Signed

You bought the EDR. You checked every box your insurance renewal asked for. In this Playbook, Max Clark, CEO of ITBroker.com, breaks down why 60% of ransomware victims had a leading EDR product deployed when they got hit, and what the other 40% were doing that they weren't. From the four tools insurance actually requires to the ones nobody budgets for until it's too late, Max walks through the gap between owning a security tool and being protected by one, and the one line item most security budgets are missing entirely.

THE PLAYBOOK
  • 00:00 The trigger: the EDR stat insurance doesn't want you thinking about
  • 00:41 The mistake: treating insurance's four checkboxes as the finish line
  • 04:22 The play, step 1: what security buyers skip past SWG, CASB, and ZTNA
  • 09:07 The play, step 2: what actually gets security budget approved, and why ROI is the wrong pitch
  • 13:19 The play, step 3: test your backups before you need them
  • 14:38 What to watch for next: measuring security by detection and containment speed, not tools bought
RESOURCES MENTIONED
  • KnowBe4 — the security awareness training platform Max says most clients end up on anyway
  • Okta — referenced as a strong IDP/SSO layer for building real ZTNA entitlement chains
  • Microsoft 365 E5 Security — the bundled EDR/security suite Max warns is only as good as the team configuring it
  • Target's 2013 HVAC vendor breach — Max's example of the IoT/third-party blind spot most companies don't monitor
ABOUT THE SHOW
Signed is the podcast for buyers in a market built for sellers. Playbooks are the solo format — 10 to 15 minutes, one trigger, one specific play. New episodes weekly at itbroker.com/podcast. If the trigger in today's Playbook is one you're facing right now, book an intro call at itbroker.com. We help buyers make the right call the first time. Buy tech without regret. Follow: @itbrokerdotcom


Full Transcript

Creators and Guests

Host
Max Clark
Founder & CEO of ITBroker.com

What is Signed?

The IT market is built for sellers, not buyers.

That's why 80% of tech buyers regret their last major purchase. Deals take longer than they should. Teams get locked into platforms that don't fit, contracts they can't escape, and vendors they wouldn't choose again. The pitches, demos, and analyst reports are built to close deals, not help buyers make the right one.

Signed is the podcast for the buyers. Host Max Clark, CEO of ITBroker.com, talks with CIOs, CFOs, operators, and founders who've lived inside real enterprise tech deals — the ones who can explain what actually determined whether the deal worked.

Plus weekly Playbooks breaking down the moments that matter most: renewals, M&A, compliance mandates, office moves, budget cuts, and the specific plays that separate buyers who get it right from those who regret it.

If you're responsible for choosing, negotiating, or living with the consequences of enterprise technology, this show is for you.

New episodes weekly. An ITBroker.com podcast.

Max Clark (00:00)
Final thought,

Max Clark (00:00)
and this is a current stat

Max Clark (00:01)
that comes from insurance.

Max Clark (00:03)
And this is interesting.

Max Clark (00:04)
60 % of ransomware victims

Max Clark (00:06)
had a leading EDR deployed.

Max Clark (00:09)
So this is my note earlier about

Max Clark (00:10)
talking about it's great to have the tool,

Max Clark (00:12)
but you have to be able

Max Clark (00:13)
to configure it and manage it.

Max Clark (00:14)
So here's the stat again,

Max Clark (00:15)
60 % of ransomware victims

Max Clark (00:17)
had a leading EDR deployed and

Max Clark (00:20)
The IT market is built for sellers. Playbooks are for buyers. This is signed, I'm Max Clark from ITBroker.com. Today's topic, cybersecurity truths you're not being told. No fluffing off the cuff, here we go.

Max Clark (00:41)
Let's start with what insurance wants. If you go through an update with your insurance and you bundle cybersecurity into it, they're gonna give you four acronyms. It's gonna be check boxes. Do you have these? And usually, who do you have?

Max Clark (00:56)
What are those four acronyms? The first one is security awareness training, SAT. Second one, multi-factor authentication, two-factor authentication, two-step verification, some sort of two-factor, whatever the branding in the industry is we're gonna call it nowadays. They're want a secure email gateway, SEG, and they're gonna want endpoint detection response, EDR. Some people call this next generation antivirus. That's really its EDR. Now, a couple of comments on these things. First off.

Max Clark (01:26)
Yes, absolutely. There's a reason why insurance wants these in place because these all meaningfully improve your security posture. If you have to choose what you're doing in what order, right? Enable two-step verification. It's free on every productivity platform you're running, cleaning the operating system. It's just Google Workspace, it on. Microsoft, it on. Intra, turn it on. If you're using an SSO tool, turn it on.

Max Clark (01:54)
Absolutely 100 % you should be mandating two-factor authentication to step out verification now we can talk about authenticator access and and text messaging and hardware keys and And pass keys and all the different stuff to or blue in the face, but just know this just turn it on Second thing is email gateway Absolutely, absolutely. Absolutely. This should be your the top of your list of things to go out and purchase and acquire There's a lot of really good platforms in the market

Max Clark (02:24)
You know, there's different ways they integrate. can integrate in front of your mail server. They can read your, your mail server's journal. Um, there's pros and cons of each platform, depending on what, if you're on 365, or if you're on workspace, you know, some other integration tools, you know, it turns into, you know, it depends in terms of which one's best for you and what you're trying to do. Um, uh, you know, pro tip, most of these platforms sell security awareness training built into it. I will tell you that most, uh, clients we work with, if they,

Max Clark (02:53)
start with their segs, security awareness training, they all seem to end up on no before at some point. So, you know, maybe skip some pain and just switch to no before. You know, obviously, I don't get anything from telling you that right now. know, EDR we've got market leaders, we've got EDR bundled within productivity, you know, suites. The big thing here is that you're running it and that you have somebody competent to manage it for you. So turning on EDR is not...

Max Clark (03:21)
like a magic and shield that you get to protect you from things. It is a tool, and then the tool does specific things, and you need to monitor and care for the tool in order for the tool to work. So if you turn it on, if you buy it, great, you turn it on, better. If you don't have anybody looking at it or managing it or configuring it for you, you just wasted your money. Security awareness training. Look, your employees, your users are not your enemies.

Max Clark (03:51)
You should not be trying to trick them. Do not send them emails from a known corporate HR address saying that they get free lunch on Thursdays if they fill out this form. You're not doing anything by being mean and nasty to your users in order to try to prove that they fell from a phishing attack. It's not serving your goals. It's not serving your purposes. There's much better ways of actually doing this.

Max Clark (04:22)
Okay, so outside of those four acronyms, what do companies need that they don't always buy? Okay, so the top of my list is a secure web gateway. So nowadays we see this has turned into a bundle, SWG, CASB, ZTNA, DLP. There's more acronyms we can throw in there, but these all have turned into what has been dubbed

Max Clark (04:51)
SSE, you might have heard of SASI, S-A-S-E, SASI, the A is the access layer or the SD-WAN. But these do a lot of things for you that are very invaluable and very important, right? So the first thing is with a SWIG, you get the ability to see what, where people are going on the internet, what they're interacting with. You get to block things, you get to.

Max Clark (05:16)
inspect payload before it gets downloaded into a computer and exploded. You get to create really strong policies against your SaaS tooling, right? So restricting what IP addresses can connect to your CRM, your ERP, your chat, your productivity, your file sharing, right? That all comes in proxy with a good CASB. Zero trust network access to ZTNA.

Max Clark (05:46)
You know this this is a This is a segment that you know has been bastardized mean different different people implement it different ways a really important thing for me with ZTNA is how you build your entitlements and what you then do right so What's a good entitlement chain would see with ZTNA first off? Do you have strong authentication? Against your you know your IDP right if you're using again 365 and intra or workspace or do you have an SSO?

Max Clark (06:14)
like Okta or any of the other tools out there in the market, do you have a strong IDP that you're authenticating with? Do you have the ability to do audit and have logs, massively important? And now, what do you build for your control? Are they on a corporate-owned device? Is a device current with patches? Does it have its MDM running? Does it have the EDR running? Are they in a physical location that makes sense for them to be in?

Max Clark (06:42)
If somebody's trying to authenticate in a country that they don't live in, that they're not supposed to be in, probably shouldn't be allowed for you in terms of entitlement. So you get really granular entitlement rules with ZTNA, way more than you would see with VPN. But if we start to be getting the most important part of that VPN, or the ZTNA, is the connection with the IDP and the logs you get out of it. You just are invisible with a lot of VPNs. And we see a lot of exploits with VPNs still to this day. And it's like...

Max Clark (07:12)
This shouldn't be a surprise to anybody anymore. Depending on the security infrastructure that you're running, what's missing from this list, everything here becomes either cloud-based or agent on a desktop-based. And what we're missing is the on-premise monitoring and the actual network flow. Now, this is usually a really hard sell and a hard item to budget. Why do we need to put a sniffer on our network? We've got these agents deployed on all of our computers, so we see everything.

Max Clark (07:41)
problem is you don't see everything. And this is the crazy one where you hear about these things of like Target's HVAC system being hacked or a fish tank, an IoT device. There's so many. It's incredible how many devices are internet connected that are IoT devices that you do not have direct IT control over. My house, I was looking at our Wi-Fi.

Max Clark (08:10)
controller the other night. And for a family of four, I've got something like 60 or 70 devices connected to my network. And I don't run smart TVs. We're very restrictive in terms of what I allow in my house and what I have there. And even within that, it's a crazy amount of devices. So if you look at the corporate enterprise, this goes through the roof and not having and being able to see that east-west traffic in addition to the north-south traffic. So east-west, stuff going left and right in your land.

Max Clark (08:39)
versus stuff going straight to and from the internet, that becomes places. Now, I've had some weird things. I've seen clients deploy a SASE tool and start rolling out the SWIG and the ZTNA and catch employees that were in countries that weren't who they said they were. we're actually using, we're up to no good. So we'll just leave it at that.

Max Clark (09:07)
Security is a hard sell. And it's a hard sell because in most tools, in most IT tools, we're taught to talk about ROI, return on investment, and total cost of ownership. And I think in security for a long time, we were also taught to talk about it in terms of insurance. But that's not accurate, because insurance pays you after your house burns down. doesn't protect you from your house. It doesn't try to prevent your house from being burned. Now they're going to.

Max Clark (09:33)
It's not exactly true because they're gonna make sure you do certain things to lower the odds of your house burning down. But the point is, they're paying you when the house burns down. And cybersecurity tools do not do that. So what are we seeing generate budget? mean, number one, course, incident response or some sort of breach event. It is incredible companies that have no money to invest in cybersecurity, then have an event, and then all of a sudden it's infinite money is available to invest in cybersecurity.

Max Clark (10:00)
saying, I know a director of security at CISO now who was out of fairly large enterprise and was asked to a budget. What would it take to implement a modern security structure for this business? And his tool budget was something like a million dollars that he proposed. And the business came back and told him, have $50,000, figure it out, right?

Max Clark (10:24)
And his view of it in a lot of places is a lot of security teams are just there to be figureheads. They get fired. It's a very cynical view, but it's hard to argue with him with his experiences. Okay. So incident response, you've had a breach. Number two, customer requirement or compliance mandate. I've seen this all the time. Companies want to do business with somebody. They want to pick on a customer. That customer is usually larger than them and has

Max Clark (10:53)
You know a GRC function that's identified supply chain risk and requires their vendors to adhere to certain standards It's incredible how quickly a company will spend money on security When they need to spend money on security to make money, that's that's the only time I think I could say that You know six cyber security have seen be ROI, you know have ROI attached to it, you know, obviously compliance mandates You can't be in business if you don't meet them Replacing something that isn't working

Max Clark (11:22)
This happens a lot, unfortunately. Company buys something, you know, for whatever reason, maybe it wasn't what they thought they were buying. The vendor can't support it. They can't deploy it. A lot of times they can't deploy it. I surprisingly, you know, the amount of, you know, cybersecurity programs where they purchase and the vendor just actually can't turn it on is staggering. And these are big brands, by the way. These aren't little companies. These aren't little logos.

Max Clark (11:51)
What else we see budget reallocation or you know looking to create additional efficiencies. What I mean by that is like, you know firewalls right, you know firewalls need to be patched and updated for every firewall that you need to patch and update you need to go through a change management process that takes however many days to get approved and you have to do the actual update then you times that by the number of firewalls that you have in your maintenance window. It's really complicated to update a big fleet of firewalls.

Max Clark (12:20)
What's not complicated to update, SASE deployment. They update for you automatically. you know, many times moving away from, know, traditional OEM, on-premise physical firewalls with support contracts that are egregious, expensive to a SASE platform, not only does it gain you a lot of efficiency, but you get a lot of features and functionality and, you know, and things you couldn't do before.

Max Clark (12:48)
It'll improve the posture of your business. Changes in team makeup and staffing, The person who was the expert in whatever tool left the company, right? And now you have to figure out how to support that tool. Maybe it's time to change tools and look at who's managing for you. What else I want to get into here? OK, some bonus tips, right? Number one, and this is still amazing that we have to talk about this today.

Max Clark (13:19)
invest in and test your backups. Invest in and test your backups. Massively important, right? And mind you, by the way, cloud does not include backup. Delete is a valid operation on every cloud platform API, right? So your backups, it's not just we've moved our servers out of our office and put it on the cloud. Now you have to back up the cloud. So invest in and test your backups. And when it hits the fan,

Max Clark (13:47)
Your backups are will make or break are what will make or break you if you have good backups Your life is going to be very different from if you don't. and And again, it's crazy that we have to say this but this is so common People think they have stuff backed up until they try to restore it and then they find out one of two things the amount of time it's going to take them to do the actual restore because of their network capacity or they're in some sort of long-term storage archive, you know, what does it actually take to run the back?

Max Clark (14:16)
What's the time to recover it and run the restore? Maybe that doesn't fit a profile that works for you. You won't know until you test it. Or guess what? You thought you were backing everything up, and it turns out you weren't. Or you thought the backups were succeeding, and guess what? They weren't. So you have to test. Testing backups, testing your restores, massive. So not technically security, but this is huge.

Max Clark (14:38)
change the mentality of what you think you're gaining with cybersecurity and what you're actually trying to achieve with it, right? Obviously, right you wanna prevent an incident or a breach, right? So that's like the ultimate goal. And the good news is that as you improve your posture, you're going to eliminate most of low-hanging fruit, we'll just go bye-bye. But the real goal that you have with investing in security,

Max Clark (15:06)
is lowering the time to detection, containment, and then restoration of your services. So the faster you can detect something going on on a device, with a user, with the network, whatever it actually is, the faster you can detect it, the faster you contain it, and the the less damage it can do. And then you know what actually occurred, and you know how to recover from it. So cybersecurity, for the most part, just think about it as

Max Clark (15:35)
detection and containment. I touched on this before. Listen, you know, since I got into it, the top threat vectors of a business have been internal employees, right? And, and, you know, forget the like accidental acts versus malicious acts versus this act versus that act, you know, people are the soft squishy parts. And they are the vulnerable parts, right? So your users are not your enemy.

Max Clark (16:05)
they're victims you're trying to protect from professionals doing a job. When you have professional threat actors out there that make money, whether it's by ransomware or breaches, lateral things, impersonation, crypto theft, whatever it is, they're really good at their jobs.

Max Clark (16:33)
Otherwise, they have to go get other jobs. don't, this isn't like an us versus them, Your cybersecurity goals are to protect your users from being victimized. And this goes back to what I was saying about security awareness training earlier. They're not the enemy, they're just their victims. Final thought, and this is a current stat that comes from insurance. And this is interesting.

Max Clark (17:03)
60 % of ransomware victims had a leading EDR deployed. So this is my note earlier about talking about it's great to have the tool, but you have to be able to configure it and manage it. So here's the stat again, 60 % of ransomware victims had a leading EDR deployed and only the ones with 24 seven MDR escaped full encryption. This was for again, for ransomware. Having buying tools that aren't being managed by professionals that understand how to manage the tool.

Max Clark (17:32)
is just a waste of money. can, for instance, if you're on 365, you can buy E5 security. It's great. There's a lot of amazing stuff in there, but there's like thousand widgets you can turn and push and configure. And if you're not an expert in doing that, if you don't have a team that's an expert, then monitoring it and responding to it, you're in for a bad time. I don't know what else to say. So anyways, that's the playbook.

Max Clark (18:01)
More is available at itbroker.com slash podcast. And if you're in the middle of a real decision and want someone in your corner, book an intro call at itbroker.com and buy tech without regret. I'm Max Clark. See you on the next one.