Cybersecurity Challenges for Small Businesses with George Skaff at OpenText World 2024
Cybersecurity is a pressing concern for small businesses, many of which lack the resources and expertise to effectively manage threats. Awareness of risks is crucial, as consumers often realize vulnerabilities only after incidents. Managed service providers are essential for support, yet SMBs face unique challenges. The integration of AI enhances threat prediction, but budget constraints hinder security investments. Stricter regulations are increasingly needed to protect against data breaches.
Transcript
This is Techron tv. Hey folks, we're back at OpenText World in Las Vegas and we're talking to George here about cybersecurity in smaller companies. So George, welcome to the show.
Thank You. Nice to be here. I think, you know, we're making progress in the enterprise on cybersecurity, but it's not clear to me that that's working its way down to the mid-size companies and even the consumer level.
So what's your assessment of our cybersecurity readiness of these smaller companies? 'cause last time I checked they didn't have a CISO standing around to solve all these issues. Yeah, That's a great observation.
However, um, it's a different play completely when you talk about cybersecurity or enterprise. And then we come down to SMB and our consumer and I run businesses for consumer and SMB. Um, lemme start bottoms up.
Obviously consumers are impacted by everyday threats that's out there. And really interesting that consumers need to be more aware and cautious about what's happened because the reality is they won't, they don't worry about what happened to them until after the fact. Like a cybersecurity, like an email, uh, attack or cybersecurity attack to them.
So we do sell to a large volume of consumers directly and through some of our strategic strategic partners on the SMB space. Uh, and by the way, most of the products sold to consumer space are not known as OpenText. So we have four brands, web Root, which is antivirus, uh, Carbonite for data, uh, protection data management.
And then we have Hightail and uh, um, one other product as well in the consumer space. We sell to millions, uh, to customers and they are impacted by everyday threat, uh, coming to them via either, uh, cyber attack or phishing email. And, you know, they're not really aware of the threats until after they happen.
So you need to be very cautious of that. So we have two main product in consumer space, antivirus as otherwise known as Web Root and then backup or Cabernet. And fortunately or unfortunately, both these brands are not known as fintex brands, so they're brands that descend on their own.
And the SMB space is a different story. We sell via large network of managed service providers, otherwise known as MSPs and sometime to VARs as well. And we also have portfolio of products from companies we acquired over the last few years offering it directly, uh, to the end users via our partners.
So completely different play than Enterprise, but we're growing in both these segments and, and there's tremendous progress happening in that area. Most of the SMBs that I know wind up doing business with a larger enterprise. So as the enterprise requirements go higher, are they getting pushed down to the SMBs who are suppliers to those folks?
And is that having a cascading effect where the SMBs are more conscious of security or their requirements are just getting higher? Yeah, actually. Interesting.
So the requirement that happens in that space are similar whether you're in the enterprise space or SMB space. However, the partners that we work with really are, do great segmentation to understand how can they respond with our product to the needs of their customers. So again, to your point earlier, there's no CISO at some of the small companies.
So they have to anticipate what's gonna happen and help them maneuver through this process to get the product not only properly selected but also deployed. So we compete against many other companies in the SM e space when we work with the MSPs to offer the product to consumers. Now, the advantage we have as a large company, that we're bringing the muscles with us of having the knowledge, the know-how the expertise, the investment, the professional services that are required if we ever need to bring it along the deal.
So in that sense, um, these MSPs that work with us, they understand that while we are small part of their business and while we represent ourself as a smaller company to them, that we rely on a much larger organization behind us. Mm-hmm. In my experience, MSPs counted for maybe 20% of the overall total market, but I feel like that's changing because cybersecurity is getting hard, it's too complex.
So are more organizations willing to rely on an MSP for their security? Yeah, absolutely. And especially the, the small ones.
I mean, just as of data point, we have between 18,000 to 19,000 MSPs that we work with. And of course you could think these are large numbers, but of course we don't manage them all directly. So we have networks that can work with them.
But we, we picked some of the few strategic ones that we worked with them very closely. Like for example, about a month ago, or less than a month ago, we launched our secure cloud, which is a platform allowing these MSPs to cherry pick or choose from the portfolio product that we have to bundle and offer the solutions directly to their customers. They love that and we work closely with some of the MSPs to make selections on what we need to offer to them.
And we realize that this has been tremendous benefit to them by working with us. So rather than spending more time doing administrative work, now they can cherry pick which product they want from the cloud offering that they have and immediately send the that proposal to the customers and they love it. I mean, again, uh, advantage of working with company like us or what we heard versus other smaller company only term MSBs, um, is tremendous.
And really this is the power of what OpenTech on is, Is the quality of the security that's being provided to those SMBs getting better. I mean, it's almost sometimes I look at some of these tools and they're like enterprise class tools that are price point that is aimed at an SMB, but the gap between capabilities isn't all that much. Yeah, correct.
I mean, this is a great point. So we could do have some product that are shared also with the enterprise space. Not a whole lot, but the ones that are shared, obviously we're leveraging, you know, the, the strength and the depth of the these product into the MSV space.
However, into SMB space, however, we also have unique product for SMB that are growing on their own. Like for example, again, not to to mention Secure Cloud, it was built from the grounds up. And this project has been going on for a while to cater for the MSP communities and really offer that product.
And, and according to what we heard so far, which is tremendous feedback, they love it because if we solve some critical problems for them, that product itself does not apply at all to the enterprise space. So we do cater to each of these segments in particular with the offer that we have. Do you think that with the rise of ai, that security is gonna be, uh, more democratized than it has been in the past?
That's required. People who are quote unquote security rocket scientists to drive it, but I think the barrier to entry for the knowledge should be coming lower and lower and I should be able to implement and consume more security technologies to be safer. Yeah, I, I think, you know, you hit it right money.
And again, if you were at the, uh, earlier today at the opening, uh, keynote, but uh, by our CEO mark when he talks about AI and the impact of AI that will have cybersecurity will have tremendous play into ai. I mean, think about this, where at some point where we can apply AI to predict is an example, right? You, you, AI will, will digest all this data out there and information available and be able to sniff if there's any threat or ransomware about to happen or happening, and immediately alert it's constituent about it, something that's gonna happen, protect yourself.
So, you know, raise the, the level of threat out there. So the people in any businesses, whether enterprise or SMB level, you know, can quickly get to apply that protection that they need so they don't get hit by ransomware or they're get hit by big threat. This is huge and only AI can be applicable in a situation like this where we have the capabilities to provide this level of technology and information so ahead of time, we can predict that, not predict, but we can anticipate what the impact would be and prevent it from taking, you know, horrible impact or some of the organization as you could see today, right?
Somebody get hit by ransomware, it's millions of dollars that's gonna cost them. Whether it's a small bank, small financial institution, small insurance company, they can't afford it. Mm-Hmm.
Do you think that we'll see more convergence of the technology stack in cybersecurity as we adopt more ai? 'cause right now I think a lot of organizations are kind of like, I'm spending a lot of time stitching a lot of things together. Um, are there things that can maybe be brought together more tightly or coupled together in more interesting ways as we go along?
Yeah, I, I, I think the, the future is here for that. I mean, we've seen some examples already of that happening. Again, you saw the demo today, if you are on stage out, you take that AI platform aviator and then how you can really run it across multiple platform.
I mean, a lot of the fact the statement, but we make multi-cloud work and our environment, we gonna make the platform work and we are gonna be with a open platform where we support other technologies out there, especially in the SME space where some companies may want to use some of our product in conjunction with some other products as well. And our AI and platforms will allow that to happen. And I think that's, that has tremendous impact.
I think one of the challenges that consumers and SMBs face is the playing field is decidedly uneven. The bad guys have a lot more expertise and a lot more tools and are a lot more automated. Are we gonna be able to kinda level that playing field soon?
And, and we fight this fight? I, that's a great observation. As a matter of fact, they not only have bigger and level field, but they're also changing.
They're learning how we're combating the threats and ransomware and they're using something different. So honestly, e every day it's a new threat and every day it's something new like a bad actor you call unquote coming in and we can, we are human cannot do the work as fast as a machine would do it in AI to predict what's happening and help us with that. So are we leveling the field?
I can't tell you that we are soon, but I know that we have the technology and the tools to eventually be on par. And if we are on par, I think that's good enough. I think business leaders sometimes get frustrated with cybersecurity.
They continue to invest in it and they're like, well, aren't we secure yet? And maybe it's not a thing that you're actually gonna achieve. It's more, to your point, the tactics and techniques evolve.
So the defenses have to evolve and it's just an ever changing game. Exactly. I I don't think there's any one company out there that can claim today or answer that, are we secure yet?
You don't know because we don't know what the next bad, bad actor is. We don't know what the next cyber attack is. We don't know what the next ransomware is coming.
All you know is that we need to have the tools in place to prevent that from happening and continue to innovate in our space to put the methods, the technology and the protection in place to safeguards in place. So these things don't happen when they can happen. You know, we can't predict the future or we can own our own destiny by putting this technology up front.
Two SMBs need the focus more on be resilient, right? We talk about cybersecurity all the time, and I think if we're gonna assume that we're gonna get attacked and maybe we gotta figure out how to, uh, respond in a way that limits the damage as much as possible. Yeah.
So it's, I mean with the SMB, there's no such person or entity SMB, it's as, you know, it's a channel in play. I think companies are starting to be more and more aware. And our job is to make sure we promote the fact that, I mean, the problem is cybersecurity is a bad thing, right?
And nobody wants to talk about it. Nobody's gonna come up and say, Hey, we were hit by a virus or ransomware. You never hear the storage except if it's a big company and blows out of proportion.
So the idea would be that, uh, we want companies to be aware, we want 'em to be ready and we want 'em to know what to deploy and when to deploy it. And ideally we want 'em to deploy it ahead of time. Are there things that you see SMBs doing that as a long time professional in this space just makes you shake your head and go, folks, we need to be better than that.
Yeah, I, I unfortunately, um, they're not spending enough, uh, money on the protection and prediction. You know, budgets are tight and easily immediately they cut the budget for cybersecurity. They, and they unfortunately also, there's not enough cybersecurity expert to be hired that can advise companies.
That's why they go into consult with other folks to learn more of what's going on. I mean, to your point, I love your metaphor at the beginning. These small companies don't have a ciso.
When you have a ciso you know that you can rely on somebody to do it. So who are they relying on? And and the reality is it's ad hoc, it's unpredictable and it's messy.
Do you think that, um, those SMBs, as they kinda look at all of this, um, the headlines have they become ignored to the know, the latest breach and the latest attack and it's not really kind of waking them up the way it used to be? I mean, I can't tell you how many times somebody said to me about a security breach. This is a wake up call for sure.
And then about like three weeks later, everybody rolls over and goes back to bed. Yeah, that's unfortunate. And, and again, when breaches happen, everybody wakes up.
To your point, some companies spend millions of dollars. Some other companies think that, I mean like all of us, how many letters have you got from these big companies about, oh, we signed you up for this Experian or whatever, you know, credit monitoring bureau. I mean, after a while you give up like, okay, what am I gonna do with this?
Right? But, but they're not protecting their constituents and that's the problem. That's the problem.
Do we need more regulations? 'cause the carrot's not working enough. So do we need more stick?
I think we have reg enough regulations happening now, I don't know about in the financial institution space, the regulations that they use. I don't know if there's something else that's being planned, but certainly they need to tighten up better the data breaches. I mean, I, I can't imagine why do have data breaches every now and then and you hear about them.
I mean, that's not good. And that's really what sets everybody like on their edge of what's gonna happen with that. Are we seeing it people become more conscious of security and assuming responsibility for security operations as part of their IT motion and that, and in SMB, you know, the IT people are pretty much in charge of everything.
But are they kind now more proactively incorporating SecOps into those IT Ops? We, we see that in the large companies enterprise level where the IT people aren't in charge and they're making difference. And again, to your point, unfortunately in the SME space, there's no one designated in IT department as a chief security officer, even VP of security, right?
They, they don't have the luxury to have the staff dedicated for that. So you probably have the IT person who's also running in through the security person, God bless them. You cannot have two hats to run your IT department and also make sure the security protocols are well, uh, managed, you know, well, uh, protected and well, well communicated.
Mm-hmm, Aren't we? Most of the organizations I know, you know, they have a, some what we used to call AV software and they have a firewall, they don't much get past that. Um, and, and if you listen to the MM MSPs, they'll tell you it's very hard to be profitable in this space delivering services largely.
'cause they compete pretty aggressively with each other and they drop their own prices to that point. But, um, can we make this motion economically viable for everybody concerned? Because the small company can't give you, you know, 20% of the IT budget for security.
The MSP can't overcharge too much, and yet we gotta pay for the r and d of the tech. So how do we make all this work? Yeah, It, it's an interesting, interesting question.
I don't know the answer to that because you're absolutely right. Uh, uh, how much of the percent of your budget are you spending on protection and prediction versus after the fact? You know, the, the, the recovery phase of that.
Um, as a small companies, they can't afford to spend a lot of it. And really the core of the problem, um, our job is to make sure that we continue to inform, educate, uh, enable, you know, all our partners with the right information so they can not only for them to make the decision, but they can pass this information well to their customers ahead of time and, and prevent them from getting into the trap of getting hacked, you know, getting subject to ransomware, you know, getting all these attacks that are happening continuously. I mean, look what happened just recently in the, in one year, you know, we not only had, um, attack as normal cyber, cyber war attacks, but you know, there's more attacks coming in during the recent elections here for no other reason and just data breaches and, and personal emails and everything like this.
But these things, you know, can escalate to much more serious level, you know, if they continue to happen because the bad actors are not giving up, they continue to try different ways and the technology continue to evolve. Alright, folks, you heard it here. If you add up all the penalties and the cost of the ransomware and every other bad thing that can happen, cybersecurity is a pretty good deal.
Hey buddy, thanks being On the show. Thank you. Thanks for having me.
Appreciate. All right. And we'll be back in a.