Profit & Practice

In this episode, Joe Popper, founder of Popper Tech Team, joins us to talk about cybersecurity, IT and AI in the wealth management space. As technology failures and security breaches become make-or-break business problems, Joe shares real-world cautionary tales and actionable frameworks for implementing AI, protecting against high-cost cyber threats, and staying compliant under the watchful eye of the SEC.
 
Joe Popper is the founder of Popper Tech Team, known by his clients as the OG IT and AI guy. He works with financial and professional services firms where technology failure isn't an option, helping them stay secure, operational, and ahead in a world where one small tech problem can quickly become a big business problem.
 
In this episode, we cover:
·         AI, Cyber Security, and Compliance: Navigating the Tech Minefield for RIAs
·         Protecting Your Client's Money: Fighting Cyber Threats and Business Email Compromise
·         The AI Revolution in Wealth Management: How Small RIAs Can Leverage Tech to Scale
·         Is Your RIA Ready for an SEC Audit? AI Governance and Compliance Essentials with Joe Popper
 
Connect with Joe:
LinkedIn | poppertechteam.com
 
Every episode closes with the same question: what's the best piece of financial advice Joe has ever received? Listen to find out.

Connect with the Show: 
Profit & Practice is hosted by Max Holvik, founder of The Advisor's CFO, a fractional CFO practice for wealth management firms.
TheAdvisorsCFO.com | LinkedIn

Creators and Guests

Guest
Joe Popper
CEO, Popper Tech Team

What is Profit & Practice?

Profit & Practice explores the business decisions that determine whether a wealth management firm thrives or struggles. Hosted by Max Holvik, CFA, a fractional CFO known as The Advisor's CFO, the show features conversations with RIA owners, operations leaders, M&A advisors, and the consultants and specialists helping advisory firms grow. If you run, manage, or advise a wealth management practice, this show is built for you.

Joe Popper (00:00)
if you're not

Looking at and adopting AI and at least trying to get a strategy around it, you are going to get left behind.

Anytime the SEC comes knocking on the door and says, we want to audit you,

They're wanting to make an example out of you. If they've gotten that far down the road to where they're knocking on your door, it's not a good day.

Max Holvik (00:36)
Hi, welcome to Profit and Practice. I am excited to introduce today's special guest, Joe Popper, founder of Popper Tech Team, also known as the OG of IT and the AI guy. Joe works with RIAs and other professional services firms where technology failure is not an option, helping them stay secure, operational, and ahead in a world where one small tech problem can quickly become a big business problem.

So welcome, Joe. It's a pleasure to have you here.

Joe Popper (01:07)
Thank you. Thank you. It's a pleasure to be here.

Max Holvik (01:10)
And I'm glad to have you. And before we dig deep into the world of IT and cybersecurity and and AI and such things, can you please share a little bit about your background and what got you into the field?

Joe Popper (01:21)
So I've been doing this for 35 years. I'm an engineer by degree, graduated from Auburn University a million years ago, War Eagle, and this is what I have been doing, and this is my fourth MSP that I've done.

Max Holvik (01:38)
you've seen quite a few things and and I've got a few questions for you later on on what you see down the road as well. so if we look at the wealth management space, how do you see the needs and the risks that a RIA faces as they grow?

Joe Popper (01:53)
So we focus on regulated spaces, which is what an RIA is, obviously. And they have enormous responsibility. They have to meet the compliance obligations. And the reason that they want to meet those compliance obligations is to keep their cybersecurity defenses up so they protect their clients' money. That's really at the end of the day, it's not just managing their money well, it is protecting it from leaving

unexpectedly, I guess. So that's very important. And then the other thing is with the advent of AI, business automation has never been more important because you can do so many things now in an automated fashion that used to be manual processes. And so I tell this to any company, but particularly in the RIA space, if you're not

Looking at and adopting AI and at least trying to get a strategy around it, you are going to get left behind.

Max Holvik (02:54)
Yeah, and then it's but it's a double double edge short, I imagine, as b considering it's being regulated, but you also want to make sure you don't left behind. So are there any areas that you think that RAS should focus on using AIs and are there any parts of the AI world that you think they should stay away from?

Joe Popper (03:11)
You have a wealth of AI tools available to you. And all of these companies have, well, not all of them, but some of them have the what they call the enterprise account where you can put the appropriate security in place. we recommend Microsoft, and I'll tell you why. Microsoft is doing what they've always been doing, which is building infrastructure. So

Their whole play is you can use whatever AI you want. So they have through their co-pilot license both Chat GPT and Claude, right? And what happens is that's running in Microsoft's governed framework. So here's the thing that's critical. You have now the ability to use both of those tools. But when the SEC comes knocking on the door and says, prove to me that you have

followed the rules and regulations, you can run an audit against all of those AI transactions and give a report back to the SEC. Here's how we used AI. Here are the things that we did and we are compliant. You can see here, right? So y you can do that through the other tools in some form or fashion, but now you have a disjointed thing that you have to manage. And so

The whole thing that Microsoft is bringing to the table is governance and compliance strategies, and you can use the tool however you want.

Max Holvik (04:39)
Gotcha. But are there are there other s certain guardrails you would put in put in place for for an RA firm? Particularly

I guess when it comes to client data and other sensitive information.

Joe Popper (04:50)
So you have a set of regulations that you have to follow, right? So as an example, you can't put client information in that chat box, right? If you if you do that, the SEC is going to declare a violation. And when they do, it's not a cheap enterprise, right? Anytime the SEC comes knocking on the door and says, we want to audit you,

They're wanting to make an example out of you. If they've gotten that far down the road to where they're knocking on your door, it's not a good day. And so the but the point is you want to have the compliance framework in place so that you can provide the appropriate reports. And you're looking at those reports, you know, weekly, monthly, quarterly, so that you can see I have an employee training issue.

I have a compliance issue and you can get in front of that before the SEC comes out.

Max Holvik (05:45)
Gotcha, gotcha. So if I'm hearing you right, you important to stay ahead of

this and important to to to not be left behind, I guess, when it comes to AI. But it's not something that you, you know, an RIA owner should just set up themselves on Chat GPT and and other random AI tools. It's there's a lot more to it,

I imagine.

Joe Popper (06:05)
you hit the nail on the head. the amount of effort and work it takes to implement all of these controls and put them in properly and correctly, it's hard for us, right? We spend a lot of time working on this and it's complicated and it's there's a lot to it. And so if a an RIA were to take that on or bring an employee in to take that on.

They're probably assuming risk they don't want to take.

Max Holvik (06:35)
Yeah, and and I imagine it's a it's an ever evolving field as well. That's that's changing more quickly than many other things as well.

Joe Popper (06:42)
it changes weekly for gosh sakes. the pace of change at at least in the AI space is just overwhelming and fantastic at the same time.

Max Holvik (06:53)
Yeah. No, it's I can't imagine that the the stuff you see on your end and I guess going a little bit into cybersecurity as well. there's a intersection there between AI and cybersecurity that's becoming more and more important, I understand.

Joe Popper (07:06)
Yes. Well so AI has made it much easier to be a thief, right? So one of we've all had the phishing emails, right? Think about this. You used to know it was a phishing email because the grammar was bad. the sentence structure didn't make sense. It was just a little off and it was like

Well, that that's clearly not written by somebody who speaks English well, right? So you knew, this is spam and I'm moving on. Well, AI fixed that. Now you get perfectly formatted letters with perfect graphics in it, and it's impossible to tell,

Max Holvik (07:40)
Yeah, and even phone calls I heard that you have clone voices and stuff.

Joe Popper (07:44)
Yeah. All of that. So the the the challenge is we now have you know, and you have to fight fire with fire. We now have a spam system.

That is based on AI as well. And it goes, it's it's doing all kinds of things that you you couldn't do as a human. So, as an example, it's checking all of those links that are in the email to make sure they make sense. And do they make sense against the context of the email? Right? So, you know, if you get an American Express email, and then the links are not to American Express, then

That's pretty easy to see, but from a formatting point of view, you, the user, can't see that. That's all behind the scenes, right? So, so the idea is you they can format that link so it goes, you know, it says American Express. It looks like it's American Express, but behind the scenes, it's sending you somewhere else, and the AI spam system can catch that.

Max Holvik (08:45)
Fascinating. Wow. So on that note, what would you say are the biggest threats from a cybersecurity, whether AI or not, biggest threats are facing the or that wealth management firms are facing today?

Joe Popper (08:58)
I would this is this is both wealth management and across the board, business email compromise is the biggest challenge. And the way a business email compromise works, I'm I I don't know if you've heard about this or not, but the idea is the bad guy breaks into your email system and then they wait. And what they're now waiting for is for a large transaction to happen, right?

And so where they really hit pay dirt is if they get the accounts receivable clerk. I've seen this in a law firm, but in an RIA where you're moving lots of money around, large sums of money around, this is how it happens. So let's just say I got the I I was able to hack into somebody in an RIA who's responsible for moving money around. Okay. I figure that out as the bad guy.

I I got a live wire here. I just wait. And then pretty soon here comes an email from client, somebody who's wanting to send money to you, whatever. And they say, hey, we'd like to move forward with your firm. We'd like to deposit a million dollars so you can manage this. And the the the guy at the RIA says, yes, that sounds great. And you have a conversation over a few days a week, whatever.

At the point that you get ready to send the money, the guy says, All right, send me the banking information. And the RIA guy says, Yep, here's our banking account information, all that, send the money. Then the bad guy who's been watching all of this jumps in about 30 minutes later and says, Oops, I made a mistake. Here's the correct banking information. And then a million dollars gets wired to the bad guys. And

I have seen it way too many times.

For this to be it's incredibly effective. Incredibly effective.

So here's the defense, and and I tell this, and it's old-fashioned. I tell this to everybody. One, whenever you're talking about banking information, send it in writing, not via email, right?

You send it in a secured document or you send it in some something they have to sign that says, I got the information, right? That's step one. Then step two is you always, as part of your getting money in, you ask for a small transaction first. Validate the money. So send me a hundred bucks, a thousand bucks, something that you if you lost it, you were not going to cry too much, right?

Whatever that amount is, but send send a small test amount and then send the balance.

I've seen a two million dollar business email compromise, and that simple trick would have

Solve the problem.

Max Holvik (11:53)
And that was two million dollars just lost to the bad guy, I imagine. Wow.

Joe Popper (11:56)
Poof, gone. Right. And so then

here's the other thing that that is really important in that is make sure you have the right insurance. Right? You've got to have cybersecurity insurance. We put it in our contract. You must have cybersecurity insurance as part of the contract. Because again, you think about what I just said. If you were to get compromised, we're all getting sued.

Right? That's an insurance problem. That's that's that's a risk mitigation problem and it's an insurance problem,

Max Holvik (12:35)
I've seen, you know, the cybersecurity applications, insurance applications become more and more complex and more and more demanding over the years. I imagine that's something that's that that folks like you guys would do to help your clients understand what to to answer on the different questions

Joe Popper (12:52)
So th this business earmail compromise, I've seen it again and again. About four or five years ago when I was with another company, I had a client. And this was when multifactor authentication MFA was first coming out, right? And so I went to a client and I said to the client,

You should get MFA. It really protects you and you need it. And blah, blah, blah. And the client said, How much is it? And they were about a 15-person firm. And I said it was six bucks a user a month. So it's less than a hundred bucks a month, right? And he said, No, that's too much money. It's too expensive. And I'm like, No, no, you really need this. And they said, Nope. And I said, Okay, roll forward three months. Business email compromised. They lost $100,000, exactly like I just described to you, right? And

Here was the thing that was crazy. So after we dealt with all of that, I went back to him and said, All right, can we get MFA now? And he said, Yeah, no, it's still too expensive. And I'm like, What's what's wrong with you? So, in answer to this is a roundabout way, I'm coming back to your question. I haven't forgotten your

question, but here was the thing.

It built POPRTEC team in our offering. We have two offerings. We have Team Care Cyber and we have Team Care Compliance. Team Care Cyber includes all of the cyber controls that you need to qualify for cyber insurance. And it's MFA, the one that the client wouldn't pay for, vulnerability assessments, training, immutable backups.

Vulnerability scans. There's at least five, and some of the insurance carriers will add more. If you buy PapperTech Team Cyber, we will bring all of the cyber security tools necessary to comply with your cyber insurance. Right?

And it's and here's the thing: it's not optional. I don't have a lesser program. Remember, I said you have to have cybersecurity insurance. So I will bring all of the cybersecurity tools, and I don't want to have the argument that.

No MFA is too expensive. It's either you're gonna go with us and we're gonna bring all of those tools or not, right? And so it's it's not an ad all that security is not an add-on, it's not an after-the-fact, it is part of the deal because

that's how we do it. And so the same with compliance. So if you're an RIA, you would want team care compliance because you have to meet the compliance standards.

And so again, we will bring all of the tools necessary for you to be compliant with SEC regulations. And it's part of the fee. And, you know, because again, we want to be able to swap out if this MFA is better than this MFA, I don't want to have to come back to you and have that discussion. I want to be able to do what's best for you as a client so that you have the best cybersecurity.

Max Holvik (15:48)
do you ever hear though the argument that hey we're we're too small to be a target? And

and does that actually work in practice?

Joe Popper (15:54)
every day. there's every excuse in the world. I'm too small. insert business and say, well the cyber guys don't go after my

business, right? And it doesn't matter what business they're in, they all say this. you know, I don't have anything to steal. You know, it's just, it's down the line, all of these things, and people don't fully appreciate the risk.

Max Holvik (16:20)
And there's so

many varieties of it too, I understand. Like I w one that's that really stuck with me was the the the scam where you have the the scammer sends out, say hypothetically, 10 million emails where they take the same stock and one is a buy strong buy signal and the other one is a strong sell signal. And then afterwards, say the stock went down, now they do a different stock and they do the same thing. Half of the recipient gets a buy.

Half of would get a sell. So after doing this five or ten times, you you have a much lower list, but still quite a few people who then see, Wow, these guys are geniuses and

Joe Popper (16:56)
Right.

Max Holvik (16:57)
and and and and get you that one and that's just one out of I don't know how many scams are out there.

Joe Popper (17:02)
Right. Well, that one is

how do you establish trust? And now you've established

trust. And the whole thing about cyber security is it relies on trust. Right? It takes advantage of trust. And so that whole scam, the idea there is you do that, you pick three stocks, you've proven to that guy that you're a world-class stock picker.

And you pick a really the the example there is you pick a really volatile stock, one that'll go way up or way down, whatever, and you're gonna look like a genius to the to the that subset of people that you pick three successful stocks to, right? And then you can do whatever you want. I got a fourth stock for you to buy, sign up for my investment program, whatever.

Max Holvik (17:47)
Exactly.

I'm curious to hear, you know, taking all of this in in in both AI, cybersecurity, IT infrastructure as a whole, looking at it from from a wealth management firm's a different sizes. Do you see the challenges, the risks, the needs change as a

a a firm grows, hypothetically, say you have a four hundred million AOM firm versus a three billion AOM firm. what's different between the two ra not just like more of the same, but are there any any structural differences that you see between different sizes of firms in the in the RAA space?

Joe Popper (18:24)
It it's interesting. The smaller firms, let's call them sub one billion, right? actually, let's let's even go a little further. It's really a half a billion dollars and down. They're really struggling. They're really struggling to to get assets and and to be able to run the business on the revenue that that generates. And that's that now they're getting squeezed, right? And they're they got to cut corners all the way around. Where do I cut corners?

The and and here's the thing that all of them will do. I I shouldn't say all, a lot of them will do. They ignore the cybersecurity. And the problem is it's expensive. To be fully compliant with SEC, it costs a bunch of money. And there's a reason that the SEC did that, and it's a good reason, which is don't lose my money, right? You know, and that was the government's intent. But it is really tough on that half a billion dollar or less.

They're struggling. And so what they do is they make all of those excuses that you just said earlier. Not gonna happen to me. They're not looking for my kind of firm. You know, I have somebody else who's holding all of my money, so I don't have a risk, all of which is nonsense, right? Every one of those excuses is what you tell yourself until the money's gone.

And that's the real that's the real tragedy in those situations is they really can lose a lot of money and because they don't have the right cyber security controls in place.

I have seen way too many of these stories in my direct sphere of influence. It's not like I heard from another guy, I you know, I read, I saw. No, these are people that I know that that you know, in my direct sphere of influence, I have seen too many losses.

So it's really, really a big risk and a big thing to protect against. But now you're asking, okay, what what if we are a billion dollars and up and we've got a good revenue stream? So we have the appropriate amount of people in place and we can afford the controls, right? That firm, the risk they have is not getting on the AI train.

If you're the small half a billion dollar RIA, right, you can use AI to fill in so many of the gaps that you have, right? If you're a larger, and and and here's the thing: you can grow your revenue, right? So you can grow your revenue, you can afford to pay for the extra cost that AI is going to bring

Joe Popper (21:07)
your opportunity to scale up is huge. And you can scale with a lot of leverage, which gives you a structural advantage over the bigger guys. The bigger guys can't implement AI and scale up so dramatically because they're so much bigger. It's harder for them. They have institutional problems. Not that they have a problem, but change is hard in any organization.

So the more people you have, the harder the changes, right? And so that firm has got to make a hard decision. And the hard decision is: can we scale our revenue up using AI? Probably not as quickly as a small firm. Therefore, in order to manage the additional AI costs, I'm gonna have to let people go. And that's a tough decision for them to make, right? Because they've got good loyal people.

never in my lifetime have I seen, and I've been doing IT for 35 years now, never have I seen the technology change so fast and so impactfully.

Popper Tech Team is two years old. And so when I started two years ago, I was using AI to for all kinds of things.

Website, copy, you know, you just all the things that you would do, right? I went back and looked at some of the text and graphics that I created two years ago compared to what they are now. And the difference is fantastic,

right? The the amount the what the quality of images that AI is generating now is unbelievable compared to what I got. And I didn't think what I got two years ago was bad, right? But it's, you know, it's leaps and bounds better.

Max Holvik (22:52)
See that see the same thing in terms of of, you know, you you asking complex questions and what it gives you back. Now, in the back of my mind I gotta be careful of okay, is it just convincingly telling me something wrong more than before versus actually knowing the stuff? But I think part of that has to comes down to knowing the field that you're asking it a question about and then being able to understand.

the context of it and whether it's right or wrong. but it's yeah, it's mind blowing what it what it actually produces these days.

Joe Popper (23:21)
Well, so you make an important point that we shouldn't let go by, which is people are still valuable. That's that's a critical point. The the the what what AI is, at least up until now, has been accelerators for human potential, right? Not replacements for because here's here's the problem that you're alluding to. The LLM has no sense of right and wrong,

It will tell you a hallucination with as much confidence as it does a real answer. And it's up to you to be able to understand which is which.

Max Holvik (23:58)
I even had its

settings changed so that I'll tell it not to create links as part of my sources because a few times it it it made up source links to research that didn't exist. So definitely be on guard.

Joe Popper (24:11)
Well that th that's the point and that's where humans are still valuable. And and the AI doesn't understand when it's wrong. It's because you're telling it it's wrong and it learns, but it doesn't understand inherently that it's wrong.

We internally created a coach, a Pauper Tech team coach. And so one of the things that's a big concern out in the marketplace is well, if AI can take our senior people and act as their assistants and and accelerate the amount of work they can do,

W why do I need junior people anymore? Well, it turns out you still need junior people, right? How do you get junior people up to speed? And one of the this is where AI can actually accelerate that. So we created a coach, an AI coach, and knows everything about Popper Tech Team. And so an engineer can ask the coach a question: how do I? And they're not technical, right? the client is asking for this. And I'll give you an RIA.

Context example, right? Had an RIA firm. They hired interns this summer. And so one of the interns, young, enterprising young woman, said, I would like Claude. The help desk engineer gets that ticket and just types in or copies what she said, puts it in the coach. And the coach says back, you can't install Claude. That's a regulated environment. You have to get sign off from the point of contact.

You also have to escalate that within Popper Tech team to the appropriate account management so that they can talk to the point of contact at the RIA and make sure that this is an approved activity within that regulatory structure. And you're like, brilliant, because you know, you just we just prevente three-week new employee from violating their compliance policy accidentally. Best of intention. He just wanted to help the person, right?

But because we've got that AI coach, we're accelerating what that person can do. Brand

new person and they got really good advice from the coach.

Max Holvik (26:20)
Yeah, 'cause 'cause if you if you don't have junior people, how are you gonna have junior people turn into senior people at some point?

Joe Popper (26:29)
Yeah, and so the the I mean instant win on the coach. Instant win. But again, the so inside popper tech team, one of the things that we keep saying is people are valuable and the coach doesn't know everything. It is your responsibility to take the feedback the coach gives you and look at it and go, does this make sense? And if it doesn't, it's your responsibility to deliver the work product.

not the coach. So make sure it's right. And so, you know, again, we're trying to instill a sense of responsibility in our team as they use these AI tools that have no sense of right and wrong.

Max Holvik (27:09)
So so basically helping in, you know, quality and and and productivity, but still maintaining the judgment, if I'm hearing you right.

Joe Popper (27:18)
That's exactly it.

We humans are the are are where the judgment comes from. And so for senior people that have judgment, AI is just puts them on steroids. For the juniors who are coming along, you are trying to put as much of that judgment in the coach to help them along, but you're still holding the humans responsible for the judgment.

Max Holvik (27:46)
thank you. This has been a a fascinating discussion.

before we wrap up, I I ask every guest the same question. What is the best financial advice that you've ever received?

Joe Popper (27:58)
You know, and thank you for allowing me to ponder that question ahead of asking me this, right? And I really all the financial advisors do this and they talk about the diversification strategy, right? You know, you need to be diversified a wide wide portfolio of things. And so I understood that, but the reality of that is when I was a young man and I I

put a plan together on how I was going to reach my retirement. I had a home, you know, the the I had a business that I was growing, I had a retirement account, I had a real estate portfolio And and I felt like that was four very strong, well diversified investment strategies.

And what happens is some of those didn't work. Right? And so all of a sudden, when you get to my age and you're looking back and you go, thank God somebody mentioned diversification. And it seems like such an obvious thing, but until you live life and understand how life goes off the rails, you don't understand the wisdom of that statement.

Max Holvik (29:15)
That's a great great insight. Yeah, some things we we have to live through to get it. I'm glad to hear the diversification strategy worked out well.

Joe Popper (29:24)
Yeah.

So I I I think that that and and and every good person, every good wealth manager says that, but until you've lived it and lived the failure of your financial plans, right, you don't understand.