The Shawn Ryan Show
The Shawn Ryan Show

#328 Kevin Mandia - The Man Who Exposed China's Military Hackers

2h ago3:17:5436,844 words
0:000:00

Kevin Mandia is CEO of Armadin, where he leads the company's mission to secure some of the world's largest and most complex environments. A globally recognized cybersecurity leader, he is also a Gener...

Transcript

EN

[MUSIC]

Kevin Mandio. Welcome to the show. Thank you. Man, cyber, cyber security is saying it, cyber. Cyber got this.

Ready? I'm ready. All right, we're gonna make it cool.

Man, I have been, uh, yeah, I always thought cyber security was boring

until I started, uh, researching new for this interview. Yeah, man, yeah, it's, uh, what a fucking badass. It's a weird world. You know, I've walked the halls of a lot of the headlines, people read in cyber security and the press never really gets it.

You know, nobody really understands what it's like to be a victim of a cyber crime. You know, whether it be someone hacking you to steal all your corporate secrets or extorting you, you know, and, yeah, hey, you got to serve a higher purpose. Mine's always been, you know, the phone rings. I answer it.

And it's a CEO, the other side saying, hey, you know, we're getting ransomed and damn it. We're not paying it. And my response is always like, hey, man, we're not paying it. You know, let's show up.

Uh, but it's a, Sean, let's see if we make this interesting for everybody.

You know, because I remember a judge, I testified once in a case, and the judge was like,

this stuff's so cool. I came away till there was like a NCIS show on it or something like that. I'm like, man, if you can see the war room in a cyber case, it's just really quiet. It looks like you're back room right there with those guys, you know, to be, and everybody's clicking on a computer going click to be, click, and there's nothing to see, but you

can see the emotional changes in the victims, you know what I mean? You can see it on the face. So we'll, we'll make it real. What is, let's talk about, what does the victim go through? Yeah.

Oh, they're like a worst case scenario for everybody here. You know, there's nothing, here's bad. You're an executive at a company and somebody breaks in and your email gets released. Now Google searchable, every, you know, you're at, let's say you got a Fortune 100, Fortune 500 company or your photos get released, you know, things like that, your private

thoughts get released. I've seen, I've been in the room with executives when they're very mail got posted. Nobody ever should have to go through that. I just, it's just the terrible thing to see. Even I get physiologically like I can't eat, no, I'm like, man, this is, this is bad.

So I think that's the worst thing, it personally impacts people, it gets exaggerated.

The press does search your emails, they do write articles about people. And it's happened to actors, you know, their photos get stolen, it happens to kids, like during our interview today, it's going to happen to some 20-year-old college kid, you know, where their photos get stolen, nobody should ever go through that stuff. So to me, those are the ones that hurt the most, company survived them, you know, you

get back up and running, you get your operations running, you get over the reputational hits that happen sometimes, I just feel for the people that, you know, go through losing the email. Yeah. And by the way, it goes in stage, they lose the email, like a month later, they lose their

family. You know, I mean, some of these things are pretty bad.

Is that how they always start, they always started your email?

No, the intrusions are all different, right? It depends on who's doing it, you know, you have the modern nations China and Russia, Iran, North Korea, North Korea hacks from money, take them off. But China hacks for respinosh, you know, so if they break into your company, they'll break into the defense industrial base, they'll break into any company doing business in China,

and they steal emails, they steal things, communications. But they don't post it online, Sean, they don't extort you, they follow rules of engagement that whatever their doctrine is, they follow it, but it's not destructive, they don't change your data, they're kind of like the plight hackers, but criminals, it's gotten hard.

And because they want to monetize any breach they've got, so they, they pull on every thread to monetize it, right? So if, if the Sean Ryan show got compromised, what they would try to do to you is steal your email, steal things that matter to you and say we're going to share with the world, I mean, should pass $5 million, $10 million.

And those are the ones that are, you know, you're always making the least bad of 10 decisions,

you know. So, short as the answer, people hack for espionage, security, scaring a nation, people maybe even hack, you know, espionage to me, supports diplomacy, and then people hack for criminal reasons. And then probably there's a third they just hack for the game of it, you know, the

attractive nuisance of it, and I don't really respond to too many of those, you know. What do you recommend for people to, like, individuals, not who executives, but just individuals

who have had the photos, they're emails had, did they pay the ransom?

Oh, it depends, meaning it's already happened. Yeah. It is, I've never said, pay the ransom or don't pay the ransom. I've never said that, but I've been in the room when people think about it. And I've sat there going, man, I think I'd pay this one.

Like if you're a hospital, somebody breaks in and they've encrypted every machine so they're unusable.

They say for $10 million, we're going to hand you back a key to unlock all yo...

again. You got two options. You either get an every doctor in a room saying, what surgeries can we do? Which surgeries can we not do? Or you're evacuating patients or you're diverting ambulances or you're paying a ransom.

And that situation, I never will pine, but boy, if I said, oh, I get it, you know, I'd

pay that one and get back online. So I've seen people pay extortions and pay ransoms and the difference is, a ransom is to

like get a key to decrypt your things. Like people will ransom and say, I've hacked into

your network. I've shut down 10,000 machines for 10 million bucks. I'll turn them back on for you. And that one, you know, if lives are at stake or you want to protect the privacy, the second of the extortion is, I've hacked in, I've stolen emails. I've stolen client data. I've hacked the law firm and I've taken your briefs. Yeah, those extortions are really painful. It's I will release the data unless you pay

me. And I see people pay it because you're protecting your customers or you're protecting people in general. So hospitals will pay. Law firms would pay. Yeah, it's a tough decision.

I'm, luckily, I've never had to make that decision. I hope I never have to. That's brutal.

Damn. Yeah. Yeah. Think about how to even know that they're going to stop if you pay him. Well, exactly. Like they're only capable of one bad thing, right? And then they're done. And you don't. The reality, though, is usually that if you're getting stored, it's highly probable, whoever's extorting you is in a safe harbor like Russia. I've not others have written that they've seen Chinese actors do this. I have personally never seen a Chinese actor extorted

company or even ransom or company. So I think culturally the Chinese really don't do this.

It comes out of Russia. And the good news is that if somebody in Russia hacks company in the United States, extorts them and company pays that extortion. Let's say they paid $20 million in

Bitcoin and anonymous currency. And then they still leak the data. The reality is, as people just

stop paying the ransom. So I actually think there's a governance over in Russia of, oh, if you get paid, you don't post. Because otherwise, people will stop paying. And they've got a good racket going. So it's been my observation when people pay the vast majority of the time the data does not leak. Makes sense. There are exceptions, Sean. It's rare. I can count the exceptions on a single hand. Wow. And there's probably over a thousand times and we respond to these things. How often is this happening?

Every day. During this call, during, I mean, this interview. It'll happen to somebody. Can we do that? During our interview, an 80-year-old American woman will probably lose 200 grand of her life savings. During our interview, a company will get compromised and probably extorted for $5 to $10 million. It is happening at a rate. And this is not a fear and certainly a doubt thing. Nobody knows the rate. So then you go to the government say, well, how much money is getting paid in Bitcoin every year

to Russian orina's crime? It's in the billions of dollars. Oh, millions. The lowest estimates are billions. All we know is the lowest bounds. But as I say here today, people I've worked with are definitely responding to extortion cases and trying to figure out. And there will be a new one today. A big one. Wow. Damn. And they're handled quietly and discreetly or sometimes they're front page news. You never really know. Wow. Yeah. Well, you're the guy to talk to about all this.

Yeah. And yeah. Exactly. And I sit there and say, hey, but yeah. By the time we get that phone call shown, like that there's been a breach, there's been an extortion. It's tough. You know,

nothing you can do about it except work through it. How do you know, how did you meet Joe Lonstel?

He's the one that couldn't access Joe. Joe, thank you. So that's a great question. First of all, he's a Texan now. So he lives outside Austin. But he moved to Woodside California. He has a place there. And so we met there. And in general, it's a small community. You know what people are doing? And he and I just knew of each other. You know, I knew what he had done with Palantir. He knew I was the cyber person. And just over time you get, you know,

if something happened, he would give me a call. Hey, listen, we got a company that needs this or a company needs that. And, you know, I've been in the cybersecurity domain for 34 years, sooner or later, you're either good at it or you're not doing it. You know, I like things. I'm still pretty good at it. So that's kind of it. You know, when people need, when people had a computer intrusion, we had a unique, my company kind of responded to every boost that mattered.

And so I think I'm on speed dial for a lot of these folks. And probably Lonstel, I'm on a speed dial

When something bad happened somewhere.

cybersecurity incidents. That's a perfect way to put it. Yeah. Let me give you a quick introduction.

Thanks. Kevin Mandia. You have 30 years on the front lines of American cyber defense.

You began your career as a United States Air Force officer serving as a computer security officer at the Pentagon and as a special agent in Air Force counter intelligence. And 2004, with no outside funding, you founded Mandia and spent the next decade building it into the gold standard for incident response. Authored the groundbreaking APT 1 report, exposing China's PLA units 61398 in a sweeping cyber espionage campaign targeting over 140 US companies, a revelation that reshaped

global cybersecurity policy led with transparency during the solar wind's breach publicly disclosing the compromise of fire eye and helping uncover one of the most significant cyber attacks in US history impacting multiple federal agencies. Over saw the four, over saw the 5.4

billion dollar acquisition of Mandian by Google, one of the largest cyber security deals ever

and led the company through integration as the CEO. Most recently, you were the founder of Armadon, a pioneering autonomous AI agents designed to identify and exploit vulnerabilities like nation state attackers backed by a record $189 million from top tier investors, including

Inc Utel, the CIA's investment arm. Why not? How is it working with Inc Utel? Why not?

You know, when you get into the offensive cyber, the cyber domain has been contested my whole life, your whole life, Sean, literally. I mean, it's something that people that are faceless nameless and have no risk and repercussions can rob people, hack people, extort people, steal information and they can do it from 10,000 miles away. And so when we started, you know, Armadon, the whole thing was, we want to support the United States government. Like the cyber

domain is contested, that's at least when it is contested. During times of peace, it's contested. Imagine during a time of war, what it might look like. So getting Inc Utel involved to me, it just felt like the right thing to do. You want to service the intelligence organizations and the military. It makes sense. I am curious, nobody has really come out and said that they have them as an investor. I don't think we just don't know how you knew that.

Wasn't the first one I would have listed. Because now, you know, you try to do business in

Germany. They're going to be like, all the US governments inside of Armadon, they're not. It's just, you want to support the warfighter. You want to support our intelligence agencies. And you want to believe, you know, America can be the beacon on the hill still. So do they have any specific stipulations that they want inside into your company that other venture capital firms are not going to, are not going to have access to? Well, you know, it's this funny that we're talking

Inc Utel is the latest Dan Brown book, Inc Utel are the bad guys in Oshia, true story. They're

the bad guys somehow. It's been my career like, I'm biased. I believe in the institutions of the US

government. You know, I served in the military. People can, people can, every institution can have its downsides and upsides. But you look at the missions of what we try to do. We try to do the right thing, you know. And it's the fastest way to bring capability to the intelligence agencies into the military is through Inc Utel sometimes. And I believe in what we're doing. And I want to make sure the American Warfighter has the advantage in the cyber domain. That's simple. Do they

have covenant? I'm sure they do. You know, did I sit here and memorize them for you show? No. I do know, they, you know, they'll attend the board meetings when we happen. And as an entrepreneur, you'll learn if you haven't yet. Man, board meetings can be long. And I've been the operator at board meetings. I'm trying to push these things off as long as I can. You know, let's start them

when when finally we will start board meetings. That's the problem. I was unfunded the first time.

So I didn't have board meetings for the first seven years of mandarin. But now I've done funding. And I'm like, should I be doing a board meeting yet? And I'm just going to sit quietly. Now, it's someone who'll listen to the show and say, "Okay, Mandy, I have a board meeting." I'm not going to really schedule until someone's begging for, you know. But I'm sure and you tell will show up. And the others will show up. But we are so early on. What's the value

in a board meeting? Yeah. You know, it's, it's, they think there's value. What are you doing with money? For me, it's let us prove ourselves and let's get some things done first. So I'm not sure I need a 90 day cadence yet. All right. All right. I just spoke my mind and I'll have one in two weeks.

I've been using Ridge for a while.

and make it cleaner, tougher, and more functional. While it's power banks, luggage, travel gear, all the stuff you actually carry in use. In fact, their power banks, I just got three charges off one

bank at the airport. Amazing. And now, Ridge is back with their annual sweepstakes for the sixth

year. And this one is insane. Two winners get to choose between a Lamborghini oracon, Storato, a Hennessy Velociraptor, a custom Ford Bronco, or $100,000 in cash. I'd probably take the Velociraptor. It's got $558 horsepower twin turbo and it's basically American muscle built into an all-terrain truck. That's a hard one to pass up. Even if you don't win, Ridge is still worth checking out. Their power bank has built in cables wireless charging,

magsave compatibility, and enough power for up to three full phone charges. Their wallets are slim,

durable, and built for every day carry. Ready to upgrade your wallet and maybe your ride?

For a limited time only, head to Ridge.com and use code SRS to check out for 10% off your order

and a chance to win Ridge's biggest sweepstakes ever. A Lamborghini oracon, Storato, a Hennessy Velociraptor, a Ford Bronco, or $100,000 in cash. No purchase necessary to enter, but every dollar you spend gets you more entries. That's Ridge.com and use code SRS. After you purchase, they'll ask you where you heard about them. Please support our show and tell them our show sent you. As you guys know, once upon a time I was in ABCL and then I contracted for CIA. We were hunting

ISIS, Taliban, terrorist organizations. China was there. Russia was there. The Iranians were there and everybody's kind of collecting on each other. One thing I learned is how important encryption

and protecting your data is. That experience is just always made me extremely paranoid about

what's being sucked out of my phone, what information are people getting? I wanted something that

could protect everybody and so we turned it into an application. We call it the Glacier App. We have Secure DNS. Now what's Secure DNS? Well very simply put Secure DNS keeps your phone from being exploited while you're browsing the internet. Just a couple of buttons. Your phone's protected. You got yourself a burner number or more. You hit connect. Done. You're protected. This is like the real James Bond ship and my six CIA level stuff made in the U.S. The Glacier App.com

or just go on the App Store and look up the Glacier App. Take your privacy back. Download Glacier today. Well before we get to into the weeds here, this is going to be a fascinating interview. I don't think anybody can make cyber as exciting as you can in your back story. Yeah. Wow. But everybody gets a gift. Oh thanks.

We've got you a couple. Thank you. Oh thank you. Those are vigilance league gummy bears made in

the USA legal in all 50 states. Not that you have to worry about that being out in Cali. But

and I'm the guy at the street store. It's in south all right now in the hotel. There's a little white bag on my table with your gift in it. So I'm going to send you something as well. And I apologize that didn't bring with me out. So you're to get here. I ran out to the car without it. No sweat. I got you one other thing to this. Okay. This is the most exciting. Yes. So here you go. Yes. So that is, that's just an iPhone. But that is, that has our new application in there.

So I got really paranoid through some of the interviews that I've been doing. This for me. This for you. I want, I want your honest feedback on that. All right. You'll get it. Wow. Thank you. So I'll give you the backstory. So I started getting paranoid about a lot of the people that I'm connected with. Okay. In the US, out of the US, then we did an interview in Taiwan with about she can. Okay. You know, all about China, we're going to talk about it later. So I started

getting really paranoid. And I wanted about my email, about my text, about my phone. Right. And secure. So I started asking a lot of the former buddies or buddies of mine that were former Intel guys. Hey, what is the latest and greatest black phone? And so I got pointed this company called Glacier. Okay. Yeah. And so Glacier was started by a handful of former Intel guys over at NSA. And so I got to talk them with them. I got one of their phones and their phones are

awesome. They, they secure VPN, all American VPN, secure DNS. They will upload and take away your

Footprint.

got back home, can re-upload it if we go back. So nothing looks fishy. And then they have also

they have virtual numbers. So I talked to them a lot about how to disappear off the internet.

And they basically said, hey, you, you have to, you need to keep that number. Your real number

sacred. So what we have here is that's awesome. You can put it in boxy to it. Any area code you want. It'll give you a list of burner numbers. It's got a great case. Thank you. It's like pull a proof right? Well, so it was hard, but we got it on the iPhone. Nice. And because nobody, nobody wants to use an Android. So that was a challenge. Yeah. The device is extremely expensive. So when I talked about going into business with them, I said, hey, you know, this is really expensive for the

everyday user, not only for the device, but for the subscription. Right. Well, a lot of money. And so I said, what would be greatest if we could, we could dub this down into an application that's a lot more consumer friendly. So we took everything, almost everything that Glacier has put it into an app. And like I said, it's it's a full-blown security suite on your privacy app on your phone, but so I'd love you're honest with you. No, you'll get it. And it's weird. So now, one of the things

I had to learn throughout my careers, how to solve the read-write storm to lead data. What's the app really do? You know, so we'll end up kind of reversing it. We'll kind of try to figure that out.

But I think you're right to be paranoid. You know what I mean? It is a strange world where,

you know, the digital exhaust we leave behind is way high, way higher than people think. Every time you browse the web, you know, whether you say, hey, I want cookies or don't want cookies. You're getting them, you know, we had a company come in and pitch us on a, we got a cookie tracker. And I'm like, you know, we didn't invest in it, but we went out and just tested their software. During, you know, while the entrepreneur was pitching us on, hey, listen, this is, this is what happens.

And we went to a medical site that everybody uses. And when we connected to a child, of course, we got the prompt. Do you want to accept cookies or not? We're like, hell, no. We got a bunch. We got over 900 cookies, just by doing one search on one site about a specific disease. And those cookies come onto your hard drive. And then when you go to other sites, you're letting a marketing company know, or you're letting a PR firm know, or in this case,

we looked at all the cookies. And one of them was dot argue, like we were sending RIP address in the site to revisiting to somewhere in Russia. And so this, this whole, yeah, like everybody, we have a whole generation, by the way, it's probably waving the right to privacy by posting everything on Facebook, you know, meta. And, but I get it, you know, it's right, it's like if I had to give one privacy tip, use iOS devices, use Apple, really, yeah, totally. It's not, if you look at,

by the way, simplest metric in the world on, hey, what's really secure? Look at the payouts.

If somebody has a zero click exploit for the iOS phone, it's in some places, it's $20 million,

and Apple itself, I think you can get four to six million on the bug bounty program.

Like if you find a zero click, someone just, hey, that looks interesting, they don't touch anything. iOS is hard to compromise. And they really, anyone who's on offense and can compromise it, it'll probably be a modern nation and they're really coming after you. But that doesn't mean it's undoable. So I love the fact that you picked iOS as the platform, and I think it's right. Thank you. And, and I think more and more people probably should think,

where is my data going? Who's getting it? Well, the other thing that I've actually can't believe in, I've got to mention this, there's, there's data blocking. So everything gets sucked out of your phone is no longer getting sucked out with that application. So it's a link in the description for anybody that wants to check it out. But you just mentioned, so when I was researching you, and we were talking about the China, that was a section I was in the China,

what is the sixth one, sixth one, sixth one, three, nine eight, sixth one, three, nine eight, and when I was researching that, you had mentioned that if anybody had done business in China, you're compromised. Pretty much. Isn't Apple knowing China, it business, well, they probably work compromised in some way. It's an interesting thing about Apple. My whole career, Apple's

never called and said, hey, man, can you respond to a breacher? So there's a couple, like, if I

went through the whole fortune 100, there might be eight of them that didn't hire us to respond to a breacher, and that said, and Apple's one of them. And there's a couple places, you know, Goldman's one, you know, they have usually homogenous networks, very similar, lots of tight controls.

If anything does happen, they detect it quickly and respond quickly.

me as one of those companies. That's pretty damn good. It's a good, you know, I mean, good to hear that. Yeah, it's, it's just, there's something different about them. I mean, think about what they did with the iOS, they closed it. It's not like you can just write an app and do it. You've got to use their libraries, their APIs, and publish it their way. You know, no one really jail breaks the iOS phone to put whatever they want on it. So if you, for the most

part, you almost have to hack yourself to hack your iPhone. You know, because a window should pop up. Hey, this software is unsafe. You have to go, I'll take it, you know, and hit it. So except for the, the, the rarest of cases is you're really targeted by like a foreign intelligence service.

That's about the only way I think you're going to see a phone get popped. Okay. Yeah.

Okay. Which is good to know. Yeah. Now it's a good selection. Thank you. Thank you. You nailed it. Right on. Well, let's, uh, let's, I want to do a full blown life story. All right. I'm ready. Where did you grow up? Where did you grow up? Where did I grow up? Farming of yours, Pittsburgh, Pennsylvania, during like the crappiest decades of living Pittsburgh. Yeah. We're winning Super Bowls. That's about the only thing we're winning. Yeah. Not a bad thing. 70s and 80s. Every steel

mill closing down. You know, I still remember, uh, probably 1983, 1984, coming home from school, my dad.

I, you know, don't know me. My dad never sat at the kitchen table unless he was eating.

And I came home from school one day and A. He was home. B. He was sitting at the kitchen table. And then it hit me something's different. And he lost his job. You know what I mean? And I remember in an instant, you know, non-verbal communication could say it all sometimes. I instantly thought, man, he'd pit cancer over this. You know what I mean? And so Pittsburgh was a rough place to grow up. And I spent, you know, the late 70s and early 80s there. And then moved away from there and I'm

back to there. And I still remember when we left to come. Man, I don't want everyone to go back there. That it three years later, by the way, hey, we're heading back. Uh, so anyway,

formative years Pittsburgh, great people, tough town. Uh, I think if you were in Pittsburgh from

1970 and 1985, all you saw is, uh, you know, a tough place. Yeah, I like Detroit. You know what I mean? Sister City Detroit, I feel for that place. Yeah, what we're into is a kid football, right? It's Pittsburgh. You know, football baseball, basketball. Um, I was as young as the four boys. I think that matters, you know, you got somebody, you know, the living, Alice Cooper fan and, you know, older brother, you know, you learn about rock music. You know, I was ten years younger,

my oldest brother. Uh, so I got a real education on music early. Um, everybody played football. Everybody, you know, didn't matter where, you know, it's a, you go in the back yard and pummel each other. Uh, you had to, you know, so it was football baseball basketball. And then you go to entertainment. It was like Magnum PI Quincy shows you probably don't know. I mean, we don't know. I know Magnum PI. You got fresh Prince Bill air. I got Quincy. The, uh, but you

get it. It, it was, uh, you know, Pittsburgh was a black and white city. You know, you move away from that and you get to see color. But in Pittsburgh, when I meant by that, it's just, it was gray. It was,

it was like, it felt like it was always winter. You know, and in hindsight, you don't know it

to you leave it and look back on it. It was depressed state. Like the people were all struggling.

You know, period, you know, and I was in one of the nicer towns. Uh, but I think I was in the sports,

you know, and then not a father who's old school, right? Old school is, hey, sun get days. What that meant is get days are all kick your ass. Yeah. That is, or winter. Similar, life's going to get real hard for you. I mean, I, I, I did, I didn't, I didn't want to find out what the alternative was. I found out. Yeah. That shot. Well, you know it then, right? I mean, my dad had a set of rules that if you broke him, you did get hit. And it was fast. I always was like,

how does this large man move so quickly? You know, uh, but he was consistent about it. You know, people are like, hey, Corporal punishment is bad. For me, at the youngest of four boys, I think it was necessary in a way. You know what I mean? Like, we were probably going to be pretty, my dad liked the order, quiet, clean. And I don't think you would get that naturally, without some enforcement, you know, and at the edge, as they say, and my dad had that. So,

I knew every time when I was going to be disciplined, it never surprised me other than how fast

he could move to do it. And by the way, would it done no good the product? Because I would have just made it worse. You know, you just got to stay there and tell you, and it wasn't like BP. It was just, you know, we had a discipline to it. Um, and so, you know, going back to original question one I was into was probably saying that every teenage boy and person was in the sports. Except I was a Vikings fan for some damn reason. Well, yeah, brought up. I figured that one out.

So, how did you, how did you, were you into cybersecurity by the time you joined here? No, I didn't even exist. So, I get a near force in 93, but you know, I graduated college in 92,

Back then there was a little bit of a lag.

riffs going on, and you could do ROTC and never actually get orders. You know, so it was an interesting

time for the military. It was time of peace for the most part. We had done Kuwait in the 1990

Desert Storm. So, I graduated college in 92, but I grew up, you know, I thought Magnum Pia was cool. You know, he's from a military. He was a, you know, soft cases. I always felt like you, you got to have a mission bigger and solve. You got to, you know, when you contribute to society, and I grew up a forensic fan. I mentioned Quincy earlier. I used to watch Quincy go, hey, man, let's solve cases. I did computer science and college from 88 to 92,

because I grew up with Pong. I still remember the first Pong game in Tendo. Wow. In television, the Odyssey by Magnum Vox. Like I grew up with the whole Atari 2600. You grew up these games, and that kind of gets you into computers. So by the time 1980 or 1981, I'm 10 or 11 years old, my Christmas present was the TLS 80 color computer. Like other kids are asking for honor,

a stretch arm strong and rock 'em, sock 'em, robots. And I'm like, hey, man, can I get a computer?

And my dad, my mom, my grandparents all pitched in and bought me like the $700 Christmas present, which back then is like, you're kidding. That's like better than a car Magnum, that actually shot.

So in hindsight, it should probably be more thankful. So in 1988, you want to get my first computer,

and even though I'm playing football baseball, basketball, running track, and I'll use pummeling people that I'd come in and be like, hey, man, I like this computer crap. You know, so I kind of grew up with the computer. I get computer science RTC at a small school in Pennsylvania called Lafayette College, where I went all out. I took a pencil, filled out the common application, planted one school, got in and went there. So it was none of this 20 schools, Ted schools. I had

like no plan B, as applied to Lafayette, did RTC at Lehigh, and did computer science. And I got stationed at a Pentagon in 1993. And the way I got into cybersecurity was I got a station of Pentagon was six, second of the tenets. And we were all waiting in line to go in to see an O6, a Colonel, full-bird Air Force Colonel, where a station I was called, the seventh communications group. And we were all, you know, chicken shitting out in the hallway who wants to go first,

what do you want to do people want to do? And I'll tell you there's this elaborate plan for me to go into cybersecurity, but what really happened is I went first. I was like, I'll go meet the Colonel, I'll go free, just crap out. So I just get first in line and I go in and the O6 behind the desk gives me, and literally there's a whole thing you go in, you know, stand at a tension, go to that, use and wait. And he lays out five options for my next couple years.

Here's what you're assuming can be. So I actually had a choice. And all the choices were bad.

And it was the weirdest thing, Sean, right at the end of it. I still remember it. He was like,

oh, when we have one slot left, one job left to do computer security. That's what he called it.

And I remember thinking all five options prior to that were horrible. Like it would have sent us to me to death. It was like job control language, mainframe programming, and the basement of the Pentagon. When he said there was one slot left, I'm a sucker for there's only one left, you know. And so I'm like, I'll take that. There's only one left. That's valuable. And you know, I'm in hindsight, I'm back to the new, you know, it ends up playing out very well. I've loved

forensics. I ended up getting a master's in forensic science at GW on my own time, I'm all serving. And computer security work, like I immediately had this job doing computer security. And what it was is who's accessing what? And about a year into me doing that job, it was 1993, the Air Force put eyes on the network for the first time. I mean, for the first time every started watching, what are people doing on the network? So I kind of got to grow up with computer security. You know,

we started watching people. The Department of Energy created a tool called the automated security incident measurement tool. Interesting. And we deployed it at the Pentagon. And for first time, every we can see what are people doing? Like what files are they transferring? And what commands are they doing? And where are they logging into? And when we lit it up, right away, we recognized weight. We're not the only ones on this network. You know what I mean? Who are these

other people audit? And so by 1995, I cross-trained into the Air Force Office of Special Investigations from Computer Security to do computer intrusion investigations. The military was starting to use the internet, you know, from 93 onwards. So we had to start figuring out who the hell's on our networks and what the hell are they up to? Who was on the networks? First one I ran into is China. Literally, go all the way back to, um, maybe a summer, 95, might have been summer, 96.

One of those summers, we, you know, at that point we had the Air Force Comput...

Team. The Air Force had one. I don't think the Army had one yet. I don't think the Navy had one yet.

And then the government had one called U.S. Cert out of Carnegie Mellon University in Pittsburgh. And so maybe there's something in the water Pittsburgh to get you into this stuff. But I, uh,

I remember, um, there was a West Coast University. I mean, the Air Force Office special investigations

in our Asim boxes showed something like 20 Air Force Paces were logged into from one university. What the hell's going on? Like no university should be logging into that many, you know, right Patterson Air Force Base, Oak Ridge, Lawrence Livermore, Los Alamos, uh, right Patterson, all of them. And they were, and, and so I flew out to the university and at that time frame. I'm in the United States military. I go to this university and I'm like, do you mind if I

monitor all traffic tuned from this machine? Now, everybody's listening to this being like, the government watches everything. We really didn't back then. I did brief the judge advocate general, hey, this is what I want to do. And to the Air Force is credit, if we did a, what we would call wire tap, and there was nothing fruitful in it. Oh, it got killed fast. Like you had to have fruitful real results or a jag was going to stop it. Get out. There, there, there was a

great control to not want and watch. But the university allowed consent. I don't know. You know, the, I often wonder if the military is the same as when I grew up maybe a topic for later, because to me, um, but then it absolutely was. I remember going, man, I need to tap this, because someone's coming from somewhere in the world into this system. And then from there, to all these military installations. So I got consent to monitor to the colleges or the

universities credit. They were like, yeah, go ahead and do it. And then I, the way I did tap back then, I just ran software on the machine itself. You know, it was a, it was a Unix machine. And I watched

all incoming traffic in the first day. I'll never forget this shot. Some are of 95, or 96 is one of

those two. The very first day I did the tap. Somebody was logging, this is how you go one hop back

every time. Like when somebody hacked you, we don't only know the first, like IP address or first address they came from. But in computer, you can connect the connect, the connect, the connect, and they're called hop points. And everybody obfuscates where they're really sitting. If you're sitting in Russia and hacking, you know, the Pentagon, you're not going straight from dot r u to Pentagon. You're going from dot r u to the uk to China to where we want. How do you pick those?

They compromise them first. Like if you're on offense, you have a network that you use to launch your attacks. And for the most part, you almost have a team that maintains that compromise and infrastructure for you. So if I'm a foreign intelligence service, I have a team that maintains access on these intermittent sites, not my real targets, just sites like universities and businesses. And it's called a non-attributed network of victim machines. At least this is

how other nations do it against United States. And then they have their operators use that infrastructure. And that's exactly what we ran into in this case. I do this tap out of West Coast University, the very first morning, I go in and down the files to look at what happened. Somebody came directly from Beijing into West Coast University using the account of a Chinese foreign nation. I went to this college, but I had since graduated and logged into 37 or so military installations.

And each login was somewhat haunting. They used an user ID like S. Ryan and then a passphrase. Then the next one, they would go to like right Pat and go, John J Smith and the right passphrase. They were validating accounts at all these different places. And I had the right choke point to see all the traffic. They came to this one machine, logged into right Pat, logged out, logged into Los Oak Ridge, logged out, logged in, you know, Los Almost, logged out, right Pat,

to keep going down the list. And they never fat-fingered the passphrase that got in every time.

And I remember thinking, how do we fix this? Like you can't, we call 37 bases, who do you call?

They were hitting Army, they were hitting Air Force, they had the Marine Corps, they had us all. I mean, just for the viewer context here, those are the most secure secret military bases that the U.S. has. Yeah, it's just the protocosted author. Yeah, and it was just, it was the defense research and engineering network is essentially what these guys are in. And the unfortunate reality in hacking, or fortunate in a few of their offense,

like if I break into the Pentagon, it's just a matter of time before I break into all the other military installations. If you break into an Ivy League school, you're going to be able to hack all the Ivy League. Because that's just where the traffic goes. That's where the information is shared.

That's what happened here.

And that was in the 90s. So, and I remember, there was no one to call, but that case went on for like

10 years. I mean, I had code names and classified names and it just kept going. There was nowhere,

I was a firstly tenant at the time. I mean, what do I do call the base? Like, hello, operator. I need the cybersecurity guy. There wasn't, there was no way to remediate it. That's simple. So, instead, what we ended up doing is running an operation largely run by the military, jointly with the FBI and we did counterintelligence. We just watched it. And then we found the Russians.

For me, every day, let's just shortcut. It is 2026. My first incident response is 1995. So, it's been

31 years. I would say every day of my 31 years, we've been responding to an intrusion out of China, somewhere on the planet here on every single day. And by the way, not just one way more than that. So, they have mass. They have just the scale that they can operate at. That's pretty high. And then probably the Russian S.V.R. had counter-friends earlier. So, they would go dark on us. And back in my day, Sean, if I responded, it is an Air Force special agent. What was amazing

to me, if I responded to Russia, every time we caught them, they just went away. They were like,

"Ah, you got us. We're going to go away for now." And there was almost like rules of engagement. If they got caught spine, they just went away. And you can tell when someone's monitoring what you're doing, you can find the tools we use or you can see that we're starting to remediate and clean up around

you or we shut off the account that you're using or we change past phrases. And the Russians never let

us observe them. Period. From literally from 1995, 1996, any time I responded to a Russian-based interest, they were super stealthy. That did change right around 2015 where they got louder and probably they stretched their mission too much to do counter forensics and counter surveillance stuff. But data, 20-year-long, we'd have them in our sights and lose them. And I went years not finding them. Like, literally, we know they're out there because that's their day job.

You know what I mean? They're paid to hack us. They show up everyday, badgeny of building and do it. But most of those cases probably got classified and I was on the outside by then. But they were really hard to find. China was more like a tank through a cornfield. I mean, they were just like, they didn't care if we saw them. They didn't do counter forensics. They didn't change data. They didn't extort. They didn't do anything. They just stole everything.

You know? Who do you think is better? It sounds like Russia's better at it. You know, yeah. For the vast majority of my 31 years responding, Russia was better, better tradecraft. Yeah. There are operators really didn't like getting caught.

You know? And they just, here's an example. Like, I think China just had so many people

shown. Like, I just said the other day, I knew a lot about religion because I took art history. I feel like I know a lot about the Chinese culture just by responding to intrusions. They definitely threw people out. And here's an example. If a Russian hacked your machine, what they would do is they would bring their own way to search your machine. They would hack your computer, then write it upload a file that would search everything on your machine looking

for specific keywords, whatever they're after, or they just grab your email. And even when they grabbed email, they would minimize it. They grabbed like the last month's worth or something like that.

They were always very precision strike. If a Chinese operator got on your machine,

alphabetically, filed by file and directed by directory, they looked through your machine. Because they had, and I thought about it, they have human capital. There's eight hours in the day. There'd be an operator on a keyboard going on on Sean's machine. Let me just look at this file. And literally, they almost did it alphabetically. The second thing I noticed is, early in my career, the SVR would always steal the foreign intelligence service out of Russia,

the SVR would always steal specific files respond to what they wanted. They were just real good at that. The Chinese would just compress a whole directory and steal it. Like if you ever used like zip or something like that, they would say, oh, this directory called documents looks interesting. I'm going to take the whole thing. So I could actually tell who the operators were just by the data theft. I'd be like, that was Russia. They took 32 files. That was China. They took three

terabytes of everything. Because China, you would even steal operating system files that were the same on every machine. But it's just that operators that would go, that was an interesting directory. I'll take everything at it. That was an interesting directory. I'll take everything there. I'm sure they had a unit that was more precise, more stealthy, every nation does. But China took front seat in 2020. Every year at the end of, so from 2004 to 2025, I worked at Mandy at

my company. At the end of the year, I'd be like, hey, guys, brief me on the coolest cases we got.

For the most part, I got involved in those during the year.

the Chinese government break in using what's called a zero day attack. There's no patch

to it. It's similar to like when we were talking early about stocks net. Zero days are attacks

that work against an application. And you can't stop. They will simply work. And the goal of attackers is to get remote access to your machine. So I can be 10,000 miles away and get to your phone or 10,000 miles away and get to your server or desktop. And then it's usually, I want your email. I want your files that you've created. I want reports that you're writing about our supreme leader or whatever might be. And in 2020, the most expensive offence of attack was done by China.

They used multiple zero days to break into a defense industrial based company. And everything they did, they were special. Like everything they did had to be custom crafted for that environment.

That is in my whole career. That is very, very rare. And China did it. So I'd say China's number one

now for scale scope and sophistication. And then China decided to get stealthy in 2020 as well. They weren't prior to that. They decided to, from a forensic standpoint, leave less fingerprints.

Wow. And Rush went the other way. By the way, Rush is now like we found them. And I think

Rush, you're with conflict and everything. They're just operating at such a scale and scope that they can't. They don't have enough operators to clean up after themselves. And it's very manual to clean up after yourself. It takes a human intelligence on a keyboard to say, I don't want to leave a trace on this machine. So I have to edit the log file, take myself out. You know, so the counter forensics of Rush is down in a notch or two right now. I mean, you were, you were

tracking nation-state hackers before the majority of people even had email.

Yeah, I think you were the first ones to do it. When you walked into that, what was the program

you were at? Well, so I made it. I mean, yeah. Yeah. Yeah. So I had to move the way. Yeah. So I had a master's in forensic science. So you can think about all these intrusions I'm responded to or like crime scenes. Like what are the fingerprints left behind by the intruders? What's the malicious code they run? It's the commands they execute. It's the encryption algorithms they use. It's the type of files they steal. It's the type of targets they even compromise. And so with my

forensic science background, I created a thing called an indicator of compromise. I, you know, I'd worked enough cases where we're like, we got to call the fingerprints something. So the indicators and we started just bucket ties in. So we respond to company A and be like, oh, the attack came from here. They use this software. And as we bucket ties or catalog the evidence, we started just seeing the same people over and over. They use the same custom code to break in.

Like I give you a weird one. Like if you break into the two dominant operating systems, our unix based operating system, UNIX and Windows. And Mac is a unix derivative. You know, in in Windows, if you break in, you do what's called a directory command. I've broken in and I want to see what's on your hard drive. I'll do DIR and just kind of look at what's on there. No, and the Russians, when they break in, they do a directory listing of everything on your drive.

And that's all they do. It's really smart. It's a great recon. They don't even poke around sometimes. They break in and go, just show me a map of everything on the machine. They download the map and five days later, come back and just take what they want it. The Chinese would break in, show me everything. And then go through it alphabetically with a human, just sitting there 10,000 miles away, looking at every single file and doing it. So we even cataloged

in UNIX. The DIR command is called LS for list. And we would catalog, did they do an LS-AL?

Option or LS-LA? Different operators typed it differently. And we could even get down to the speed at which they typed. I mean, we were tracking on a lot of cases. We had it up to 650 criteria. We would track, but only like 10 mattered. Longs were made sure. We just took the fingerprints of each group. And it turns out the Chinese did great training. And the Russians did great training. So they were actually really consistent. You know, the commands they typed. If you're a kid and you break

into a machine, you just get undisciplined. You start going, I'll check out this directory. And then randomly this directory. And then randomly this. And I'll look over here and I'll do this. And they're all over the place. It looks like a monkey's shit fight at the zoo, right? And then you responded yes, we are. And it's just all economics. They did a directory listing and left. That's it. God, kids don't do that. Foreign intelligence service to do that. Because they're going to come back

in after they've looked at the file listing. And just by names alone, they know what they want. Or even the apps they want to steal. And at the time I started responding to intrusions in 95,

We didn't export our super computers.

systems were done on super computers. The crazy 90, the origin 2000. The front nodes to all the

super computers were what we would respond to. The Chinese and Russians would hack these things.

And literally they would run our modeling and simulation on our systems. But export the output

all the way back to the China Russian. And that amazing. So one of the first cases I would

do with Russia, they were literally running, they were stealing stuff. And they were running the modeling and simulation of a certain system we were creating on classified though. But they were exporting the display right to their desktop. So they were just sitting back watching, "Oh, there's the model." And this is how it looks. They were literally stealing it that way in 95. So again though, those fingerprints, that's just an example fingerprints. The commands they type,

how fast they type, the malware they use, who they target and how they operate. At my company, mandate, we started creating these dossiers basically. And we were boring. We didn't know what the call, we didn't name the groups like, you know, this is fluffy snuggle dock. And this group's called, you know, whatever bad rabbit. We just called them managers, a pete advanced persistent threat one was China. It actually was PL unit 61398. And we just named them managers. And now we're up to, I don't know,

50 something. And that's where we have definite attribution. Like we can get you to building their

common out of, you know. So when we started this, we had maybe 40 groups in the first eight years

that we had fingerprinted only, 40 different fingerprints for every cybercrime. Now we're in a, I don't know, 6,000. How big was your team back then? Oh, but a time, I mean, was one mean, and then we threw it to about five. Yeah, the whole clock. No, no, no, no, no, I started it, right? But we were about, but a time or labeling groups, APT, 1, 2, 3, we're 350, 350 people. All ex-government, like at one point, mandate was 500 people. And I'd say 350 came from the U.S. military.

I'm sorry, I meant, I meant, oh, just the Intel Air Force. Oh, in the Air Force when you were successful, when I was doing that, there's 13 of us. I think we doubled at the 26. Yeah, it kept doubling. And, you know, cyber was new in 1995 when I was in the Air Force doing this. And so they kept doubling the teams. Now I bet it's hundreds and hundreds. Like if you're a special agent in the FBI today, and you're not digitally forensically educated, you're not very useful. I mean,

you have to know, networks function, how every case has digital evidence now. Counterintelligence,

crime, estimate, all of it, period. But when I started doing this, there was like the computer aware agent and the non-technical, non-computer aware agent. I think that one's almost obsolete at this point. Yeah, unless you're a great accountant or you speak 20 languages. I don't know how you can be an agent today, investigating anything without understanding digital forensics. So, small team, 13, 14 of us massively grew, even while I was doing, we were called computer crime investigators.

And we did the, and the FBI to think called the cart team. I don't even remember what that stands for,

it was like computer forensic stuff. And all I can tell is we're always no matter what, it was

almost like we had a sticking line where we're always six months behind. No matter what the case was, we were six months behind on the forensics. You know, it was like, uh, because it was real hard to keep up with all the digital evidence pile enough. So, here at Sean Ryan Show, we cover subjects they get complicated fast. Intelligence, war, technology. And when you're dealing with topics like that,

the hard part isn't just finding information, it's making sense of it all. That's why we use

Claude. Claude helps us take a messy topic and start connecting the pieces. Timelines, contradictions, different angles, follow-up questions, things we may have missed. It helps us slow down the research process and think more clearly before we ever sit down for an interview. And we use it across the show, episode prep, research, strategy, and even our hot question segment. It's become one of those tools that help sharpen the work behind the scenes. Claude is the AI for minds that don't stop

it good enough. It's the collaborator that actually understands your entire workflow and thinks with you. Whether you're debugging code at midnight or strategizing your next business move, Claude extends your thinking to tackle the problems that matter. And with features like deep research and connectors, Claude can help pull context together from the tools you already use and turn complicated information into something that you can actually work with.

Companies like Stripe and Shopify trust anthropic with the rollout of AI in their businesses. For problems we're solving, get started with Claude at Claude.ai/saurus. That's Claude.ai/saurus

Check out Claude Pro, which includes access to all the features mentioned in ...

Claude.ai/saurus.

Let's talk about if we're ready for this. Let's talk about exposing China the APT-1 report.

February 2013 released a 76 page report publicly naming PLA units 61398, operating from a 12-story building in Shanghai's Poudong district. Yeah. As the source of espionage against 141 U.S. organizations across 20 industries unprecedented. Yeah. Still technology, blueprints, manufacturing processes, test results, business plans, and executives context list. How did you, I mean? Well, this is, yeah. This is all you. Yeah, but I think the government knew. You know, so this was

2013. The back story on that is I start mandarin in 2004 and out of premise, let's respond to every breach that matters because in the cyber domain prior to mandarin, here was the intelligence model in cyber. It was McAfeean's Mantek Anavars. You've probably heard of them, right? McAfeean's Mantek. You'd run Anavars on your machine. If Anavars missed a bad file on malicious file that was

stealing your stuff. The only way semantic a McAfeean got smarter is you would be like, "Hey,

man, you missed this malware." So I'm going to submit it to you so that you can detect it next time.

Well, here's the problem. My mother's never going to find malware on her system. And Sean,

you're never going to find it either unless you read a 800 page book I wrote that report a hell out of you. You know, it's hard to find this crap. It's ridiculous. So I decided we need to new intelligence model in the cyber. Let's learn from all the, all the red teams out there, the offense from Russia, China, the criminal element, North Korea. Let's respond to every breach that matters and learn from it and build the defenses because I thought Anavars and I hate to say it. Thinking semantic a McAfee was

securing you at that time was like believing in the Easter Bunny. I mean, it literally was so easy to invade. I was actually talking to one of your guys earlier. And we were talking about he even experimented with offensive cyber and could have made AV because all you had to do is encrypt or compress your executable, put it on your machine. And when it executed, it would decrypt itself. Meaning you had no signature. So AV would miss it. So long to make short, we needed a new model in

cyber. How do we build better defense? Well, let's actually get in a ring with the offense.

Look at what the hell they're doing. So I think I was the first company ever started with. We're

going to respond every breach that matters. And I got to be honest with you, I didn't know if

breaches would go on forever. But I had that phrase. I think I made my first website and your

entrepreneur. So you know, there is no website team. I had to make my own website back in 2004. And I literally wrote on the website. The first phrase was you cannot solely rely on preventive measures. And that was boring. So I went with security breaches aren't available. No one believed it. I think the only reason Mandy it was successful is out of premise. Security breaches aren't available. We'll respond to everyone that happens so that we can build a better defense against them.

First knowledge, first move from knowledge on what the bad guys are really doing to circumvent defense. Nobody believed that premise. So we had no competition. So every damn major breach my phone rang. I sort of know how to help my number got out there. But we had to be good at it. And then everybody recommended us. And breaches took off. In 2004, when I started a company every election year, both sides have a problem. I can tell you that right now. So in 2004, you get the respond. If you're

respond to Pepsi, you don't respond to Coke. If you're responded, the RNC, you don't respond at the DNC. But those things are heavily targeted. But in 2004, when I started Mandy and writing the summer 2004, we were only like a, I started a company February. By June or July, we're nine people in a basement in Old Town, Alexandria. And we get a phone call from the Defense Industrial Base. And we couldn't respond to it. We're already fully pegged responding to a breach somewhere else,

because it was an election year. But it was Honeywell. And I guess I can say that now, because

that was 20 years ago, they were the first ones I saw, where the Chinese government that I was

responding to and dot mill, the military, just went, I'm going to shoot the headlight over here and hit Honeywell now. Then they go through the whole dip. They go after Lockheed Martin. They go after Boeing. They go after Rolls Royce. They go after UTX and Rathiot. And it was all of us,

Well, you know, they're heavily attacked in the cyber domain every day by China.

Fairish. I mean, I was constantly coming for Lockheed. And these companies have like, what's funny, people would be like, man, the banks have great security. Well, in cyber, the best security I ever saw at one point in time is Lockheed Martin. I mean, what they did on defense was, I mean, all the defense contractors trust me. They do everything they can to secure their stuff. But they also have these joint projects that are, you know, a bunch of mad professors getting

together. But in 2004, 2005, I saw the military of China suddenly expand scope and go after our defense industrial base. And that was right when Mandy had started. So all those companies hired us. And we would respond. And I remember I would brief, hey, this is a guy in Beijing doing this. And, you know, it was the beginning of it. You know, that's when we realized China's all over our

networks. I guess I always knew it, topmilk.mil felt fair game. I think nobody really expected them

in China to suddenly say, hey, let's hit dot com. And then they went way down dot com. They, like, if you're a law firm, if you were an accounting firm, if you were doing business in China, any capacity, they had guys in uniform at you. So they don't separate economic dominance from military dominance in China, probably. You know, they hack. We would hack on offense as a country for security purposes and defense purposes. China hacks for economics. So and then since then,

Sean, everything went public. General Alexander running the NSA, largest theft of IP and human history. You know, to the credit, Chinese didn't damage anything. They didn't delete stuff. In my whole career, responding to the Chinese threat actor, I only saw like one operator, the lead, the logs once. You know what I mean? They leave everything there. But they got way more certitious lately. So yeah, and since 1995, Toneau, China's heavily targeted or defense industrial.

But what, what do you think, and when you figure out that the CCP is hacking into our defense

tech companies are, like, like, Lockheed, Ray, the, like, these are the first of the companies that

hold the keys. Well, I think, you know, a lot of folks think when a nation targets you,

you should be able to withstand it. But I've always thought, like, they now Jiu, while I'll use

this one, you are sealed. If a seal wants to rob the Lego store at the mall, they're going to evade Paul blurt the mall cop and rob the store. You know what I mean? No problem. When you have the Chinese government trying to hack you and your company, you will lose over time. There is nothing, I don't think it's reasonable for the American people to think any company can withstand a foreign intelligence service time to break in and cyber to me. It's not. And, and so I remember early on,

every victim company wouldn't tell anybody, you know, but it became because you'd get you'd say it, and then you'd have pundits on the hill, go, hey, what are your responsibilities to let the Chinese hack you? Are you kidding? It's like your grandmother in an ultimate fighting championship. It's simply an unfair fight, and still is today, even for the companies that do everything they can in cybersecurity. You really don't want to come under the lens of the SBR and the MSS when they

decide to go on offense. It's a tough thing to do. So we had like eight, that's why we went public

in 2013. I mean, I just told you in 2004, the first company I saw China go, hey, we're going after

was Honeywell. And I just, I hate saying that out loud. I don't know if I've ever said that publicly, but with this amount of separation, they can live with it. They, in years ago, man, you know, the thermostat company, but they also made, you know, helicopters and dashboards, and they're a defense contractor, but they all had the Chinese come for them. And it's a soccer punch at that time, from there's no actually true story, Sean. There was no defense for how China was breaking

him back down. It didn't exist. We had no software to detect it, really. You could just log in. You could just do things. There was no reasonable way to defend yourself in the cyber domain against the nation back down. Shit. Yeah. I mean, that's, yeah, pretty fucking scary. Just the enemy just now. Yeah. I'm, you know what I mean? Well, we wouldn't want on you back then when you saw

it happening. But then you're more tactical. Yeah. You know, well, that's why we went public.

You know, we had Mike Rogers, Congressman from Michigan. We had Congressman from Maryland. They wanted to do, they wanted to make it so you could share when you've been compromised. Like stop, like hiding the fact that we're all in this together. They wanted to have more of team ball, like team America. So we decided, let's help the US government with like some information sharing

That when you're hacked and you know it, you can share that information and n...

by the government for doing it. You know, you kind of got a safe harbor. And so we, we recognize two things kind of, there's like eight reasons why we went public with this report. I'll give you three of them. First, Mandy and at the time were bunch of XUS soldiers and we were like, "Skoo China for doing this." You know what I mean? So I wasn't going to be able to stop going public or my team wrote this. I was just a face on it. But we knew it was China from 2004 onwards.

So it took us nine years before we find you said, "Hey, man, let's just tell the world what the house is going on here." Second, you could feel the government knew about this. But they didn't know what to do about it. And at least, you know, the House Intelligence Committee was like, "Let's pass a law that allows people to share information so we can defend each other." And then the third thing was the CEOs were like, "What the hell?" You know, I would sit

out at the CEOs of these companies. They were like, "We're doing a joint project with China. Why do they hack and steal all this crap?" And the companies knew, "Hey, it's on us to defend

ourselves." But they also, at some point in time, I remember thinking, hopefully, maybe if we just

bring it up, the heads of state would actually come up with, "Hey, let's knock this crap off." You can hack us for espionage, but don't hack Disney because they're trying to open Disney China. Or don't hack, you know, whatever, software and company, or somebody else because they're trying to do some bottling in China. It was time to have dialogue. So we did go live in 2013 and do that. It just so happens that the day that Obama was going to meet with Xi Jinping to talk about some

cyber stuff in optimistic sounding, sunny land, California in 2013, that was when I snowed in

week. And that stole the show. So I've always believed since 2004 when I first started responding

as a private company to these intrusions, that neither China nor United States really wants a whole cyber conflict. You know what I mean? Neither nation really wants it. And at least that's two nations that come to the table and probably have a dialogue and come up with rules of engagement. I don't know if you can do that with Russia, too much criminal element. I don't think you can do that with North Korea, and I don't think you can do it with Iran. But China is the one place where I've seen

them follow rules. We have to infer the rules shown when we respond. But China follows rules in etiquette when they act still. Their operators are predictable. Interesting. What kind of stuff

did they steal? It would be hard to say what they didn't. You know? That's why general

Alexander read the testimony from the director of the NSA, largest IP theft in history, Admiral Rogers, after him, General Nakasoni, all of them kind of allude to China's kind of

taken a ton. Now there was a dialogue. After that report, here's what's amazing.

Mandy and what we were doing is we were kind of monitoring victim networks, meaning we sell all traffic coming in and out with consent. And the whole defense industrial base was working together by then. They started a whole consortium. We were rafion and lockied and Boeing. They all worked together to figure out what's kind of doing, how do we thwart this? So they do played team ball now and it's actually pretty organized. But I remember at the time going, we're seeing over 70

companies a month compromised by China right now. Just in our little network of watching what they do. After we went public with that report, it went down to zero for a while. So I think they noticed. We changed behavior. Or some say, well, maybe just lost vision on them. Because when we wrote that report, one of the things we didn't kind of say in the report is we provided that trace evidence, the fingerprints. We provided over 5,000 fingerprints. This is their infrastructure. They're using

the hackers. This is the malware they're using. So all the defense companies that make software to stop it, we could just stop them. So we kind of burn their infrastructure. We burn their methods. Their TTPs or tools, tactics and strategies were fried. So we fried it. So they had to go away anyway and recreate all that stuff. But again, going from anywhere from 10 to 70 companies hacked a month, just in what we could see. And I could tell we probably saw less than 1% of what

they were doing. We'll never know. Did we see 80% or 2% was probably closer to 2. Down to zero

for a few months and then it starts creeping back up again. Just for the audience, can you

can you elaborate on some of the stuff that you thought was most concerning that they had access?

And do flag officers email. I always hated that stuff. You know, because you get to see what contracts matter, what weapon systems matter. I'd never read those emails. You know, I didn't want to know. But when you see a communication of a high-level official gets stolen, I've always felt, oh man, like there's unvarnished truth in that period. Like no matter what we're trying to posture publicly, you really, you've got the the back door story in China as to what we're thinking

How we're going to arbitrate.

and it was in the mid 90s that China got flag officers email, just instinctively went, man, that's bad. First off, the good news, most flag officers, definitely use email back then. But what did you put in it? You thought it was private? You know, and I just felt, I didn't like that. Like

sippernet email? No, no, I've never seen a sippernet breach. You know, not that's got to be physical

separation. I've heard rumors of it. I've never been involved in one, and I don't know. I personally don't think it's happened, but probably a physical security issue if there's a sippernet breach, someone got to a sippernet terminal. They get blueprints to weapons. The problem we've got as a nation is we're so damn open, you know, and academia, everything that becomes classified somewhere was on classified first for the most part. You know, how it's used and who's using it, and where

they're using it, and you use these classified. But we have this, you know, you look at universal Illinois or Bonnesham pain, LSU, Penn State, all these great American universe Harvard MIT. I can name them all. I almost all them Berkeley. They're all doing work with the government. And

you want to, like, the easiest thing to compromise an offense is a university, period. So,

go do it, and go look at the programs and you're probably, I mean, I'm given the playbook, but the Chinese already knew the playbook. The students, I mean, we have a bunch of Chinese foreign nationals at the schools. That's the challenge. And, you know, somebody once came to me, Sean, and they said, hey, man, if you were working out a company in another country, an uncle Sam came to you and said, can you just take this force? Would you do it? I'm like, yeah,

you know, I'll do that for Uncle Sam. I'll do that for you. It's got it. You know, it's an album

unemployable to any foreign company. That's what's happening here. You know, with all the, you know,

we went with this global economy and we said, come work here and we'll take your best and brightest.

The problem is where are their families? And who are they truly loyal to? So, I actually felt,

you know, the compromises occurred because you can do it from 10,000 miles away and there's no risk to it. But I actually felt, and I remember for years working with the defense industrial base, we always thought to ourselves, if we locked down the cyber door, are we just going to have an HR problem? Are we going to be hiring the scientists that steals everything? And most people would rather have a cyber problem than personnel working at their company, stay on their stuff, you know? So,

it's a tough man. When you're heavily targeted, like the div is defense industrial basis, it's a complex place to secure. Wow. It looks like at that time, for a my IP theft by China was an estimated 300 billion in 1.2 million American jobs per year. Impacted? Yeah. I mean, there's no question, like they want in solar power, right? Do you think they have the solar power come as probably every damn one of them? Everybody makes fun of, you know, the space shuttles all look the same.

Well, how did I get it? You know, the least risky way to spy, cyber, period, and probably

the most comprehensive, because when you spy, you want comms, you want the communication, right?

Did they ever, China ever confirmed that they did it? No, when we went live, certain quotes you remember your whole life, I'll probably get this one wrong. But when we went live, you know, we went live because we did that report in conjunction with the New York Times, by the way, deciding that they were going to go live, because they had to report or compromise. They had a reporter named Mike Barbosa, from China, and the Chinese are still in his email.

And you know, when we wrote that report, by the way, I remember it was like a movie in a way, I remember getting on the phone with David Sanger, who wrote the article from New York Times, but all of our press were compromised. They were going after Washington Post. They were going after New York Times, they were going at the USA today. They were going after all the press, because China wants to see what are you going to publish about us before you publish it?

I don't know why, but they do that, especially if you have a bureau in China. And I just remember getting on a call, and on the other side, it's like, yeah, it's Barbosa. You know, if the New York Times wanted to verify PLA unit 61398, so we gave them an address,

and I think Barbosa wasn't checked it out, and like, oh, man, it's like a whole bunch of noodle shops.

And then there's this NSA looking thing with antenna everywhere, right in the middle of them all, and a bunch of dudes in uniform going in every day. We had it right, because we used Google Earth, Sean. We saw the building get built. And that insane, we just watched it grow, you know, on Google. And we went, okay, that's where they're doing it from. We finished it. We figured it out in a couple of ways. Everyone, and you got to look every day to find it, because a lot of evidence will pop up and disappear.

We were finding resumes by Chinese students that were transferring schools or going for jobs.

We had Mandarin speaking folks who were translate these resumes.

This was before you could just use Google translator and just read everything in English. So we had to hire our own translators, and we were translating were resumes. And we kept hearing about this PLA unit 61398, and what people did there. And when you read the bullets, you know, you transferred from Chinese character set English.

It was basically like, you know, we hack for a living. We get our orders. We hack those companies.

That was it. And we had, we knew where they were. But the New York Times went public at the same time frame about their compromise. And they were the first ones, really one of the first victims. Google was another first victim. Google so big when they were hacked by China, they just told everybody. And they actually withdrew doing business in China. They were just like, "Yeah, this isn't worth it."

You know, because China does hack to learn about the Chinese dissidents here and what they're doing. And so, bottom line of, you know, whenever it was ideological conflict, you're going to see cyberactivity. And we have plenty of that right now. Wow. Wow. You know, speaking of China, we've familiar with Pauli Market. Oh yeah, yeah. Speaking of China, people in Pauli Market say,

there is a 93% chance that China will not invade invade Taiwan by the end of 2026. Only 10% say that they say, "What do you think?" I'm talking about this for a while. Yeah, it's at lines 2027.

Yeah, I think that's what people say. You know, to me,

and this is Kevin Mani, anecdotal, you know, dad from California thinking about it, unofficial, I don't think they need to evade it. I think just population growth alone.

You never know the will of a nation, like Ukraine surprised me how hard they're fighting back.

You know, I didn't go over to Ukraine. I didn't know the Ukrainian people. I didn't know the will to be independent. I didn't know if they had the leadership for it. And I think like many Americans, when the invasion happened in February of 22, I remember thinking, "Well, that's going to take three days and look where we're at," right? I mean, this is unbelievable. But then I apply that. I don't know what Taiwan would do either, but it's it's different.

It just feels like we never acknowledged it as a standalone nation. You know, I think no one really recognizes. There's only 12 countries in the world that recognize it as its own nation. And so think about it culturally, how tight it is. And then I think population-wise, I've always just guessed, like, look at Singapore. Like, I think it's 30 to 40% Chinese foreign nationals. Like, how long is it survive? You just look at population growth.

And what point is, is there just a majority? So I think China could just win. Everybody says the population China's going down. I'd be fascinated if we look globally. Is the population of the Chinese culture going down? I doubt it. So I just think that that's a tough one. I don't know. I'm the wrong guy to ask. I just go on

God alone. They might be winning without having the fight. See, that's what I want over there.

They have this thing. I mean, cognitive warfare. It seems to be the thing that the Taiwanese are most concerned about. Yeah. It'd be, I'd be basically, in a nutshell, it's a SIOP to convince the Taiwanese people that they still belong to China. Well, and then I just don't know throughout history. They've been offensive when we're like, you know what I mean? I just think they probably went through, if they,

everybody says that their culture has a longer term view of things. Okay? Well, the longer term view is over time. We'll just win Taiwan over ideologically. That's kind of what I'm getting. Yeah, and there's a reason why it's 93. There way out of that. They don't win. I think they're winning. So it's like if you're going like this, up into the right, why go to war? It's heading in the direction you want. That's just my gut though. And I haven't read enough on it

and I should. But I even looked at, you know, I was very interested in our war or whatever we're calling it with Iran. You know, what would China's response be? And it just doesn't seem very aggressive. It's almost like, hey, whatever's happened and it's happened. They feel like they're not even in the scene or they're, they've exited stage left for now. And I just feel like a country that's prepping for war might want to exert a little more muscle than that. You think

they're standing off. I'd be, what do you think? I think they're standing up because I think they're hoping that the Petra dollar turns into the Petra you had. Yeah, maybe, oh, good point. Well, and I do know longer this goes on to look, the more pissed off everybody's going to get it

us. Yeah, I think the dialogue in DC is never been a ramp up of navy in history as much as the

Chinese have ramped up their navy. If you'll get Taiwan, well, that's a naval battle. That's a naval

blockade. That's navy, navy, navy. So there's evidence that shows it. But if you want to be a global

power, I still feel like we're one of the only nations that can project force remotely. You know, I've heard, we may not depend on you. You listen to, we may not be able to project in two fronts anymore. And I've always felt we were always built to at least do two wars at once. That may not

Be the case.

center or whatever beautiful white ships around the world with Teddy Roosevelt or whenever you

care a big stick. And I wonder when China's going to do that, if they're already doing it,

I think they're probably already doing it in parts of the world. Yeah. But we'll see if they do a globally someday. Yeah. You brought up Snowden earlier. Yeah. What do you think about that leak?

You know, I'm never a leaker. You know, I get it that the dialogue needed to happen. But I'm

even I'm the wrong guy to ask. I'm pro. It is a weird sense that I've had my whole life. I got to probably, and maybe as I get older, I'm less trustworthy. But I believed in the institution of the NSA and still do. And I've known the leaders there. Nobody is trying to do the wrong thing. I really don't believe it. And, you know, there's tons of inspection there. I would almost argue, we inspect so much. We almost hamstring ourselves. You know? And so I'm in the, I don't know,

I'm probably in a minority camp. I trust the NSA to do the right thing. I really do. And I, and I, but again, I've walked the halls there and I believe in the people in the

mission. And, and I think you should never, there's their hat. You would like to think there's

another patty could have taken if that was his fight. And I, and I still believed in, um, you know, they looked at the violations done. I can't remember the exact code that came out of the, you know, I think they called it the Patriot Law for one for a while. But, um, you know, there was a huge investigation into what were the procedures and who were the people, um, and they even had people from, uh, I mean, that left liberals that right, went that everybody, and it really came back

and nothing burger from the extent, at least from my understanding of it as to what we were really doing. So, I don't know. To me, it's a spies, a spy. I still believe that you can whistle blow appropriately. But I could be wrong, Sean. I'm, I'm Professor, you're a pitted. If I were sitting

in a building, I'd never have done it. But, uh, you know, maybe I'm a weaker person. Maybe it

takes the dialogue is good to have all the time, right? The checks and balances. That's why we had the press and freedom of the press. You know, to keep the government in check, you know, I still, I still think marketing companies probably know more, way more about us than the government ever could next year probably right. Yeah, but marketing companies won't break down

your door and take your assets. You know what I mean? So we don't worry about them as much, right?

So I do believe in checks and balances and the government's got to get called out whether appropriately or inappropriately it's always a good check. Yeah, no matter what. I get worried. I see both sides too. I mean, I get worried about it. Obviously. I mean, we're just talking about glacier. Yeah. But obviously, I get, I get really worried about it. But, um, but I can see both angles. I do. I get concerned about government overreach. Yeah, I do. If unchecked over time doesn't

it automatically go there. I mean, that's just the fear I've always had. Is that it is a good

thing to have healthy debate. No matter what spawned it, right? Whether it's, so even my opinion on Snowden, whether positive or negative, it's a great conversation to have all the time. You know, so that was kind of my take at the time. I just wish what I don't know and what I'm probably nobody in the general public knows is what were the downside problems that that created. I'm certain there are certain lives that became real complicated due to those leaks. Yeah. Yeah. Yeah.

We'll come and let's take a quick break. We'll come back. We'll get into solar winds. This episode is sponsored by Better Health. You've heard me talk about Better Health for a long time. And one of the things that stands out is how many people have shared real positive experiences with it. Therapy is personal, so hearing directly from the people who have used the service matters. Better Health makes those reviews easy to find at betterhelp.com/reviews. And they update them every day.

Better Health has an average live therapy session rating of 4.9 out of 5. That's based on over 1.7 million client session reviews. That kind of feedback from people who've actually used the service speaks for itself. And getting started is simple. You answer a few questions. Better Health matches you with a therapist based on your needs. And if that's not the right fit, you can switch therapists at any time. More than 6 million people have used Better Health

globally. And their therapist have at least three years and 1,000 hours of hands-on experience. See the reviews? See what stands out? And see if Better Health is right for you. Visit betterhelp.com/sures. That's BetterHELP.com/sures. Looking for another way to support the Sean Ryan Show, head to SeanRyanShow.com and check out the latest drops from vigilance elite. We just released new gear, including this

beautiful, moisture-wicking VE performance hat, and SRS campfire mugs, and you guessed it,

Vigilance elite gummy bears.

and helps us continue bringing you independent conversations without compromise.

Visit SeanRyanShow.com and grab yours today. All right, Kevin, we're back from the break. You were just telling me a story about, oh yeah, when you expose a 6198, you know, even when I went live with that, I didn't know the five digits right away. You know, I remember being on like 60 minutes, I'm like six, two, four, three, you know, it had been, it's like, you were about those damp things

and as I got older, I forget it. But yeah, when we did that story, David Sanger, kind of, and Nicole Prova, from New York Times, it was kind of coincided with the New York Times, just compromised by the Chinese government. That's a little weird. And they decided to go live with it, and we decided, well, let's go with who did it, and what they've been doing. That's the PLA unit 6198 thing. And it was Sanger's idea and Nicole's idea, let's just put this on a front page.

And I remember like the day before, I don't know where, everyone's why I think I'm an expert when

I don't know shit. You know what I mean? So I'm literally on the phone with Sanger, and I'm thinking, I know his job better than him. He's like, this is going to be a big deal. I'm like, no, it's not. David, you were wrong. Nobody gives a damn of hacking. And I've been doing this for 20 years, no one's ever cared, and they still don't. I go into work the next morning, and I get in, I still remember my lights weren't even on in my office yet. And I go in, it's, you know,

now is in Virginia. It's about 720 in the morning. And it's live. We're on, you know, it was like February 13th, 2013, we're the front page. And I don't remember what the headline said. And what's weird, too, you're an entrepreneur. You know, it's like no matter how good yesterday was, you know,

he never matters as tomorrow. I already been dumb, gone. We're fine, we're on the front page,

you give the shit, we're off, let's get our workday done. And all of a sudden, my cell phone

rings now answer it, and it's my now ex-wife. And her exact words, exact words were, what the

fuck did you do? And I went, and I mean, because I'm a guy, I'm like, what left field thing on my own trouble for now? Like, I didn't know it. Why she was saying it? And I'm like, what do you talk about? You know, I probably got the fence right, like, what the hell you talk about? I didn't do anything, you know? She's like, turn on your TV, and I have a TV right in my office. I turn it on, and I'm not even kidding. The very first scene I saw is a building, I recognize the building in the background.

It's PLA units 6138 headquarters. And there's like a dude in a taxi going, travel away, drive away. And I look at the bottom and say, you know, or Mandy report, and all that's something like, oh crap, what did I do? Like, I didn't even know. We didn't think about people are like, it was a marketing drill. Really? No, wasn't. It was a bunch of former U.S. soldiers saying, screw this. It's Chinese New Year. Let's get the report out. It's burn their infrastructure, burn their

operation, give our government a tool. So the government doesn't have to point to finger. A China will do it for them. And let's just see what happens. And we dialed that report back. We actually had the names of a few of the soldiers. Like, we knew who they were. And we pulled, I remember I had to do those things out. I'm like, no, we're not going to put that in there. Because I didn't know what would happen to these guys for getting caught. But anyway, ended up that day doing about

13 interviews or something like that. And by the, with no staff, like, nobody's handed me

power bars, nobody's coordinating. I think, you know, I just ran around trying to get out

the truth of it. Because what's weird is if I didn't go out and do those Sean, those interviews, someone would make crap up or say something. And we were on, we were in the ring. Like, you know, we were in the ring. We knew exactly what China was doing. So I just felt, let's be the voice of reason on this one and get it out there. Nobody hit even heard of six one, eight, six one, six one, eight, nine. I don't know. To be honest, I had neither of my team wrote it. We picked

here's what's weird. We had like three groups who could have picked in China. There's like a

little naval group called APT4. We chose APT1 for a lot of different criteria. But one was, they kind of, they weren't, they weren't the might Tyson in the rant, you know, in his prime. They were more you know, Buster Douglas. We knew we could take the upper cut coming back from them. And so we literally picked them. And it was a tool to give, you know, Congressman Rogers, you know, something, the government. Like, US government, we know we probably know you know,

but we'll let you guys have this work of art from us. So we did it. Have you heard of, you know, we were just talking about Snowden. Yeah. Yeah. And if you heard of this Pfizer thing that's going on today, Pfizer court stuff. No, what's happening? This is a tweet from Thomas Massey. The House, the House passed Pfizer section 702 renewal yesterday. voted. No, this was a unaparty vote in favor of unchecked government surveillance without adequate warrants or an accountability.

The vote, the vote, the vote, Tally is Republicans have voted. Yes, 192, 42 Democrats voted. Yes,

NA Republicans 22 Democrats 169 total.

what I would tell the viewer just like, and my view at a time when I was in the US government

and in law enforcement, I never ever saw witness or knew about unchecked surveillance period.

And I feel that's healthy skepticism for folks to have. I personally never saw it. And never executed it. In fact, it was hard for me to get the ability to do it. You really did have to go talk to judges. You really had process. So, Pfizer's foreign intelligence, uh, kind of taps, right? And to me, US law protects US citizens. I think a lot of times you forget that, you know, and so, you know, bottom line, it's good for the viewer know that I never ever witnessed or saw

what I would consider unchecked governments. I dug into this a little bit this morning. Yeah, and I understand why everybody's making a big deal of it. But the way I read it and deciphered it

was that in order for the government to actually surveil you under this, you have to be in contact

and talking with a foreign state actor. And there's still a Pfizer court. They're watching. Yeah, there's still anybody from any foreigner, a foreign state actor that is, that's already on their investigations. There's a Pfizer court. And that's all classified stuff. And you go and present to a special Pfizer judge and you get your ability to go do it. I had to get approval for consent monitoring. Like little people like you can monitor, but no, I actually can't. I got to ask,

you know, my jag, if I can go do that. So, people could have asked us to come in to monitor, we wouldn't have been allowed to do it. You know, and in cyber at the time, some people did, you know, like if the government knows more about what the bad guys are doing or offensive anybody else, why not let the government help protect the defense industrial base or why not let them protect the banks or protect a hospital? And we can't do that as a nation because of the

separation between the two. So, it just, I think, I would rest assured of fire in this country

that I've never seen, and I don't know of, and I'm in DC all the time, you know, there's nobody,

it's not unchecked. You know, it's not not for my. That's good to hear, and it's, yeah, that's great to hear. I guess, you know, everybody can instantly make mistakes, and yeah, I've never had to brief a Pfizer court, but I've had to brief, you know, a judge. It's not easy to monitor anybody in this country. I haven't found it to be easy. Maybe it was cyber stuff. Maybe it was me. I'm not conventional. I get front and be like,

"We need to do this today, but I can't." But, you know, anyway, I'm not worried about it. I believe in my gut is if we restrict our ability to spy, we're hurting Europe, we're hurting ourselves, we're hurting a lot of people. And so, I think I would trust our organizations to do the job.

All right. Let's move into solar ones. Thank you. I'll just jump right in then for you. Imagine

Sean, you're sitting at work one day. I had about 4,000 employees. I was the CEO of a public company called Fire Eye. And I looked down on my schedule. I'd just done a, uh, an all-hands with 4,000 employees, where I told them, and it was fall of 2020. So it's during COVID. Now, I'm doing weekly calls during COVID, because you want to keep the wheels on the bus. And we have 25 year olds in Alexander Virginia living by themselves and their parents want to see them because they're so

free to the damn of COVID. So I'm doing weekly all-hands, guest speakers. I felt like I was doing Kevin Mania show. Every Wednesday, I do it twice. Just to keep people in the ring together, an entertained almost because I had a lot of, uh, a lot of folks struggling during COVID to stay motivated and stay human. Late COVID, you know, so it's November of 2020. I do my all-hands where

Blackstone did a $4 million investment in my company, so I could split it. You know, so I could split

my company and sell off the more mature portion of my portfolio and, and carve Mandy into out to be a standalone company. Blackstone gave me the air cover to do it. So I do the announcement to the whole company. I hang up, they all hands, you know, me Zoom call. And I looked out of my calendar and it says that my chief friend for me security officer wants to talk to me at 1 o'clock. And it's a Friday. It's 12.57. And I'm not kidding. I'm about to go downstairs and grab beer. You know, I'm like

man, this has been a long week. I just did a $4 million raise. I just wrote my presentation. It's pre-AI at the right all my speeches, you know, nothing to help. And, uh, and I don't have the company's going to be like wait am I going to be in the part of the company he sells or been

Part of the company keeps and we were still kind of figuring out which studen...

laughing. It was complex and it was something had to be done in a public market. I see this invite

I get on the phone at one and man, I should have known it was going to be bad news. You know,

I mean, chief and friend security officer really wants to talk to the CEO. I get on the call

and one of the first, and I'm getting a briefing from one of our IT guys who ended up moving into

the security operations center. And he's telling me that somebody is logged into our network and in the very next thing they did after they logged in is they dumped all our user accounts and past phrases from a Microsoft tool called Active Directory. So in other words, that's like somebody broke into the hotel and the first thing they do when they broke into the Marriott is they didn't grab the room key that just opened up room 101. They grabbed the room key that opens up every

roof. They had the master key. You don't get the master key to first time you break into the hotel. You know what I mean? So I luckily, I'm a CEO that's responded to breaches this whole career because when I get that news, I literally go call board meeting. This is the one this is the

one I'm worried about. And even my sister was like, call board meeting. What the hell you're doing?

And I'm like, I think this is Russia. Like their accessing our network the way we do. That's perfect offense. Access the network that you're targeting the same way the employees

access it using their accounts. And that's what whoever this was did. So 10 minutes into my briefing

my heart sank. I'm like, well, I'm not getting that beer today. And honestly, every day, Sean, I remember going, I got the board together a couple hours later. And I think I gave them like the the solid speech. I'm letting a plane on the Hudson. I just said, brace for impact, man. This is going to go from bad to worse. We're cybersecurity company, summons in our network. They got all the keys. They've got all of our accounts. Did you, did you know,

did you think you were the only company? No, at least. Yeah, we just October 2019, Russian SVR has inject malicious code into the solar ones, Orian update used by 300,000 customers. Yeah, March 2020, the back door goes live US Treasury State Homeland Security in the Pentagon compromised for over a year. Yeah, for anyone noticed. December 8, 2020, Mandy discovers Mandy and itself has been hacked. Yep. Red team tool stolen goes public.

Yep, put her company blog the same day against most legal and PR advice. Yeah, because, well, we found out beforehand. We went live as soon as we could. But here's what held up us going live in faster is so Friday, I get the briefing Friday afternoon. Sunday, I just already scheduled a board meeting for Sunday afternoon. And luckily, I did the

job of computer forensics. How did people break in? It was always what happened? What to do about it?

That was my job for my every day of my career. You know, what happened? What to do about it? Every computer investigation. And then sometimes you did it. And on this one, I just felt right way it was the SVR. Just my gut went, okay, this is a problem. On that Sunday, three days or two days after I knew we were probably compromised, I would get an update every day and just got worse every day. I'm like, man, I hope they don't get to our secret server that has all our past phrases.

Like, a hour later, a guy would call, hey, we just did forensics on the secret server. They've got it. You know, I'd be like, oh, I hope they don't grab some of our email. Day one, I caught our best email investigator and said, hey, I'm pulling you off the job and you got to go look at our email that's stored at Microsoft. He called me back exactly 47 minutes later with we got a problem. You know,

so if we didn't know to look, Sean, we'd never looked, but we knew to look so we did. And we started

noticing why is our backup account backing up our email all the time? It's not backing up our email. They were using our backup account the login and steal our emails. You know, and I just went, oh, this is going to get ugly. Sunday night, I call frontline responder for a pep talk. We're working around the clock. And I can tell you day one, even as an incident response company, I didn't think my team was taking it serious enough. My guys, this is the one, this is the one

we're worried about. By day three, everything was changing. The team went, yeah, it's the one we got to work. You know, and so I call frontline guys, Sunday night, he's working around the clock. And I just happen to be talking to him. And he goes, yeah, they stole our red team tools. These are tools that we use to be seraptitious and break into our customers. You know, kind of simulate the offense, simulate bad guys. And the minute we lost them, I was like, well, can we stop them? Can we stop our own

red team tools? And the answer was we couldn't. We made software to stop bad guys. The unfortunate reality is we had created all this offense to stuff that our defense of platform couldn't even stop. And I'm like, I can't go live with that. You know, we got to fix this to the credit of Microsoft, to the credit of CrowdStrike, to the credit of Palo Alto networks. We didn't have anywhere from me to go on the government, really. I went to the NSA because it's a damn lonely world when

You're compromised.

don't email us. Don't don't talk to my guys, don't email my guys. I have no idea how bad this is, but it's going to go from bad to worse and it did. And to their credit, they were a great ally. Second, we, we immediately started reversing our own red team tools to figure out how to detect them. And then we called, I called the CEOs of these companies. Like, head into cash. Could you please have Palo Alto networks help us out? Before we ever went public, Sean, we were working inside

the community. And to the credit, these are companies that competed with us. They helped me. Thank God. Wow. You know, as I came George at Crowley, can you please? We were given them the rule set to stop

our cyber weapons. Just in case the Russians used them. They've never used them that were aware of,

but they sure saw a learn a lot from it. And, um, boy, was I scared. Like, the whole time is like, I'm going to be the reason the internet goes down. I'm going to be the reason, you know, all hell breaks loose. So I was in a race to go public no matter what. Catholic guilt, call it, the right thing to do. I remember I got so much unsolicited advice during this intrusion from employees and the board that I remember two things distinctly. One, every time I was advising a

CEO during their own intrusion, I would tell them, this is your day job now. You got to get through the crisis. So I remember my own voice in my head of what I told other people. Now I had to live byboiled advice. It was a little weird that almost was like, you know, bipolar. I was telling myself how to handle my own incident, period, you know, coaching myself at the same words. I told other people. Um, but we were in a race to go live right away. And I was so worried the Russians would

use what they took to their credit and thankfully they didn't. Um, and I, I think I didn't think we

were alone. Because yes, we are always as multiple victims. It's not to happen on company at once.

But I could feel when I went out to the community, it starts NSA to me. I go right to them. Hey, man, we got something new in novel. We don't know what the hell we're dealing with. You wanted to defend the military first. We do have, and then they go to five eyes with we got something new in novel. And it kind of purcolates through. And it doesn't go to go public right away, because all you're going to do is scare the hell out of everybody. There's nothing

they can do about it. So we did get Microsoft's help. Thank God they showed up in a big way. Turns out they were compromised by the same people. Crowdstrike showed up in big way. Palatone at works. Forternet, all the cyber security companies kind of rallied. But it was all informal. And even today, Sean, if we knew a cyber attack was coming, there's no way for the nation to go shields up with coordination. The way you do it is you call the vendors personally and go, hey, you know, we got something new

in novel and we need help. I had to protect America from the very tools we had made. You know,

so we did it. And I'll never forget to my boards credit too. I went into a board meeting. This

was December 8th when I went public. There was no legal obligation to go public about the breach. We didn't violate anything. We didn't lose any covered data by statute. We uh, and the lawyers

a great guy, incredible lawyer. And he gave the whole board a presentation on you have no legal

obligation to go public. And I had like five pages and notes and I was ready to fight my board. With I'm going public. Anyway, God damn it. And here's why they rolled over in 10 seconds. There's of easiest board meeting I ever had was conveying the news to the public. And by the way, here's what happens when you're hacked and you know it and you tell the world. Market cap goes down by 20% for us. We get sued right away by shareholders and you're considered negligent. And I even had

a phone call and then you're calling on your customers and I've lived this with a lot of folks. I called one money center bank and the guy on the other end who I've known for 20 years is like Mandy, how did you let this happen? How did you let your company get compromised? And I remember saying internally don't lose your shit. And I just went let this happen and I lost my shit. I didn't let it happen. Nobody lets it happen. We have a modern nation with an incredibly smart

people coming after America. We're going to lose. We can't throw a perfect game every day. I was so pissed off because let it happen. Every day we woke up. I I spent every Friday on that downside to my jobs is every Friday I'd get a threatening email from a ransom or actor and they were real people and they'd say we're going to have to do this weekend. And the reason why is because we were preventing payouts. We'd respond to an intrusion, bottle it up so fast

that companies didn't feel they needed to pay the ransom. So they threatened us and they did break into us and we'd have to play this whack-a-mo game with them before they could do anything. We made our own security software. We could program it anyway. We wanted. And we can't even stop

the criminal on it. That's how asymmetric this fight is. So I remember every weekend any time

any time my lawyer called my heart rate would go to 130. No matter what, you don't know. Yeah, you had the food ring. Certain times just like oh shit, I had it every weekend. And then

When this and then so during solvowins I think part of that side of me came out.

Nobody lets this happen. We're getting soccer punched here. We're giving Wayne Gretzky unlimited

shots on goal. I mean the puck's going to get in the net sooner or later for God's sake. You know? And that's what we're doing. So I remember just you've had those moments where you're like don't lose your shit, don't lose your shit and then you lose it anyway. I had that one over the other day. You got it. That was what it was. You know, that don't do it. Don't do it. And then I didn't let this happen. But solvowins for me was a you learn under crisis, whether you're gain weight or lose weight,

I lose weight. And it's weird because it's not like you're bleeding out in Afghanistan.

That's what I kept telling the team. This is a cyber intrusion. We're still healthy. You know?

But what I've learned is when your credibility gets attacked or your confidence gets attacked, it is, it's I personally don't respond well to it. You know, like every time I got a subpoena as a public company, you know, I didn't do any wrong. But you read the first paragraph. And I just get this energy like f this. I didn't do this. You know, I got that during solowins. A lot of energy to prove we're not incompetent. We're good people. I got, you know, just lost that day to

foreign intelligence service that really kicked their ass. What did they get from all the government agencies from department's home land? I mean, what, what do they get out of that? In my experience,

the Russians always had an etiquette where I'd never really seen them take the top person's email.

It's almost like they're like, hey, man, don't take the secretary's email. Just take all the people that report to them. You know what I mean? True story. I've always felt that. It's always the email. Yeah, it is because everything's there. They took email and they took from us our red team tools.

I think it was source code for some of the victims. It was emails for some of the victims.

It was methodologies. A lot of it was how do we detect them? Find them? And what do we know about them? You know, to their credit, they did a lot of keyword searches. You know, so we could see what they're looking for. That's a gold mine force. I've never seen trying to do it well. That's not true. I have seen the Chinese recently do keyword searches. And that's a gold mine force because you know what they're interested in.

Keyword search means they hack into the machine and they say find any document has towards secret it or you know, headset than it or whatever the hell it is. You know, they pick their words and it go. The Russians did that on us. So I could tell you exactly what they were after our red team tools. I mean, they were absolutely after us. So let me, I'm just curious. Let me ask you this. You're coming from the intelligence world. I mean, you have, you have whole signs. You have

code names. You have all that kind of shit. Yeah. Is it, do, do, does the USG use pseudo names, pseudo names and emails? Have we started? Not that I'm going to attack it like that. Yeah. So, yeah. So, you know, there's, here's the reality. We're, there was a whole idea once by a company that started in a since pivoted where they were like, we're going to make a bunch of fake stuff. So when the Chinese steal it all, they won't know

what's real and what's fake. Well, here's the problem. Even companies don't know the last version of something. We have bad enough document control and email control on our own shit, let alone this fake amount or head fake or code names. And I did protect their services

when I was in the Air Force, I'd augment the secret service. I can tell you, we did do code names

that because the radios were probably not even encrypted. There were just big bricks with war.

And I remember the very first thing I ever happened, and I don't know if it was for show,

just to scare the 27-year-old Air Force guy, but it was like Raven 1 and Raven 3. And the response was, I'm Raven 1, you dip shit. No, I'm Raven 1. We argued about who was Raven 1 or something. You don't have to be. So, you know, you use code names. You got to change them all the time. And I don't think it's going to work. So, I don't know of any real obfuscation you encrypt. And you try to keep your communications out of

playing view from the Chinese. So, but SolarWinds was something that it was a supply chain hatch on, where SolarWinds was a company that we all use for kind of controlling our infrastructure. And I feel bad for them in a way. You know, I mean, imagine this. I had to call them. We found an implant in their published code. That's no different than like Microsoft getting hacked. And you get the next update of Microsoft and it's a back door for the SVR to steal all your email.

It's or you're on your phone and you download an app and like, well, thank god I updated my app and the update itself signed by SolarWinds had a back door and it that the Russians now had a menu of who do we want to hack today? Well, we have a choice of at the time 18,000 and 42 companies had downloaded the new version with the back door. So, they had a menu of 18,000 and 42 companies into the Russian SVR's credit. They didn't hit everybody. They could have literally shut us all

down. Just delete everything. You know, if it was a destructive attack, well, there's a whole out of data that we did right now. And that's that. What they did was very precision-based real espionage. You know, they went in and took what they wanted. You described this as a special operations

Cyber unit.

was a sniper shot, not a spray and spray. They went right at the 50 something. I'm aware of about

50 or so companies that are US government agencies that went after.

Wait, we were a 2021 you testified before the Senate Intelligence Committee was the most credible. You were the most credible voice in the room. You said that. That was a mandatory breach disclosure laws that still don't fully exist. They still don't fully exist. Yeah, there's no national level breach disclosure law that I'm aware of. That is useful or helpful in any

way, shape or form. The problem we had is the privacy laws, the privacy outlets got their first

and said, if you're hacked and you know it and you lose, like, your personal data shown, then we got to tell, you know, 48 state governments or whatever it is. Now, it's probably all 50. And so there was things to protect American citizens when you lost their email or their data birth or the social security number or their bank account number or private bank account number. It's called covered data and that's great. But what covers the Chinese going in and just stealing

all your IP? Nothing. There's no disclosure law required. And the problem with that is no company gets better from it. Like if companies hacked today and the Chinese use all new and novel techniques to break in, no one's learning from it. You know, so if they can go to one place and say, listen, we're broken into, even if I hate to say it, I was even a proponent of, if it's defense industrial based or criminal infrastructure, hell, let the best in government show up and help.

Because then we can go shield up, learn the tools tactics and procedures that were successful at company A and they should be the only victim that I preach. Period. And then you just kind of

create a better, marginal line. You have to have a learning system. As a nation, we haven't built a

learning system where we learn from everyone's compromise and we all get bolstered from all the breaches of respondent to. Like just I could just pick any of them. Hell, it's every single brand you can name. But if you get compromise today, wouldn't you feel good about, well, at least nobody else has to go through this? You know what I mean? So I think if we get compromised, I would immediately say, here's the TTPs used against us. It'd better be a new novel attack. I don't want

anything that pre-exist to work against us. And we got to get it out there to make sure they only victim. We got to do that. It's no different neighborhood watch. You see an asshole, Robin House, you better tell everybody in the neighborhood, you know, and they drive this car and they're doing this. We need that as a nation and we could do better there. We're in a neighborhood where people are getting robbed and no one's telling either they're driving a white van and there's

there are plate numbers and three dudes in the van. We need it. Are we working on this?

Yes, the challenge is that every time you go public no matter what, there's never really a

safe harbor for you. So unfortunately, and I can never guess. When you're hacked, and you know it, and you tell the government, I've never been sure what the government's response would be. And I can never tell the public's response. Example would be like when Target was breached, you know, they lost credit card numbers and they over communicated and they had great people, great talent, but people also had a job over that breach. I happened in really 2013,

beginning of 2014. Almost exact same breach happens at Home Depot and nothing happened. Public wasn't in an upper-era or anything. But there's some about this target breach that it's just got a lot of attention. It was during Christmas times holidays. It was the front-day page every day. And then Home Depot, same thing happens. Someone hacks deals credit data and does stuff. And Home Depot would say, "Well, we handled it better." There wasn't that big of difference

in handling of it. It's just a public response a different. You know? And maybe there's a few

minor tweaks here and there between those responses, but I never know. And so a lot of times companies

get hacked and they do disclose. And then they stuff to show up and test find front of the government. And you'll have a senator from Oregon saying, "Well, how come you don't have firewalls?" And you go like, "Dude, firewalls don't do damn thing." Like, are you kidding? That's, that's a signing of padlock and cyberspace. You know, it's, it's, you just get held to account that in a matter of what. Yeah. Damn. Damn. Let's talk about the colonial pipe behind and critical

plan. Yeah, sure. May 2021, dark side, ransomware hits colonial pipeline. Yeah, 45% of East Coast fuel supply, Mandy and called into response six days of shutdown, $4.4 million of ransom, gas lines across the southeast shutdown. Yep. If I can tell you, I found out and you know, with a

Lot of these, you never know how much it's still under litigation or not, but...

you always get to see the leadership. And you get to learn from them. So for me, Sean, kind of like

you're doing the show. I get to show up and talk to the seat yo. And I just feel like colonial like great leadership. You know, just like unflappable calm. Yep. Here's what we got to do. But when ever there's a cyber attack, like when somebody ransoms you, they break in and they encrypt your hard drive. It's not like you know what's going on. Machines start to just go dark. They just shut down. And some of them shut down after 30 minutes, some three minutes, some 50 minutes.

And if you're imagine being in a control room and all of a sudden, hey, my machine doesn't work. Hey, my machine's not working. Hey, I'm going down. You have no idea what the house is going on. Mm-hmm. Mm-hmm. And you don't know if there's a physical threat. You don't have some kind of electric wire. You like, it non-siber people have different responses. And I feel like whether it's Sony pictures had to deal with something like this. So many companies have, you know, different

defense firms had to deal with it. And then colonial pipeline. The way that one came to me is,

I think we were responding on a Friday and somehow some way, my young frontline responders didn't

see this as national security issues. So I never got the update. My phone rings from somebody

who works in the government. And literally they opened up. It's eight in a morning. I'm just waking up to go to the gym, which means that's a late morning. And I get a call from someone I know in the government, they're like, hey, are you responding to colonial pipeline? And I don't want to act like I don't know. So I have to say, well, let me check, you know, I'll get back to you. And actually it was weirder than that. I think he called and said, is it true the Iranians

hack the pipeline or something like that? I'm like, what are you talking about? And then I was like, let me go check. I call my front and by the way, I'm thinking colonial pipeline, you make faucets. You know what I mean? Oh, I don't know who to hell they are. So I get on the phone with my guys, sure enough for responding. And then I hear what they do. And I'm lecturing my frontline nerd, because these guys are so into cybersecurity, you're like, all right, you've been breached. What

happened? What to do about it? They never thought to escalate. Hey, man, 40% of the U.S. fuel on the East Coast is going to be not transmitted. I got a call from the government on that first. And that does happen for me every once in a while. I've had that at maybe at least three times in my life. I learned we're responding to a breach because someone from the White House called me, you know? But on this one, I got a call from somebody I named and then I looked in and it was definitely not Iranians

right out of the gates where you knew who it was. And that's based on again, we're cataloging forensic evidence at every breach of response to. So we can go into like a colonial pipeline, look at the evidence. And plus they said they were, makes a lot easier and they wanted to get paid. So you know who you're paying. You can pull the evidence out and just match it and marry it up. So we're pretty confident through they were. But on that one, it's just an example of many of them

where first there's always a fog war, you have no idea what's happening. If you're a hospital

and stuff starts going down, you just a lot of hospitals will be like physically secure the hospital. Like you call security and say guard all the exits. Because you don't know if there's someone on the inside doing it. You know, it's a weird uncontrollable moment. But I've seen incredible leadership and I did attend a lot of the calls of colonial where you do your daily briefs and they were just they did, they show that you plan ahead, like do the plan that you wrote when you weren't

underdress. And that's exactly what they actually, that's the best way to say it. They had already

kind of said, hey, if something like this happens here is what we're going to do and they just pulled out that playbook and did it and it works because it keeps everybody calm because there is nothing, it is a weird thing when you're hacked and you know, you know, I've lived it where I'm like man, I wonder if they're still my email right now. You know what the hell's in that? Nobody knows what's in the email. So colonial pipeline again, no, it's just all of these, whether it's

colonial pipeline, hospital, cell company, every one of them, it's a full sprint the whole time, no matter what, like you show up and our job is always physically impactful, Sean, like when we show up, we have to figure out what happened what to do about it. We're not really sleeping, like you show up and you're just triaging and working around the clock. And it's a clone, it was no different. Like some of these intrusions, we did United healthcare. I mean,

do you remember what happened to them? I think it was last year. Yeah. Somebody hacked United

healthcare and ran some of them and people couldn't get their drugs at pharmacies. People literally worked themselves in the hospital visits. I'm not making that up. Where people literally worked around the clock, like one guy didn't show up at a meeting, they had to go find him and he was like passed out on a ground and a hospitalizing. You know what I mean? So these things are absolute races. Colonial, the upside they had is, they don't have a competitor. You know what I mean? You just

got to get it right. And I think what they had is the constant, like it's everything, like when

You, it's political issue, you got to get oil and gas.

I'm not aware of it, but my gut is they felt an incredible men's pressure to get back up and run

you know, and most companies do. I don't care, I did. Yeah, I think I've got to be right on people think.

4.4 million in ransom for 45% of the East Coast fuel supply seems pretty minimal. You know, to me, yeah, you never apply in whether people should pay or not. Obviously,

here's what I will tell you. I've never met a CEO who wanted to pay. Not like it was never the

default answer, but you certainly see the logic and pay in that one. Right. I do. 4 million? Yeah, I had to pay. I've gone through the hypothetical of what would I have paid to keep my legal counsel's email from getting posted. Now I'm advertising to the bad guys, but I would pay to not read the amount of lawsuit you get as a public company CEO if your general counsel's email is online. It's amazing. I mean, reported read it. They write articles on this stuff, you know? It's a, it's a

tough situation. What about texts? Do they ever go after text messaging? Well, do some reading on a, yes, the answer. Modern nations do and, you know, both of all our cell companies have a,

there are certain industries that you need to withstand military grade attacks or modern nations

attacking them. Our cell companies are phone companies are definitely one of them. They are fair game for us, been Ozzie every day. Last year, there was widely publicized breach in 18 team Verizon, opposed in 2024 and 25. And the advice from the FBI was, and it's pretty telling, hey, you signal are you shooting me? No, meeting texts are in the clear, and texts can be found. And, um, and cell companies are fair game. And, and in reality, they are so valuable to

aspenage most likely that, uh, if you're on offense against us, you're trying to place people there. You're trying to hack them. You're trying to do anything you can to make sure you maintain access to the data from those companies. You're a technology. I think, signal is like you use it. There's

always ways around everything, but you have to have a massive, like, in transit signals legit. Like,

if somebody hacked your phone, my gut is they can get to at least half the equation and maybe be able to decrypt it. That means it's a modern nation targeting you specifically, but signal is is infinitely better than not using it. Same with glacier. Like, these things are massively annoying if you're on offense. Because that means I can't just intercept your dialogue and read it. And I can't find it stored in plain text. I have to do a lot of work to get to that.

Ben, didn't they just, uh, didn't they just, what was I read in this? I can't remember what it was,

but they broke signal and they were able to get the messages through notifications by breaking into the app. Have you heard about this? Now there's usually work around like that. Like it, I can tell you usually, I wouldn't say usually. In the times where we needed to decrypt something

and we only have one key, we always were able to decrypt it over time. And usually there's two

keys, a public and private key to something. Um, and so there was a time where we could decrypt that my company remote desktop protocol for Microsoft. And we thought we were the smartest guys on the plan. We're like, look what we can do and if we can do it, China can do it. In reality, none of our customers care that we could do it, but what it allowed us to do is whenever the Chinese broke in, they would remote desktop to all these machines, we could see exactly what

they were doing because we could tap it. And even though it was encrypted, we could decrypt it. We thought, oh, we're awesome. Nobody really cared. Um, but the reality is, uh, most of today probably can't be decrypted, easily till you have quantum compute come out. And then realize you have two problems. If you're worried about this, one someone got your traffic or your data somehow. And then two, they can decrypt it, right? Um, but in a quantum, that's the biggest

issue of quantum compute. And that's going to come like AI, everything's coming fast and we want. When the Chinese and the Russians and others have quantum, the vast majority of things we've done in the past that they've already intercepted tap stole, that's encrypted, we'll be decrypt it. That'll be the risk we run. The secrets that we once kept will no longer be secret. How far away from that? Under 10 years. For the most where, here's the good news. The Chinese really don't

have a whole lot to decrypt. They accessed everything with a valid key, meaning a valid user, a count, and passphrase. So everything was presented in plain text anyway. I actually think to threat from quantum as far less than people realized because for the most part, even when the

Russians were still on stuff, it was not encrypted.

speaking with like 5,000 plus intrusions, investigations, behind me, very rarely does an attacker after overcoming encryption because they're accessing your data with your keys, your credentials,

and so it's just plain text anyway. So I think quantum's not going to be a big issue. It is for

some things, but we'll see what comes out then, Sean. You'll have a lot of good shows then. I'll bet I will. Yeah, it scares the shit out of me. The way I understood. But your hour half is buried or something. I mean, it's just, you know, people, people to describe it is that your banks will be done, all your passwords will be gone. Every financial network will be completely, I think they're asking impact that more than anything because you have a

idea of doing trades, not humans. So, imagine a whole system of a diet doing all the trades, some point, the market's going to be managed by them, the AI agents and all the humans. You've heard me talk about Caldera Lab before, and lately the product I've been reaching for the most is the good between being a dad, hosting the show, traveling, training, and trying to keep up with everything else. I don't have time for some complicated skincare routine. I don't want

10 steps. I don't want a cabinet full of products, and I don't want something that takes a bunch of time every morning and every night. I just want one simple product that actually does something.

That's what I like about the good. It's an antioxidant rich, facial oil serum made specifically

for men's skin. The good is formulated with 27 botanicals, and it's designed to help deeply moisturize, support skin recovery, even skin tone, and visibly reduce the appearance of lines and wrinkles. For me, the biggest thing is that my skin doesn't look as dry or worn down. It feels softer, smoother, and just looks healthier. And the results back it up. 96% reported healthier looking skin, 91% reported less dryness in 89% showed improved radiance in luminosity. If you're looking

for one simple product that actually makes a difference, that's the good. Visit calderalab.com/srs and use code srs for 20% off your first order. Again, that's calderalab.com/srs in use code srs for

20% off your first order. What is the worst case scenario for a cyber attack on US critical

infrastructure? What is the worst case? I'll start with this. Nobody knows what would happen when the gloves come off. And there are a couple of reasons why. We're in times of basically at least ostensibly. We're at peace right now. The modern nations like China and Russia. We may be fighting proxy things or ideological differences. But on defense, we don't know if we've seen 99% of their capability on offense or 20%. My gut is it's like 80%. In other words, they have stuff on the shelf

showing they've never deployed. We haven't seen it yet. That you save for the moment of need, right? So the first thing I would tell you, there's a book by Ted Coppola called Lights Out. And I've read enough for that to go. I don't know if that happens. I don't think it's that bad. But genuinely, nobody knows what would happen if all minor nations go all out in cyber. I could tell you, our kids probably aren't going to school. I can tell you some regional trains aren't running.

But I don't know if it's like the there's De Niro. There's a book, the movie out on Netflix called Zero Day. And it's all about this exact situation. But it's done by Hollywood. And I couldn't make a pass the first 10 minutes. Trains were crashing into each other. Some child gets killed or some people get killed in a car accident because the lights aren't changing right traffic lights.

And I was like, man, I don't want to watch this. The problem is, I think you're going to get a situation

that there's such a rippling butterfly effect that most of society will come to an absolute would better go back to the old way. I'll give you an example. Well, like there was an attack in 2021 and it worked. It shut down softer that was used by a lot of restaurants. And I mean, you and I've been ordering food and restaurants for long before the internet or at least, you know, someone wrote down your order. What I was amazed at is when the internet went down at about 800

restaurants, just the the app itself that they were using got compromised, the majority of the restaurants couldn't take orders. They didn't know how to run their business off the grid.

If you want to do something weird, see how many Fortune 500 companies can actually run their business

if they're off the internet. The answer is probably none of them. Some aspect or most of their

business might actually falter. And that's unfortunately probably what will happen if the

Gods come off in the cyber domain.

so many weird things. Like you're running app. Hey, how far to our Monday? Oh, my running app doesn't work now. Or you're tracking calories. You can't track calories. You your schedule blows up. Your organization can't get on the grid or you can't transact or you can't sell or you can't get your money or you can't believe what you're reading. And there's a lot of different kinds of attacks. Like if I had to privilege a couple of times of teaching a modern warfare class at the

Naval Academy, I'd show up in cast lecture and I'd depress myself because first off, the attack

started year out and you won't even know it's us. Yeah, I won't even give you the playbook. But when

the cyber stuff happens, you know, I think we're staying home from work that day. I don't think

the grid crashes. I think hospitals function. You don't think the power grid crash. I think of my crash in the Midwest. The mom and pop utilities, Sean are going to have a problem. Maybe some of the water facilities. But it also depends on who's doing the attack and what their goal is. I would like to dive into that a little bit more because that is one of them. That's where I thought we were going was the reds going down water treatment. You better have felt tolerance.

I think some will. I mean, there's a, I mean, the way I understand the way things are going,

China manufacturers, all of our, damn near all of our power infrastructure, the transformers.

Water treatment. Well, and so if they're manufacturing that ship, they're putting stuff in there to be able to access it. You got to trust the country you do business with and it was a former FBI director said that they are in our power grid and our, well, they hacked into it. Yeah, they have it and not everywhere and that we know of nobody knows what'll happen. That the challenge, here's where I will tell you. The minimum is small, you,

municipalities are going to lose electricity. They're going to have their water works, probably shut down. Now again, it depends on the attack and if we go full monti right away versus gradual and communalism, most wars, gradually increment, depends on the actor because there's a

blunt force way to attack us that might not be as successful as a slow erosion of our capabilities.

Well, it's that's here. Here's why, if I break into a major utility, you know, like, Conad runs, you know, is New York City or PG&E or, you know, down in LA or Southern Code, these are strong cybersecurity entities. If you broke into any of them and tried to run malware, they probably can detect them out with compensating controls and stop it. Or if you try to just delete everything on a machine, they'll have redundancy. So what you actually have to do is reverse,

so how does this utility work? And what commands do I issue that will be unique to every single one of them to get it to perform differently or to impact it negatively? That's lower and slower. You got to read the freaking manuals. Does that make sense? On the little or guide, you probably can just delete everything. I call that blunt force trauma. We hacked in and we just said, hey, delete everything. Go. That might shut down municipalities. It won't shut down the bigs.

They're, they're going to keep giving you an energy. The bigger problem with the bigs is the load,

they've got to take if things start to shut down. We saw that happen in Texas, right?

They're like, early winter or late winter. And all of a sudden, the whole darn thing ripples across the state, you know, because if one utility went down, the other tried to bear the load, and it couldn't do it and pops down. We had that cascading and August of whatever was when a New York went down. You remember that happened in maybe 2003, 2004? It was 2002, maybe. I can't remember. It was 2003. Greg goes down in New York City. You know, and there's all peace and happiness

because it got back up in three days, but what's it like after five? I was actually in New York at the time is really good because people learned after 9/11, how to work together during crises. And that was August of 2003. But I also remember walking around the city going, it's August. It's hot as hell. Aircon's not working. How long before this thing unravels? You know, but I think if I'm on offense against us, you take out energy, you take out everything.

That's healthcare. That's finance. That's everything. And I think that's, that's what you

got to work about. And then you're just going to get this weird ripple effect of regional transit and not working. ATMs may be not working. You know, life will change. So what about water treatment facilities? Hard to defend. They just made minor changes to how they treated to what they're going to and how they're all different. They're shown. That's the thing. Like there's, you're going to have to fucking poisonous. Yeah. I think you got to know

more than that. I think they're going to go for, that's why I said, you either shut down or alter.

Shut down is blunt force.

commands being executed. They're unique per utility. They really are. Like you got to read the manual.

That means that being said, if I ever hack a company, I find the manuals. They're not hard to find. They really aren't. You just look at it. You like everybody stores them in the same place. It's usually called the name of the system and the user guide. Read the freaking manual. We do a lot of assessments of these utilities. And if my red team, we would sit in here and be like, yeah, we usually, if we can get to the OT or operational network, that's a problem.

So what you have to do is segment the internet network is the IT network. We've all heard IT, right?

You've got to keep that IT separate from the OT. You better have one hell of a wall between the two.

The problem is everybody has a crossover somewhere. It's almost like never net the separate net.

You know, we can go one way but not the other. You know, you've got to figure it out this out. I think the small utilities are uniquely disadvantaged at time of war. So you're from Missouri, hometown. Probably not going to do great. Yeah, I don't really like thinking about it. We've got to think about it all the time. Let's try it out. I'm not a pessimist or an optimist. I'm a realist. I do think we can have a future with AI. Everybody's going to say,

AI on offense is going to create a problem. And that is true. I think it's near term pain with AI on offense and what, you know, and we can probably get more into that. But I do see a future where

AI on offense will be uniquely available built by the good guys. That's what Armadden is doing

to train your AI on defense. The biggest problem we have in cybersecurity is there's a starvation line. The big companies have great expertise, great talent and great software to defend it. Then you hit a poverty line and all these utilities can't defend themselves. And all the small companies can't defend themselves. With AI, we're going to get the scale of the expert. The problem is we have to live that transition period, Sean. And the advantage will go to offense

during a transition period. And we're in that now. Yeah, it's just emerging. It will advantage offense. However, in the long run, it will advantage the defense. But we're going to have an ugly transition. So when you talk about a, like a sl... How did you not, not blunt force? When you have a bad hack, like a farm on offense, I don't do blunt force because I don't want you to

notice. I've hacked you and I've screwed with you towards too late. So what does that look like?

You slowly erode a system. How would you do it? Slowly pollute the water, slowly degrade the utilities. Yeah. But I would have to read the manual because it's unique to different things. That, you know, I almost hate given the playbook away, you know, because I'd already have, if I were against us, I'd already have people working there. I'd already know how to bring down the major utilities because I have one guy on the inside feeding me the manuals. Feed me the access if

I needed as well. You know, so it's real hard to stop that. We have a very international culture and not all the loyalty's lie in the same place. So, you know, I hate thinking about what, and I instantly shall go, what would I do if I were against us? And I just don't like what the outcome would be. So I'm hoping that our adversary is gradually increment. We have to have a proportionate response. If someone attacks us in cyber, our best deterrence is not in cyber. It's explosive. It's kinetic.

It's you bring the pain. That's the unfortunate reality. We are in the glass house and cyber compared to the rest of the world. You know, I think China might be too because they have such centralized control. We may be the two biggest glass houses. You know, if you're, if North Korea hacks us and we think, you know, we're going to hit for tap by hacking back, they're in a mud hut, throwing rocks at a glass house and we're in a glass house, so in rocks at a mud hut, it's stupid.

It's not the right domain to fight the conflict then. And I think unfortunate that's the reality. We have to, if somebody starts hacking our utilities, we have to respond very quickly and violently to what about the financial markets. I don't even think I start a number one. And they like to think they are. You know, you talked to the banks. But to me, I've never, ever had a scenario in my head where I targeted the banks. No one gives them about money if they can't go to a hospital.

You know, I go after electric first and foremost, probably water, you know, because it's, it's unguarded. It's hard to protect and healthcare. That's it. The financials are so well

defended and they're so good at it. They can always roll back to one second and go, they have

bought comments everywhere. They're confidence games, they cover losses. And I would put, if you could wage a war on every front in the cyber domain, yeah, I'd go after every domain.

I'd go after every industry.

That can hack 24/7 in total recall. And that's what's common unfortunately, Sean. There's a future where all of us, there's an attempt to hack against all of us all the time. It's almost that bad now, you know. But it will be that way with AI. So it's like a lot of needles coming at the balloon. You know, it takes one to pop it. You know, how do you, I mean, what, what do you, what would you tell the just the average American to prepare for if that were to happen?

Everybody needs to be able to live off the grid. You know, that's actually fact. We talk businesses. I call them red bevel events. If I'm meaning a seat, you know, any company.

Never forget how to do business to what you used to just in case you're under conflict.

Be able to dust off a book and say, OK, man, we're going to have to do insurance claims. But

pen and paper, again, whatever it is, because you never know what conflict can bring and what

you may have to work. Like if you're a wrestling for God's sake, you ought to be able to take an order without the internet and without a damn iPad. You ought to be able to write it down, walk back to the kitchen and do it. And I saw a 50% of restaurants falter with no internet. Literally couldn't operate the business. In fact, weight staff didn't even know the menu. Because they were so used to it. So great companies spent, and by the way, critical infrastructure

of damn sure, you drill the red lever events off the grid, how well to operate. Every machine becomes an operable right now, how fast to recovery. Those are like, pull the lever, what happens? And most companies, when they do those red lever events have unique findings.

Like, wait, I never thought about it. No one can park in the parking garage. When we come off the

internet, when people badge to go into the parking garage, your badge gets digitized and sent somewhere for authorization, open the gate. No internet, no gate. Traffic jams, the whole block of LA. So you got to figure out how do people buy lunch at work? No internet. Can't take visa cards. How do we, you know, I, critical infrastructure needs to operate off the grid and needs to know the way to do it. It needs to be able to operate how it used to. I believe that.

What about for people, about for businesses? People? You know, there's no way to, unfortunately, you know, for me for people, it's, when we're talking about the rest moments,

I hate to say it. I, and I know you believe this, you have to at least have a family plan

for what do we do if the dirty bottom comes off? What do we do if the earthquake hits? What do we do if blank? You know, great idea about technology. I do believe with proper diligence, you can know where your kids are, know where your family is and do so in a safe way. You can have protocols in place, you're in communicating a safe way. The grid comes down, I don't know how to do that, but you can't really take down the internet, you know,

it's state. That's why I was created survived nuclear war. That's literally how we went from packet, you know, packet switching from circuit switching. Circuit switching was one line. You sever it. No comms. The internet was created, literally, so we could communicate after nuclear fallout. That was one of its reasons. So you're not shutting down the internet here. And there's ways to have redundancy, go satellite and fiber to your house, have backups.

But it's virtually impossible for me to say to any individual you should prepare to

stand an AI-based attack coming from a modern nation. That's going to fall in the hands of the companies that protect us at that point. Okay. Yeah. Apple's got to protect us. Google's got to protect us. Amazon and AWS needs protect us. Microsoft protect us. Crowd strike. Palo Alto Network is for net Cisco. You go through the brands that we all really, you know, like use for infrastructure, use for applications and say, hey, guys, you got to be able to

shields up during conflict. And they know that, you know, they're actually I would argue they are

critical of structure. If we think Google Cloud's not critical of structure, it is. It's running

a lot of businesses. So it's AWS. So it's Microsoft's Azure. So you got to put them in the category of their critical. And they should have, I hate to say, at wartime protocol. What do we do? What about the USG? I mean, you're talking about the capabilities of China, Russia and the next segment after this, we'll talk about China, Russia, Iran, North Korea. But what are our capabilities? Are we, are we, do we have an offensive hacking arm that is conducting espionage on our behalf?

You know, anything we do offensively is going to be classified. And one of the things I will tell you is I started arm it into absolutely benefit the offense for nations that are governed by laws. And there's laws or things we aspire to, by too, and we do it. I've always felt on gut intuition and to some extent experience. We were the best in the world. We probably still are. And, you know, but China is great. And the problem is, Sean, AI is the equalizer between all of us.

AI will enable nations like Saudi Arabia, UAE, other nations to have the same...

offenses as us potentially over time, because you can train systems. It only takes one exceptional offense of mine that can do vulnerability, discovery, exploitation development. All these skills were going to be automated into AI. And then, and so that highest trunch of talent and capability, it's just going to get more distributed over the next few years. So it used to be U.S. was in a

land of its own, Israel is incredible in offense. I'm starting to realize war makes you innovate

faster. And Israel could be the best world on offense. And maybe there's certain platforms, different nations are number one. And like the mobile platform, got to give some shoutouts to the Israeli offense of capability and mobile period, right? And I don't know how, how did you respond when

pages exploded and supply training? Do you think about when command control is eroded like that?

Who do hell wants to be part of that network, huh? The radio explodes. The pages explode. I don't want the next thing you're giving me, you know? Just give you a smoke signal from mile away. Now, and hell, that'll probably blow. So there's a lot of nations that the thing about cyber is one smart person is infinitely scalable. So all you need is that one or two great offensive minds at the right time, you know? And the vulnerabilities in cyber change, like today there might be

first time an internet history no zero days work, but right now there's two twenty-three-year-old kids working on an app that everybody's got to have. Do we know who those we right now are? Uh, or the different times. Like today it could be that um, the architecture of matters of Siemens tomorrow could be parsnists. And the next day it could be Cisco. You don't know what skills you need on offense till the moment. I'm actually talking about a foreign adversaries

offense. Do we know who those great minds are? Do we know who to take out? Ooh, they hit us.

I would think it's hard. Yeah, I doubt we know. We probably know some. You always know the lowest

bounds, right? Whatever you know, it's the lowest bounds of your knowledge. Um, but now and I think

ours aren't really well known either. I think the best offense I've ever seen, nobody knows who these guys are. Yeah, they're smart. They go home, walk their dog and they don't blog about it, you know. Um, they don't go to black hat or conferences and really share what they're doing. And the great thing about offense is the government's mission still draws in incredible talent. But at the same time for him, in my lifetime, I remember growing up going the best road at physics

would be in the US government. The best in the world at offense is cyber to be in the US government. The best in the world at big data would be in the US government. And now that I've worked at Google, all right, I'm familiar with Amazon and I see the paid differentials that are probably expanded massively in our lives. I'm starting to think that there's more talent on the outside,

right? So, um, but I would put the US always be excellent on our offense. We have the, you know,

and I hope we just stay there. It's good to hear. Yeah, stake one more bird. Got it. All right, Kevin, we're back from the break. We had a, we had a really good discussion off camera on what you would do if you were going to hack into a nation. How would you? Yeah, you know, if you were, you always wanted what would our enemies do to the United States of America? And one of the things

that you need to ask that first amendment allows any, you know, there's a, there's no line between

you have to say the truth when you're speaking your mind. You know, what's the difference to you know, really, really bad opinion and, uh, being out now lying to and say to riot, you know, and nobody knows where these bright lines are. With the first amendment in the United States and the freedoms that everybody's afforded for that, I think were uniquely susceptible to manipulation to the hearts and minds of the American people. And, you know, there, what I was trying

to remember Sean is, sometime in, I think August of 2015, I'd want to my Intel folks. We built a global intelligence infrastructure of mandarin. So we had hundreds of people that spoke 30 more than 30 languages in over 30 countries. And one of these guys just walked in my room one day and said foreign intelligence from Russia is influenced in the hearts and minds of people through these ex-handles, these Facebook walls, and he just unloaded, and it was like a hundred-page document.

And I remember going, this feels wrong. I don't, this is before anybody ever talked about, Russia's trying to influence the US elections. We're no crap. Every nation is, right, with whatever they've got. I mean, if you're getting funding in your Liberia, wouldn't you maybe try to get a few votes for that side? I think there's no different, there's good people trying to manipulate hearts and minds for good reasons. But what we saw on what I saw in a hundred pages, and we went

Public as a company about this, with about 90 of those pages.

flew back in and it's brief Senator Warner. He was, you know, the Senate intelligence could be

saying, I don't know what to do with this, but here's what's happening. Like Facebook walls are

being started. And when we went back and we traced it, I don't remember the details now other than our guys were really good. They spent their whole time kind of tracing certain Russian actors. And they're like, this is them. This is them using these platforms. And all they did is amplify would already exist. They weren't even really making stuff. They were just like, let's push this issue. Let's push that issue. And they were just driving things. And people would ask, well, what side

did they push? I'm not sure they gave a damn about any of that. I think they'd more cared about

just push American people this way, put directions. You know, and I apologize. I don't remember the details as well as I did, you know, a decade ago. But I mean, that was the cool part of my job. It's literally a guy just walks in my office. You're going to want to read this. And me read it and go, what the hell do I do with this? You know? And then you just talk to people like,

you know, we got Facebook and Bob. We got Google and Bob. There was a third, oh, X. And we did

talk to their trust people. And all of us were like, yeah, this doesn't feel right. But we didn't know what to do. You know, going to be it. It was the earliest onset in my opinion of social media being used. And you can't tell what's artificial amplification versus real amplification. That's a problem, right? You can't tell if this is an issue that matters to Americans or not based on the number of hits and number of volumes. And that's those feeding our algorithms and changing things.

So we got to figure this one out. I know a lot of work's been done since I expected it. So I'm sure today there's a constant whack a mole at the social media company. Say, that's a foreign actor killer killed that. And yet people don't want that to happen either because it's censorship. But I can tell you it's real. And if I were on offense against us, because of the first amendment and you're right to say anything you want for the most part, you know, Shiaovskyman fire and a crowded

movie theater kind of thing, we are susceptible to attacks Iran is not, and Russia is not. And China is not. They're not bastions of internet freedom. They control their press. And we can't really push back on the buttons there as effectively as you can push our buttons. So you even can look at our nation today and many people describe it as divided. I can't tell because I think people are amplifying the edge. And I think we're getting that through our media in such

drastic numbers that nobody really knows what's normal anymore. And it's too easy to do, you know? So I think if you go on offense against us, you just get us terror cells apart.

You know, that's what you do. And psychological work. Absolutely. And you can, you know,

and if we've even seen that, you know, no matter what people say about the DNC breach of 2015 and the documents leak in 2016, a lot of people are all like to talk about that. It became a political issue, but somebody hacked these servers and somebody leaked documents. We'll leave it at that. I would say that the, to me, all of the facts did align in my experience to really was the Russian GRU and SVR that did it. Just all the same tools. And what's

interesting about those guys, by the way, they really used their own crap. So if you find their crap, it's them. I don't think they're leaking it out and giving their custom tooling to other people.

And I've never seen a modern nation hack and then leaked documents before. That was kind of the

first. That was a escalation in my domain. China doesn't do that. They're not going to hack Sean Ryan and then take all your email and throw them out in the internet. Russia seems to

do that now. Yeah, it's a little bit different. But that's what I do. And then what would stop you

from hacking people like Hillary Clinton or Obama? They lost our emails before to what we would attribute as foreign actors, leaked the emails, make crap up in them. I mean, we are a culture now, where I don't even know if you need the evidence to, to solve someone under the bus. You know, so I think the way I'd go to war with the US is maybe what we're already seeing. You create division. Absolutely. You, you create discord. It doesn't matter. You don't even pick aside.

You pick all sides. Just throw it at us. I would actually pick the two opposite sides and keep pushing both of them. And you see it. It's just, it's going to make it tough to lead in our country. And, and it's that freedom of speech. Everybody has the right to say whatever they want. And so we got to figure out how to protect that freedom while still showing, I would argue the biggest thing we have to do is find artificial amplification of ideas and quash it. Does that make sense?

Because you think it's like 50% of America thinks something, but it's like 3% plus amplification. But that's really hard to do. And in reality, the biggest guilty people for amplification are

Marketing people.

but unfortunately, so do U.S. organizations. You have to do this. Or, you know, here's the cure. So it's really, it's a tough battle. And you know, you often study, there's a book,

you have kids now. So you have to read these things. And you look into the anxious generation,

the same person that wrote the coddling of the American mind. And when I leave, I'll send you these books. It's a reporter. You don't even need to read the book, Sean, just look at the graphs. Ever since the iPhone came out and people use social media, depression goes skyrocketing thousands of percent. Suicide goes skyrocketing hundreds to thousands of percent. They don't know anything other

than well. It all starts going bad in 2007, the year the first iPhone. You don't blame Apple,

but was the species ready for what we were actually developing. The tech finally get out in front of us in a way where we couldn't manage the fallout from it. And to some extent, a social media, I think that's the case. It is social media in many ways, because in the anonymity behind it, does have the propensity to amplify the minority. It has that possibility. So anyway, it's a tough one. So if I'm on offense against United States, I'm all hearts and minds. Fake media, synthetic media.

Even if you know it's fake, you won't get it out of your mind. Right? You know, we even have an administration at users. And I think it's, uh, we're going to have a future where we won't be able to tell properly between synthetic media and non-synthetic. I think we're already there. And I think you're right. And so the hearts and minds, when you have a nation like us with this openness, I mean, we're pulling ourselves apart pretty pretty hardcore. I know, feels that way.

I mean, you would even mention bridging companies. It's all rating riff. Oh, absolutely. The companies absolutely get the just very business leaders. I hate saying these ideas, publicly, because you can do it, discredit public leadership in credible ways. I don't even think any credible ways, but just do it in credible ways. Meaning say, you had someone to get their email, leak it. I've seen what that does to people, but leak it. Nothing stops you from adding to it.

And doing it in a frenzyly sound way or in a way where some, there's always a pun in to go,

well, it's definitely real. I'm an expert and that's real. And then you have someone who really knows what to do and going on. It looks fabricated. I've worked cases where all the evidence was fabricated digitally. That was amazing to me. Couldn't believe it. My opinion was it was and people agreed with it. And today's day and age, it's just too easy. We all have digital lives. We all rely on

technology more than ever before. You have wearables to tell you how much sleep when you should take

pills or drugs. You have wearables that might even, you may even have apps that require prescription at some point time because, you know, you have something on your rest that says, you need more of something. You know, I'm sure it already exists. We rely on this text so much, but the unfortunate reality is you can take it. You can take that data. You can skew that data. You can use it against people. We have a whole generation Sean. I think they, all their deepest sauces already written

down. You know, in the text they shared, in the photos they share, maybe we've waived the right the privacy. And maybe that's the transition mankind's going through from the private life. And, you know, people didn't need to know our thoughts to it. Now, everybody knows everything we're thinking. And maybe we cross the, the chasm and just recognize it's okay to think whatever to hell you want. How dark it is or how great it is. But we haven't crossed it yet. So, damn.

Yeah, so that's what I would do on offense. That's what I thought, you know, when I was at the

Navel Academy, we were talking about, and everybody was coming out with their neutron bomb, blow up GPS, and that's what we do before we were. I'm like, how about a road confidence in your lawmakers and your business leaders? And how easy that is to do? And it is easy to do. One allegation creates doubt in a lot of people, whether it's founded or not. So, we need to have a better system to, they call it a cancel culture. You know, it's tough.

Damn. Yeah, sorry. Dark stuff, man. We got to end on a, we need some sunshine. I don't think we're going to get it any tough. But the hypothetical is, how do you attack us?

What do we do about it? Boy, is there ever a time for critical thinking? You know what I mean?

And how do you teach that? And how do you change that? And honestly, and I've heard you talk about this, you know, exactly right. And this is a cyber security episode. But when studying cyber security, it's directly related to ideological conflict, you know, period. It really is. And people with opposite opinions got along talk and respect each other. The American way is got to be, you can have a disagreement, still be fans of each other. Yeah. You know? So,

we kind of, we have definitely lost the, it refarts it in cyber space, too. It really does.

Like, it's, it's, we used to be able to.

If you committed cyber crime in the United States, you got caught. And penalties were stiff.

They were, a lot of people would argue they were really stiff. Because judges and lawmakers didn't like the invisible crime and the anonymity of it. And they wanted to stop it because there was maybe too easy. So you have a severe penalty because of how easy it is. And suddenly, in the last few years, we were running the Western Hemisphere hackers and they're not getting arrested. And I don't know why. You know what I mean? Like, in my career, at least a 25 year run. If you had from L.A. Oh,

man, you got caught. If you had from anywhere in this country, got caught. If you're doing it in Canada, you got caught. It's seemingly getting harder. And our, what's going on, but we do now have in my career,

where responding to intrusions and the threat actors are on our continent. Isn't that weird?

Didn't used to be the case. And hopefully we get, you know, we get back to where we were.

We push all unauthorized or unlawful internet-based activity for the most part. We got to get that. We ought to be able to control our backyard. The internet wasn't built with your privacy in mind, but Glacier was, open the app, tap Connect, Don, you're protected. Remember, privacy isn't paranoia. It's protection. Do you ever wonder what it takes to make an episode of the Sean Ryan Show in this exclusive

studio tour? I'm taking you behind the scenes for an in-depth look at every part of the operation from the editing room in the main studio to the spaces where we film range day, content, and more.

You'll see how the show comes together. Meet some of the people behind it and get a closer look at

the work that happens off camera. When you become a paid member of the SRS Patreon community, you get more than just the podcast. Watch new episodes early alongside other members. Join monthly live shows with guest Q&As and submit questions just like you see on the show for upcoming guests on the protector tier. You'll also unlock exclusive range day videos behind the scenes content in premium ambience videos that you're not going to find anywhere else.

Join the Patreon community today and get access to the full experience. Let's move into our four-ever series. Yeah. Who are they? In Cyber, you got to go with Russia. It's two-trick pony, criminal, and real foreign intelligence services, high capability. When focused, they are Wayne Gratsky on an appellate shot. They're the real good. China, massive scale and scope. You can add all the threat groups I tell you up and they do not create the volume of compromise

that the Chinese government does. So all of it together. Criminal, Russia, North Korea, Iran, all of it together doesn't add up to the steady tsunami of Chinese-based intelligence. And we only know what we know. But we look at my old company, Mania, response over 1,000 cybersecurity breaches a year, Sean, and these aren't the ones you're five minutes behind. We get hired when the scale and scope of the intrusion requires additional expertise.

And that's us. And we're responding with companies that have great talent and great defense and we're still showing off going on. How did they break in? And it is new and novel attacks. It is things that would work 99% of the time or higher. And that's, you know, so we've got to respond to those. And when we look at that, without a doubt, since 2004, China has led away.

We've always responded way more to breaches coming out of China. They follow rules of engagement

that I don't think are written down, but they are polite hackers. They don't delete your data and destroy your systems. They steal things. Russia hacks for security reasons. You know, the SVR, in my opinion, follows probably the same rules our offense does. But their FSB, TRU, a little bit more broad than what we would ever probably allow. And I've heard stories of Russian threat actors that hack for the government during the day and hack.

To make money at night, I'd believe it. Certainly Russia condones all crime being done in the cyber domain period. And they actually, yeah, from one I've heard book China and Russia. I mean, they have put on classes courses schools. Oh, totally. And at the schools, they, they actually

just hack the US as a trend. Probably. I think we're trying to, they'll hack not to make money,

though. You know, not not directly Russia, they would. And so North Korea only hack to make money

It seems.

every day, or at least showing I do to get in, are hacking to make money because they fund themselves.

Is that incredible? And have you heard about the North Korean IT problem? Where it's not hundreds.

Thousands of North Koreans have been hired by companies United States because we all started to hire and remotely during COVID. We hire IT professionals. They speak English. They know what they're talking about. But they're actually North Koreans. And you hire them in a couple of days after you hire them. They just deal all your crap and go. And sometimes they keep working for you because you're paying them 130 grand a year. There's a podcast coming out by Nicole Pearl off and maybe

you'll meet Nicole. She's a New York Times reporter. She's doing her story on this now. Her last podcast was on the Chinese Cyber Asponage Campaigns. And she can do things I can't. Like she'll

say things I won't say. Or she'll talk to the victims and follow up when I never got to do that.

She saw the ramifications of companies losing their IP. I just saw what the attackers did and how to clean it up. She's doing a North Korean thing now. And when I first heard that problem,

hey North Korea, you know, has IT workers getting hired. I'm like burst out laughing at it. There's no

freaking way that this can be a problem. And I was at a conference with a bunch of heads of security from really reputable companies. And as soon as I was like laughing it off, like a five of them came up to me and starts to say, hey, no, we have the problem. And when they explained what happened, I went, there's no fix for it. The fix is you've got to get people in the chair across from you and hire them. And the problem is we literally hire internationally. Many US companies will

hire people in Europe through Zoom, Google Meet, you know, or Microsoft Teams. And these are programmers that can answer your questions, right? I mean, and quite frankly, they all even do the damn job for you. It just so happens you're paying someone who's working for a weapons of mass destruction unit. You know what I mean? Literally. And so the North Koreans, you may hire them and then they have to steal Bitcoin. They're hacking to make money.

Russia's hacking for spying and crime, China's hacking for spying and long-term economic gain through theft of IP. And Iran right now, you know, with what's going on the excursion going on right now, the, it's like, the cyber domain was already a crappy neighborhood. Think of it as it's like, Camden New Jersey, elephants, Camden, tough place. It just got five new gangs to it. You know what I mean? It's like cranking it as they say in spinal tap, crank it to 11.

The cyber domain, if you can be hacked by an Iranian effort, they'll do so. But the way they break in right now is with user accounts and passphrases that are already on the dark web. Like you lost your user ID and passphrase from some prior breach somewhere, maybe your own company, maybe somebody else's. They tend to brute force long yet and then they're going to delete everything at the get-in right now. Whoever they are, the gangs that want to support the

Iranian cause. So yeah, these things will soon be retaliation from in the cyber space, from what's

going on in Iran right now. I think right now there's probably automated programs running on behalf of

the Ministry of Security Intelligence and Security MIS over there that if a Ken break in will. And then they gotta get a human operator to do something with it. It doesn't take a lot of bandwidth, bandwidth if you can get, you know, you don't need a whole lot of satellite dishes to get something working for you there. Yeah, you'll see something. And it'll be real hard to tell, show them whether it's really the Iranians or proxy or just somebody who wants to have for the

hell of it and you make some noise. Which one of these, you know, out of Russia, China, Iran, North Korea, which ones, who are you most worried about? You were about them for different reasons. I would say

sophistication now goes to China for how they first break in, how people break in will always change.

China seems to be the forerunner of what's called zero-day development now. They can find a tax that are going to work. And then, but when they break in, they're not leaking your email to the press. They're not extorting you. Those are really complicated. So I would say Russian criminal, really hard to go against. There's some now Western hemisphere criminal gangs. There's a group called Shiny Hunters. There's a few others that they break in with social engineering. They'll

like call your helpdesk and helpdesk help people. And they have whole scripts written and they're very bold. And they get one time authentication into your network and they, you know, then go in. And once you can get any beach head in the cyber domain, use that means you take the island. You just need that one boot on the ground and you'll do fine. So you need one way to access and that work you'll you'll spread from that. The Russian criminals are really hard to deal with.

US now we have Western hemisphere criminals. They're really, really hard.

Iran's going to delete everything right now.

fun cleanup. They're all bad. I mean, that's the reality show. But the public humiliation does not come from being hacked by the Chinese. That, you know, those you can handle

quietly in the screen. I think it's the Russian and the North Korean and the Iranians probably

are going to go public. And that just adds complexity to your response. Gotcha. Yeah. Gotcha. All right. How are you hanging there on the cyber in there? The scary shit. Yeah. So yeah, we got to get more optimistic. This will move into your new company. Yeah. That's a question. Yeah. So, you know, Claude, I'm sure. Oh, God. You can't throw up it. Yeah. So we had Claude Anthropics. Say I scraped the internet to ask you a question.

How did it do? And here's what it came up with. In 2010,

Stuxnet became widely known as the worst first the world's first cyber weapon. The US and Israel used it to physically destroy Iran's nuclear centrifuges. That was 15 years ago. Now with AGI being reported as achieved, do you think AI is the new

cyber weapon and why? Fast answer. Yes. You have to use all technology to advance crime,

to advance war, to advance societies. It does all of it. It does good. It does bad. The invention of the gun helped the hunter, but it also helped criminals to some extent. Depending on your frame of reference, AI will make the speed of intrusion take the human out of the loop. That's what it will do. It's too fast at discovering vulnerabilities. The so I started armoured in and combined what's called red team consultants. The best red teamers in the world. These

are folks that get paid to hacking the Fortune 500 companies and see if you can stop the train or corrupt the food or shut down the grid or steal the email from the CFO. We took those guys and we're still hiring a bunch of them and we paired them up with AI native developers and said

automate what we humans do. We started this company September of last year, Sean. Here's what

I can tell you happens already. If somebody tells us they hire our red team and says, take a look at this custom application. You build an application that you gave me here. A man someone will say, take a look at this application. Can you hack it? Well, used to take us five days with two smart humans is five minutes to ten minutes with AI now. That already exists today. So what you see is the compression down. But it gets unfortunately more daunting. When we go on offense as humans,

we only find one way in at one point a time to achieve the goal. You've told us to try to achieve, try to shut down the assembly line, try to get to our IP. We find the fastest path in, we prove it, and then you fix that. With AI, we launch a hundred thousand threads coming out. You would find all paths in, almost immediately. But it does a few things humans can't do. Has total recall the next time we ask it to do that. So if there's a vulnerability, it found that company A two months ago,

an instinctively already knows. Look for that again. Just case you didn't fix it. It's the speed, though, the fact that AI can think learn and has total recall and can be trained, it will be the cyber weapon in the future. Just like no different in drones. If you think you can fight the next war and when you better have software that thinks learns and is secure and you better hope it

thinks the fastest learns the fastest and is the most cured when that war. Are you going to lose?

And that's going to be cyber domain. That's going to be autonomous planes drones. You name it. So yeah, there's a follow-up. Got it. On a different note by 2027, every new car in America will have an infrared camera pointed at the driver's face. And that's by federal law. From a cyber security experts perspective, what's your honest take on this? Is this the vulnerability for our adversaries to hack American vehicles? There's been an equal and opposite compiling argument side security since

the dawn of time. If we're distributed, it's harder to beat us. But it's harder to defend us. If all our eggs in one basket, it's easier to defend, but easier to beat us. Does that make sense? Right now, we're putting data about everything everywhere. I mean, I grew up, there were no cell phones

in college. Otherwise, I would never be able to be a Supreme Court justice. Evidence would exist.

Now there's cameras everywhere for everything. There's just no question, even though it's going to get harder and harder to compromise things. I believe that. The internet was pretty damn open in the '90s. And I've lived that. It was pretty damn open in 2000. It really took 2020, 2021.

We're in a whole different world.

less vulnerabilities. But at the same time frame, should someone break in? I think the impact is going to be far more than what it used to be in the past. You know, early on in this interview,

yes, what's the worst breach we saw? And I remember going, I always hated it if a flag officer

lost his email. That's just weird. You know, because they do important things. Fast forward to now, with wearable devices and our dependency on everything, whole businesses can operate if the internet goes down. So AI will be the offensive choice. And unfortunately, because of the speed of compute,

AI is going to have to be the answer on defense. And that's why I arm it in exists. We will be the

ultimate offense, built by the good guys to train and automate the defense. And every company is going to need a different defense. We're all going to write our own apps. We talked about anthropic and Claude. Talk about magic. I had a computer science degree. I hate to say it. Don't tell your kids to get a computer science degree. Okay. Hack asked the CEOs of these companies at a, you know, asked Dargo at an anthropic. Hey, do you want your kid to learn computer science? You'd press it.

It's like learning Latin. No one's going to speak it. The computers are going to do it for us. The whole goal of Anthropics to have Anthropics Claude build the next Claude. At arm it in, we want to get our AI tack would be so good. It's building its next AI attacker. They self-propagate. And the unfortunate reality is we have to build it or the adversary will. And it is the only way to get to autonomy. But back to your original question, yeah, we're going to have cameras in the cars,

cameras on the streets, cameras in our homes, data everywhere. I think it'll be harder to break into all that stuff. But should the break in occur? I think the impact will be grave, more grave

than in the past. Now, I'm thinking today, two years from now, you should be driving a car

that has something in it that instantiates normal Sean driving. And if anything happens, something very bespoke to you can recognize and say, that's not him. That's not what he wants. That's not what he does. And it may save you. I may do the opposite of that. But we are going to have

defense that can thwart attacks we've never seen before. And do it in a way that a human's not in the

loop for. Something's asking this system to do something's never done before. It may automatically get stopped and ask for a human in a loop. Say, hey, listen, does it never happen in this car before? Do you really want it to happen? Or does it never happen on your computer before or on this camera before or on your HVAC before? Do you really want to allow it? Stuff like that will exist. That's interesting. And then you'll pick in your house, you'll say, I want to be prompted every

time someone's accessing my camera. Other people don't get trained specific to them. It'll get one time. Human loop go ahead and allow tapping. And after like three times where the user says, go ahead and allow the program to do something. It'll just do it from their own end. Well, I'll have be spooked software trained by you. You're fun on the being trained by you. The a on your phone will know you be personal to you. There's got to be voter abilities within that alone.

Well, yeah, you're often wondering, now we're talking to two AI Skynet story, right?

One brain in the sky doesn't mean we all share one brain over time. And that brain will always

reflect the culture of those who built it, to some extent, right? And then all AI models, no matter what anybody says, we had to add armament and build a way to as soon as they update at the front two laps or models. We plug them right into our shooting range and see which ones are the best at the things we normally do now. And no flip and flop all the time, or they'll be about equitable and we test them on the range as they say, but these things you test them day one,

you test them day 20, they're already different. They're like, they're like organisms that grow. These models learn and change in sway in ways that are different. Like how we what we get out of a model today could be totally different model. Not totally different. It's always, you know, to me, I haven't gotten hallucination at a long time. And I use Gemini a lot and I use Cloud a lot. I'm a little less open AI. And I use it for real stuff every day. It's common. I have like

Cloud running on something that I want, because it's great. I'm making PowerPoint slides. And I have Gemini making some graphics for me or answering questions. I'm using them both. Interesting. Yeah, interesting. Where did the motivation come from to start armament and has to exist? Right? It's two, two things. One, I wanted our, the first motivation is, you know, my company got bought by Google. And I'm an entrepreneur. You know, some people would say once

you're an entrepreneur, you can't sell your baby. I had no problem being a public company and getting bought. Companies no longer mind. I was the face for it. But if you're a great entrepreneur, at some point in time, you're also the owner. But, you know, I had no problem letting it go.

I was bought by Google and I went in like a lion.

It really can. The resources it has. I just didn't fit. You know, so I was a little upset

in a way that I didn't fit there because I, I know the power and capability of that company or

Amazon or Microsoft. We have great companies. They can do great things in cybersecurity. And you

want to be a part of that. But one thing they would never do is offense. And I respect that.

I'd get it. I wouldn't fit with a large brand. And I thought to myself, the exact thesis I had was the first intel in the internet was terrible. You had to find what semantic missed and give it to them. The second intel in the internet, I feel I created. We'll respond every breed step matters. And people are like, that's not even a market. There aren't no breaches. Oh, there were. And we responded to all of them. And we learned about the new and novel text first

so that we could build better defenses against them. Well, the third wave of intel is, we're going to create the attacks. And we're going to create them before the bad guys do. And we're going to fix your problem before they come out. It's almost, you know, I guess they called gamification in a way

for viruses. But if you can create the viruses that are coming 10 years from now and unoccupied today,

we're ready. You know, same thing here. But we have to build it because, hey, it's going to be

what we're up against. And if you want to know if a bulletproof vest works, you've got to shoot a bullet

at it. We're going to be shooting bullets at networks. And if you understand our bullets, the assumption and what we want to become is that seal of approval. If armoured in camp break in, oh, you're good to go. Brief the board. Let them know. There's no other way to reduce your cyber risk. And I actually believe that. So we started armoured in so that we can dry around and practice what we're up against. And it's common. There are no risk of repercussions to the folks stealing from us, hacking us.

Just we haven't shown a means to impose risk to be threat actors. So you get you got into it a little bit. But what is the future of cyber warfare with AI coming online? Oh, boy. You will have systems dedicated. I think. So the general models are what are called horizontal models. Like anthropics cloud is a horizontal model, right? Open AI, horizontal model, X as a model, Gemini for Google. There's going to be very verticalized models where you train them and learn from these huge

models that have read every book, every humans ever written or watched every YouTube video of everything. You've contributed to models, probably you don't even know it. And you're going to, you're going to have offense against very specific things. Like we're going to end up creating models that are offense against cell phone, offense against drone, offense RF against drone, offense against windows, like deep models that are actively working the same way a human did,

but at thousands and thousands of times the speed. And doing the same task we did to try to find vulnerable code, vulnerable IP, you know, it'll all be automated and specialized for the targets they go after. It's just going to happen. And the sad thing is we had to build arm it in because it's automatically going to happen. Every shift I lived through this shot in 2000, there was a guy named Alexey Ivanov and a guy named Vasily Gorchka. At the time in 2000, Alexey was 18 in Chelyubin's

Russia, Vasily was 25 in Chelyubin's Russia. These guys extorted hundreds of U.S. companies. They break in and what they did is they scripted everything. They even scripted. We got to do the forensics on their laptops. These two Russians were lured to the United States for jobs. And the jobs they got were worth the FBI. FBI lured them over. They flew into sea tech airport to come and airport. And they got arrested. And when you look at what they did, it was at a time

when PayPal was just coming out. eBay was getting big. These guys hadn't monetized that they could steal credit cards. And they wrote software that would sell fictional items on eBay by it was stolen PayPal credit cards. And they were making money. Some fictional stuff. And the whole thing was automated. They could literally hit buttons, scripted, and walk off and come back with, we made $72,000 selling stuff we don't even own. And buying it with fake stuff happened. So every shift

changes embraced by every personality. AI is going to be embraced by the criminal element in

this comment. And we can't withstand it unless we build it ourselves and figure it out. So I always

believed the best way to build a safe at a bank is to get the best bank robber to build it for you.

You know, you got it out of Rob Banks to investigate a bank robbery. And I had the privilege of training thousands of FBI agents to FBI Academy. So when it came to cyber, we taught him how to break it. Get a sense of what you're up against. The actors, why they do it, how they do it, and now well, it's investigate what they did. And you couldn't really just start with let's just investigate it. It just wouldn't work. You had to give them that sense of doing the criminal act

That investigating it.

So Arminen's going to build the cyber cannon. We're going to shoot it at the best companies in the

world. And those companies, if they can withstand the blast, they're good to go. And if they can't

work over time with no human in the loop, building fixes to however we broke it. If we find a permeable membrane and we get through, you're going to patch it. You're going to compensate for it.

And that is the future. And oddly enough, that future scalable. Finally, you can, once we build

the A on offense or say on defense, we can go down to the utility and now equipped with Pennsylvania and say the water works is not going to be compromised. And the small mom and pop electric company in Missouri will not be compromised. Because we can now instantiate a national risk policy through an offensive cyber cannon training to defense. And it's just software. You're not going to be people dependent. It really is going to happen. And we'll

have flaws. Will we get beaten? Yes. Everyone's wrong. Be something on offense that gets through. But you can literally use the analogy of drone swarm in the cyber domain. Like you're going to send 3,000 drones out of city and we can only shoot down 2,900 90. You know, we're not the same problem in the cyber domain. We're trying. But the best part of it is it will be automated and it's

actually going to raise the tide for cybersecurity for most people. And then the bigs will always

have their own team still doing stuff. That'll secure. I'm just curious and I'm sure it's very different. But on average, how many vulnerabilities are you finding for company? And now fast, do you find them with these AI agents? As I sit here today, it's never taken longer than data break in. Shit. Yeah. With any. Yeah. And here's what's interesting. So I can tell you this. I still think the best findings we had were by humans. But that's going to go away within a year.

And nobody knows how fast, but AI keeps surprising us. But here's how we broke in the first time. A fortunate 100 company that you literally said, hey, break into us and see if you can

break this custom application we built. Very important application. We have an AI agent, they didn't

even expect us to do this, but we've done this a lot. We had an AI agent go out to the dark web and go to a bunch of password brokers. And we found 440 or so accounts that were the domain of this company. And all we did is try it all of them at human speed, not AI speed because AI speeds too fast. You can rate limit and block it. Cisco routers can block fast attacks. We just logged in. Seven of the accounts actually just logged into the app. We just logged in. And this is an app.

You don't really want people logging into. And on one of the thing and we did all human speed, you saw a browser just kind of pop up on our agent screen. It was acting like it was a human. Try it all the accounts it found. It gets in seven times. But on one of them, the app we broke into prompted you don't have multi-factor authentication turned on. Would you like to register your phone? So we did. So now we literally hacked the company. All I stuff we found on the internet.

And but humans wouldn't have found it because it's really a painting your arms. If you scripted it's too fast and you get blocked or detected. If you have a human login every time it takes days and it's annoying and they're going to fat finger stuff. We just all automated no human intervention hack the company. That was it. And that works. I would have bought that when I was a CEO. I would have been like, I just want that. I don't even need you to try to hack my app and break

in the old way of the vulnerability. Just tell me if you log into my damn network because that stuff changes. Everybody thinks, oh, we have two-factor authentication meaning user account passphrase and then the digits to your phone or you know your fingerprint and all this other crap. I would want it. There is no magic wand that says do we have two-factor everywhere. It doesn't exist. But this would prove it. The attackers view of your network matters and AI can

comprehensively do that. So I'm not convinced. Just yesterday I got a text. I'll show you when we're off camera of what we do to a company yesterday. 100% ownership of every machine

day one. We've gone in all of it. And here's the secret in cyber. So for everybody out there listening,

the hardest part is getting in from the internet. Every company does everything they can to, well, at least above the poverty line in the cyber domain. The 1A enterprise is to about everything they can to not have a breach. They don't want to deal with it. And they're truthful about that. They hire good people and they try. If we can't get in, I would say over 90% of the time we do. But once we get in, it's easiest health. It's all downhill skating at that point.

You know, so Sean, that's just the problem right now. Everybody has built their marginal line. And they've hardened that as much as they can. If we get around it, oh, it's just wallets and then

the Paris. You know, it's too easy once we break it. Everything we need is on the very first machine

we get to. And usually the Achilles heel is, every company has one account that works everywhere.

You can patch things.

That's just the Achilles heel. So it's funny. The very thing you used to make sure you're

secure is probably the very thing that we get every time to make you insecure. So anyway, we will get better. Everything as bad as this whole three hours or so is gone. Everyone's getting better at cyber defense. We are in a tough time.

The offense is still uniquely advantage. That's the problem. I think it does change in under two years.

Two equitable. I don't think defenses. The only advantage defense has is we should have access to the software we build to make it secure before the offense can try to hack it. That's our only advantage. We can secure our code before we publish it. Get it out of the market. And the and the and for optics of the world are making that a reality. Microsoft and for a Google really are making it. So the code we're writing is better today now than worse.

That is happening. So in theory, it'll get better. Sean. Let's go. No. It's just we're going through

two years now. This dialogue would be different. I would say, you know what we're stopping 99.999999 99%

of attacks now. It's just the best in the world. We never get to stop them. They are their scoring.

Wow. Yeah. We'll have them. We'll wrap it up here. It's just has been. I've learned a ton really. Yeah. So thank you for coming. And so one last question. Sure. Yeah. Three guests to recommend for the show. Who would they be? Well, I love Bruce Springsteen. Bruce Springsteen. All right. All right. Three guests for your background. If you do another one in cyber, the best person that can bring us to everyone is Nicole Pearl off the New York Times reporter.

I told you she is exceptional on camera and she tells better stories than I do. You know, because I came up through computer science and I had to solve the problems. I had less of a humanity

side to me when I met CEOs. I was always like, hey man, sucking up deal with crisis. She's

better at it. She tells better stories as to what China did and what the North Koreans are doing. She's more personable, more likable. So she's a great one for cyber. I was able to, you know, and I don't know. You're doing a great job. People like listening to like, I listen to Kent, the guy that you said I don't catch. Yeah. I thought he was great. I made political. I won the United States to be successful. I thought he did an incredibly good job doing the same being a political.

People probably hate the guy. I'm probably getting trouble saying it. I just listened to it and thought, okay, I learned something. You know, you listen to, you know, bottom line, you get both sides.

You get people at least earn. I think one's attention. I get a lot of money. Yeah, I mean,

it's, uh, it's important. Sorry, I'll give you those two. Spring scenes will be good. Or if I'm getting old. Kevin, I really appreciate it. Thank you. Hope to see you again. No matter where you're watching the Sean Ryan show from, if you get anything out of this at all, anything, please like, comment, and subscribe. And most importantly, share this everywhere you possibly can. And if you're feeling extra generous, head to Apple Podcasts and Spotify and leave us a review.

Compare and Explore