The Launch of Cowbell Resiliency Services with Rajeev Gupta
Discussing the recent launch of the company’s Cowbell Resiliency Services (CRS) unit, Rajeev runs through what state-of-the-art offerings like Managed Detection and Response, Penetration Testing, and Cybersecurity Training – implemented alongside traditional cyberinsurance – can do to help organizations address escalating cyber risk, safeguard their assets and streamline defense strategies.
Transcript
This is Textron tv. Hey, everyone. Welcome back here to Textron tv.
My next guest is Mr. Rajiv Gupta. Rajiv is the cow co-founder of Cowbell.
You may have heard of Cowbell. If not, we'll tell you more about him. But first, let's welcome Rajiv and find out a little bit about him.
Hey, Rajiv, welcome to Tech Drunk tv. Uh, thanks, Alan. Uh, glad to be here.
Absolutely. So, Rajiv Rajiv, as I mentioned, you are co-founder of Cowbell, but give us an idea what exactly is cowbell and, uh, You know? Yeah, absolutely.
I'll, um, I'll talk about, uh, I'll give you a little bit background myself, and then also about the Cowell. Great. Just to give perspective of, uh, you know, why, why I started, um, decided to start Cowell, uh, along with the two of my other partners.
Um, so my background actually is more from cybersecurity space. Uh, or if I go even more further back, uh, I'm, uh, ex alum, uh, sun Alumni. A lot of my roots, uh, uh, go deep into the operating system layers.
And, uh, I know there's a, some, there's a lot of alumni out there on sun, and, uh, I know Sun has fed a lot of, uh, interesting technology and a lot of entrepreneurs into the industry. Sure It did. And, uh, so I, I go back, uh, you know, uh, you know, the, I think if I go back about 10 years or so ago, I, you know, was part of a startup where we were trying to shift left, uh, on, uh, how do you do better?
com, you know, trying to shift left in terms of how mm-hmm. How to do things better, faster, cheaper, you know, uh, find defects. Sure.
They make their way into the, uh, development mainstream. And then, uh, the startup before Cobell, I was helping shifting security left and trying to see how we can actually build more secure software, uh, from the get go. And, uh, so my background is primarily, I'm a more of a techie, a tinkerer, uh, a builder.
Um, you know, there's a lot of ways to describe. I spend all my free time, uh, you know, uh, building, uh, some small AI things, robots, uh, you know, I'm, I'm a tinkerer at heart means I, I like to build things, break things, rebuild them. And, um, so about, uh, five, six years ago, uh, I ran into Jack, uh, I've known Jack for about a decade or more about since 2010.
Um, you know, we started talking about, uh, you know, how things are shifting. You know, uh, everybody who's from cybersecurity, we all know that it's not a matter of if, it's a matter of when somebody gonna get attacked. So we, you know, even in my discussions with my customers, we used to always come, started to talk about the cyber insurance, and it was very intriguing because you say, you know what?
That's, that's the thing. Because if we do get attacked, uh, the most important thing, as you mentioned Alan, is resiliency. How do I spring back up on my feet and, uh, get back to work?
Right? And insurance, uh, is perfect play. And, you know, started looking into what options are out there in the market.
You know, I had gone through the buying process myself, uh, you know, and saying, you know, what does it take to buy a cyber insurance? And it was painful, it was lengthy paperwork, lot of questions. And I, I actually cautioned the entire process because there was no way the insurance company understood my security posture based on the q and a.
And, uh, you know, the, the kind of discussion I had, and I felt like, looks like, uh, this underwriting is being done, uh, with a big black box and just throwing it, and it's just not uncommon in insurance, right? You know, generally most people do a portfolio writing and, you know, making big strokes and whatnot. But with cyber such a big, you know, such a core of the tech, we have to use tech to underwrite tech.
I felt like, you know, with the advent of ai, with everything that was going on, you know, it made sense to, um, uh, you know, use the data for our advantage, for the advantage of the underwriters to really do a better job in, uh, assessing the risk and, uh, underwriting the risk, and then not knowing a lot about insurance that time. I felt like insurance is, is all about risk transfer, if you think about it, right? I means if I'm taking on the risk as an insurance company from a policy holder, I need to be, to quantify that risk, then, then only I can take it on.
Sure. You know, if I can't even quantify what am I taking on the risk? Like what is the transfer happening?
Um, so that, uh, kind of, uh, is the starting of the journey and, uh, now, uh, five, six years later, Kabul is, um, is a force. I think we help a lot of SMEs. We, we are, um, we cater to a small medium enterprises up to a billion dollar in revenue.
We have close to about 30,000 customers in United States and you Wow. And, uh, we, we believe that we are part of the security fabric. We are, uh, uh, part of this, um, you know, helping businesses stay, stay afloat, stay resilient, make sure they can actually open up the doors on Monday morning if they get attacked on a Friday night, right?
How we can actually do things to help, you know, keep, keep, uh, keep them on their feet, keep them, uh, you know, whatever the goal the, you know, of that business is, whatever they're trying to achieve, you know, they shouldn't have to worry about shutting down doors just because they got a ransomware attack. Fair enough. You know, a funny thing happened on the way to market with these cyber insurance companies, though, IV is, I, I always like to tell people this, that somehow the, the cyber insurance companies became the big stick, right?
We, we exist unfortunately, and as at least here in the us less so in Europe where the government, it's very hard for the government to get anything done from a cyber perspective. You get some executive orders, you've got the csa or you had the CSA organization putting some stuff out. But in terms of real legislation and regulation, our government, we, we can't rely on the federal government it seems, 'cause they don't have the will to do anything about it.
And then when you start getting into state government regulation, you very quickly get a patchwork, a quilt where you could do this in that state, but you can't do it in this state. And vice versa. It's that, that's hard.
Now, in years past, we relied on some big regulatory bodies, like for instance, PCI, right? Mm-hmm. Payment card industry.
They said, if you're gonna use credit cards, this is minimum, and this is how we, you know, this is what's good security looks like mm-hmm. In the, especially the SMB market, but even bigger where cybersecurity has become such a, uh, a must have, right? Because the risk is too great.
It, it gave the cyber insurance like cowbell a chance to say, Hey, if you want us to ensure you, you need to be doing, you gotta have good resiliency plans, you've gotta have, you know, a good security architecture and strategy and, and so forth. And so the cybersecurity insurance companies became the big stick, the enforces of security best practices, and then we needed that. Yeah.
I, we, we do run into that where I have discussions with CSOs and they tell me that, Hey, rajiva, I've been trying to roll out, uh, you know, uh, enterprise wide MFA policy, and I have been unsuccessful for the last two years. I am so happy that you put it as a subjectivity in the insurance policy. And it has now given me a stick to go really make sure is enterprise wide.
So there is definitely that, uh, piece to it. You know, you can, you can use the analogy of, uh, you buy a home insurance and home insurance sends you a letter thing that, hey, you need to cut down those, trim down those trees around your house. Otherwise, and before you know it, the, the, the thing that you were laying for a year, year and a half, or you call the gardener and get them trimmed right away, right.
Those, Yeah. No, look, I live in Florida, it's even worse. They're sending drones over houses Yeah.
And telling you you need a new roof or whatever. So, uh, I think it's real. We as human beings, as enterprises, we tend to delay it, uh, just to, puts a little bit of spotlight, makes it happen, and end result is it's a more, uh, secure, uh, business, more resilient business.
And, uh, it's good for everybody. Hmm. Absolutely.
Now, of course, you know, security is always moving. Mm-hmm. And, you know, the big, well, the big thing in technology in general is AI now, right?
Everybody's talking about how AI's changing the game and generative ai, agentic ai, all, all of these things. Um, you know, but the in, in security and cyber in particular, the bad guys are as smart as we are, and they're really well organized. And any new technology like this, they're, they're harnessing it and using it too, Even at a faster pace than us because, um, you know, for a business, I have to run my business, cater to my, you know, I'm, I'm not in the business of, uh, figuring it out how to use ai, and my goal is to actually deliver the business outcome, whatever that is, right?
And, uh, security just happened to be one of the things I need to worry about. But there are a gazillion other things as an entrepreneur, as a business owner, I have to worry about. But for a bad actor, that's the only thing they worry about.
That's, you know, they get better every day. And AI is giving them this automation, the speed accuracy, and, you know, they don't have to try a thousand times to see which one they're gonna get in. Now they can run simulations and they can actually be born more precise in their attacks.
And, uh, so I think, uh, definitely both the frequency, the severity is going up in terms of the attack as a result of the AI use by the bad actors. Agreed. I agree with you, Matt.
Yeah. Um, so now again, the big stick has to talk right in, in light of these new attack methods and technologies. You know, how Bell, I assume is, is asking companies to do more or to, to be aware of this.
Um, what, what are, and, and, and as I, we were talking, you know, before we got online, look, a lot of the action today is around the resiliency aspect of it. How do I respond? How do I bounce back from these things?
So what are the kinds of things you are recommending to cowbell customers for, you know, to remain resilient in the face of this whole new class of threats? Yeah, it's a great question. So I think, you know, it's a, it's not entirely new stuff.
Uh, you know, the things that, uh, cybersecurity industry and insurance, uh, we've been preaching for a while. You know, the basic hygiene, like continuous monitoring of your, uh, you know, uh, internet facing compute, uh, you know, threat assessment, somebody watching, uh, you know, the whole, um, uh, threat intelligence and the telemetry of, uh, data that gets generated from your routers and systems to see if there's a threat actor already present or trying to get in, uh, basic, uh, cybersecurity awareness training, you know, believe it or not, means the human still remains the, you know, the weakest link in the cyber cybersecurity kill chain. Uh, you know, it's very easy, especially with the AI crafted, uh, emails and whatnot, to get through the spear phishing campaign and make the, make a human click in or, uh, you know, do something that, uh, used to be hard because we used to train, uh, you know, uh, everybody saying that, Hey, look for spelling mistakes, other things, so, you know, the, the craft of the email, but now these emails are, they look perfect, right?
There's no error. Yeah, you are perfect. You know, even, even most of these bad actors are not in a natively English speaking countries, you know, before they used to make mistakes and just grammar and just spelling and whatnot.
But now these emails are perfect. So I think the, the bar is higher. What that means is the companies have to do more.
Uh, and that's the reason, by the way, we just launched last month, uh, Kabul Resiliency Services, and we are, uh, trying to figure it out. How do, how do we help these SMEs even even more, right? Try to bring in, uh, a suite of free services that can help, uh, policy holders, uh, stay up to speed with their continuous monitoring and, uh, whatnot.
We provide a full one year of, uh, free cybersecurity, uh, training to all our policy holders, no matter whether you're 20 employees or 20,000 employees. You know, it's, uh, it's all free for the first year. So we were trying to, you know, make the barriers to entry lower so that, uh, more and more policy holders can actually do the basic stuff like, you know, a a a pen testing, for example.
It's a, something that we all know that, uh, a checklist is one thing, right? I can say that, yep. I can fill the questionnaire, all the things I have gone through, I can look at the, the NIST or, uh, any of the CSF benchmark and say, yep, I, you know, I'm, I'm good, good, good, good.
But that doesn't really, you know, do the job. We have to employ a third party to see if, uh, you know, we can do a, a penetration testing that helps us really understand those, uh, weak points in our infrastructure so that we can fix it before the bad guys actually exploit those things. So, you know, uh, to, to net it out, basically we are, we are still talking about, uh, uh, you know, cybersecurity training, regular pen testing, um, tools like, uh, managed detection and response.
Um, no enterprise, you know, especially in the SME space, has the time or the manpower to employ cybersecurity exports, uh, who are there 24 by seven. Even if I'm a business with five, 700 employees, uh, decent size, um, I, you know, I could have a cybersecurity people employed, but you know, these, uh, it's hard to do a 24 by seven, um, view of what's happening in the environment. And that's why these managed services work really, really well.
Um, think about most of the attacks happen in the evenings, the weekends, and the, uh, holidays, long weekends, and that's the time where employees are taking time off, where all the cybersecurity teams we hire, they also take time off. And that's exactly the time where, uh, the attacks mostly spike up. So we, we need to use the best of the technology out there, best of the services that are available.
And that's exactly what we are trying to do with our resiliency services, trying to bring these, uh, best of the breed, uh, solutions and services to our policy holders. Yeah. Is this Rajiv, is this crossing a line though, from just providing insurance and giving best practices that people should use to actually providing security services?
Yeah, so more and more insurance companies are realizing that, uh, you know, to staying on the, uh, right side of the boom, uh, on the aftermath of an event, uh, it works, but, uh, because of, as you mentioned, you know, there's more AI driven attacks and things that are happening, the speed at which things are rising up, uh, they're finding that it behooves us to partner with the cybersecurity industry to bring the best of the breach solutions to our policy holders. Uh, SME doesn't have a, uh, the kind of time to really evaluate, oh, there are so many, so many solutions out there. What, which one is the right one?
You know, should I buy this? Should I buy that one? And then, okay, I did the evaluation, but then I need somebody to configure it, right?
You know, then I need to find an MSP to say, okay, I have found the solution. It's, I deployed correctly, but then that doesn't end it there. I need to now keep an eye on the, uh, telemetry data that it generates.
Now I need see some security experts to be able to look at the data and say, well, is it a real threat or is it a false positive? So if you think about it, it is too much for SME to take on, and that's where I think, uh, you know, it makes sense for the insurance companies to your point, right? It's not just about the stick.
It's not about me saying that, Hey, you need to trim down the tree, but I also tell you that, hey, here is the, the best, uh, person to trim that, uh, tree down, uh, to mitigate the risk, right? So we, we bring these services, uh, to make it easier for the policy holders so they don't have to go shopping around, go, don't have to waste time, get the job done as ASAP. Love it.
Rajiv, I don't think we mentioned the website for cowbell. Oh, yeah. So, KA insurer, um, you know, it's, um, a lot of information there for anybody who's interested, uh, including the resilience services.
Uh, you know, it's a great place to, to learn. And by the way, we also have Kabul Academy, uh, which is a really, really good place for even the brokers and the agents to go, uh, learn more about cyber security and cyber insurance. They can even take, uh, some of those credits that they can apply towards their, um, you know, um, the license renewals and, you know, the, the credits they need, uh, to stay on top of, uh, the tech and everything.
Love it. Thanks for coming on Tax Truck TV and making us a little smarter today. Keep us posted.
You gonna be at RSA conference? Uh, probably gonna be, yeah. I'll be visiting, yeah.
A couple of days there. Yeah, absolutely. Well, we'll be there, live on broadcast all, maybe come by and say hello.
Absolutely. I would love to. All righty.
Rajiv Gupta, co-founder Cowbell, cowbell Cyber Insurance, uh, check it out. We're watching Techstrong. We'll be back in a minute.