Security Confidential S6 E4 Brian Haugli

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to Brian Haugli. Brian is a Managing Partner and Chief Executive Officer at SideChannel. Brian has been driving security programs for two decades and brings a true practitioner’s approach to the industry. He has led programs for the DoD, Pentagon, Intelligence Community, Fortune 500, and many others. Brian is a renowned speaker and expert on NIST guidance, threat intelligence implementations, and strategic organizational initiatives. He is also a contributing author for the latest book from Wiley, “Cybersecurity Risk Management: Mastering the Fundamentals Using the NIST Cybersecurity Framework“. Lastly, he is a professor at Boston College, in the Woods College of Advancing Studies, Master’s Program in Cybersecurity.

 

00:00 Introduction

01:50 How do you see the threat landscape changing in cybersecurity?

05:00 Do you think the mid-market understands that cybersecurity is not an IT problem but a business problem?

08:30 Why are SMBs such hot targets?

12:35 Insurance brokers typically do not understand cybersecurity postures, they deal in applications. How can an SMB leverage the broker to get an underwriter to understand their posture?

20:50 Is it possible for you the client to get in front of the carrier?

23:42 How does a company access its security posture?

27:00 How do these businesses go about this practically?

33:20 News from Brian

Transcript

Manoj Tandon:
Hello everyone, welcome to another episode of Dark Rhino Security: Security Confidential. I’m your host, Manoj Tandon, and joining me today is Brian Haugli. Brian is a highly experienced cybersecurity leader, currently the Managing Partner and CEO at SideChannel, as well as a professor in the Master’s Cybersecurity program at Boston College. He has spent over two decades building and leading security programs across the Department of Defense, the Pentagon, the intelligence community, and Fortune 500 companies. He’s also the author of Cybersecurity Risk Management: Mastering the Fundamentals Using the NIST CSF. Brian, welcome to the show. Thank you for being here.

Brian Haugli:
Thank you for having me. I appreciate it.

Manoj Tandon:
We’re really excited to have you. A large part of our audience is made up of small to mid-sized businesses, so your insights are going to be incredibly valuable. Cybersecurity is constantly in the news—malware, ransomware, breaches—it’s nonstop. With your experience, what do you see coming in the cybersecurity landscape? How is it evolving?

Brian Haugli:
One of the biggest things I’ve focused on over the last few years—both at SideChannel and before—is the mid-market and small business space. It’s a very underserved community. These organizations often don’t have access to the right leadership or guidance because those resources are typically reserved for larger enterprises.

What I consistently hear from these businesses is that they want to make the right decisions with limited resources. They don’t have room for error. Over the next few years, I think the biggest shift will come from regulation. We’re already seeing it with the SEC for publicly traded companies, and that affects more than just large enterprises—there are thousands of mid-sized publicly traded organizations.

We’re also seeing regulatory pressure from frameworks like New York DFS and movements like CMMC from the DoD, which will impact hundreds of thousands of companies. That pressure is cascading down supply chains. The idea that “I’m too small to be a target” is no longer valid—not just because of attackers, but because of compliance requirements.

The biggest shift won’t necessarily be the types of attacks—we can’t always predict those—but rather how organizations view cyber risk. It’s becoming a business risk that must be addressed strategically, not just a technical issue.

Manoj Tandon:
That’s a great point. Where do you think the mid-market stands today in understanding that cybersecurity is a business problem, not just an IT problem?

Brian Haugli:
It’s evolving. The more mature organizations are starting to understand and embrace that idea. I often say that I don’t sell cybersecurity—you either acknowledge it as a business risk or you don’t. If you do, we can have a conversation. If you don’t, you eventually will—hopefully not on your worst day.

I’ve seen very small startups take this seriously from day one, and I’ve also seen established small businesses completely ignore it. Some industries—like law firms or professional services—are particularly resistant. They assume they’re not targets, which simply isn’t true. Eventually, many of them learn the hard way.

My focus is on strategy—helping organizations build a program before something goes wrong. Because once you’re in the middle of an incident, you’re not calling someone for strategy—you’re calling incident response teams to clean up the damage. Strategy comes before that, not after.

Manoj Tandon:
That’s absolutely right, and the cost of reacting after the fact is significantly higher. Let’s talk about why small and mid-sized businesses are such common targets.

Brian Haugli:
It comes down to return on investment for attackers. Cybercrime is a business. These groups are structured—they have operations, HR, marketing. They think in terms of efficiency and profitability.

If it’s easier and more profitable to attack a smaller organization than a heavily protected enterprise, that’s what they’ll do. The barrier to entry is lower, and the return can still be significant. Also, smaller organizations are often connected to larger ones, so they become entry points into bigger targets.

There’s still a misconception that attackers are just individuals in basements. That’s outdated. These are organized, well-funded operations. If you’re connected to the internet, you are a potential target. It’s that simple.

Manoj Tandon:
We’ve seen that firsthand. Even small firms—like a 10-person law office handling escrow transactions—can become prime targets because it’s easier to exploit them than a large financial institution.

Brian Haugli:
Exactly. The barrier to entry is much lower. And unfortunately, some industries still rely on outdated assumptions, like thinking legal privilege somehow protects their data from cyber threats. It doesn’t. If an attacker gets into your systems, that data is exposed regardless of legal protections.

Many professionals are highly intelligent but still underestimate cyber risk. They assume it won’t happen to them—until it does. And often, organizations only take action after a near-miss or an incident.

Manoj Tandon:
Let’s talk about another misconception—companies that think having a firewall, antivirus, and cyber insurance is enough. What would you say to them?

Brian Haugli:
Cyber insurance is often misunderstood. It’s not like auto insurance where you fill out a form and get coverage based on well-established risk models. Cyber insurance doesn’t have that level of historical data or standardization.

The process is also fragmented. Different carriers have different applications, different questions, and varying levels of understanding. Underwriters often lack deep cybersecurity expertise, and brokers may not fully understand how to represent a company’s security posture.

On top of that, many organizations don’t actually understand or articulate their own security posture. Saying “I have a firewall and antivirus” is not a security program. You need a structured approach based on a recognized framework.

The breakdown happens across all parties—the company, the broker, and the carrier. To improve outcomes, organizations need to clearly understand and communicate their security posture, ideally aligned to a standard.

Manoj Tandon:
That makes sense. So how should a company go about assessing its security posture?

Brian Haugli:
Start with a framework. That’s the most important step. I’m a big advocate for NIST, especially for U.S.-based organizations. For small businesses, the NIST Small Business Fundamentals is a great starting point. It’s not overwhelming and provides a solid foundation.

From there, you assess your current state—where are you strong, where are you weak? Frameworks like NIST CSF break things into categories, which helps you see where you may be over-investing or under-investing.

Then define your target state. What do you want your program to look like in 6, 12, or 18 months? You don’t need to implement everything, but you do need a plan. That’s where strategy comes in—building a roadmap and aligning resources accordingly.

Manoj Tandon:
A lot of small businesses feel overwhelmed by frameworks. They may not have a CISO or even a CIO. How do they realistically approach this?

Brian Haugli:
At some point, you need expertise. There’s no real shortcut around that. You can use tools or simplified frameworks to get started, but having someone who understands cybersecurity—whether internal or external—is critical.

That said, start small. Use something like the NIST Fundamentals. It’s manageable and covers the basics—asset inventory, access control, account management, and so on. These are foundational controls that prevent a large percentage of incidents.

It’s similar to building a house—you need a blueprint. Without that, you’re just guessing. Even basic controls, like managing administrative privileges, can significantly reduce risk. Many breaches still trace back to those fundamental issues.

Manoj Tandon:
That’s a great point—even large enterprises struggle with some of these basics. Before we wrap up, is there anything you’d like to share with our audience?

Brian Haugli:
If you’re interested in learning more about NIST CSF, my book—co-authored with Cynthia—is available and provides a practical way to understand and apply the framework.

More broadly, I’m excited to see a shift happening in the industry. Organizations are starting to take risk management more seriously and make better decisions. We’re also doing monthly webinars focused on helping organizations understand their current posture and improve toward a better target state.

And on a personal note, I’m excited about the recent announcement of our merger with Cipherloc. We’re looking forward to bringing new capabilities to the market.

If anyone wants to connect, you can find me on LinkedIn or follow #CISOLife. I’m always happy to continue the conversation.

Manoj Tandon:
That’s fantastic. Brian, thank you again for your time today. We appreciate your insights, and we’d love to have you back to continue the conversation.

Brian Haugli:
Happy to come back anytime. Thanks again.

Manoj Tandon:
Thank you. Take care.

To learn more about Tim on his Linkedin

Check out the other episodes in Season 6:

Ep. 0 Bonus: Why do People Get Hacked?

Ep. 1 Brian Stoner – VP of StellarCyber

Ep. 2 Dr. Joseph – Russia, Ukraine, and Cybersecurity

Ep. 3 Tim Chase – Ethical Hacker, CISO

Ep. 4 Brian Haugli – CEO of SideChannel

Ep. 5 Nat Schere – Cybersecurity as a revenue

Ep. 6 Endre Walls – Starting in Cyber, Vendors, and Diversity

Ep. 7 Erika Carrara – Veteran, Mentor, C-suite executive

Ep. 8 Eddie Thomason – Podcast Host, Author, and Entrepreneur

Ep. 9 Greg Schaffer – vCISO, Author, and Podcast Host

Ep. 10 Jake Belcher – Sr. Director of Security Strategy

Brian Haugli's profile picture for Dark Rhiino Security's Security Confidential podcast

Brian is a Managing Partner and Chief Executive Officer at SideChannel. Brian has been driving security programs for two decades and brings a true practitioner’s approach to the industry. He has led programs for the DoD, Pentagon, Intelligence Community, Fortune 500, and many others. Brian is a renowned speaker and expert on NIST guidance, threat intelligence implementations, and strategic organizational initiatives. He is also a contributing author for the latest book from Wiley, “Cybersecurity Risk Management: Mastering the Fundamentals Using the NIST Cybersecurity Framework“. Lastly, he is a professor at Boston College, in the Woods College of Advancing Studies, Master’s Program in Cybersecurity.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top