidation. That’s where the technology is headed today. Instead of 500 vendors, clients wanna consolidate.
So a modern security architecture to complement that digital space looks something like this. There are five elements to it. You must have some or all of these at various degrees in any given company to be able to be protected today against the threats we have today. So if you guys wanna take a picture of this, and obviously, this will be in Telarus University later.
So each of these is critical to to safeguarding that environment, and we have solutions from our great suppliers in each of these categories. So if you go in the hub and you’re looking for any of these five, you will find them in in the hub. If we go to the discovery questions, Chandler There we go. So there’s three discovery questions here.
Chad, I’d love your input on Yeah.
Yeah. In any of these three. So when your data moved to the cloud, who took over securing it? You are the provider.
What do you how would you position? Would you position this question? Would is this something that you would use for a client?
Absolutely. Because most of the time, when a client moves from either premise based or or moves completely into a cloud or SaaS based type of solution for their day to day operations, they think that it’s all being secured and handled, by that SaaS provider or by the cloud provider. Whether it’s public cloud or private cloud, we see this more and more often on the public cloud side is, oh, it’s in Azure or it’s a Microsoft product. I’m I’m good.
I don’t have to worry about it. Or it’s in AWS. It’s in Google Cloud. Everything’s great.
No. It’s not. You still need to protect the employees using the the endpoints. You need to protect the information that’s in there.
All of that needs a a concise and cohesive wrapper around it in the security space for sure.
So true. So true. And then devices. Right? We have so many IoT devices now in a company that touch company data today, and it’s not visible to the IT team or the security team.
So that’s a great question to ask. How many devices touch your company data today? I bet you anything they’re not gonna know. And that’s where that’s your end to help them see, hey.
We can bring in a CMDB. We can bring bring a scanning tool in to see exactly what’s writing on your network. And that opens the door into a security assessment, into a cloud assessment, and, you know, land and expand your book today. Yep.
And then customer calls, how do your agents know whose voice is on the line? So as you can see, each the each three of these questions each of these questions is from cloud practice area, network practice area, CX practice area, and it’s to help you cross sell into security from any point wherever you are in your discussions with your clients. Because it’s not about a new prospect, every time. It’s about a better question inside the meeting you’re already having.
Vendor consolidation, vendor loyalty is at an all time low instead of renewals. Use that time to reset. Have a new conversations that can help you expand your book of business. Bring in Telarus engineering team.
Bring in Chad and I. We’d love to help you go crush it with your clients.
Yeah. Absolutely. That’s what we’re here for. We’re help to help you understand. Kenneth asked a great question, and I’m gonna wrap on this. So what is the solution for the SMB businesses that may not have the budget to pay the same as a larger company? Well, we have those solutions.
Sumera and I have worked together to make sure that we have suppliers in the portfolio that that can provide everything from an SMB space. An SMB in that instance, we’re looking at five to 10 users, employees, all the way up to the tens of thousands. So we can cover the full range of a customer base and, again, be able to help you get to the suppliers that are gonna resolve this the the questions and help your customers become a secure and cloud based operator and and know that they have all the coverage there that they need for sure.