Beyond the Firewall. Powered by HUB Tech

The Forgotten Security Gap: Protecting Data Once It Leaves the Network

HUB Tech

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 53:55

Firewalls, EDR, and cloud security get all the attention, but sensitive data rarely “escapes” through a Hollywood-style hack. It walks out the door in plain sight, copied by a well-meaning employee, saved to a USB drive, shipped in a physical backup rotation, or pasted into a public AI chatbot because someone is trying to get their work done faster.

We talk with Kyle Zemke and Matt Buckley from iStorage / Kanguru about the forgotten security gap: protecting data once it leaves the network. We break down what kinds of information are most exposed (payroll, customer files, contracts, healthcare and student data), why remote work and cloud-first habits make the company perimeter feel endless, and how organizations can regain control with visibility, classification, sensitivity labels, and DLP.

The conversation gets practical with real-world stories: lost drives, monitoring “last known” location, a USB that ends up in peanut butter, and even what happens when a stolen encrypted device gets resold online. We also tackle the AI problem head-on, including the risk of employees using public LLMs for work tasks and unintentionally leaking confidential data.

If you want a clear, usable approach to data security beyond the firewall, this one is for you. Subscribe, share this episode with your IT or security team, and leave a review on the biggest way data leaves your organization today.

----

More about iStorage / Kanguru: https://www.kanguru.com/

More about Acronis: https://www.acronis.com/en/

The Beyond the Firewall podcast features discussions with technology leaders and practitioners who provide valuable insights into today’s IT and business challenges. 

Follow the podcast to stay updated on new episodes, and watch full episodes and video highlights on YouTube. 

To learn more about HUB Tech and the services that support IT modernization, visit the HUB Tech website at https://hubtech.com/.

Announcement

Welcome to the VIP Firewall Podcast. Powered by HubTech, where we go past the headlines to talk with technology leaders, industry experts, and IT practitioners shaping how we work, live, and lead. Let's get into today's episode.

Adam Shaffer - Host

Hello everyone, and welcome to another episode of Beyond the Firewall, powered by Hub Tech. I'm your host, Adam Shaffer. Today's topic is one that doesn't receive nearly enough attention. Organizations spend millions protecting networks and endpoints, cloud applications, and email systems. Yet sensitive data continues to leave the network every day through employees, contractors, third-party vendors, remote workers, backups, and portable storage devices. The reality is that many security incidents don't happen because someone hacked through a firewall. They happen because sensitive data was lost, misplaced, mishandled, or left unprotected after it left the network. Today, we're discussing the forgotten security gap, protecting data once it leaves the network. Joining me as always is my co-host, Chris Daggett, and our special guests, Kyle Zemke and Matt Buckley from iStorage Kanguru. Kyle serves a senior product manager at iStorage Kangaroo, where he works closely with engineering product development and customers to help organizations address evolving cybersecurity and data protection challenges. And Matt is a product manager at iStorage Kangaroo, focused on developing software and data security solutions that help organizations better protect and manage critical information. Kyle and Matt bring a frontline perspective on the challenges organizations face when protect us protecting sensitive data and managing risk. Kyle, Matt, welcome to Beyond the Firewall Podcast. Thank you. Thank you for having us. Glad to be here. Hey, and hey, Chris. Thanks as always for joining us today. So I love the name. I love the name iStorage Kanguru. So is that like a is that like a combination of two companies? How did how did that happen? Or you just like having two names? That wasn't like a trick question. It was just like to get us going.

Kyle Zemke

No, it's two companies. Um we have uh a joining of the two uh to become iStorage Kanguru. It's a a conglomerate of uh encrypted data security and storage. It takes some of the best uh remote management monitoring and some of the best hardware encryption pin pet technology and mashes them together to form this powerhouse company.

Adam Shaffer - Host

Oh, that love that powerhouse company. That's awesome. Well, thanks for joining us today because I I actually never really think about it that much because I spent so much time uh you know with Chris and the team, and we're always talking about you know, how do we protect customers' infrastructure, their endpoints, but we never talk that much about what happens when data leaves. And you guys brought up a great point that that's another vulnerability that people just don't talk about enough, and it's important. So, with that, I wanted to, you know, let's mix it up with you guys and try to figure this out a little bit. So when organizations think about cybersecurity, why do you believe protecting data after it leaves the network is just like not even thought of? Like, I don't even think about it. Either Matt or Kyle, throw it throw it in.

Matt Buckley

Yeah, yeah. I mean, from my perspective, I see that a lot of the um foundation on just general security is really based on how it was beforehand before a lot of removable storage was around. Um, you know, the idea of keeping the bad guys out, cool, we're all safe. Um, times have changed, especially since the the pandemic. Data is moving all over the place, it's stored up in the cloud. And it takes a lot of time, I feel like, for everyone to really get a grasp of it and understand that because the times are changing, we need to start thinking a little bit outside the box. Um, that's been a big item that I've been looking at for several years now, as far as you know, how does remote work? How does you know Stacy from accounting, um, you know, doing all our finances remotely, how is that going to impact certain things and how can that remain secure?

Adam Shaffer - Host

That's pretty cool. Um, well, I again I don't think about it enough, but Chris, you know, you're dealing with customers every day. Do you see organizations focusing more on network security or data security? Or is it you see it the same?

Chris Daggett

Yeah, I mean, Adam, definitely. Um, I think a lot of organizations, they start out with, you know, the network uh always, you know, they're always thinking about, you know, firewalls, antivirus, VPNs, keeping the attackers out, right? Um, you know, and all that does matter. But the question I always come back to is, you know, what about the data? You know, it's who has access to it? Where is it going? Um, you know, is it classified? Um, you know, things of that nature. Um, you know, what happens when it leaves the protected environment? You know, those are discussions that we need to have uh in today's day and age. Um you know, at Hub, we're always talking about, you know, with customers these days, about those those particular topics, because you know, to Matt's point, they're not thinking about that. You know, the they really have this, you know, kind of traditional mindset of all right, I have the basics in place, but you know, we have shifted to a uh kind of you know office less uh environment due to COVID and data's all over the place. So, you know, you you really need to secure that data first and foremost in a modern uh infrastructure, especially with the uh you know AI coming in.

Matt Buckley

Yeah, yeah, AI has been a huge item on this.

Adam Shaffer - Host

Yep. Yeah, but what's interesting is I I always like I'm an idiot, like I always download stuff that I need because I want to take it with me somewhere, and I put it on this like a little USB, and then I lose the USB or I leave it in Starbucks or something like that. And I don't know why I do, but um, it's just it's like it's small. And and so let's talk

The Most Exposed Sensitive Information

Adam Shaffer - Host

about the type of data that you guys are worried about the most. You mentioned the woman in accounting. I can imagine that's pretty sensitive, but what what other types of sensitive uh data are organizations most concerned about?

Chris Daggett

You know, we're looking at um, employee records, payroll, financial information, customer files, uh contracts, healthcare data, student information, legal documents, you know, it's all over the map. Sounds like everything.

Adam Shaffer - Host

Yeah. I'm always interested in customer data. Like that's what I always like to take. Um, because I I'm a marketing guy and I like to market to them. And I download this stuff like an idiot, and like I say, I can walk around with it. Um, so um it's kind of crazy. But but Kyle, you were gonna say something?

Kyle Zemke

Yeah, it's just that you have a lot of uh companies that are being remote first or almost completely cloud-based services. It it's almost the entire data set from, like you said, accounting all the way to customer data to even code bases are being uh used remotely. Uh people are working from home, and you have to have these different like layers of data that is allowed to leave and what services and permissions are available, like what Chris was saying. So with the creation of these like remote first companies, you're kind of stretching like where does the company network start and where does it end kind of thing.

Backup Reality And Physical Copies

Adam Shaffer - Host

And and when you guys talk about like, you know, we talked about data leaves through people putting USBs in or uh backups. So like when you backup, I always thought people like they're backing up to some cloud. Are you actually backing up to physical um hardware? Are people doing that?

Matt Buckley

Yeah, yeah. Um, I would say people are for the most part backing up to two to three different locations. So um cloud backups are always big and very convenient, especially these days. Um but the more you go up into the cloud, the more vulnerable you are. So, what a lot of uh companies are still doing, and I will always recommend this, is sure do a cloud backup, but do a physical backup. And you know, physical backups that can be stored in a safe, um, depending on your your uh types of data. Um, it can even root be removed from the from the facility and stored at a second uh facility. Um but again, it's one of those things that if you're taking a physical backup, you know, things can happen. Building can burn down. Um so if it's gonna stay in the office, make sure it's in a in a secured fireproof safe, something like that. If you're gonna take it home, same thing, make sure it's it's protected. Um, but yeah, yeah, yeah. I would always recommend two types of backups, always uh because you never know what happens.

Adam Shaffer - Host

Um things go missing, things stop. Before cloud existed, I used to do backups and put them on tape, and I used to have Monday through Friday, right? So I'd like Monday to Friday, like on the tape, and I knew what it was, but um somehow I screwed that up and I made Tuesday, Wednesday, or Wednesday, Tuesday, or something, and then there was a problem, and of course I had the wrong tape. But is that like still people do that? Like they they have a weekly backup they have each day, and then they they put it in like some box and hide it 100%.

Matt Buckley

Um I know that um a couple places that I used to work, they um they didn't do it based on day. Um the the creator of the backup program um used Greek gods, and they uh that's awesome. They labeled each um each device that they would physically backup to with the Greek god, and then set a calendar reminder for um whoever was in charge of taking that backup that day, and it just said, you know, Zeus backup, um, or something on those lines, and that's how they always did it. And the thought process was yeah, it was a little fun, but if somebody were to get the backup, um, they would have absolutely no clue why this drive is just labeled as Zeus, um, and you know, Hades and all of that stuff. So it was uh, yeah, a little tongue-in-cheek, but also this is how they're gonna do an extra layer of security on top of you know everything else that they have.

Chris Daggett

And I think to add to Matt, what Matt just said, you know, is the data production data or is it archive data for regulatory purposes? You know, labeling it Zeus, you know, may not be too intuitive, you know, especially, you know, study, you know, you need to recover data.

Adam Shaffer - Host

Yeah, I thought I was pretty smart with Monday, Tuesday, Wednesday, Thursday, Friday, but um until I switched the dates. But that was something else. And and you know, it was funny, like what was the data I was backing up? I thought I was backing up the entire ERP. Maybe I wasn't. I have to figure that, but it took forever back then anyway. So so that's um interesting. I can't believe like

Lost Media Risks And USB Study

Adam Shaffer - Host

we're still doing all that today. Um what you know so so let's now get to okay, so now we we either backed up data or we borrowed some data to take with us on a road trip or something like that. What what what's the the risk if you you actually lose this stuff? Can anybody just pick up the USB and plug it in and check it out or take your tapes and review it? Like how do you how do you protect this stuff?

Kyle Zemke

So the best thing you can do is to have some form of encryption on a lot of your remote or external assets. Um encrypted USBs are getting more and more popular. Um but yeah, anybody who finds your USB can open it up and take a look. There's actually a study between a few different universities and Google that came out a couple of years ago, and they did testing with uh USBs. They put them like in parking lots, in like dorm rooms, in classrooms, and they labeled them like homework or exams, and they actually had I think not bank account or something. Not bank account. Yeah, no, not bank account, but um they had like in the high like 80% of USBs got picked up and and plugged in or tested. And it's not just dangerous for you, but it's also dangerous if it was like someone who was trying to do something malicious.

Adam Shaffer - Host

Yeah, no, that's what I would think. Like, that's why I wouldn't put it on. I would the first thing the first thing I think about is somebody's messing with me. It's like when they leave a dollar on the sidewalk with like dog poop on it and they want you to pick it up and they think it's funny. Like they leave to like the grocery store floor. Yeah, you know, like I'm like, I'll just leave it there. But like I see a USB, I'm like, is somebody trying to so it's like it's kind of scary. Do I want to put it in and risk it, or do I want to see what's going on? And um, I don't know. So, but you're saying 80% of the people did it? Yeah, there was a really high number. Sorry, go ahead, Matt.

Matt Buckley

No, I was just gonna say it was uh it was either 80 or 90 percent, somewhere in that range. It was an amazing study. Um, and it just really emphasized the the risk. Um, if I remember correct, Kyle, I believe that they had a a small program or uh like a bat file or something that yeah, um, right when it was plugged in, it would ping a uh a service so they could keep a live count of you know, this drive was connected and it's pinging home now. Um and it was like three or four colleges, I believe, that did this almost at the same exact time. It was crazy. They were dropping them everywhere parking lots, Starbucks, um even at like bus stations, and people were just picking them up and connecting them to general computers, both work and personal ones.

Kyle Zemke

Within a few hours. It wasn't even like taking a day of like, hmm, maybe I should, maybe I shouldn't, but like that is that is messed up.

Adam Shaffer - Host

I think I go to the library and use one of their PCs or something. I don't know, but uh right, that's a safe choice. Well, not not necessarily for the county, but for me for me, yeah. But but uh but but so now we go back to this, and and so you got you got all this stuff going on, like cyber attacks, and now we have this new thing, or not really new thing, new to me, where I don't even think about this as like a cyber security issue, but it is. I have cyber attacks, and people are always trying to break into my system from the outside, whether uh they're doing it just because they do it to everybody or because they're really trying to get into our place, and now I have a lost backup or a lost USB or a lost thing. Which is more dangerous, the person that loses it or the cyber attack, where they again both the same. How how do you how do you position that? I mean I go ahead, guys.

Matt Buckley

Oh no, go for it, Chris. Go for it.

Adam Shaffer - Host

I I didn't

Insider Threats And Monitoring Controls

Adam Shaffer - Host

mean to stump you, but like I I don't know, like I I think like a cyber attack, at least we're trying to knock them down all the time.

Chris Daggett

Right. Yeah, I mean, I think that there's an equal equal risk there. You know, it's um you have an insider threat risk where, you know, granted the person isn't uh necessarily doing that maliciously, but you know, if something does get lost, which things happen, we're humans, right? Um, you know, that's a risk right there. But you know, the the cyber attackers, they're they're trying every possible way that they can to either compromise an account to get data or to you know break into a device, you know, whatever the case may be. Um, you know, I think this holds true and not even and not only you know removable devices, but you know, laptops themselves, because you know, a good practice is to have encryption on the laptop as well. Um so you know, there's a lot of different ways to kind of spin it, but you know, at the very end of the day, everything's a risk. Um 100% you know, putting precautions in place and putting those layers in, right? Um, you know, you you need to have layers and a good security posture, a good security strategy. So, you know, if you do leverage um, you know, the the hardware that uh kangaroo offers, or you know, in addition to all the other things that you can implement, you know, that's just gonna lessen your risk at the end of the day.

Adam Shaffer - Host

So so when you when you work with companies, and of course, you know, I know HubTech does, and we we spend time trying to explain to companies how to behave. Are is there like a process that you talk about about what data you should let people download and take and what data you don't? Like, is there a um uh SOP for this?

Chris Daggett

Yeah, I mean, at the at the end of the day, you know, the biggest challenge is visibility. You know, a lot of customers don't know where the sensitive data sits. And, you know, it could be in multiple places, you know, um, you know, it could have been copied to SharePoint, gets emailed, downloaded, you know, the the use cases are endless, right? Um, but you know, putting a good um, you know, sensitivity labels on data, making sure that you have good data leakage controls in place, you know, things like that are are super important to ensure that you know the exfiltration of the data doesn't happen. You know, there are technology solutions that um you know you can get out there that will um essentially you know block anything that's coming out of SharePoint after it does a scan or uh email or off of your system, you know, things like that. A lot of um these EDR tools actually have DLP built into them. So there's a lot of different areas where data leakage could happen. Um, but again, it's all about those security layers to lessen that risk.

Matt Buckley

Yeah, 100%.

Adam Shaffer - Host

Could companies tell if you're downloading data onto a USB or something? Do they know who's doing it?

Chris Daggett

Or I know exactly who downloads data onto USBs with a no. And I get a learning appropriately.

Adam Shaffer - Host

But but you get a like so there's like a dashboard, you say this person downloaded this, this person downloaded this.

Matt Buckley

Oh yeah, oh yeah. Um if you have the proper controls in place, um yeah, yeah, yeah. It's an item that it's very easy to tell. Um, you can see when, who uh did it, where it was done. Um in most cases, uh now you can even uh get like the exact device, uh like serial number and everything. Um so it's it's a very common item, I would say.

Adam Shaffer - Host

And so you mentioned it before, Chris, but you talked about um it wasn't malicious. But usually when an insider is borrowing or taking data, are they almost always trying to do it for bad, or is it like they're just doing it because they don't know any better?

Chris Daggett

I think it comes down to lack of you know education, um, things like that. The some folks are just stuck in their ways, and you know, it's you know, it's having that old mindset, right? You know, the the threats weren't as you know out there as they are now, um, you know, with with the data leakage and things like that. But you know, hackers can break into just about anything with the right amount of time. You know, it's that's just inevitable. Um it's our job to you know put those controls in place and put the layers in place to to slow them down because they will move on eventually. But you know, to to to roll back to the question, um you know, it all depends on the the savviness of your workforce. You know, we have a lot of different generations in IT and they all handle things differently. And you know, you get somebody that's a little older. Um, you know, and if you think about it, right? Not everybody, you know, you have Susie in accounting that doesn't know what the IT department knows. So the folks in the IT department may be, you know, okay, you know, you shouldn't be doing this, you shouldn't be doing that. But if you don't have cybersecurity awareness training in place, you know, that could help with, you know, the awareness of, okay, you know, these are the do's and don'ts, you know, the the good security, um, you know, hygiene steps. Um But again, it all comes down to education.

Adam Shaffer - Host

But most but most people most people aren't doing it because they're cr they're criminals or they're bad they have bad intentions. Doing it because they they don't always make their job easy at the end of the day.

Matt Buckley

Yeah, yeah. Right. Um I would say the majority of insider threats are for the most part just innocent people that are just trying to do their job. Um, you know, just like you were saying earlier, you had a backup, you went to Starbucks, um, you know, you just want to do a little work, and then your coffee got called. So you went up there and you didn't even think about, oh man, I I left all of my customer data right there. Um, it was just I need a coffee. So I would say, more often than not, you know, it's innocent. Um, training is a huge item, and I will always, always recommend it. Um, insider threats is one of the areas I absolutely love working on because most of it's just educating.

Adam Shaffer - Host

Um but what are you telling these guys? You're telling them, hey, you know, here's your training for today. Don't download this stuff. Like, what do you what are you telling them? Like, what's the training? Yeah, you can do this.

Chris Daggett

Stand behind them with the ruler and uh no, it's all about giving them good um relatable use cases at them. And you know, if you can, you know, put some simple use cases together, like for example, the Starbucks, you know, situation that we were just discussing. That's a great use case that that that will resonate with a lot of different people. So, you know, if you can come up with some relatable use cases, it's really gonna help the comprehension of of the content.

Adam Shaffer - Host

You know, I don't think you guys remember because I'm old and you're not as old, but there was a famous um nothing to do with cybersecurity, but just security, where the this is before the Knicks were super great and won the the championship, but the Knicks were playing Indiana in the playoffs, and Malik Seely, who went to St. John's, was taking the subway and he left his playbook on the subway. And and so that he he basically almost got kicked off the team for that. Like that was like the biggest issue of all time. So, like to me, that's almost like he left his USB on the train or something. And so, so do people get fired for this kind of stuff all the time.

Chris Daggett

Yeah. Yeah, really mostly in in the higher level, you know, if you're working in financial um or something like that, something that's tied to money or healthcare, um, that can be a big, big prop problem uh due to you know regulatory requirements and things like that. But it's absolutely a firewall offense.

Adam Shaffer - Host

Okay, so maybe there's like one strike, but if it's like major, like they're they're gone. That's uh that's scary. So I definitely would have to be more careful when I take this stuff. But okay, so now let's get to the kind of the bad guy. But I see this often, and people jump around from job to job. Salespeople always are jumping around from job to job. And so the big deal used to be I have my company notebook and I got to give it back in 24 hours, but I want to download every single thing I can, even though you're not supposed to. And you sign something that's confidential, you're not supposed to take the data, but they're out there downloading everything. Like, so what what happens when you're going to lay somebody off or somebody's gonna leave the company? You might not even know that they're gonna quit. So they might they might even be quitting and planning this for a while. Like, like if when somebody leaves the company, are you doing an audit? Do you see what's going on?

Chris Daggett

Well, you know, I know I can only speak for for hub, but we, you know, do monitor when people um you know move data around, you know, especially to a USB drive or something like that. So, you know, we're getting alerted real time. So whether, you know, they're trying to be slick about it, you know, whatever the case may be, you know, we we have a lot of monitoring in place that will prevent

AI Tools As A New Data Leak

Chris Daggett

you know such acts if they, you know, if they maliciously do it, you know, it is, you know, legal will get involved. And you know, it's it's a big problem.

Adam Shaffer - Host

You you guys mentioned AI before. Like, so where does AI come into play for any of this? Does AI help you try and predict like when people are downloading certain things, there's probably a chance they're gonna resign? Is that does that exist? If not, we should build we should invent it. If it existed, I am not authorized to discuss it.

Kyle Zemke

Oh no. The biggest thing with AI is that people don't understand the difference between like um when hub tech or or another like MSP offers like Office 365, that copilot instance is separated from regular copilot. It's just a corporate level AI. But a lot of people will use GPT or anything in their browser and think it's safe because they're on the corporate network. And so they're putting in data, they're putting in files and documents into this public LLM instead of like their corporate LLM, and that's all of a sudden being provided as training. You know, the information's out there. And you've seen over the past like six, eight, ten months, people being able to retrieve info from other companies because it was added into the learning sequence.

Chris Daggett

Right. And it's all done because people don't know what they don't know, you know, they're leveraging these free tools, and we come back to a common theme here, right? It's um, you know, they're trying to do their job easier. So whether it's using a USB or leveraging AI, you know, they they're just trying to get through their day because we're busier than ever. Um, you know, it's just the nature of the beast.

Matt Buckley

Yeah, yeah. AI overall is a phenomenal tool. I will always support it as a tool, but it comes down to, I would say, proper awareness training and some really strict policies. Um, you know, ChatGPT is is a phenomenal asset, but I would never trust it on a company environment.

Chris Daggett

Um not to mention a company environment that doesn't have a solid data governance um strategy in place. Yeah, 100%. Yeah.

Adam Shaffer - Host

Well, that's uh interesting. I mean, Chris taught me that story, but I was I was using uh he he explained the whole thing that we have to have it protected and uh you can't just use it out in the wild. So I got that one a while ago. But with regard to people taking data, that's a way that you're releasing data, right? But you're not pulling it off. Chat GTP is telling everybody about it.

Matt Buckley

Um if you're using Chat GPT, um technically speaking, if you're on your private account, you could technically upload the files to Chat GPT, go onto your personal system, uh, log in, and then download the same files that you just uploaded. Oh, I'm not saying that anyone should do that, um, but that's a that's a sneaky way that you can get around some safeguards because at that point you're not looking at a USB device that files are being uploaded, you're looking at um possibly something that's not checked by your system. So that's that's possibly a way around it. And I'm now scaring myself.

Adam Shaffer - Host

We might have to edit that from the show because that might be a big issue. People get a copy your idea anyway. Well, maybe they'll comment about it. That'd be great. So so and I I

Encryption That People Will Use

Adam Shaffer - Host

love this stuff. So so with regard to um now protecting data, you talked about encryption. What what kind of encryption is on these devices? I could just see me having an encrypted USB and I'll never figure out how to get back in it. Like, is it like password protected? Is that what it is?

Kyle Zemke

Yeah, you can use password protected. Um some USBs also will offer like a pin pad or like some kind of internal cryptographic controller. Um the most important thing is just to have some layer of encryption that's easy to use, right? Because if it becomes too complex, people don't want to use it. Yeah, I mean that's why I wouldn't want to use it because I I forget I I have five million passwords, I hate it. Right. So the best thing to do is to have like alternatives or support stuff like single sign-on, I know it's a big one, especially here and at Hub Tech. You know, having less passwords or or more unified way of keeping everything secure and monitored is good. And USBs are no different. You know, we went from having single computers uh back in the day before we had you know networks, and then we ended up getting local networks. Now we've got cloud authentication. We're just continuously, you know, expanding the uh levels of management, and we have to do it for all of our devices.

Adam Shaffer - Host

So I love good examples, and you have to be careful about who you talk about, but you could be anonymous. But do you have any good stories about where somebody lost or took information? Either they were a bad guy. Like I just love some story, some data story data story. Lay it on us. I want to I I gotta get this. If you want to put you know, if you want to say names, that's great too.

Matt Buckley

But if you don't don't so um I I worked support for uh Kangaroo eye storage um for the first couple years here. Um and so one of the support calls that I I received was a person uh lost their lost their encrypted USB drive, and they called uh called me up asking how can they retrieve the data from their lost drive or stop any of their data from getting out there.

Adam Shaffer - Host

But but this is a USB drive or uh Yeah, yeah, just a little USB drive.

Matt Buckley

Um they then after I told them if it's lost, um, it was one of our unencrypted drives. Um, so if it was lost, like yeah, try to look around.

Adam Shaffer - Host

Um okay, so it's an unencrypted drive.

Matt Buckley

Yeah, yeah.

Adam Shaffer - Host

It's just a USB, it's just a USB drive.

Matt Buckley

Yeah, just a regular one. They wanted uh, they just lost their lost their drive. It had a bunch of their sensitive data on it. They didn't know about encryption. They just needed all of their data safe. Um, after I told them, no, uh I'm sorry, um, we uh it's not protected. Uh they they hung up and about 20 minutes later they called me up and told me they found their USB drive. Um, they were making a peanut butter and jelly sandwich, um and they weren't paying attention, used it as a knife. Oh put it on their bread. After the call with me, they went to go have some peanut butter uh as like a uh stress reliever. Um they opened up the jar and they found their USB drive just sticking in the peanut butter.

Adam Shaffer - Host

Well, was it was the drive bad now?

Matt Buckley

I don't remember. Um, I just remember them calling me up and uh actually speaking to one of my other techs who was cracking up because they uh they were talking about how they found their drive and wanted to apologize to whoever they spoke to before because they found their peanut butter covered drive.

Adam Shaffer - Host

Maybe that's not a bad added feature. It's a USB drive and a peanut butter spreader. But but but but you just brought something pretty cool up. I mean, do you do you are there drives that like locate me kind of thing, like the iPhone where you could try to figure out where it is?

Kyle Zemke

Yeah, we we have monitoring software that we use that will do like last location, even IP address or host name of uh

Real-World Loss Stories And eBay Drives

Kyle Zemke

the USB. And um, that actually works out really well with the story I have, which was um we got a call from someone who bought a drive off eBay, and it turns out that it was from a company where they let somebody go and the employee was disgruntled and stole a USB and then sold it on eBay, and they were really lucky because the company was using encrypted drives, and so they were calling us asking us for the encryption key.

Adam Shaffer - Host

But but they were selling it on eBay saying, hey, buy this USB drive loaded with somebody's data.

Kyle Zemke

I don't know if it was being advertised as somebody's data, but I think it was just the fact that it was like a cheap offer, they were trying to like stick it to the company and just took it and left.

Matt Buckley

I would say more often than not, Kyle, because that happens a lot. Um most of the time it's not about the data, it's just I have this drive for company A. I no longer work there either voluntarily or forced. I don't need it anymore. Let me uh you know, let me make a quick $30, $40.

Kyle Zemke

The value must go up and down based on the company and how well known it is.

Adam Shaffer - Host

Exactly. So they called you trying to get in to crack the USB drive?

Kyle Zemke

Yeah, yeah. The drive happened to be encrypted and um all the data from the company was still there, but because they didn't have the password or the key, they were trying to call us up to get access to it. So what do you do? Well, the first thing is that we tell them, you know, we don't keep the encryption keys. The devices, most devices are self-sustaining, right? They have their own internal process, and so it's not expedited, there's no like backup of the encryption key. So it's it was very safe. Unfortunately for them, they wasted their money buying it off eBay, but that company was very lucky that none of the data was breached, even though the USB had gone from I think it was a US company and someone bought it and shipped it to Germany.

Matt Buckley

If I remember Germany, yeah, I remember that case you're talking about.

Adam Shaffer - Host

Um North Korea, okay.

Matt Buckley

No, no, but it is an item that you know, if we do get a case like that and we're able to properly locate it, um, normally we'll inform the company, you know, this is what's going on, um, and leave it into the company's hands as far as you know, it's your call, it's your property, do do what you want with it. Um if you if you want to be nice and let the user have it, remove all the data, uh, you know, something like that.

Adam Shaffer - Host

So I don't know if you guys um know about this or were involved about it, but I do know that there's this crazy story that one of these doge kids um stole the social security information from the government, and I think he put it on a USB drive. Like I think that's how he I think that's how he stole and then he was selling it to data brokers. I I don't know. Do you know this whole story? But like people like now we're talking about the federal government. Don't they have protections against that? Or maybe his doge credentials got him in, but he just downloaded all this stuff onto a drive.

Chris Daggett

Yeah. Uh go for it, Chris. Sounds like they didn't have you know the right controls in place.

Matt Buckley

It was um from what I know. Well, the government was definitely in a little bit of uh turnover at that point. Um people didn't necessarily know who was in charge of what, um, and the controls were definitely lacking. Um, but yeah, yeah, yeah. I know some of the details about it because I was cracking up about it. It was on like hacker news um talking about um how this leak would have occurred and um what we need to do to prevent it. But yeah, um, it was from what I remember, a um a general USB drive. No encryption was used on it. Oh wow. Um and they they downloaded, I'd like to say 25,000 records or something. I I thought it was more. Um and yeah, they brought it out and started um disseminating that uh around. Uh now whether it was for money or whether it was just just because I don't know.

Adam Shaffer - Host

No, no, they were they were they were selling it.

Matt Buckley

Okay and what I run understanding, they're selling it to crazy.

Adam Shaffer - Host

It was uh the data broker. The data broker just happened to be data broker just happened to be in China, North Korea, and and Russia. So it's I'm sure it was fine, nothing happened bad. But um, but that's that's actually actually shocking. So so I guess you know I learned a lot about if you're gonna take data, you have to understand which data you can take, you got to protect it, you should make sure it's encrypted. If it's encrypted, you got to do it in a way that you can't forget how to use it, or you'll never want to use encrypted drives. Like, so um are are people using authenticators like you know, Microsoft Authenticator or something like that, to be able to get into their drive, or is it is it like always something you have to remember?

Kyle Zemke

So you can use authenticator as like uh second factor authentication. Um, but a lot of drives that are encrypted or come with some kind of software management will have the ability to do like a forgot password or like, you know,

Remote Wipe And Admin Management

Kyle Zemke

um what we do is we usually have an admin who monitors uh a bunch of different USBs and they can change the password uh remotely, uh same way as uh doing like a remote wipe. So to your story of having the government uh or having that one of those doge guys take a drive, it could be remotely wiped as soon as you see it leave the the location or leave the business. I was yeah, I didn't know if that was uh out there or not.

Adam Shaffer - Host

Is it is that out there? You can you can wipe it?

Kyle Zemke

Yeah, we have the ability to send remote wipes and remote resets uh when a drive is connected.

Adam Shaffer - Host

That's a good, I mean that that makes sense.

Matt Buckley

So there's some caveats to that, obviously. You have to connect it to a computer that has networked access, but yeah, yeah, yeah. That's uh that's a primary feature on that because people are afraid of the scenario that you just mentioned.

Adam Shaffer - Host

So so are you finding people um that are interested in encrypted storage? Um, and and I'm talking USB, but then I also see kind of like these bigger, I don't maybe you want to call them SSDs or something where they have numbers on them where you could punch in a code or something like that. Um, is this more of a government thing that people are doing, or is is it commercial? Who's using most

Who Uses Encrypted Storage Now

Adam Shaffer - Host

of the encrypted drives out there?

Kyle Zemke

It's all around. It's it's universal. You know, you've got like um, like you said, government and corporate, but also like mom and pop, small businesses, even really like you know, families and things like that. We had a uh drive that worked on fingerprint, you know, uh four or five years ago, and people were storing like tax information or medical information on them so that they can be, you know, traded and exchanged between family members. If you know me and my wife have one that we store information on, uh if something happens to me, it happens to her, we'll be able to decipher and decrypt the information uh from the drive. So it's it's a good way to share data because I mean I don't share my laptop with my wife, she has her own laptop, and so having a common space at home and not having to spend you know a couple thousand bucks on a NAS to run on my home environment, you know, a USB just makes sense.

Adam Shaffer - Host

And uh the the cost differential between make getting encrypted and not encrypted, is it is it is a big difference? Because I never actually tried to price this stuff out. So I'm not saying you guys are expensive, I'm just saying just in general, it's like if I go to buy like a sand disk USB drive or some encrypted drive, is it is it a major increase in expense? It depends on the feature set, I think.

Kyle Zemke

And it's the same thing with getting like you know, one car over another is the different feature sets, but um as it kind of levels itself out a little bit. But I would say encryption is getting more and more popular, so I think they're gonna slowly get closer and closer in similar price, but um encrypted is as of today still a little bit more expensive, uh, but you're you're paying extra for that safety.

Matt Buckley

Yeah, I mean, on top of that, you have uh like internal drives. Um so uh SEDs and the Opal uh security. Uh I mean that's that's been around for years. Um if you have an external drive, um, I'll say, you know, from you Bought from Amazon, there's a chance that there's built-in security there. You just need to enable it. Um, and because that's just there, right? For the most part, you're not seeing an increase in price because everything else is already already encrypted. You just need to figure out you know whether or not you have to enable it. So I would say generally on a USB drive, yeah, there's there's probably gonna be a little bit of an upcharge, but for um like an SSD, uh especially uh an NVMe these days, it's probably already there. You the user just doesn't know about it.

Adam Shaffer - Host

Yeah, well, PC prices have gone up, so I don't think they're charging for the encryption, but they're charging for everything else. Oh but uh I was pricing out of Surface the other night. My God. So um interesting. So so if you're a company and you have a bunch of employees and there's a bunch of remote employees, is the play that somebody in IT or somebody in management is saying, hey, we should go by and give these people that work for us,

Policy Ownership Compliance And Chain Of Custody

Adam Shaffer - Host

certain people, these encrypted drives if they're gonna do something with it? Or how how does it how does it actually work? Or is it up to the employee?

Chris Daggett

Usually that's dictated by you know company policy and the sensitivity of the data, right? Um, there are folks that work with all different data types across the board. Um, the folks like the HR executives, things like that. You know, their their rules may be different from somebody in the warehouse.

Adam Shaffer - Host

But is the company making the decision, somebody up high saying, okay, if you're gonna do this, you need to use here. Here's the drive.

Chris Daggett

Yes. Yep. Yeah, it's typically your you know, whoever leads your security practice or your risk.

Adam Shaffer - Host

So it's a it's a corporate decision. If people are gonna take data off-site, whether it's the IT people making backups, they're gonna be okay, you have to use these encrypted drives. But if it's the HR guy or the finance person, somebody, IT security or CISO or somebody is gonna say, you you have to use here's the drives, do not put it on some unencrypted drive. Yep.

Matt Buckley

Yeah, 100%. Uh, with all the regulations and compliance items out there, um, it's I believe mandated in most major ones these days that there's some sort of remote control uh as far as what type of data can be removed or moved off site and on what type of device can it be on.

Adam Shaffer - Host

So is that is that part of like cyber insurance? Are they looking at this also? Or is that not part of the cyber insurance uh play?

Kyle Zemke

Yeah, if it's something in your security policy, usually that's sets up to the cyber insurance as well. Um, I know a lot of uh cyber insurance companies are also mandating uh security training, which is a big one too, especially around you know data protection and labels, like Chris was saying earlier, determining PII or company confidential, etc.

Chris Daggett

And then Adam, there's also another scenario, right? If so, me as an MSP, right? If I'm dealing with a customer that has an environment where data, a large amount of data needs to move from physical site A to physical site B, um, there could be a chain of custody process in place with sign-offs. Um, you know, if it needs to be disposed of, there's a disposal process with sign-offs and certifications and things like that. So again, it's understanding the data that you have and the life cycle of it. You know, um, when it's in production, you need these safeguards in place. When you sunset it, you know, this is what needs to happen. Um, but it's all about following the the correct protocols that are put in place by your risk and your security teams and ensuring that you know everybody in every business plays a role in protecting company data.

Adam Shaffer - Host

But but who who's making the call on it? Who who's the like yeah, I'm um, I can see like a CISO maybe or somebody that works for a CISO in a large company, but now I'm an SMB with 100, 200 people. Who who makes the call on all this stuff?

Chris Daggett

It it could be um compliance driven, um, or it could be, you know, you have a good security uh awareness, you know, as a uh you know, at your your executive level. Um you know, typically, you know, you have a small SMB, you're not gonna have a huge staff, right? So you need to whomever is running that part of the business needs to kind of dictate policy, procedure, you know, SOPs need to be in place, people need to be trained and educated on the the the proper way to move uh data from point A to point B.

Adam Shaffer - Host

You know, I think what you're saying is you're saying you're saying they need a great managed service provider. Exactly.

Matt Buckley

Like Kangaroo has, you know. Yeah, yeah, yeah. We have a we have a great um great company that we work with and they handle all of that for us. Um definitely on the education side. Um, but yeah, yeah, yeah. If you're working in a small place, um you know, you you lean on your known assets. And if you have um, you know, one or two guys that knows generally cybersecurity um or knows that you know we have to be compliant with these items, then you you work towards that. And if you don't have um the skills or the manpower, um, then yeah, yeah, you go to uh to an amazing company like Hub Tech, um and you shameless plug exactly and you uh you ask for assistance. And so um I I look at using your assets and your tools properly. Um so even if you're on a one-man team, there's always a way. Yeah, you can always get help, um one way or another.

Adam Shaffer - Host

Cool. So so you know, just bringing it to down, uh big big picture and trying to wrap things up. If you don't have to let any data ever out of your environment, that would be great. But in a world of remote and backups and physical backups and things need to move around sometimes outside of the network, making sure your data is encrypted, making sure you have uh education in place, making sure that your people aren't just using um naked USB drives, making sure they know the rules, reminding them not to leave their stuff at Starbucks or on the subway. That's that's it. But I mean, it'd be great if nobody ever had to move anything, but it would be uh impossible in the world we live in, especially remote world. So I think that's kind of the big picture. So with that, I think we've got to wrap it up. So any final words, Matt and Kyle, for our listeners?

Matt Buckley

Please don't use AI improperly. Um just be smart. Um, you know, make sure that all your users are trained properly. And for me, you know, make sure that you're looking at what the big picture is. Um you know, having security is fantastic, but if it's too secure and it's impacting the user's life, then they're not going to use it. So finding that fine line between secure and manageable, and secure and definitely not manageable is I think a big item.

Kyle Zemke

Kyle? Yeah, I I completely agree with what Matt was saying. And going back to the uh training and and reaching out for help, don't let the uh normal things start to become automatic where you're not paying attention to changes in the environment, changes in the network, security and cybersecurity in general. We all want to help each other. It's not like a oh, I'm gonna keep the secret. Like there's always help out there. And make sure you'd be nicer to uh Stacy and Susie from accounting. They seem to get picked on a lot in uh these kinds of conversations. Obviously, yeah.

Chris Daggett

For sure.

Adam Shaffer - Host

And Chris, anything you want to say?

Chris Daggett

No, these guys uh summed it up very well. You know, it's I I echo uh what they had said.

Adam Shaffer - Host

So with that, we're gonna wrap up the show and we really appreciate you guys joining. If people want to get in touch with either Matt or Kyle or both, what's the best way to reach out to you guys?

Kyle Zemke

We're online, LinkedIn, kangaroo.com, iStorage dash uk, uh anywhere, or even through HubTech. You know, we can jump on and do another podcast anytime.

Adam Shaffer - Host

Super. So with that, thanks again for joining. Let's do this again sometime. Let's protect our data and don't leave that playbook on the subway. Thank you. And no peanut butter, my god, that was gross. Okay.

Announcement

Thanks for tuning in to the Beyond the Firewall podcast powered by HubTech. If you found this conversation useful, follow or subscribe wherever you listen to stay updated on new episodes. For more information about HubTech's IT solutions and services, please visit hubtech.com.