The Strategic Evolution of IT Partnerships - Balancing Security and Creativity
Thomas Bray, COVI’s Senior Tier 3 Technician, brings decades of cybersecurity expertise to organizations navigating today’s complex threat landscape. In our latest podcast discussion, Thomas revealed how dramatically the cybersecurity world has evolved from simple spam campaigns to sophisticated ransomware-as-a-service operations worth $10.5 trillion globally. The most alarming shift is that over 50% of small businesses now experience successful cyberattacks, with average breach costs reaching $4.9 million and many organizations closing their doors within six months of a major incident.
The foundation of effective cybersecurity lies in understanding that technology alone cannot protect an organization—security must become deeply cultural. Thomas emphasizes that while COVI implements advanced technical safeguards like multi-factor authentication and email filtering, the human element remains the primary attack vector through social engineering and phishing campaigns. This reality requires comprehensive security awareness training platforms like UsSecure, which COVI uses both internally and with clients to create ongoing education rather than one-time compliance exercises. The key insight is that security awareness must be embedded throughout an organization’s operations, with leadership driving cultural change that makes every team member a knowledgeable first line of defense.
Business leaders can immediately strengthen their security posture through three strategic actions: implementing enterprise-grade password management systems to prevent credential stuffing attacks, establishing clear vendor communication protocols to prevent business email compromise, and working with IT providers to implement domain spoofing protections at no additional cost. Thomas’s practical advice centers on viewing cybersecurity not as a technical burden but as a fundamental business risk that requires the same strategic attention as financial planning or market development. As threats continue to evolve from simple nuisances to business-ending catastrophes, the organizations that thrive will be those that proactively build security into their culture while maintaining the productivity and innovation that drive growth.
Episode Summary:
In this episode of The Covi Way, Tier 3 Tech Expert Thomas Bray joins host Dave Vint for a candid, eye-opening conversation about the rapidly evolving cybersecurity landscape and why security in 2025 is no longer just about tools and tech. From ransomware-as-a-service and credential stuffing to phishing simulations and cultural awareness, Thomas breaks down what businesses of all sizes need to know to stay protected in an era where attacks are no longer a question of if, but when. It’s not just about blocking threats — it’s about creating resilient systems, embedding security into culture, and empowering people to recognize risk before it becomes a breach. Whether you’re a business leader, IT pro, or nonprofit exec, this episode will shift how you think about cybersecurity.
Key Quotes:
-
“Security isn’t just the IT department’s job, it’s everybody’s job.”
-
“We build better castles, they build bigger ladders.”
-
“More than 50% of small businesses experience a breach, and many don’t recover.”
-
“The most secure computer is at the bottom of the ocean… but that’s not very productive.”
-
“You’re either preparing or you’re reacting. One costs a lot less.”
Connect with COVI:
Instagram | Facebook | Website | FREE IT Strategy Analysis
Links to The COVI Way Podcast
YouTube | Apple Podcasts | Spotify
Episode Transcript
The COVI Way - Episode 8
Featuring Dave Vint and Thomas Bray
Welcome to The COVI Way, the podcast where we break down the intersection of people and technology because technology shouldn’t be just about solving problems, but enabling people to do their best work. Today, I’m sitting down once again with Thomas Bray, our senior tier three tech, as we talk through security, modern risks to modern businesses and things you can do about it. Let’s jump right in.
Dave: All right, let’s start big picture, Thomas, and then we’ll zoom in. How has the security landscape changed over the last five years? And why is this a different conversation than what it used to be?
Thomas: Yeah, it used to be that attackers, people trying to get into your accounts, into your business were pretty, I don’t know, not low key, but their goals were pretty low. They were really trying to get into your email so that they could send out a bunch of spam about whatever platform they were trying to promote some fake product or something, try to get somebody to buy something fishy online. But nowadays, the bar for a very sophisticated attack is so low because the bad guys have also gotten in on the subscription game. They’ve started to build ransomware as a service platforms where anybody can go out and exchange some cryptocurrency to run a ransomware service and take your data, charge you a ransom for that, and then also encrypt you and charge you a separate ransom for that so that you’re kind of stuck. So we’ve come a long way from having to send out the follow on email notification to your contact list that’s like, oh, hey, sorry, my account. Somebody got into my account and they sent you that email that wasn’t really me, even though it was from me. So it is big business.
Dave: So it sounds like it has literally turned into a business, a scalable business.
Thomas: No, 100%. And it sounds like the means of attacking individual users has gotten easier, but also the means for bad actors to gain access to those tools has gotten easier. So that just sounds like a recipe for disaster across the board.
Dave: Yep. And as we’ve gone into a more connected online world, the attack surface is so much bigger than it used to be. It’s not the network edge at the corporate office. It is anywhere. It’s I’m out in public and I get an email on my phone. Maybe it’s legitimate, maybe it’s not. And if the proper controls aren’t in place, you know, it’s pretty easy to pivot from somebody clicking on a phishing link on their phone to their cloud storage to then try to compromise a vendor from that identity or a device on the corporate estate.
Thomas: Sure. Yeah. And arguably, one might assume we’ve just talked about technical side of security issues nowadays, not to mention phishing and smishing and all of those other ishing things where social engineering is involved, right?
Dave: Definitely. Yeah, that is, I’d say, other than something like a device vulnerability or a software vendor having a supply chain attack, social engineering and spearfishing are the most common and the biggest threats for any organization nowadays because the human is the pivot point to the data and is really what they’re after.
Thomas: Yeah, makes sense. So you’ve got the technical side and you have the people side and then you have bad actors combining all of those at their disposal. And we’re all trying to get more done with less time and the leaner budgets, we’re trying to do more with less and sometimes we’re moving too quickly and it’s really easy to get yourself in a bad spot. That’s yeah, it’s you know, we talk about this stuff in the office all the time and we share it in sales presentations and do workshops for our customers. But every time it comes up, I’m still like, God, this is big. This is just a tough environment for a business to run in and for an MSP to grow in.
Dave: Yeah, 100%. It’s trickiest times. My goodness. I just sat down for my podcast conversation with Cody. We were talking about the need to balance a really strong security environment with a really strong productivity environment and how that is the modern challenge for an MSP.
Thomas: Definitely. It’s tough because you want to make sure that you as the organization, as the management team, are aware of how you and your people are going to be the most productive while also making sure that you are leveraging platform functionality in your business operating system of choice, Microsoft 365, Google Workspace, whatever, to make sure that only the right people on the right devices are accessing the right data.
Dave: Man, the scope is immense.
Thomas: Yeah. It’s huge. It’s tough. It’s tough. We also cannot understate the point around bad actors growing this as a business themselves. I was looking up the most recent statistics and data before we sat down for a conversation. And the current number is 10.5 trillion. That’s size of the industry.
Dave: Yeah. So that that’s the business for bad actors to acquire the tools to jump in and make a malicious move.
Thomas: Yeah. 10.5 trillion. When you think of a lot of businesses that exist in our world today that have lesser size.
Dave: Oh, 100%. That’s absolutely unbelievable. Unfortunately, every penny of that 10.5 trillion comes out of some legitimate business’s pocket.
Thomas: Exactly. It’s crazy. The risk is huge. Yet the opportunity for greater productivity with technology is also huge. The need to balance those is crazy. We know that at COVI, we want to empower as much creativity as possible. We also want to keep our users as secure as possible. And we believe that starts with awareness.
Dave: 100%. Yep. So with that awareness, walk our viewers and listeners through the basic categories. What are the basic types of security threats that a business should be aware of or a nonprofit for that matter?
Thomas: Yeah, 100%. So like we said earlier, the biggest one is social engineering. So security awareness training for your people should be top of mind and making sure that people really do genuinely, that they can recognize that something is wrong. One of the industries always want to add acronyms, right? It’s the best. There is a methodology called the SLAM method. So you are looking at the subject line of the email. Sorry, actually, sender. You’re looking at any links that are in that email. You’re carefully reviewing whatever attachments are there. And then finally realizing like, okay, if any of the prior things have tripped any red flags, then I probably shouldn’t even look at this message.
Above and beyond that, even your vendors and other organizations that you work with, you should really, when you’re starting to establish those business relationships, you should make sure that everybody’s on the same page, especially with something like a financial transaction to make sure that there are backstops in place so that people aren’t changing banking information or payroll information off of a single method or a single form of communication. Those things, they can end your business for sure if you get caught in a bad spot.
But other than social engineering, making sure that your devices are as up to date as you can, it can be pretty tough when the new Windows or Mac OS updates roll around to find the time to get them installed and reboot during your work day. Device vulnerabilities are up there. If a bad guy can get on a machine, there is a good chance that they will be able to take it over, unfortunately. And even in a more secure environment, it’s still risky. Devices are always a risk. But the only secure computer is one that’s turned off, thrown in a box at the bottom of the ocean. Unfortunately, those don’t work very well.
But other risk factors, and this is maybe a little bit more in the weeds, something that IT nerds would talk about. Consider the software vendors that you’re working with and their potential likelihood for being compromised themselves. We’ve had a handful of, not we, COVI, but we, the industry, has had a handful of big supply chain attacks over the last five years or so, where an attacker will target an organization that provides software to its customers. And those attackers are looking to get into specific customer networks. So they will take control of a usually something like a software signing certificate. They’ll write a bad malicious piece of software, sign it with the vendor’s valid code, signing cert, and then deploy it using their software update mechanisms. So it is always good to consider, like, are these companies that I’m working with and relying on to run my business, are they following good practices? Do they have good instant response programs? Do they have internal security teams? So it is a as you start to realize the threat landscape, it’s overwhelming. But you take it one day at a time and lots of angles.
Dave: Yes, all right. So we talked about as far as some basic risk areas, email, how you exchange data. We also talked about how you manage best practices with your vendors and other folks that you interact with on a daily basis. And we also talked about choosing your software platforms intentionally.
Thomas: Yep, very careful. And understanding their risk factors. And at COVI, those are all things that we help our customers with to keep things balanced.
Dave: With understanding of some of, really just some, of those basic inlets, if you will, share with our viewers and listeners some of the basic ways that bad actors get in. Tell us a little bit more about how social engineering works and how they combine some of these means of entry to steal money, do damage and hurt reputation.
Thomas: Yeah, definitely. Probably the most common thing that we run into or are brought into organizations to work with them on are situations where legitimate external parties have had their accounts compromised and they will leverage that existing relationship to send a just legitimate enough looking email that prompts you to sign in and do a docu-sign or an Adobe e-signature or log in to see this file on SharePoint. And leveraging these kind of normal access patterns, it can be really tricky unless your people are very aware of what to look for and what doesn’t feel right based on how they’ve worked with these other vendors in the past.
But, you know, somebody finding an email in their inbox, clicking on it, putting in their Microsoft 365 credentials or Google Workspace credentials, that is the most common attack vector. And even nowadays, over the last few years, the bad guys have figured out how to not just take your username and password from you, but stand in the middle between you and your collaboration platform and proxy through the multi-factor authentication requests. So it is not even multi-factor authentication is not perfect. There are additional layers of security that should really be there to backstop those kind of standard walls that we’ve built over time.
Dave: For those who don’t know, what is multi-factor?
Thomas: Yeah, multi-factor authentication is typically a combination of three things. So you’ll have something you know, like a password, something that you are. Typically, that’ll be face ID on your iPhone or a fingerprint reader. The third thing is often something you have. So if you have a most commonly, these are little security keys that you would plug into the device or hold it near for NFC functionality. And that validates that, it’s a pretty good bet that Dave Vint is the one that has the security key and is signing in with his username and password.
Dave: So an example of that inside of our organization is the Authenticator app.
Thomas: Yep, right? Yep, Microsoft Authenticator. It I log into my my line of business application in the morning, our ticket system, and I’ll get a notification to my phone that’s like, hey, notice we have a login. Enter enter the numbers here to validate that I myself, Thomas, can see that, yes, I am logging into the system. Move the numbers from the computer screen to the phone screen. And it also tells me like, hey, are you really in Indianapolis? Was this you? And, you know, if everything’s good, then yes, proceed. You’re in. And I’m in.
Dave: What’s neat about the two factor process with, for example, the Microsoft Authenticator app is it’s not something that I believe most of us think about when we are jumping in in the morning and that it’s not distracting. It’s not invasive. On the other hand, like any good security measure, once you become so comfortable with it, it can be easy to approve someone else’s login.
Thomas: Definitely, which is why we have things like the number matching there, where it can present as a layer of friction for you in that moment to be like, oh, did I request that? I don’t think so. Oh, that’s not coming from Indianapolis. That’s coming from some other place. That doesn’t look right. There are. We’re not in Kansas anymore.
Dave: No, no, we’re not. But even then, like I said, it is still possible to get tricked if you’re trying to move quickly, if you’re tied on a deadline, you’re thinking, oh, well, I’m here. I just tried to log in. It’s fine. And then you push it on through. And there are absolutely some security measures that we were actively rolling out and working with our customers to validate for them, for their businesses, to manage that balance of security and usability. But yeah, it is an ever-changing landscape. And as we start to build better castles. The attackers build bigger ladders. They have a cave troll.
Thomas: So it’s an excellent opportunity to segue because something we talk a lot about, COVI’s going to work very, very hard to stay ahead of the game, stay ahead of the industry and create tools that are harder and harder to break. However, it is just as important that security is cultural.
Dave: 100%. Yep. And so if security is not cultural to your organization, then you can have the strongest tools in the world. But you said it earlier, the key point of most attacks is still a human being, especially in the modern age. So when we’re talking about something like two factor, which is a very clever, very intense and very secure system that has been well tested over decades, it can still be defeated by one muscle memory tap, right? Oh yeah, I approve this login.
Thomas: And or one social engineering component of, yeah, that just looks like Joe from accounting.
Dave: Yeah, one fake phone call from an attacker impersonating an internal IT help desk. Exactly. Like, hey, we’re just validating your identity. Can you give us the code? We just want to make sure you’re you, not knowing that you’re handing over access to your account to somebody that you don’t know who they are.
Thomas: That was, I think, the most alarming piece to me as I was jumping in and reintegrating with the current state of things is, my God, the skill of human intervention that is occurring alongside these attacks. We’ve come a long way from the hacker in the back of the coffee shop.
Dave: Kind of present. It’s, wow. Or the poorly written email from the Nigerian prince.
Thomas: Exactly. I still haven’t gotten my money.
Dave: Exactly. It’s in the mail, check’s in the mail. That’s what you keep telling me. I don’t know. So yes, it’s as cultural as it is not. And it has to start from the top. And it has, yes. It can’t only be IT trying to hold up a shield, say, all right, behind me. It needs to be the whole organization, needs to be rowing together in those situations. Because only by embedding the culture and operations are people going to be or are ever going to have a chance to be successful.
Thomas: Yeah, that’s seriously a chance. Yeah. So at COVI, we work really hard to fight for the technical, but we are very invested in the people side for that reason, because we know that that strategy has to have the cultural component. And one of those platforms that we’re a really big fan of and the name of that constant awareness is UsSecure.
Dave: Will you share with our listeners more about what that platform is, how we implement it, and what it does?
Thomas: Yeah, UsSecure is a great channel, MSP-friendly, but also very solid security awareness training platform that allows us to work with our points of contact and managers at organizations to let them, to set it up and let them run the show on what their teams, what they are concerned about with our consulting on security awareness. So they can get great reporting out of the platform tools so that they can see who on the team might need more modules or less. It also gives us the ability to leverage Microsoft’s APIs to directly place fake or real suspicious emails into mailboxes to do phishing simulations. And those simulation templates are ever-changing and ever-growing. So it’s really great. It lets us help our customers make sure that they are covered from a security awareness training perspective, especially when they commit to such things in contracts or cyber liability insurance, while not being so overwhelming that people just kind of drop it out of a lack of capacity. So it rides that line really well.
Dave: Yeah. And it’s something that we use here with our own team, even though we’re all IT nerds and we live free We all need it too. Awareness has to be a cultural thing regardless of the current skill of your team. It’s the constant reminder.
Thomas: That’s absolutely right. What are some other things that COVI does to make security cultural?
Dave: We work really closely with our customers that when we get, so occasionally you’ll get an email or a suspicious or not suspicious email that gets caught by the email filter. And we try to have really good conversations with our end users, end customers and points of contact on those requests to make sure that we’re doing our due diligence, but also making sure that we’re not halting production by catching clean emails in a mail filter that relies on us to release it. So we talk pretty in depth about that when we bring people onto our email platforms. And I think we try really, the technical teams try really hard and work very closely with our account managers to make sure they up to date on current threats that we’re seeing and what our mitigations as we roll them out are going to be. Is security is the probably the biggest thing that I do on a weekly basis.
Thomas: To our viewers, I can vouch for that. Absolutely. And it’s appropriate that it would be and something that I would say is a key chunk of all of our time in the company. It’s just one of the biggest parts of what we do. It’s not going away. We say a lot here. It’s not if, but when.
Dave: Yeah. There will be an attempt. And if not an attempt, a successful compromise. Exactly like we we design systems around the concept of zero trust and a zoom assuming breach like, OK, you know, I’m going to bet that at some point in the future, somebody will get in. And what are we going to do about it? How are we going to build our services and our platforms and our team so that we can respond to those situations in a way that takes care of our customers and minimizes their risk.
Thomas: That is another statistic that I looked up for the most recent numbers. And it’s growing, which is alarming. I mean, just thinking about it now, it is alarming how fast this is growing. Over the next, well, I believe the statistic was or the last six months, literally over 50% of small businesses have experienced a successful attack. Of those businesses, the average breach cost is now $4.9 million. Wow. Now, obviously, there are lot of factors that go into that, and small business is a broad definition. Absolutely. That’s not necessarily just 5, 10 seats. Right. That’s obviously a lot bigger than that. But what was more alarming than that is that because of the success of the attack, over half of them end up closing their doors. Over six months or over the next six months. Now again, we have to be careful with data. That could be correlation, not causation. But when you’re talking about that amount of loss, it’s not that difficult to make the connection.
Dave: Which is why modern IT and having a good IT provider is so freaking important because this is as important as having a good lock on your door, a good marketing plan, and the right salesperson in place. Without this, it’s now one of the key legs of your business stool.
Thomas: Yeah. And especially as governments and regulatory bodies are starting to realize in their somewhat slow way the risk to their industries or their assigned, the agency assigned industries, then they’re starting to mandate greater cybersecurity requirements and also reporting, public reporting of incidents. So I can definitely imagine a multimillion dollar situation out of a big enough account compromise where it’s like, well, we lost the data of this many people. And per our industry regulations, we have to report that publicly within probably less than 30 days. So you don’t really have a lot of time to plan. And if you’re planning reactively, then yeah, it’s not going to be good.
Dave: Yeah. And that’s and certainly the let’s put aside the financial risk for a second. And let’s even put aside the trust risk for a second, because the trust that’s lost with your vendors, with your customers, when something like this happens and you’re ill prepared. But let’s just talk about the opportunity cost, the time lost when a company is navigating a successful attack that they could have spent growing their business.
Thomas: Right. Yeah. My gosh. It’s nobody’s day job to do incident response other than instance response providers. That’s why we engage them. That’s right. Or insurance engages them when necessary. It takes away, it takes all the oxygen out of the room. And it’s like, all right, well, we can’t do anything else until we solve this. That’s right. This is clearly the biggest threat to modern day business. It’s crazy. It’s absolutely crazy.
Dave: As we wrap today’s show, what are some things that you really hope our viewers will walk away with?
Thomas: Yeah, I think some of the lowest friction highest gain things you can do as a small to medium sized organization is to start recognizing that cybersecurity is a huge component of your business’s risk and risk profile. And that’s not easy, but starting to work with your legal and compliance teams, if you have them work with your internal or external IT providers to start understanding where you are a state and where you’re at, what your risk is, even just starting down that journey is going to mean that you are more prepared tomorrow than you are today.
As far as good tactical things to do, my favorite is always implementing a credential manager, some sort of password management in your organization. I could not live without it these days. Seriously. More common, a little old school at this point, but one of the more common attack vectors for businesses is credential stuffing, where somebody will use a password or reuse a password between a corporate important service and a personal unimportant or an unimportant corporate service that is like, well, you know, really, this isn’t that important. So I’ll just sign up. use my normal password that I usually use. And if that data gets exfiltrated in any sort of attack down the line, they can turn around and try those credentials on more important things like Microsoft or Google or bank accounts, QuickBooks. And if people are reusing credentials and not using something like a password manager, then it’s really easy for somebody to stumble onto an unlocked door, more or less.
Yeah, think credential management. Trying to walk down that risk journey. And I think my small favorite that is of no charge, which is my favorite sort of security improvement, is making sure that you’re working with and talking to your internal or external IT provider and make sure that your company domains are protected from spoofing. The details of this can get pretty intense, but making sure that you have a demark policy in place for your domains and that you have prevented other people from commandeering you as a means of attack. That is, is free. It is pretty easy to do. It’s a little involved. So have to make sure that all your email sending services are properly authenticated. You know, it’s most, if not all modern mail platforms and mail sending services will allow this to work because otherwise those businesses wouldn’t exist. That is my final tip.
Dave: We appreciate the freebie there. And freebie that doesn’t cost much to implement. And obviously, listeners, if your IT department does not currently know what some of those words were, it might be time to explore other IT departments.
Thomas: Yeah, free job. That’s right.
Dave: So all right. In all seriousness, as we wrap up today, a couple of points in closing, one, security, it’s not the job of the IT department alone. It should be cultural. Two, there are a lot of easy things that you can do to prevent significant attacks, but they have to be strategic and they have to be planned. And then three, the risk to your business, the biggest risk to your business today is very likely information security. And it covers even more than what we discussed today. It talks about things like, your data secure when employees are hired and exit your company? Are your devices secure? Beyond even bad actors, crimes of convenience. The question is, do you have a plan in place and do you have someone you can talk to about that plan to make sure it’s as strong as it can be? We have guys that work full time staying ahead of it. Do you? And that’s a wrap for The COVI Way. See you next time.