Episode 129

Steve Tcherchian: Securing Mission Critical Systems in the Age of AI

With Steve Tcherchian, CEO of XYPRO
May 1, 2026

What we talked about

Steve Tcherchian, CEO of XYPRO, explains how XYPRO protects mission critical systems that move money, run payments, settle trades, and support national infrastructure on HPE NonStop. He shares that most customers do not complain about hackers first. They complain about complexity: too many tools, dashboards, audits, and reports that create work without reducing risk. Steve breaks down common misconceptions, including “compliance equals security" and "uptime equals security,” and argues security must be treated as a real business risk, not just a technical problem.

Show notes

When Steve Tcherchian asks a room of executives who owns incident response, who talks to the board, who talks to regulators, who is authorized to make decisions when an attack is in progress, the room typically goes quiet. That silence, he says, is the single most reliable warning sign that a company is not ready. Steve has spent 20-plus years in cybersecurity protecting HPE NonStop systems, the mission-critical infrastructure that runs payments, stock exchanges, and bank settlements, systems where downtime has immediate, measurable economic consequences.

What we covered

  • Compliance and security are not the same thing. Compliance is a backward-looking activity: a list of things that have gone wrong in the past. It does not address modern threats. Steve’s framing: “We don’t want to get hit with a fine” is a liability strategy, not a security strategy, and the two should never be confused.
  • AI did not invent new attack types, it made average attackers significantly better. Phishing messages that once gave themselves away through broken English or grammatical errors are now polished and natural. Reconnaissance is faster. Malware mutates more quickly. Steve’s advice: compare your current inbox to what phishing emails looked like 12 months ago, and the improvement is visible.
  • Attackers know that most security cameras, metaphorically speaking, are pointed at production systems. So they enter through the less-watched development or backup systems, which are connected to production. Ransomware groups typically go after the backups first, disabling recovery capability, and then exfiltrate that backup data separately to sell on the dark web repeatedly, independent of whether the ransom is paid.
  • The mean time to detection for a breach currently hovers around 200 days, more than six months. Marriott’s breach went undetected for over four years. Steve argues this reality shifts the goal from “prevent everything” to “detect and recover as fast as possible,” and that resilience needs to receive equal investment alongside prevention.
  • Adding security friction to users is counterproductive. Complex password policies cause users to store credentials in a desktop file called password.txt. Steve noted this is one of the first files an attacker looks for after entering a system. The same dynamic applies to any security control that makes people’s jobs harder: they will route around it.
  • His advice to aspiring security leaders: learn to speak in business terms. Security professionals who can explain risk in financial terms get budgets. Those who can explain it in board terms get authority. Being technically right is not enough, influence matters more than intelligence, and culture will outperform any documented security strategy if it is not backed by genuine buy-in from the top.

About Steve

Steve Tcherchian is the CEO of XYPRO, a cybersecurity company specializing in the protection, compliance, and resilience of HPE NonStop environments used by banks, payment processors, and stock exchanges. He is a patent holder and previously served as XYPRO’s Chief Product Officer and CISO before taking the CEO role.


Episode 129 of the PreVetted Podcast.

Full transcript

Federico Ramallo (00:00) Welcome back to the pre-vetted podcast where we spotlight extraordinary people and remarkable talent reshaping our world. Today I’m joined by Steve Chernian, his CEO of Xypro. Steve has spent 20 plus years in cybersecurity and has led Xypro across product, go-to-market and security leadership, most recently serving as CPO and CISO.

before stepping into the CEO role. He’s also a patent holder and a long time advocate for making cybersecurity clearer, more practical, and more human. Steve, welcome to the show.

Steve Tcherchian (00:42) Thank you, Frederico, glad to be here.

Federico Ramallo (00:46) honored to have you here today. tell us what XyPro does and who is it built for?

Steve Tcherchian (00:52) Sure.

So, Zypro protects mission critical systems. These are the systems that move money, run payments, settle trades, manufacture goods, and keep the economy functioning. So, we’re built for organizations running HPE’s mainframe system called HPE NonStop. So, this is used by banks, payment processors, stock exchanges, large enterprises. These aren’t marketing websites. These are national infrastructure systems.

go down, real things stop. we focus, as Nipro, focuses ours on security, compliance, resilience for environments that are designed for uptime. But now that have to survive modern cyber threats as well.

Federico Ramallo (01:37) Right, right, because in the age of AI, I understand that cybersecurity threats are going to get more complex and difficult to detect from real humans, right?

Steve Tcherchian (01:48) exponentially, you’ve got these AI systems that are mimicking real human behavior, which are almost impossible to sort out from actual human behavior.

Federico Ramallo (01:58) Right, right. And it’s a double-edged sword, right? Because now we have more powerful tools that can be used to build something amazing, but also to do harmful things, right?

Steve Tcherchian (02:09) Absolutely, and the bad guys have unlimited resources, even more resources than the good guys. So they’re innovating at a much faster pace than the good guys can play catch-up.

Federico Ramallo (02:18) Right, right. And what problems do your customers complain about the most?

Steve Tcherchian (02:28) They don’t complain about hackers, interestingly enough. They complain about complexity. Too many tools, too many dashboards, too many security audits, too many reports that actually don’t reduce risk, too much work, not the right type of work to actually secure the environment. Most security teams aren’t short on products. They’re short on clarity, and they’re short on understanding what they actually need to do to secure their company from threats.

Federico Ramallo (02:31) interesting.

Interesting, interesting. mean, the red tape is supposed to make the company safer, right? Even though it could be a lot of work. But what you’re talking about is that there is nonsense red tape that is not adding value or security.

Steve Tcherchian (02:58) Yeah. ⁓

There’s a lot of There’s a lot of red tape and there’s a lot of let’s just throw money at the problem and solve it. There’s a lot of security because it’s technology based. It gets relegated down to the technology people. And in a lot of cases, it’s not treated as a proper business risk. And security in 2026 and going forward needs to be treated as a proper business risk, just like any other business risk.

Federico Ramallo (03:40) Right, right. I used to work on HIPAA compliant projects. ⁓ we probably went above and beyond what was required, right? Because we care about the project, the client, and the users. But I’ve seen people just delivering the minimum of what was required to comply. And basically,

Steve Tcherchian (03:46) Mm-hmm.

Yep.

Yeah.

Federico Ramallo (04:04) know, they risk their business by just saying, well, we did our job and then, you know, they delegate the accountability and responsibility to somebody else and that’s it, right? But then when you see what is actually being done, it’s not reducing the risks, right?

Steve Tcherchian (04:16) Yeah.

Yeah, that’s a big misunderstanding in terms of cybersecurity is compliance doesn’t equal security. Compliance is a backwards looking activity. Compliance means these are all the things that we realize have gone wrong over time, so don’t do these things. But that doesn’t address in any way, shape, or form modern threats. So compliance is backward looking. Cybersecurity is something completely different.

Federico Ramallo (04:45) Right, right, it’s about liability and not security, right?

Steve Tcherchian (04:48) Yeah, that’s

right. Yeah, yeah. We don’t want to get hit with a fine.

Federico Ramallo (04:52) Right, don’t want to, yeah, what is the minimum we need to do so we don’t get hit with a fine? But that doesn’t mean, right, that doesn’t mean that you’re increasing your security levels, right? Yeah. So what is, you we’re talking about this misconception, what other misunderstanding that people has about cybersecurity?

Steve Tcherchian (04:56) capable to find that, right?

Right.

Yeah,

that’s a great question. So one thing that I see quite often is uptime equals security. A system can be up 24-7 and still be completely compromised. So availability, for example, is not integrity. Compliance, like we were just talking about, is not resilience. Buying tools and throwing money at the problem is not a strategy. Just think about that.

You see that quite often. You see all these vendors saying, buy my latest tool, my next generation this, my newest WinsBang, or the most common term thrown around right now is AI. I’ve got AI in my product. Buy my product, it’ll solve all your problems. But buying tools is not a strategy.

Federico Ramallo (05:51) Right, right. It actually adds complexity to your work.

Steve Tcherchian (05:56) There’s a concept called shelf-ware and a lot of these tools, you’d be surprised, end up as shelf-ware, especially in large organizations. I talk quite often with my customers, thinking about large banks, retailers, government agencies, and the common tongue-in-cheek joke is, well, we own at least one of every single tool that’s out there. Whether it’s implemented or not is not the concern. They just own the tool and at some level that gives them some reassurance or peace of mind.

that they’re secure. They’re not.

Federico Ramallo (06:27) Right, right. And in big corporations, I’ve seen that you have multiple people involved, that they have a very narrow responsibility. they’re basically, well, I used to call that taking care of your own garden, right? I mean, you can take care of your own garden, make sure it’s OK. But at the end of the day, the whole strategy is wrong.

Steve Tcherchian (06:42) Yeah.

Federico Ramallo (06:49) Nobody’s saying, hey, we need to rethink how we’re doing things, right?

Steve Tcherchian (06:52) Yeah, and you’ve got disjointed objectives and everybody’s focused on their narrow path. And at some point, they all need to converge to turn into a strategy. And oftentimes, that’s not the case.

Federico Ramallo (06:56) Ryan.

Right, right. I understand that insecurity, having layers of protection, it’s usually the best strategy. Does that apply the same for cybersecurity?

Steve Tcherchian (07:19) It is to an extent. Layers only work when the layer beneath another layer or above another layer is doing its job properly. If one of those links in the chain don’t work the way they’re supposed to, you’re leaving a window open. You’re locking your door, but you’re leaving a window open.

Federico Ramallo (07:34) Right, right, interesting. The other issue that I’ve seen in cybersecurity, well, in security in general, is the false positives. I’ve seen it with house alarms, residential alarms, and any alarm at all. Basically, after a few false positives, people kind of stop listening to the alarm. Does that same thing happen in cybersecurity?

Steve Tcherchian (07:43) Yeah.

Absolutely,

Absolutely, I used to work in data centers and security operations centers. You’d get 400 of the same alert and we’d have a running joke where you click on the first one, you shift click on the last one and just delete them. They’re all the same thing. But how do you know that that one alert in the middle of those 400 alerts is the one you need to pay attention to? So there is such a thing absolutely as alert fatigue and that’s caused a lot of

Federico Ramallo (08:18) Bye.

Steve Tcherchian (08:23) The attackers know that. So they know that they can hide their activity in volumes of alert or innocuous user activity. With AI tools becoming more and more common and being more refined and more focused on this type of alerting activity, that’s becoming a little better where you can separate the noise from the real data, but it’s still a challenge. It’s absolutely a challenge. And like I said, the attackers often have more resources available to them.

step ahead if not multiple steps ahead of where the good guys and their tools are.

Federico Ramallo (08:53) Right, right. And they only need to get once. Right.

Steve Tcherchian (08:57) That’s

right, they only need to be right once. That’s a common thing in cybersecurity. The attackers only need to be right once. We need to be right 100 % of the time.

Federico Ramallo (09:08) Right, right. So it’s hard to not treat every threat as a real threat, But that generates fatigue.

Steve Tcherchian (09:18) Yeah, yeah, just think about it.

Yeah, think about it. Those 400 alerts I was talking about, it’s 400, let’s say you get failed authentication alerts. Nobody’s paying attention to that. What you need to really pay attention to is not the 400 failed authentication alerts. It’s the one alert where the user actually logged in.

Federico Ramallo (09:37) Right, right. And then the other thought I have about this is if you go overboard with security, you start affecting the users, right? I think about airport security used to be more of a hassle, now it’s less of a hassle because we’re able to optimize it, right? Does that?

Steve Tcherchian (09:48) Yep.

Federico Ramallo (09:58) the same thing happens in cybersecurity.

Steve Tcherchian (10:00) Same thing, the more friction you add with security for the user, the more opportunity it gives them to find ways around that security. Great analogy I like to use is password and password complexity. If you’ve got these very difficult password complexity policies and rules, your password’s got to be 20 characters long, it’s got to have multiple upper and lowercase characters, it’s got to have multiple symbols and other types of special characters.

Federico Ramallo (10:08) you

Steve Tcherchian (10:26) All that’s going to do is cause the user to create a password, put it in the notepad file on their desktop, save it as password.txt, and they’ve gotten around all of your security complexity.

Federico Ramallo (10:38) Right, right. And the more you ask for a user to change their password, the more likely that happens because they’re, right.

Steve Tcherchian (10:44) The more likely for that to happen, the more likely for them

to keep that same password and just put a one exclamation mark at the end or two exclamation mark at the end. And again, know all these tactics. They know it. Once your system is compromised, one of the first things I would do is go on your desktop or go in your folders and look for a file called password.txt or password.xls.

Federico Ramallo (10:50) you

Right, right. We can build these complex security systems, but the weaker point is the human involved, Yeah.

Steve Tcherchian (11:15) It’s always

the human, yeah. And the more friction you add between the human and their job, the more opportunity it’s going to give them to find ways around it.

Federico Ramallo (11:23) Right, right. And social hacking and just phishing, it’s another easy way. If you ask for too many password changes, then phishing is more likely to happen. Yeah.

Steve Tcherchian (11:32) ⁓ yeah.

Absolutely,

and with the the advent of AI and AI being so commonplace now the attackers are using that to craft their phishing messages They don’t even need to spend time Building a profile about you the AI can do all of that for you and then launch phishing attack easy peasy

Federico Ramallo (11:54) So we were talking a bit about AI. What has changed in cyber attacks in the last few years?

Steve Tcherchian (12:01) It’s an interesting question because AI didn’t create new types of attacks. It made, just like the example I just gave, it made the average attacker better.

Whereas in the phishing example I just gave, you’re having to craft a message. And if English is not your first language, then you’re going to have spelling errors or grammatical errors or conversation errors in that message, which are obvious giveaways. And we’ve all been through those cybersecurity training courses where it says look out for misspelled words or natural language is not the proper way.

AI makes all of that goes away. So it’s taking these average attackers where English isn’t their primary language and made them a whole hell of a lot better. So phishing now becomes cleaner. Social engineering is now more believable. Reconnaissance is faster. They can build profiles on users very, quickly. Moldware mutates quicker. So AI has really turned into an amplifier. And amplification favors speed. And speed

Federico Ramallo (12:35) Right.

Steve Tcherchian (12:58) is what causes mistakes for the user interacting with that attack.

Federico Ramallo (13:04) Right, right. Wow, that’s very interesting. I haven’t thought about natural language being improved by AI, but it makes sense, Yeah.

Steve Tcherchian (13:13) Just take a look at your inbox

and just compare it the types of phishing messages you used to get a year ago and see how much they vastly improved.

Federico Ramallo (13:22) Right. Right. Yeah, I’ve seen huge improvements in the last year or so.

Steve Tcherchian (13:25) Yeah, yeah, and you’re

seeing more and more stories on the news where people are falling victim and their life savings are being drained by these phishing attacks. Not just phishing attacks, the gen AI types of attacks and all of that coming into play now.

Federico Ramallo (13:35) wow.

Right, right, and the agents being, you know, smarter, quote unquote, but you know, now they can make better decisions and you can automate those attacks much easier. Interesting. And what is AI security idea that is overhyped?

Steve Tcherchian (13:50) Yeah, they can automate it. Absolutely.

what’s in the ice here units overhived that a automatically and autonomously defender company you look at all of the cyber security vendors other every one of them is talking about it and the misinterpretation of that is if you buy this tool that your autonomous that it’s been autonomously defender company so you need less staff you need less resources you need less people

It’s not judgment. It’s not going to replace human AI can detect patterns and it can do it faster than any human can, but it can’t understand business context. It can’t understand legal implications. It definitely can’t understand brand damage if something were to go wrong.

Federico Ramallo (14:29) Hahaha

Steve Tcherchian (14:42) So the notion that AI is going to replace security teams, we’re not going to replace security teams with AI. We’re going to raise the speed of the game. So the AI tool is going to be an enabler. It’s going to augment the security team. It’s not going to replace it.

Federico Ramallo (14:59) Right, right. Yeah, I I have this hypothesis, I guess is the word, because I haven’t tested it, that in the age of AI, the core skills are going to become much more relevant, right? Because on every role we have, you know, average people that can look great on paper because, you know,

Steve Tcherchian (15:13) Yes, absolutely.

Federico Ramallo (15:22) they enhance their CV with AI, or they do the interview with AI, or they do their work with AI, and they look great. But then if they don’t have the right criteria, the course kills, then it’s a ticking bomb. Right.

Steve Tcherchian (15:37) The AI is useless at that point. Yes, it’s

a dead bomb, that’s right.

Federico Ramallo (15:41) And I see the same, you you’re describing kind of the same thing on cybersecurity, right? ⁓ Yeah, I don’t think that AI is going to replace cybersecurity jobs, it’s going to replace, but somebody that knows how to leverage AI is going to replace, you know, people that don’t, right?

Steve Tcherchian (15:46) Yeah.

That’s right. Yep, that’s 100 % right. If

you understand prompt engineering, if you know how the AI works, if you know how to harness the power of the AI tool, absolutely. It’s going to go leaps and bounds ahead of what a human can do, what multiple humans can do. And it’s going to do it at a much faster rate. But it’s not going to replace human judgment.

Federico Ramallo (16:22) Human judgment is the key. Yeah, yeah. And human judgment, you develop it through experience and knowledge. Yeah. So I don’t know how the next generations are going to be able to get that experience if they over rely on AI tools, right? Because, yeah.

Steve Tcherchian (16:24) and judgments.

Experience.

Yeah, that’s a great point is

those of us who have been through the trenches and carry the battle scars, there’s going to be those are the ones that if you can mend that with AI and understanding how to leverage the AI, those are the careers that are going to go far. yes, it’s going to, you’re 100 % right, Frederico, it’s going to give, it’s going to prevent that next generation from gaining that experience because they’re going to be heavily reliant on AI.

And it’s not going to allow them to maneuver when something goes wrong.

Federico Ramallo (17:20) Right, right. And with automation, could go, you know, if it goes wrong, it goes wrong really, really bad because it multiplies, right?

Steve Tcherchian (17:29) Yeah, exactly. It’s going to compound and once it’s compounded before you catch it, it might have moved too far away for you to catch it and reel that back in.

Federico Ramallo (17:38) So what are the biggest warning signs a company or a team should look for when they’re not ready for an attack or they’re exposed?

Steve Tcherchian (17:45) Yeah,

it’s another interesting question. what I like to do is I like to ask, who owns incident response? Who talks to the board? Who talks to customers? Who talks to regulators? Who’s the one making the decisions of what to do next? And you’d be surprised, most of the time, the room gets quiet.

Federico Ramallo (17:49) Yeah.

Steve Tcherchian (18:06) and that’s the indicator right there is when they start looking at each other in the room gets quiet that is the biggest indicator that’s the biggest warning sign that you’re not ready for an attack so

Federico Ramallo (18:06) ⁓

Steve Tcherchian (18:16) Another one, and this is very obvious, but it just blows my mind how often it does not happen, that backups don’t get tested. So hope is not a recovery strategy. You hear it all the time. Yes, we’ve got three copies of backup, one local, one on the cloud, one off site or whatever. We’ve got air gap systems. We’ve got a white room, all of these things. But if they’re not testing and validating that they can recover with those backups, it’s a waste of time.

So

you can even tell your real ransomware story that if any of these things happen and you get hit with ransomware, you’re not going to be able to recover on it. Those ransomwares, one of the first things that they do is they target the backups. Because what they’re trying to do is prevent you from restoring the data.

and not having to pay the ransom. So they’re going to target the backups first, they’re going to disable your ability to restore, they’re going to back you into a corner and ensure that there’s no other option than paying that ransom. And it happens. I look at the MGM story from, I mean, MGM didn’t pay the ransom a couple of years ago when they got hit, but it cost them a lot more than what they could have done if they paid the ransom.

Federico Ramallo (19:24) Bye.

Right, right. But there is that sense of don’t negotiating with terrorists, right?

Steve Tcherchian (19:41) Yeah, and it’s funny, that’s what the FBI and other agencies say is don’t negotiate with terrorists, don’t pay the ransom, it’s just gonna invite more and more of this behavior. But before MGM got hit, they went to Caesars first, which is right across the street. And they did the exact same thing. What did Caesars do? They paid the ransom. So the attackers took the money and they went away. They went across the street to MGM, they did the same thing. MGM told them to go pound sand and it cost them a whole lot more.

in recovery, in reputation damage, in losses, in having to rebuild those systems. But I guarantee you, that company is a lot better positioned from a resiliency standpoint now than they were two years ago.

Federico Ramallo (20:22) Right, right.

Pain, you know, the pain, it’s what makes them do better,

Steve Tcherchian (20:30) Yes, yeah. Yeah,

it’s like insurance. hear it all the, well, why are we paying for it? We’re never gonna need it and nothing’s ever happened until it does.

Federico Ramallo (20:41) Right, right, and then why didn’t I have insurance when I needed it, right? Yeah.

Steve Tcherchian (20:45) Yeah. Yeah, we hear it all the time

in the cyber security space with cyber security tools as well. Yes, people are willing to spend money on tools, but after a while when you’re spending money over and over and over on these tools and nothing’s gone wrong, the question starts being asked, well, why are we paying for it? Well, because exactly that, nothing’s gone wrong. That’s why.

Federico Ramallo (21:06) Right, right. Yeah, I mean I am running a staffing agency, right? And I have engineers in Mexico where one of the concerns is protection of IP, is my data going to be exposed, right? My code base is going to be exposed, right? I had an engineer from other companies.

reaching out to me, offering me the code base of the project that we’re working on. So I build layers of, and the reason I’m mentioning this, because it’s not necessarily cybersecurity, but it’s the risk in the whole situation. And I hope for the best, but I plan for the worst. So we have contingency plans.

Steve Tcherchian (21:33) Yeah.

for the worst, right?

Federico Ramallo (21:50) On the legal side, we have legal coverage in Mexico, legal coverage in the US, physical recovery in case. We never had to use it in the last 10 years that we’ve been operating, but still, I’d have it than never need it. I trust the people that I bring in, but then again, I have to set up all this in place in case I have to do something. ⁓

Steve Tcherchian (22:00) Yeah.

Exactly.

That’s right.

Federico Ramallo (22:15) Yeah, and it becomes an insurance policy, right? And it’s a peace of mind for me and I can transmit that peace of mind to my clients, right?

Steve Tcherchian (22:24) Yeah,

but going back to what I said earlier is unless you’re validating that what you think is in place is actually in place and working the way it’s supposed to, it’s a hope and pray strategy and hope is not a strategy.

Federico Ramallo (22:39) Right, right, hope is not a strategy, yeah. And it’s interesting that you mentioned the backups because they are the, mean, people protect the production environment, they don’t protect the backups, right? ⁓

Steve Tcherchian (22:41) Yeah.

Yes. Yeah, yeah. And

it’s quite off. I have this debate all the time. They’re willing to spend and overspend on their production systems where all of the eyes, where all the security cameras are on. But they don’t put the same level of emphasis on the development systems or the backup systems or the other non-production, non-money-making systems. But…

The attackers know all the security cameras are on this So they’re not going to go in there and start touching that production system. They’re going use the other systems that are connected to their production system to find an entry point.

Federico Ramallo (23:27) Right, right. And once they get the backups, then they can attack the main.

Steve Tcherchian (23:32) my gosh,

so many things that can be done. I talked about backups being targeted and either being disabled ⁓ or being corrupted, but even before they do that, quite often the first thing you’re going to see is exfiltration of that backup data.

Federico Ramallo (23:39) Right.

Steve Tcherchian (23:47) so they can monetize it and remonetize it and remonetize it again. Because if I’ve got your backup data, now I can put a sample of it online to prove to you that your systems have been compromised, encouraging you more to pay that ransom. And even if you pay that ransom, I’m still going to take that backup data that I’ve got in my hand. It can be customer data, it can be employee data, it can be intellectual property. And I’m going to sell it and resell it onto dark web, in other locations.

Federico Ramallo (23:59) way.

Steve Tcherchian (24:15) I’m going to use your employee data that I’ve got compromised your to get them to pressure the company to pay the ransom. There’s all kinds of things, all kinds of ways that the backup data can be used and reused and reused.

Federico Ramallo (24:19) Right.

Right, right, and the cost of one more copy is zero, almost zero, right? So, you know, even if I say, I’m giving you the copy, you don’t really know if that’s the only copy.

Steve Tcherchian (24:37) Zero? Yeah, exactly.

That’s right. That’s exactly right. And oftentimes it’s not.

Federico Ramallo (24:48) Right, right. And there’s so many things you can use the data to exploit that it’s.

Steve Tcherchian (24:53) Yes, you’ll find

most of these compromised databases and lists and information, you’re to find them on the dark web. And as time goes by and as the between the time of the breach and when somebody wants access to that data, obviously the value goes down. That’s why you’re constantly seeing more and more breaches.

Federico Ramallo (25:00) Right.

Because the moment you get the data, it starts to become obsolete.

Steve Tcherchian (25:16) It’s got

a life span. If it’s credit card numbers, for example, they’ll have a life span. If it’s HIPAA information, it might have a different life span.

Federico Ramallo (25:25) Right, right. And so do you work with your clients on reducing those attacks, risk for attacks?

Steve Tcherchian (25:33) Yeah, that’s our primary

focus is we focus on compliance number one, because if you’re not doing, if you don’t handle compliance first, everything else is built on.

shaky ground. So we help them be compliant, at least put in the controls that will close the doors, lock the windows, make sure that the walls are up, the guard dogs are out, the security cameras are online, everything is hardened. That way, if anybody even attempts to try and get past our controls, the layers that we were talking about before, the security cameras are going to catch them right away. But there’s no point in putting security cameras up if you’re

Federico Ramallo (25:45) Right.

Bye.

Steve Tcherchian (26:09) you’re not going to lock the doors, close the windows, and secure the environment. And that’s what we do a lot of is help our customers understand what their landscape looks like, put in the controls that will prevent somebody from entering their environment, and put up the security cameras that will catch somebody if they even attempt to try and get into their environment.

Federico Ramallo (26:28) Right, right. When people put security cameras and they don’t do the rest of the warning system, I find that in Mexico they’re doing something similar where they put panic buttons on the streets. I think that that’s inefficient or useless because now you can see the…

Steve Tcherchian (26:41) huh. Yeah.

Federico Ramallo (26:49) You can see the rubber getting in, getting into your house, getting out with your stuff or whatever it is. But it’s not effective for prevention. It’s not effective for finding who did it. So what’s the point?

Steve Tcherchian (26:53) Yeah.

That’s right. And when I

say security cameras, I’m using it as an analogy. When I talk about security cameras in our sense, I’m talking about threat detection tools, anomaly detection tools, the tools that are going to, when we see a pattern that we don’t recognize and that shouldn’t be there, that we’re going to send an alert about that right away.

Federico Ramallo (27:24) Right, right. Yeah, I mean, I’m following on that analogy. mean, if you have the threat detection that raises an alarm, but then the team doesn’t do anything with that, they don’t react, then you’re going to have a detailed logo of how you’ve been hacked, right?

Steve Tcherchian (27:37) Yeah,

and you’re probably not even going look at it for two weeks after it happened, which is the case most of the time. And that goes back to what I was talking about is locking the doors, locking the windows, putting the controls in place. Because if that controls aren’t done first, you’re going to get flooded with alerts, whether they’re legitimate alerts, false positive alerts, and you’re just going to get inundated with all of these alerts that nobody’s going to look at.

So the key is to really lock the system down, harden it, make sure that only the people that need access to the data, the application, the workload, whatever, are the only ones that have access to it. Everybody else is locked out. That way, you know that the only people that are going to be able to access it are the people that have to access it. Anything else, you’re going to raise an alert for. If you don’t do that, if you don’t put your controls in, if you don’t harden the system, you’re going to get

alert for everything. Normal behavior, people that shouldn’t be in there that are in there, attackers in there, and all of those alerts are going to land on your SOC team. They’re going to fall into an alert fatigue. Nobody’s going to look at them and you’re going to find out that you’ve been compromised in the news two weeks later.

Federico Ramallo (28:47) Right, right. So you help your clients setting up the systems, setting up the criteria. Do you also help your clients building procedures on what to do before they get hacked or when they get hacked?

Steve Tcherchian (29:00) Yeah, we often

help them. So we’ll often go in there and we’ll do what’s called a gap assessment. We’ll get a thorough understanding of what’s there, what’s not there, what are we trying to protect, how are we trying to protect it, why are we trying to protect it. Every time we do this, we uncover things that they didn’t even realize that they had. So they might be holding data that they didn’t realize was there. It could be social security numbers, could be credit card information, it can be other things, things that have been copied around the system over time.

that

nobody paused and cleaned up afterwards. So we take a look at the whole landscape. And this is the case for any system, not just what we do. For anybody that’s going to implement security, without that gap assessment, you’re just spending money on tools and again, hoping and praying that nothing happens. But a gap assessment will create a roadmap of what are the things that you need to do next.

Federico Ramallo (29:37) Right.

Steve Tcherchian (29:53) What data do you have? What users have out? What things, items users have access to? All of that. And then you can map the controls. Then you can go back to what I was talking about, harden the system based on what you have, what you’re trying to protect, and how you’re trying to work. So yes, we oftentimes get called in to do that for our customers.

Federico Ramallo (30:13) And then you also build mitigation plans on, you know, after you got hacked, after you got exposed, what are the steps that you need to do to reduce that, the damage, right?

Steve Tcherchian (30:23) Yeah, often times we’ll help our customers with that, most of the time they’ll have internal policies and procedures on how to do that. we can give them the plan, we can help augment their plan, but at the end of the day, preparation is key. And internally, if they don’t have the proper support from an executive level for this type of activity, that’s where it often breaks down. It’s executive support for mitigation and your response

Federico Ramallo (30:31) Right.

Steve Tcherchian (30:49) response

plan and what you do when something goes wrong, you’ve got to have support at the highest levels of your organization to do that properly.

Federico Ramallo (30:56) Right. Usually in the movies, they convey the hacking us. I’m typing in the keyboard, and you’re the hacker, and you’re typing the keyboard, who types faster wins, ⁓ which I understand. On the movie, you need to have that action. But that’s completely different to reality.

Steve Tcherchian (31:06) Yeah. Yeah. Yeah.

Yeah.

That’s not reality.

When I talk about this, often say hacking is not what you see in the movies. It’s not somebody with 20 screens in front of them banging away on the keyboard while all the source code is going past their screen. That’s not hacking. Hacking is somebody tricking somebody into giving you their username and password and walking right in through the front door. That’s what hacking is.

Federico Ramallo (31:42) Right, right. And can you describe a little bit more of what happens when an executive learns about that they’ve got attacked, they got exposed, so they can learn a little bit more of, they can have a little bit more of awareness of that experience so we can prepare them a little bit more to not get hacked.

Steve Tcherchian (32:04) Yeah, I’ve been through

this quite a few times and what I’ve seen quite often is the instinct is panicking or blaming somebody. And that’s not helpful in a situation like this. So the right move is slow down. First let’s contain. Let’s understand what’s happening and let’s contain it to prevent it from spreading. Communication is key.

Federico Ramallo (32:12) Right.

Steve Tcherchian (32:26) There needs to be a leader. There needs to be somebody that can make decisions, that’s authorized to make decisions. whether it’s talking to customers, talking to law enforcement, talking to regulators, directing the team. There needs to be a documented process of what that chain of command looks like. Decisions need to be made beforehand. If this happens, we need to do this, and then this, and then this.

Because keep in mind, you’ve got to protect, it’s not just the systems you need to protect, but for a business leader, they’ve got to protect the credibility of their brand and their business and their customers. So all of that is key. That’s why I was saying earlier that executive support is paramount to successfully surviving a cyber attack.

Federico Ramallo (33:10) Right, right. It’s a moral support, the legal support, the operational support to give the person in charge, to put a person in charge to be able to make decisions to reduce the impact as quickly as possible.

Steve Tcherchian (33:25) Yeah,

yeah, often times though, it’s security is having to be sold. These types of things are having to be sold from the bottom up rather from the top down. And you’re going to have the best success to survive something like this if you have support from the top down because everybody will fall in love.

Federico Ramallo (33:41) I, now that we’re talking about this, I remember a joke from the Simpsons. I grew up watching the Simpsons, where they are in the power plant and they go through checkpoints and checkpoints and checkpoints. And then they have a crappy door that goes outside and a dog is inside the security room. And when you’re talking about this, I feel that, you know.

Steve Tcherchian (33:51) I love the show.

I remember that. Yeah.

Federico Ramallo (34:09) The same thing happens in corporations,

Steve Tcherchian (34:11) Yeah, absolutely. You’ve got to have these processes. You’ve got to have support from the top. You’ve got to have these processes documented. You’ve got to have them practice in not a live situation. So in a live situation where to ever occur, everybody knows what they’re supposed to do. Everybody knows their roles. Nobody’s panicking. Nobody’s blaming. Everybody just does what they’re supposed to do.

Federico Ramallo (34:31) Right, so you help companies doing audits? You call that gap analysis? Right, okay, okay.

Steve Tcherchian (34:35) We don’t do the audit ourselves, we prepare them to pass it on. So we provide

the expertise, we provide the tools, we provide the assistance to secure their systems, to comply, to monitor their compliance, to generate the evidence, so then they can successfully pass their audit.

Federico Ramallo (34:54) Right, right. So you help on the gap analysis. You also help on doing the simulations, right?

Steve Tcherchian (34:58) Yes.

Not necessarily. We’ll help putting the controls and then they’ll run their simulations internally. Or they’ll bring in another person.

Federico Ramallo (35:07) Right, so you advise

on how to run the simulation so they can do it.

Steve Tcherchian (35:12) We’ll

advise and we also build and provide the tools that will help them become compliant.

Federico Ramallo (35:20) Right, right. That’s very interesting. we were talking lot about AI. this also goes with AI as well. But what is a big change you expect in cybersecurity in the following years?

Steve Tcherchian (35:34) Yeah, we’re seeing a shift from perimeter defense, firewalls and VPNs to identity and behavior defense. So AI is going to make these types of attacks much faster, which means detection and response for these types of attacks need to be in real time. So security is going to shift from did it happen to how fast did we detect and recover it. So there’s a saying that there’s two types of companies in this world, the ones that

that have already been attacked and the ones that have been attacked and don’t yet know about it.

So it’s all about being able to detect and recover as quickly as possible. So it’s not so much about prevention. Prevention is key, absolutely. But resilience now needs to be just as important because you can prevent, prevent, prevent. But again, we have to be right 100 % of the time. And you miss that one thing that an attacker can exploit. You need to plan for that and know how to recover from that very quickly.

Federico Ramallo (36:07) ⁓

Steve Tcherchian (36:32) So resilience needs to be 100 % in focus going forward.

Federico Ramallo (36:38) Right. This reminds me of, I mean, I ride motorcycles. And we have a saying that says, there are two types of motorcyclists, right? The ones that already fell or the ones that are going to fall, right? So yeah. So I feel that something similar happens here, right? I mean, there are two types of companies that are already hacked or are going to be hacked, right? So how prepared are you to that?

Steve Tcherchian (36:52) Going to fall.

Yeah.

Yep. Well, it’s not even going

to be hacked. It’s even scarier than that. It’s the ones that have been hacked and the ones that have been hacked that don’t know about it.

Federico Ramallo (37:08) and don’t know about it. Yes,

yes. Because then they get hacked continuously, right? They get exploited with information and they don’t know about it, right?

Steve Tcherchian (37:18) Yep.

The perfect example is this is several years ago now, but the Marriott breach. Marriott had been compromised for over four years before they realized that they had been hacked. So there was somebody or some bodies on their systems for four years doing whatever they wanted to do, whatever they had access to, stealing whatever data they wanted before somebody realized that they’d been compromised.

Federico Ramallo (37:29) Wow.

Wow.

Steve Tcherchian (37:46) Yeah. The meantime to detection is still hovering around 200 days right now. That’s over six months. That means systems and companies are compromised for six months on average before somebody realizes that there’s somebody on their systems doing things that they shouldn’t be doing.

Federico Ramallo (38:05) Right, right. That’s scary. Yes.

Steve Tcherchian (38:07) That’s scary.

It’s scary for the company and it’s scary for that company’s customers as well. But it’s the one thing that I really I’m uncomfortable with is how much we’ve normalized these security breaches. We hear about it so much in the news constantly that we’ve become numb to it. There’s another security breach. well, my credentials are out there. I mean over and over and over. It feels like on a monthly basis now I’m getting a letter to my house that this provider got compromised or this service got compromised.

or this data was leaked from this agency. We’re becoming numb to it. And that shouldn’t be the case for Grigori.

Federico Ramallo (38:45) Wow.

And with AI, it’s going to get worse and worse, unless companies do something.

Steve Tcherchian (38:52) It’s going to get worse and worse. Yeah.

Federico Ramallo (38:57) So what advice would you give to a new security dealer in a corporation?

Steve Tcherchian (39:03) Learn your business. Learn the business because if you can’t explain risk in financial terms, you’re going to lose influence. So you’re not going to have an impact. Security leader, security is not just technology. So security leaders who speak technology but can speak it in board terms will get a budget. Security leaders who can speak to business will get authority.

So if you can speak technology, you understand the technology, you understand what needs to be done, great. You mean you can probably convince your board to allocate budget for your initiatives. But if you can put it in business terms and business risk, now you’re going to have influence. Now you’re going to have authority.

Federico Ramallo (39:42) Wow, that’s very interesting. Coming from the technical world, it’s hard for me to sometimes convey it in business terms, right? So I understand the challenge.

Steve Tcherchian (39:48) Yeah, it’s the leaders.

The leaders that I see do really, really well are the ones that can speak to their audience up, that can speak sideways and can speak down. And when I say down to the people reporting to them, to their peers and counterparts, and to their leadership.

Federico Ramallo (40:04) So let me ask you one last question before we wrap it up. So what is one mistake you tell your younger self to avoid? Or lesson learned, if you like.

Steve Tcherchian (40:13) I know.

Yeah, yeah, yeah. Great question. So I used to think that being right was enough. Having all of the answers was enough. It’s not. What I’ve learned over time is influence matters more than intelligence. Clarity matters more than complexity. If you can simplify things to the person you’re talking to, you’re going to have influence over them. And in culture,

This is key. Culture eats strategy and security all day long. You’ve got to have that bond with the team. You’ve got to get everybody to buy in. You’ve got to get everybody to think the same way. And now, see how easy strategy becomes.

Federico Ramallo (40:57) Interesting, interesting. Yeah, I’ve been through the same lesson learned because I used to think that I was right. And probably I was right, but being right, that allowed me to be a show off. And I realized, yeah, I should.

Steve Tcherchian (41:15) Yeah, yeah,

and it’s interesting, as technical people, and I see this quite often with engineers and other technical people, is they want to be right all the time. They want to have all the answers to everything. But all that does is compartmentalize you. And it limits your, it really does limit your career. So you’ve got to be able to balance that with influence and communication and clarity.

Federico Ramallo (41:33) Right.

Steve Tcherchian (41:39) And with all of that, you can harness that and use that to your career advantage, to your company’s advantage, you’re going to build a culture. You’re going to be organically building a culture that’s going to be magnetic. And you’re going to get everybody to buy in. like I said, look how easy then the work becomes. Look how fulfilling the work will become.

Federico Ramallo (41:59) Right, because instead of you alienate the relationship with the people, and you build this us versus them kind of thing. Rather than saying, well, we’re in this together, and let’s collaborate towards the same goal.

Steve Tcherchian (42:06) Yes.

Yeah,

yeah, with my teams, I don’t want them to treat this as just a job because if they treat it as just a job, then you’re just going to get that type of output. But if they treat it as their own, if they’re passionate about it, if they… People want to believe in something. People always want to be led. They want to follow. They want to believe in something. They want to know that their work is contributing to something bigger.

And that’s why I said culture eats strategy all day long. You can sit there and create PowerPoints and workflow diagrams and all these documents and tell people to do this and this and this. But culture will trump that any day. If you have culture, the second part becomes very, very easy.

Federico Ramallo (42:36) Right.

Right, amazing, amazing. So we’re running out of time, but I truly appreciated you being here today. We learned a lot about cybersecurity. We’re going to leave the links to CyPro on the description of the podcast so people can reach out. Any final remarks before we wrap it up?

Steve Tcherchian (43:12) I really enjoyed the conversation, Federico. I think this is a great topic. There were some great questions here. I would say two key takeaways from any type of cybersecurity discussion. Number one, if you’re not using multi-factor authentication for everything,

drop what you’re doing right now and turn it on for everything. That’s is multi-factor authentication on everything at work, at home, everything needs to have it turned on. It’s the best bang for your buck when it comes to cybersecurity right now. And number two, we all hear this and we constantly get bombarded with it, but just be careful on the links you click on. Phishing is becoming more and more

Natural it’s becoming more organic So the red flag that we would seen even 12 months ago You’re seeing you’re starting to see less and less of those so people are starting to fall victim to very simple phishing attacks because of AI They’re falling victim to gen AI type attacks. Just be very very careful on what you’re clicking on and what you’re opening

Federico Ramallo (44:16) I disabled preview links on everything because of that. Because I want to be able to click the link, copy the link, see the URL, and then decide I want to click on it and open it.

Steve Tcherchian (44:19) Yeah. Yeah.

Yeah, or you go straight to, you get an email from Amazon, for example, you don’t click the link, you just go, you just type amazon.com in your browser and then go retrieve the message that way.

Federico Ramallo (44:39) Yes, yes, I do the same thing. I know how the URLs work, so I can remove the params and things like that, check the domains or subdomains. But it’s more of a technical hassle that I’m more used to do. But yeah, if you can just type instead of clicking, that’s even better.

Steve Tcherchian (44:48) Yeah.

That’s great.

Yeah, this was great. That was great questions. Thank you, Frederico.

Presented by Density Labs. We help mid-market companies ship AI to production, not demos. New: Agentic AI, explained from production — what an AI agent actually is, and when a workflow ships instead.
Don't miss it

Listen on your favorite app