This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to Purandar Das and Ken Foster. Ken Foster is a highly accomplished Security Expert with over 25 years of leadership experience in cybersecurity, infrastructure, and risk management. As a former CISO, technology leader, and US Navy Veteran, he brings a unique blend of strategic and operational expertise in information risk governance, IT enterprise operations, and security architecture across both the public and private sectors. In addition to his executive roles, He serves as an advisory board member and Chief Compliance Officer
Purandar Das is back on our show. For those of you who may not remember, Purandar is a visionary leader in tech, having served as CTO for two of the largest marketing services companies. He is now the CEO of Sotero, a data protection company. His shift from data monetization to security was driven by the alarming rate of cyber threats, like those faced by JP Morgan. He’s built systems that have reached millions, and now he’s safeguarding a petabyte and a half of critical data.
Chapter Titles:
00:00 Introduction
03:03 What’s new in Data Security?
06:20 Laws are changing
10:10 Does ‘forget my data’ work?
12:15 Prompting on ChatGPT can reveal hidden data
22:00 Not just a checkbox
30:23 It takes a lot of transactions
41:14 Not impossible but difficult
47:26 Loss of revenue due to a breach
54:21 Learn more about Soltero
Audio:
Important Links:
Transcript
Manoj Tandon (00:01.052)
Hello everyone. Welcome to another episode of Dark Rhiino Security, Security Confidential. Today we are honored to have two guests. This is kind of new for us. We haven’t done one of these in a couple of years, but we’re really grateful to Purandar Das and Ken Foster for joining us. Purandar is an alum of the show. You folks can go back and look at his last episode. In fact, we’ll try and put a link in to the show notes for it.
He’s a visionary leader. He’s been a CTO. He is the CEO of Sotero, which is a data protection company. And he’s going to talk a little bit about that. And he shifted from data monetization to security. He was totally motivated by the alarming rate of cyber threats. And like those faced by large organizations like JP Morgan, he’s built systems that have reached millions. And he’s safeguarding a petabyte and a half of critical data right now.
And there’s a lot more to him, but please check him out. And Ken is a first-time guest. We’re really honored to have him on the show. He is a 25-year veteran in the security industry. He’s a security expert. He’s a former CISO, a former U.S. Navy veteran. He has a very unique blend of strategic and operational expertise as a result of his experiences, both in the military and in the private sector.
And he currently serves as an advisory board member and a chief compliance officer. And he’s going to talk a lot to us about some of the changes that are coming in the PCI standards and needed compliances. So, gentlemen, welcome to the show. Thank you for being here.
Purandar Das (01:47.516)
Thank you. Thank you. Thank you for having us back.
KEN FOSTER (01:49.25)
Yeah, thank you.
Manoj Tandon (01:51.336)
Thank you very much for joining us. So, friend there, let’s start off with you a little bit. Just do a quick recap on data security. What’s changed since your last appearance or what’s happened?
Purandar Das (02:02.652)
I mean, the most obvious and visible change are the headlines around how many more companies continue to lose their data, right? That’s the most obvious one. It’s reaching, if it wasn’t scary before, it’s reaching horrendous proportions, right? mean, whatever’s been done, obviously the hackers, the criminals, whatever you call the state actors, whatever you want to call them.
have just continued to increase their sophistication and their attacks on stealing data, not just from individuals, but from organizations, government entities, and hospitals, name them, right? I mean, they’re going after everything because the opportunity is so tempting. That’s the scary part of it. The opportunity and the challenge part of it is the introduction of so many new capabilities, right? I when you think of AI, everybody’s talking about how it…
what AI can do and is doing and will do. But it’s driven by two things. One is compute capacity or capability, whatever you want to call it. The second thing is data, right? And now the whole focus of how to collect data, to preserve the security and the privacy of data, how to interact securely, that has become a challenge. Then you layer on quantum computing and quantum encryption. You have convergence of a lot of different factors.
that have continued to increase the spotlight on security capabilities, especially at the data level, and how to enable organizations and individuals to securely interact and collect and store data.
Manoj Tandon (03:41.704)
So, Purandar, have we done anything to change the motivation of the bad actors at all?
Purandar Das (03:50.236)
I think, mean, so the motivation for the bad actors is the money or the opportunity, right? I mean, it’s one of two things. For the individuals or the true criminals, it’s money, right? I mean, it’s really simple. There’s just so much money there that they’re willing to take that risk. I mean, that’s their motivation. On the state side of it, it’s the motivation is different. It’s threats or allegiance, loyalty, misguided loyalty, whatever you want to call it.
Manoj Tandon (04:04.081)
Yeah.
Purandar Das (04:19.6)
Those are two things that are hard to change, right? The only thing that we can do and the only thing that companies can do is to increase their security capabilities to a level that exceeds what the bad actors can do.
Manoj Tandon (04:34.652)
But and that’s a bit of a cat and mouse game because no matter what we do, they will always, you know, as long as money’s involved, there will be a lot of motivation to make sure.
Purandar Das (04:45.306)
Yeah, yeah, I think the key there is to stop underestimating the bad actors. I think for far too long, when you talk to people who’s hacking your data, they typically write it off as some 18-year-old, some teen sitting in his mother’s basement, or it’s some idiot that doesn’t know what they’re doing. That’s not really the case. As you said, there’s so much money, it’s become an organized business. So acknowledging that should be the first thing in terms of how you prepare to deal with and stop the attacks.
Manoj Tandon (05:20.978)
Ken, you were in the Navy and you have some foreign intelligence, I guess a lot of operational experience in this arena. Do you see any changes coming here or anything that we’ve done that really would have a reductionary impact on the amount of cybercrime that’s taking place and the data exfiltration that’s taking place?
KEN FOSTER (05:44.878)
No, it’s actually going the opposite direction, right? Yeah. Yeah. It’s, it’s, I mean, the thing is, that look, data is growing at a rate and companies and people are generating data at a rate that is just, it’s hard to wrap your head around how much data is being generated and what we’re using it for.
Manoj Tandon (05:47.528)
That’s been our experience too. We all three of us agree on that one now.
KEN FOSTER (06:10.446)
And in today’s world, as people figure out more and more things to do with that data set, more and more insights to be gained from it, more and more revenue to be generated from it, more efficiencies, just more insight in general to how we do business, that data is going to proliferate and it moves around. The problem is people don’t understand fully the risk of…
that data being exposed and how it’s being exposed necessarily, because it’s being exposed today not only from bad security practices, not encrypting the data, letting everybody have access to sensitive data, not understanding what sensitive data is nowadays and why it could impact your company. Like Perender was talking about, people just do not understand
when a data could impact you and why it’s impacting you. Sometimes it’s just purely about money and a lot of times it’s purely about monetization of that and it’s very easy and the impact of that is relatively easy to see nowadays because it’s in the news and we can all see these revenue losses by companies that have been breached or lost this data. But every day the privacy laws are changing, every day there’s a new regulation coming out globally that says,
This data is now sensitive because it contains a piece of information about a citizen of this location. So there’s other financial impacts besides just people who are wanting to steal your data and monetize that or a threat actor who is, whether it’s a nation state or whether it is a competitor, someone who’s interested in doing damage to your business and getting monetary gain that way, right?
Manoj Tandon (07:46.682)
Absolutely.
KEN FOSTER (07:59.936)
shorting your stock, causing financial impact to you because they’re betting on your competitor or they’re betting against you. So there’s a lot of reasons out there why people would want to attack you. But then we’ve got the users who are inadvertently exposing the data because of the lack of control and governance around those data sets and how they’re being used, which exposes you to that regulatory risk and that privacy risk or sensitive data risk because you’re
you’re moving it out into a public repository or an exposed repository to the public that now has opened you up to all kinds of fines or other issues coming down the pipe because you didn’t realize where your data moved to and who had access to it. So it’s not a unique problem. It’s not a new problem. We’ve been dealing with this since the dawn of secrets.
Manoj Tandon (08:46.504)
Mm.
KEN FOSTER (08:55.822)
and used to we kept it on files and locked cabinets, now it’s digitally and it’s actually easier to get to now that it’s out there. So yeah, it’s an interesting problem that we still struggle with.
Manoj Tandon (09:06.344)
Well, well, Ken and Pirenda, both of you, if you could chime in on this, one thing Ken, you just mentioned was the compliances and they keep changing. And my question is this, with AI ML, are any of those compliances really even enforceable? And as an example, like you have the right to forget law over in Europe.
You know, or you got the California Privacy Act or the New York Privacy Act. Once you train an ML model with data, that data, you can’t undo it. There’s no forget Minoge out of the data. It doesn’t exist. Right? That neural net, you don’t even know how that data is stored. We’re not even storing the data like we used to in a database with columns and rows and attributes anymore. You know, the neural engines are
machine learning data model is totally different. So how is that even remotely addressable or with any kind of a compliance framework?
Purandar Das (10:12.952)
Well, think I mean, sorry, Ken, I’ll jump in first. I think, I mean, the literal interpretation, forget my data, forget me, is part of the challenge, right? I mean, you can interpret that in many ways, right? The fundamental thing that’s being ignored or left out in that thing is people are less worried about you physically deleting that data.
KEN FOSTER (10:16.046)
No, go ahead.
Purandar Das (10:41.116)
But more in the organizations are more looking for a guarantee that even if you have the data that it’s inaccessible will not be used in business processes and will not be made accessible to individuals that shouldn’t be looked at it. If you take that same lens and apply that to a neural network, as long as you’ve got the filters and the safeguards and the privacy enforcement in place, it’s OK for that thing to have.
been trained on data when it was available, as long as you’ve got ways to eliminate the access, use, and ongoing persistence of that information in interactions.
Manoj Tandon (11:18.226)
But Prerna, we’re already seeing that we can with, and I’ll just pick on chat GPT because it’s ubiquitous. You can absolutely, even though the data has been hidden or obfuscated in some way, or form, the right level of prompting can absolutely reveal that data.
Purandar Das (11:42.48)
Yeah, so the right level of prompting, I mean, that’s where you come up with prompt sanitization or prompt filtering. People don’t understand all of the different interactions and the interaction models yet, right? So if privacy, if there is a requirement and if there’s enough time spent, you’re going to people or technologies are going to improve to the point where there’s going to be prompt sanitization that eliminates that possibility.
Manoj Tandon (11:42.674)
Right?
Manoj Tandon (12:12.89)
Yeah, I think there’s a lot of work to be done in that.
Purandar Das (12:15.676)
Absolutely. I was just thinking about this. Let’s take a very, very simple example. If you thought about banking 10 years ago, for the most part, people walked into a bank, wrote on a piece of paper what they wanted to do, handed it over, and the transaction was in the secure confines of a branch. The interaction limited to just a teller and you, and you walked out of there with your money or you deposited your money and walked away.
That shifted to online activity where everything was through a web port, right? That dramatically shifted things. So the bad actors started to go after user IDs and passwords.
KEN FOSTER (12:53.88)
the other.
Purandar Das (12:57.308)
Because that’s what they needed to get access to. Then they said, we’re going to have two-party multi-factor authentication or two-factor authentication as a way to think. So that was the next level of security. did the bad actors do? They looked at Simspoof. So it’s an ongoing thing and it keeps coming. I mean, think about where it is today from where it started. It was a personal interaction with another human being within the safe confines of a bank branch.
Manoj Tandon (13:13.394)
Yeah.
Purandar Das (13:26.626)
Now we are talking about the bad actors somehow conning the telecommunication companies into changing the SIM destinations.
Manoj Tandon (13:36.04)
Hey, $500 can buy you a lot of things.
And that’s not even half a joke. There was a, yeah. Well, Ken, was that whole, you know, the biggest heist in Bitcoin from a private citizen, was like 20 million or something. It was a teenager in New York City that did it. And they did it through sim spoofing. They paid off somebody at one of the major telcos. And the interesting thing was there’s a federal court case on that that held the telco.
KEN FOSTER (13:44.558)
You actually do it for a lot less.
Manoj Tandon (14:10.632)
as harmless. They were not responsible for their employee actually transferring the SIM, which is pretty crazy to me. mean, from a compliance perspective, they have no liability in this whatsoever.
Purandar Das (14:24.252)
Yeah, I mean, we talk about $500 as being some insignificant amount, but it depends on what the context, right? $500 in a different country that’s providing services to a US-based thing, $500 is a lot of So it just depends on who the target is and how they go after it. mean, that’s…
And because of globalization, the interconnectivity of both services and products, the avenues are just way too many, which is what we say with our own product and our platform is you can’t look at security as being one product or one platform or one channel. It’s a connected platform. There are so many interaction points and so many gateways, so many channels, so many user access points.
You have to look at it broadly and say, does the old mechanism still work? Or is it the most effective? Or do we need to shift our minds and look at a different way of approaching data security and privacy?
Manoj Tandon (15:27.77)
And that, I think is at the heart of the problem. When you think about cybersecurity, or I should say not you, when the industry or most people think about cybersecurity, they’re thinking of it as primarily a technology problem. And it is not a tech problem. It is a business problem. It’s a people problem. And when we try and educate people on it, they’re like, no, you know what, we’re going with our
vendor, ABC, PDQ, whatever it might be, and they’re going to provide a product and we’ll be all secure. Like, well, do you know what you’re securing? Do you understand your revenue chain? In your revenue chain, what is your critical processes? What technological assets govern those processes? Right? If you’re going to do a business email compromise, that’s a lot more than getting into someone’s email system. It’s understanding how POs are cut, what the approvals are.
what the various stages of funding are before those funds are released so I can willingly get you to write me a check. I don’t even have to steal it.
Purandar Das (16:35.266)
I mean, people talk about that Hong Kong.
Manoj Tandon (16:36.68)
And they don’t do it. I mean, can you want to say something? Please go ahead, jump in.
KEN FOSTER (16:41.484)
Yeah, so I think this goes back to the root of what we started talking about, you know, like you said, the carts, the horses out of the barn and a lot of these public models, right? The data is a lot of sensitive data is getting put out there. And you’re right. The technology problem is fairly easy to solve. have to, we have technologies that can fix most of this stuff, can stop it. The problem is, is it causes friction.
and the lack of understanding the full scope and the business process and the impact to that revenue stream. So go back to Frander’s example of you used to go into a bank and then we went digital and then we’re like MFA. You know how long it’s taken? It’s still, and that’s a new requirement in PCI now is that you do have to have it on PCI data because it never was really definitive. It was more you should have it. Now it’s a, you must have it.
just like the encryption of the field level is, it must be encrypted at a sensitive data field level now instead of just a block level, right? Which only did kept you from stealing the hard drive and taking it home with you, right? If you were accessing it through the application, it didn’t matter. The problem is, is most businesses are afraid to have that conversation with their customers and say, we’re going to implement a new security measure to help protect that data. To go back to what Parandra was talking about is,
We need to be doing things for the average user who doesn’t understand this in a way that it protects them because, but we’re afraid that they’re no longer going to do business with us because we’re adding an extra step. So most businesses, when you sit down and start having a conversation around increasing security controls, A, one, you better have a damn good understanding of what your business does and how it generates revenue. And you’re exactly right. What is that entire process?
How are we going to use this data? It also feeds into all the privacy stuff that we’re talking about and the right to be forgotten and the business use cases around how am I using your data? You better understand how my data is going to flow through your environment. What pieces of information do you really need about me in your process to actually accomplish what you’re trying to accomplish? Now you may come up with a new interesting insight on, I need to know.
KEN FOSTER (19:08.406)
three pieces of information that can identify me or my banking information. But I’m going to now need to limit access to it. I’m going to need to encrypt it. I’m going to need to make sure it’s not being publicly put into a public AI model. So it’s educating the teams that are building out the strategy. It’s educating the business and it’s educating the end user. We all need to understand what those risk triggers are.
and how doing certain things exposes us to risk or doesn’t expose us to risk. But we need to be able to do it in a way that still allows the business to accomplish what it’s trying to accomplish, which is generate revenue ultimately, right? None of us are in business for fun of it. We’re in business to make money, right? Or of some kind. It’s about revenue generation.
Manoj Tandon (19:47.964)
revenue. Yep.
KEN FOSTER (20:00.406)
You can simplify this back to something that we still deal with today and dealt with it early on in my IT careers. How do I do business continuity? Well, hell, you sit down and talk to a bunch of business leaders and application development teams and security teams and infrastructure teams and goes, how’s all this work together? Rarely can some one person sit down and tell you how all these things are interconnected, which makes it very difficult to build a strategy on just how to get the business back up if something happens.
Manoj Tandon (20:29.682)
That’s right.
KEN FOSTER (20:29.902)
Right? And you think about BEC, about business email compromise. It’s a very common attack. It normally comes around for ransomware most of the time or a little bit of spearfishing or whaling, right? But it’s, the problem is, is most people don’t understand how that email system is connected into other things in their environment. And like, well, we can’t run our CRM if the email isn’t running. We can’t run our invoice system if the email isn’t running. And so you start walking through all this stuff and it…
We have gotten to the point where we’ve gotten so myopically focused in specialization that it’s very difficult for someone to step back and take a look and interpret what the business is doing and what the technology teams are doing. And now add a security person or a privacy person or a data protection person in there. Go add all that together and go, how are we going to interconnect all these things? And how are we going to be able to secure it?
in a way that makes it almost transparent with low friction so that the users can still accomplish what they need to accomplish. We can still generate revenue and we don’t piss anybody off and namely a customer or in that standpoint, but protect them from the people who are absolutely coming after this. No matter what size company you are and what you think you just do. And I’ve heard this so many times by business leaders, by IT leaders. We just do X. We just make…
Manoj Tandon (21:58.13)
Yeah
KEN FOSTER (21:59.054)
this little thing. Why does anybody care about that? Well, because you don’t care about it. So you’re a soft target. You’re easy to get and monetize. And all they care about is how quick can I get some money out of you and move on to the next guy. And if I can get 500, let’s go back to that $500 thing. Yeah, $500 in certain countries is not that much money. In other countries, it’s a huge amount of money. But if I can get $500 10,000 times from a bunch of small places that are not
Manoj Tandon (22:02.013)
KEN FOSTER (22:27.53)
equally protected or not taking care of this. So that $500 equals up, gets very big number very quickly, right? So it’s not, sometimes it’s about volume, not necessarily about quantity, right? So, and that’s one thing I think people fail to realize is that those smaller targets that they may only be taking, if you’ve ever had your credit or debit card compromised, you realize they start with small amounts. They always start with a small amount. It’s a test fee.
Manoj Tandon (22:39.056)
Yeah.
Manoj Tandon (22:52.84)
yeah.
KEN FOSTER (22:56.258)
Let’s see how many times we can take this small amount before they recognize it. And then we’ll go for the big amount, because normally the big amounts, most people nowadays have enough learning set up and stuff that a large amount is going to cause a problem. Same with data protection and data exfiltration. If I try to move a big amount of data all at once, most of our environments trigger and alert us to that. If I can…
Manoj Tandon (23:17.596)
Yeah.
KEN FOSTER (23:20.694)
chunk it into small pieces and move it out into something that looks like a business process and looks like it’s supposed to be happening, I’m going to be able to exfiltrate all the data I want because you’re not going to notice it. I haven’t gotten noisy. And that’s the things we have to be thinking about is how are these criminals thinking? How are they exfiltrating this data? How are they attacking us? And what are we doing to reduce that?
Manoj Tandon (23:45.02)
And Ken, that’s what’s missing. So people do not think like that, right? They’re thinking to a checklist, which gets us to the whole PCI DSS 4.0. And before we start down that, I’ll say what our experience, or at least my personal experience has been, is that anytime a compliance has come out, people want to build to the standard. They just want to do enough that they check the boxes and they can say,
KEN FOSTER (23:47.234)
Yes.
Manoj Tandon (24:14.832)
We did it, we’re done. It has very little to do with security.
KEN FOSTER (24:17.558)
It’s actually worse than that. They want to do it to the least cost that they can get away with to check that box. Now, is PCI 4.0, if you implemented it perfectly every time, is it going to keep you from getting breached? Absolutely not. 100%. It’s not. No compliance framework is going to stop you from having a breach. Is it a good starting point? And is it a good…
Manoj Tandon (24:24.294)
That’s exactly right.
KEN FOSTER (24:43.918)
place to build a risk mitigation framework and mindset off of? Yes. Right? Is it going to put some basic things in place that are going to keep the easy stuff from happening from the kid who logs onto the Facebook website, pays $25 to get a DNS attack against you or a denial of service? Yeah, you can mitigate that kind of stuff with these frameworks. Is it going to stop the dedicated person who is
determined to impact your business or steal what you have? No, because they only got to get lucky. They got to get lucky one time. You have to be perfect every time when you’re defending this and they and there’s because of the pace that we make changes, the technology changes, it’s impossible for us to keep up with it. Think about what you brought up about AI. AI is a
Manoj Tandon (25:22.568)
That’s right.
KEN FOSTER (25:37.974)
Wonderful tool set that’s coming out that’s going to do great things for us and is going to really help us the problem is is it got ahead of the practitioners and People started using it because it was a publicly available and that data will got put out there faster than we reacted to it So you saw data exposures from big companies because it got out there faster than people were thinking about it And it’s still going and it’s going to
Manoj Tandon (26:02.224)
And it’s still getting out there, by the way. You’d be surprised.
KEN FOSTER (26:05.294)
because it’s an education problem. People do not understand it. the best thing I can say about businesses are when a new technology comes out, if you’re dealing with your user population, if you’re not providing them a service internally that allows them to take advantage of these tools that are being sold as the best thing that’s going to help you do your job, if you don’t have a service internally that you’ve protected and are providing that, they’re going to go around you.
and they’re going to go use a public service and put you at risk because you weren’t moving fast enough to provide a service to them. Back in the day of email with BlackBerrys and cell phones, nobody was thinking about business email on a phone, but as soon as BlackBerry come out and people said, I can get my email on my phone, they started putting email on phone. They were figuring it out. So we were exposing it to a device we had no control over. Same with data. And we’re catching up.
Manoj Tandon (26:52.488)
That’s right.
KEN FOSTER (27:04.046)
to that technology, but we’re not catching up fast enough.
Manoj Tandon (27:08.018)
You’re absolutely right. the pressure to provide that service internally is not easily met, Ken, because you look at like Microsoft Copilot. If you’re going to let that loose inside your four walls, you better have your data sanitized or guess what? People are going to be searching on, how much money is Perender making? Let’s go see. Who got written up for sexual harassment? Let’s go see. Because all that Copilot doesn’t know.
KEN FOSTER (27:34.348)
Well, and Microsoft just turned it on for most of their customers, right? So it wasn’t something you actually had control over initially. They just said, you’ve got an E5 or an E3 license. It’s available. Go for it. Because, Microsoft wants you to use their product, right? Microsoft wants you to use a product because guess what they’re doing with all the data they’re collecting on the backend on that? They’re figuring out how to sell you more Microsoft products.
Manoj Tandon (27:41.617)
you
Manoj Tandon (27:48.444)
That’s right.
Purandar Das (27:56.506)
Yep.
Manoj Tandon (27:57.128)
That’s right.
KEN FOSTER (27:57.374)
Right. And that’s the whole thing about it is it’s going to be biased towards buying more Microsoft product. And if you don’t think that’s true, you’re a fool. You know, it’s just some of the stuff you got to think about with this thing. But it’s the pace that we move at today that unfortunately opens us up to a lot of risk. Now, when you get into the more regulated environments where PCI and ISO and NIST and all this comes out, they’re
Manoj Tandon (28:06.534)
I love it.
KEN FOSTER (28:25.888)
Sometimes you’re forced to be a little slower because you have to meet these checkpoints because you have an auditor coming in. But again, still the biggest problem with most of these frameworks and most of this nowadays is it’s still a point in time assessment. It’s not tenuous.
Manoj Tandon (28:41.285)
Exactly.
Purandar Das (28:41.372)
I I would throw this question out there, right? The whole thing about PCI DSS. The primary motivator is cynically, you could point out that the primary motivator for PCI DSS was the amount of fraud in the financial and the credit card space. They didn’t do it out of the goodness of their heart because the credit card companies were losing their shirts off of this thing. They said, we’ve got to find a way to control this. They looked at the most common.
Manoj Tandon (28:45.992)
Please.
Purandar Das (29:09.722)
ways they were getting scammed and said, here’s a way that along with fraud detection engines were the two things that came, that got put in place to help protect themselves. Ironically, whenever they do something that protects themselves, there is no concern about what friction it causes and how much it slows things down. If they were to go and tell you and me as the consumer and say, hey, your interaction or your experience with our website, with our product is going to slow down.
a bit or by this much because if we don’t do it the cost of our losses are going to be transferred to you which we normally do. Most of us raise our hands and say yep fine I’m willing to live with a little bit slower response.
KEN FOSTER (29:54.542)
Well, and the other thing is, this, and as somebody who sat on the technical council for PCI back when I was in a larger FinTech, right, is you start having these conversations where your big companies, your Fortune 500s, Fortune 1000s, can actually afford to implement these security controls or buy these tools. You run into a problem when we start talking those small mom and pop shops, they can’t afford.
to implement these processes and these tools because A, they’re either buying that service from somebody else who is to be one of the big companies and they’re raising their prices because PCI or whatever the compliance said raised their cost to do a business. And when you get into this, into the PCI world, right, it is literally a number of transactions and volume business. The companies who are doing making money off of this, they’re making
pennies and nickels maybe 25 cents off of a transaction you as the
Manoj Tandon (30:58.566)
That’s a lot of money when you cut through billions of transactions a minute.
KEN FOSTER (31:02.018)
Well, they are. I you look at these big credit card processors and the big credit card companies, right? They’re multi-billion dollar fortune, sometimes 150 companies, right? It’s a lot of money, but it takes a lot of transactions. Trillions of transactions are moving across their environment. So they have to move at speed. They have to do this. Now you move it down to the local coffee shop that’s doing
a thousand customers a day if they’re lucky. And they can’t afford to spend a lot of money to buy a new endpoint or a new credit card processing machine, a new POS machine that the big company wants to charge them $5,000 for this new POS machine that actually accepts modern certificates and encryption algorithms.
Right? But because that’s a problem, right? Because once they sold this POS, when they first got it, it only went up to what was current at the time that hardware was built. Now you have to redo that hardware. And that means there’s a cost incurred. The same thing happens in the medical industry with HIPAA and stuff like that. To get a piece of equipment certified to be authorized in medical environments, it’s very expensive process to get it as certified hardware.
Well, that means now the hospitals who don’t want to incur cost on buying new software and new hardware are going to run this piece of equipment until it will not run anymore. And then they’re actually, when they do replace it, they’re going to repurpose that computer as somebody’s desktop. So now they’ve got this unsecured device that they’re now also still keeping it on the network, right? And you think through this and it’s about…
Manoj Tandon (32:47.186)
That’s very true.
KEN FOSTER (32:50.99)
minimization of cost of expenditure and what it costs to actually be secure in it to be secure. There’s expenditure and it’s going to impact revenue. The thing is, is how much are you going to put on that revenue? And now it becomes a risk weighing exercise. I need to understand how much risk I’m exposed to and what that risk is going to impact my revenue and how much is it going to cost me to fix it? If it cost me $5 to fix
to protect $1 doesn’t make sense. If it cost me $2 to protect $10, maybe that does make sense. So that’s ultimately what it comes down to a lot of times though is that discussion point.
Manoj Tandon (33:28.774)
Yeah.
But well, can and you know, lot of times when you’re talking about risk and you just quantified it with an example, unless that quantification is really simple for a decision maker to understand, they won’t understand why they should spend the additional amounts of money. I’ll give you a simple example. Like if you if you’re in the business, if you’re a law firm and you get hit by.
a cyber attack and your data is exfiltrated. Well, you might have hundreds of thousands of records that were exfiltrated. I can guarantee you most law firms don’t understand that they have to put a stamp on 100,000 envelopes and inform all the people whose data was taken out that that was done and it’s done by mail. What is the cost of that?
KEN FOSTER (34:27.928)
So.
Manoj Tandon (34:28.198)
If you’ve got 200,000 records, the cost of a stamp, the cost of the envelope, the cost of printing, stuffing, putting all that, you’re broke.
KEN FOSTER (34:34.638)
So think about, this would have been probably 20 and I kind of remember because we were a customer of theirs and I was looking into it, but think about Anthem. When Anthem got breached, I think it was 20 million plus people, right? And even if you get a discounted mailing rate and all the bulk printing and all that, you’re still talking
Manoj Tandon (34:48.571)
yeah.
KEN FOSTER (35:01.848)
You’re still talking about two and a half million dollars just to send out the mail.
Manoj Tandon (35:06.214)
That’s right. And that’s not including the cost of credit monitoring that goes on top of it and your reputational and legal losses.
KEN FOSTER (35:11.532)
Right? Now, you get into what we’re talking about with privacy in California and Massachusetts and New York. So now you got a whole industry that’s spun up that’s about breach notification, right? Because you have to time all your deliveries so that one state doesn’t get notified before another state. And this is where a group of CISOs that I’ve been involved with for years, we’ve been talking about trying to get the federal government to impose a federal breach notification law instead of 48.
different ones because it’s costing us extra money when we do have an incident because more than likely you’re going to have an incident of some kind whether it meets the level of breaches and truth is is those breach numbers are under reported because depending on the state you’re in depending on the industry and you may not have to report the breach because it may not
Manoj Tandon (35:46.45)
Ken, there’s too much logic in that. You know that.
Manoj Tandon (36:03.64)
or depending on who you are and you may decide it, I’m not gonna report it.
KEN FOSTER (36:07.916)
Well, and we’ve seen that in the news too, right? But that’s the weird thing about this entire environment. And PCI is a great one. I know I’m circling back to what we originally talked about, but a lot of businesses will look at the, like Parunder said, PCI is because the credit card companies were losing money. It’s not a law. It’s not a regulation. It’s a set of guidelines put forth by the four major credit card companies that provide credit cards.
Manoj Tandon (36:10.352)
Yeah, yeah.
KEN FOSTER (36:38.018)
right? They will fine you if you don’t meet PCI. Not stop you from transacting credit cards initially, they fine you. And those fines are fairly small. And matter of fact, I’ve seen it a lot and had a lot of conversations about it. Some companies will look at that as a cost of doing business. We’re not securing it because it’s cheaper to pay the fine to the credit card company.
Purandar Das (37:02.63)
This is pretty.
KEN FOSTER (37:05.954)
than it is to implement this tool or this process. Now, after a certain amount of time of you failing it over a number of quarters or years, they will eventually tell you you can’t transact credit cards anymore. But those are normally gonna be a small credit card transaction company, not a large credit card transaction company. They’re going to go, yeah, yeah, we’re not gonna stop you. Keep paying this fine. We may increase the fine on you.
But eventually something’s gotta happen where there’s a little bit of teeth in it. And that’s the one interesting thing about the privacy laws. They actually have teeth. Their fines actually have teeth, right? When you’re talking 4 % of global turnover can be fined by the EU, which we saw that with Uber, right? 400 million Euro is the fine.
Manoj Tandon (37:54.908)
They haven’t paid that out though.
KEN FOSTER (37:56.184)
They haven’t, and it’ll take forever for it to be paid because it’s going to be appealed just like the Facebook one, just like the Google one. They’ll appeal it forever until they come to a settlement number that’s, I guess, palatable by both entities, right? Because it’s still a negotiation. But again, those numbers that they can find you are bet the business type numbers. PCI is not a bet the business type number.
Manoj Tandon (38:09.576)
$5 million.
KEN FOSTER (38:26.166)
most of the time from a fine stick.
Manoj Tandon (38:27.336)
So what’s new in 4.0?
KEN FOSTER (38:29.922)
I mean, one of the biggest things around, especially what we’re talking about here is data encryption level, right? There are new technical controls, there are new process controls there, but the big ones that we’re talking about, I think today, it was really about data encryption, right? Up until 4.0, data encryption in PCI was encrypt your data. That was it. There was no real…
Manoj Tandon (38:52.519)
Okay.
KEN FOSTER (38:55.862)
Yeah, no rule. It just had to be encrypted. So a lot of people did block level encryption, which if you don’t know what block level encryption is, most hard drive storage arrays that are enterprises, they’re capable of being block encrypted. So what that’ll keeps me from doing is taking a hard drive out, walking off with it, plugging it into another computer and looking at the data. That’s all doesn’t do anything about me accessing it through an application. So that’s why they even if you were encrypted, didn’t matter.
because if they came through the application, which is typically how they stole the data, it was decrypted anyway because the application was decrypting it. Now it’s requiring you to be field, file or database level encrypted. So it is encrypted for the application access as well. So unless you have the appropriate permission, you can’t view that sensitive data. So it’s a much tighter, much better level of encryption.
Unfortunately, it’s a cumbersome process to implement it, can be expensive and can be destructive. And that’s one of the things I think that’s interesting about what Sotero offers, right, is it’s why I’ve talked with Prandra about this is the ability to encrypt data in transit and flow and keep it encrypted to where it’s not ever exposed outside of your application flow, right? And only the right people have access to it. Then you’ve got the whole…
encryption levels, algorithms, right? You’ve got to have the right appropriate level and only be encrypted at an appropriate level that makes it difficult to crack. Impossible to crack? No, because as Prader talked about earlier, as quantum is coming, nothing today will not be uncrackable. We get, we’re working on it. People are working towards this quantum resistant encryption, but we’re not…
Manoj Tandon (40:35.624)
Sure.
Manoj Tandon (40:47.794)
But it’s resistant, it’s not proof.
KEN FOSTER (40:50.412)
It’s math. mean, let’s be honest. Encryption is math. If you’ve got the whole… If you have the time and the compute power, which normally means the money, if you have the time and access to the data and the money to put behind it, you will crack it eventually. Right? It’s just… Nothing is uncrackable, right? Because it’s math. And as long as you can do math, you’re going to figure this out.
Manoj Tandon (40:51.912)
Yeah.
Manoj Tandon (41:01.174)
Right.
Manoj Tandon (41:18.216)
because
KEN FOSTER (41:19.95)
It just, most people, right, when we start talking, we’ll go back to cracking passwords, because it’s a little simpler discussion, right? Just going from a eight-character password to a 14-character password adds hundreds of years onto the time it takes to crack a password from it being, you don’t have to make it complex, you don’t have to make it lowercase, you don’t have to put special characters. Just make it 14 characters. 14 characters, I think, adds like 600 years to the amount of time it takes to crack a password, right?
right? Because it’s compute power. Now quantum is going to reduce that. So now 26 characters may become the thing that it’s going to put it to a length of time and a cost of compute that makes it unattractive or un… actually it’s not unattractive, it just makes it non-revenue generating. And you got to look at it the same thing you think about when I’m doing business. Am I doing something that still allows me to regenerate revenue?
Well, the bad guys typically are generating revenue. It’s just they’re doing it maliciously, but they’re still generating revenue. Have I put enough roadblocks and enough things in the way to make it not cost effective for their revenue generation stream? That’s what we’re trying to accomplish. That’s the game we’re playing a lot of times today is have I made myself unattractive enough from a revenue generation for them that they’re going to leave me alone and move to the next easy target.
Manoj Tandon (42:24.882)
Sure.
KEN FOSTER (42:48.556)
And that’s where these small companies forget that they’re sometimes the entry point to that larger company because they’re doing business.
Manoj Tandon (42:54.696)
believe me, Ken, we’ve had so many guests on this show. We have talked about this a lot of small businesses are like, nobody’s interested in us. Well, you do business with, you supply widgets to somebody much bigger. And you know what?
KEN FOSTER (43:09.474)
Yeah. Well, let’s think about it when we get into it. Let’s think not the criminal, this lower level criminal is just trying to steal money and data and quickly monetize it. Let’s think about the people who play the stock market. Criminals and the bigger industries that are playing the stock market. Let’s find out that you’re a supplier of widgets to this bigger company that supplies widgets. Can I implement…
Manoj Tandon (43:23.996)
That’s right.
KEN FOSTER (43:33.592)
Can I impact your logistics? Can I impact your manufacturing process? Can I impact it in a way where you can’t supply your widget to this bigger company and now I’m going to short their stock on the long term and play against them because they’re unable to deliver and their stock price is going to go down because of the supply chain. Yeah.
Manoj Tandon (43:49.096)
Or can the other, that same example, do I, can I see how many widgets you’re shipping? Cause then I’ll know what their next quarterly report’s gonna be. And I’m gonna play that. No harm, no foul. Nobody even knows any better.
KEN FOSTER (44:02.444)
Yeah, guess where that data is probably going to be the easiest to attack.
Manoj Tandon (44:10.704)
at the small visit.
KEN FOSTER (44:12.032)
at the logistics company that they’re using because it’s probably a maybe national at best, but it’s probably a regional carrier who’s probably a small 10 to $15 million a year company, maybe.
Manoj Tandon (44:29.926)
and likely they went to Costco and bought some antivirus and said, that’s my cybersecurity. I’m, friend there you laugh, but I’m not, I can’t make some of this stuff up. I’m telling you.
KEN FOSTER (44:35.294)
Exactly.
Purandar Das (44:35.494)
Yeah.
Purandar Das (44:42.236)
I mean, believe me, I see this, we as a team see this constantly. I mean, the reasons and the reasoning for them not to do something is just unbelievable. It’s like people are in a mindset where they don’t want to do anything that they’ve decided is their normal course.
course of business. And there’s still a lot of reasons to not do it, right? Whether it’s money, the time, the effort, the lack of support within the organization, the different priorities, perceived priorities and imposed priorities. There’s just a lot of reasons people can come up with not to do things. But I mean, what I tell them is just look at the news on a weekly or a daily basis and you’ll understand how impactful.
This can be getting your data stolen or being breached, being hacked, falling for an email phishing scam, business email compromise. Any one of these, as Ken said, they can wipe you out. mean, just to put some perspective into this, right? mean, I think everybody’s seen the change healthcare cost as it stands today as a result of that attack.
is 3.4 billion 3.4 billion who do you think is ultimately going to bear that cost
Manoj Tandon (46:17.106)
the consumer.
Purandar Das (46:19.77)
Yeah, it’s all coming back on us. The company can be worried. All the press releases and all the stuff is fine, but ultimately they’re just going to pass the cost back on to us.
Manoj Tandon (46:22.672)
It’s gonna show up somewhere.
KEN FOSTER (46:33.358)
Great point, then you’re 100 % right. mean, you look at any of the major breaches over the last 25 years and go back and revisit what it’s totally cost them. Not all of it you can find, but those numbers are staggering. And if you look at this year’s breach report, the cost went up of the cost of recovering from a breach and what the biggest cost increase in there was actually because they’re now looking in at loss of revenue.
revenue that was lost due to the breach. And Change Healthcare is a great example, right? Because they were down. And not only were they down, all the people who relied on them were down or couldn’t bill, couldn’t get payments. that loss of revenue number is huge. It’s not necessarily stock price.
Purandar Das (47:16.983)
different
Manoj Tandon (47:19.304)
Sure.
KEN FOSTER (47:28.174)
Because unfortunately, stock price for a publicly traded company bounces back fairly quickly. But when you look at the loss of revenue and the cost to acquire a new customer after that, because there’s a loss of trust, that number is interesting to look at as well as that acquisition of new customers going forward goes up significantly.
Manoj Tandon (47:47.314)
So is there, do you think can the insurance industry imposing more controls and increasing premiums and is that gonna have a bigger impact than standards potentially?
KEN FOSTER (48:03.114)
It is, I mean it already is right because they’re, right you’re right our premiums are going up, it’s getting harder to get cybersecurity insurance, it’s you know I’m still and I think it’s starting but I’ve been preaching this for a while is that I am assuming that eventually to get insurance they’re going to come up with their own audit process.
They are already hiring cyber security experts to come do assessments. I think they’re going to become just like PCI or just like the government NIST or something like that. They’re going to require you to go through an insurance assessment and an official assessment. They’re going to require you to pay to do it. And then
they’re going to rank you on how much coverage you can get and what your premium is going to be based on, your insurability is going to be based on those actual real tables that they’re going to build off of your assessments that they’re going to perform on you. So in a lot of ways, I think it’s going to become very similar to PCI. It’s going to be an industry specific assessment and guideline that you have to meet. And I think if you’re not doing some of the basic things, if your data is not encrypted, you’re not using
good identity and access control, good password, MFA, they’re going to ask you these basic questions. If you don’t have these basic things in place, they’re not going to insure you. Or they’re going to make the premium so high and the coverage they’re going to give you is going to be so low that it’s not going to be worth anything anyway. Because also they won’t pay it. They already know. They’re already not paying it because they’re to go back and look back through time and go,
Manoj Tandon (49:43.09)
They well, they’re they’re already not. It’s like 30 cents on the dollar.
KEN FOSTER (49:49.666)
Well, did you implement this or was it implemented correctly? And I want to go circle back to something that we were talking about early on is that these people run out and buy all these tools and never properly implement them or do all that. But I also think that’s a problem in our industry because it leads us to a false sense of security because we’ve went out and bought a bunch of tools that on the paper we went, we’re good because of, I have X tool. I have this endpoint.
Manoj Tandon (50:01.948)
Yeah.
KEN FOSTER (50:19.106)
protection device. Well, is it fully rolled out? Is it on every endpoint you have? Is it working effectively? Do I know when it’s not working? Do I know when it’s the problem with my environment and causes operational impact? Can I answer all those questions with 100 % confidence across my environment?
And by the way, maybe I can answer it for this six month period that you came in and asked me a question. What happens six months from now when you come back? What happened in that six month period? Because I may have gotten it to work for the six months while you were in looking at my logs and doing all this, but as soon as you left, I turned it back off because it was causing a production problem that was impacting revenue. And I’ve turned it back off and went back to it’s not working. And I’m waiting on you to tell me the next time you come to do my assessment so I can turn it back on and get the logged evidence that you want.
Purandar Das (50:51.644)
you
KEN FOSTER (51:11.864)
that happens a lot in this industry is people turn stuff on just to get, and this is where the compliance, it doesn’t mean security problem. You can scope PCI, you can scope SOC 2, can scope Sarbanes-Oxley, you can scope any framework to a small enough environment that you can pass it. Doesn’t mean you’re doing what you’re supposed to be doing. And that’s the problem with, that is one of the biggest issues with compliance frameworks in our environment today is
you can get yourself passed. Doesn’t mean you’re doing what you’re supposed to be doing all the time. Doesn’t mean you’re doing it maliciously either. It just means you may have such a complex and big environment that you don’t understand everywhere that data has moved to. You’re doing your best, but you really have got to get, we’ve really got to get away from point time assessments and get to continuous monitoring. And everything we have as an API in it today, we can interrogate it look at the configurations on stuff for the most part.
We should be able to interrogate it, measure it against a known good standard or a known good control. And you also very rarely are able to take any one control framework. I don’t care which one it is, call it PCI NIST, ISO, CIS, whatever. You’re going to have to customize that control set for your environment. And you’ve got to have a group of people who understand the business, understand how revenue is working.
and understand what controls are important, understand where your gaps are, and build a custom control set that allows you to meet your control objectives while still generating revenue and keeping the business running at the volume and the speed that the business wants to run at. If you can’t do that, you don’t deserve to be in the seat as the top of the security team. Sorry.
Manoj Tandon (52:58.6)
there. Ken, I think on that note, that’s worth putting in quotes and making sure that people actually, if they listen to nothing else, listen to the last 30 seconds of this podcast, because you just said a lot. There’s a lot to unpack there. And it was very eloquently put. I love it. I love the passion on it, man. And it’s absolutely correct.
But we are at the hour and we still want to make sure that we give you both gentlemen a chance to plug whatever you would like to. So the floor is yours if you want to guys want to take a minute. Perender, anything you want to say.
KEN FOSTER (53:38.903)
I’m gonna turn my time over to Perender since I just rambled for 30 seconds. So I’m here to support him.
Purandar Das (53:42.716)
No, simply, I mean, we discussed a lot, right? I mean, we discussed why companies don’t do what they do. The little that they do is either driven by regulation or compliance or the insurance companies, right? And there are lot of reasons why they don’t do it as well because products are complex, technologies are complex. PCI DSS itself as a good framework, right? Just talks about a little piece of it.
Manoj Tandon (53:42.938)
You did it.
Purandar Das (54:10.588)
But there is more to data security, there’s more to data privacy. Companies need to evolve from what they’ve done in the past and continue to stop kicking the can down the road and saying, if I twist myself a little this way, I may be able to get through the next regulation. Maybe I can turn my monitor 30 degrees to the left, do this. I think companies need to stop doing that. There are products. And mean, I’ll shamelessly plug our own company.
We are one such platform that brings a new perspective, new thought, new technologies to help achieve and simplify the challenges associated with data security. I mean, the context of this conversation was around PCI DSS 4.0 and the new requirements that it puts in place. Take a look at a product like Sotero. We help companies achieve that compliance and go beyond that to achieve security, comprehensively across all of their data assets.
Manoj Tandon (55:08.376)
fantastic. If they want to learn more about Sotero, what’s the best way to do it?
Purandar Das (55:12.921)
Our website is a great place, soterosoft.com. We are on LinkedIn and on Twitter as well, sotero secure on Twitter, LinkedIn at soterosoft.com, soterosoft as well.
Manoj Tandon (55:17.576)
Okay.
Manoj Tandon (55:25.382)
That’s fantastic, Brenda. We’ll hopefully, you know, and is your technology meant for the Fortune 50 or are small medium businesses able to?
Purandar Das (55:36.452)
It’s meant for anybody with data. It’s meant for anybody with data. We have different ways we structure and package the product. Small medium companies, we support them as well. Obviously, enterprise companies on a different level, both the complexity and the scale, we support everybody.
Manoj Tandon (55:53.96)
That’s fantastic. And with that, gentlemen, I would really appreciate you both being on the show. Thanks for your knowledge and advice. It was a wonderful conversation. We hope you gentlemen come back again.
Purandar Das (56:09.456)
Thank you for having us. Thank you. Love to be back.
KEN FOSTER (56:09.826)
Thank
Manoj Tandon (56:13.34)
Thank you.
Read more about Purandar on his LinkedIn
Read more about Ken Foster on his LinkedIn
Check out Sotero
Check out the vCISO bot we created
Check out the other episodes in Season 16:
Ep. 0 Jim Love – Company Data on ChatGPT: Why What You Share Could Stay Forever
Ep. 1 Ken Underhill – Breaking Into Cybersecurity: Job Hunting Tips and Ghost Job Realities
Ep. 2 Allie Hunter – The Dark Side of Online Gaming
Ep. 3 Purandar Das and Ken Foster – “Delete My Data” Doesn’t work
Ep. 4 Tammy Klotz – Communicate properly with your team
Ep. 5 Sandra Estok – My Identity was Stolen
Ep. 6 Brett Johnson – Inside the Mind of a Former Cybercriminal
Ep. 7 Darren Mott – “Hackers Aren’t Breaking In—They’re Logging In”
Ep. 8 Stacey Champagne – “Red Flags in Cybersecurity Coaching”
Ep. 9 Craig Taylor – Phishing, Encryption, and Cybersecurity Training
Ep. 10 Christopher Rees – Will AI Change the Way We Learn
About Ken Foster

Ken Foster is a highly accomplished Security Expert with over 25 years of leadership experience in cybersecurity, infrastructure, and risk management.
As a former CISO, technology leader, and US Navy Veteran, he brings a unique blend of strategic and operational expertise in information risk governance, IT enterprise operations, and security architecture across both the public and private sectors.
In addition to his executive roles, He serves as an advisory board member and Chief Compliance Officer
About Purandar Das

Purandar Das is back on our show.
For those of you who may not remember, Purandar is a visionary leader in tech, having served as CTO for two of the largest marketing services companies.
He is now the CEO of Sotero, a data protection company. His shift from data monetization to security was driven by the alarming rate of cyber threats, like those faced by JP Morgan.
He’s built systems that have reached millions, and now he’s safeguarding a petabyte and a half of critical data.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
