Glitch: Welcome to NPC Grade Security and Architecture, episode twelve. I'm on fire incident response. I'm your host, Galitch. Cypher: And I'm Cypher and today we get to talk about the fun of IR, Glitch: IRA? What are we, the Irish Republican Army of Canada? Yeah, you did. Cypher: The love of dogs. I I walked right into that one. I'll give it to you. All right. Okay. All right. And take two. So we're talking about IR. huh. Glitch: How beautifully articulate of you. I wasn't sure if you were a Canadian there for a second, But now I think you're just half donkey. Cypher: Danke. Glitch: I figured it would be a good topic because you know, it's right there at the intersection of security, architecture, leadership process, and why is everyone suddenly on the Teams call at two thirteen AM? Cypher: On a Friday or Saturday night, of course. can't did you ever notice it can't ever actually be during normal business hours. It always has to be when it's off shift. And I think that's one of the things though that makes my job so interesting. I mean think about it. How many accountants have to worry about their ledger trying to suddenly destroy the G and A budget at two thirteen in the morning, you know? Glitch: w which is the interesting part? Losing sleep on any day that ends in Y? Okay. Okay. For every day that ends in Y. Cypher: Only at two thirteen in the morning. No, I mean but seriously, how many other professions, you know, have to deal with their their stuff like being undermined? Glitch: truth, truth. I I'd say more professionals don't have criminals and ne'er duels actively trying to undermine them all the time though, right? Maybe that's why I like you cyber folks so much. Well there's lots of reasons. But one of the reasons, you're just a different breed. But anyhow, Cypher, there's thing I there's one thing I absolutely want to know. Cypher: Just the one thing. Glitch: Well, the one thing for starters. you know I can't just stop at one thing. Cypher: Okay. Fireway. Glitch: All right. I talk to SOC analysts and engineers all the time. I look at our EDR dashboards and our CIM and I see the word incident all the time. If I were to take that literally, we've got like IRs running all day every day. Cypher: Well, I mean well so sort of, but not exactly. okay. Glitch: Okay, explain. Cypher: Words matter, right? So yes, while cyber teams are dealing with routine things all day long that are technically considered security incidents, they they don't all kind of qualify as things that would activate an IRP or an an incident response plan. Glitch: okay. Well so Cypher, I got a hypothetical question for ya. Cypher: I mean those are never hypothetical from you, so maybe just ask a polite one. Glitch: Okay. All right. So this is me politely asking a non hypothetical question. Tell us what activate an incident respond plant actually entails. Is is that a big red button? Is there a bat phone involved? Cypher: my God, that would be so freaking cool. But no. No. That would be so cool. Like the Glitch: Can I be Commissioner Gordon? I'm the you know. Cypher: bat signals in the air. It's time to like activate the IRP. But no, no. So, you know, organizations tailor the language and a good IR plan shouldn't rely on like one magic trigger, even if it is super cool, like a bat phone or a bat signal. honestly you should have a severity matrix with things like scope, business impact, critical systems. data sensitivity, threat activity, legal or regulatory exposure, and and then obviously if the event itself is still spreading, like active malware on multiple endpoints that's not being contained, evidence of data exfiltration, unauthorized privilege access, or any kind of an incident that crosses multiple business units, those can all push you up in that matrix that you've got established. So essentially it's for When we say an incident and you activate the IRP, that's for things that aren't those kind of run of the mill with well worn playbooks types of things. Glitch: Okay, so since you said words matter, is that the same thing as declaring an incident? Cypher: that is glitch. That's a good question. Huh. All right. There it is. There it went. Okay. Glitch: That that's that's my one for today. Yeah. Cypher: So the short answer is no. They are not the same. Declaring an incident means that you're officially recognizing something has happened and we need to track and manage it. Like that's the big part. We need to track and manage it. So that doesn't mean that we have to be all hands on deck because the severity of the incident on that matrix is really what drives that. So when you activate the IRP, that means that you're launching the organization's kind of the formal response process. You're assigning roles, you're escalating leadership, you are preserving evidence, you're coordinating the communications, and you're following hopefully a lot of predefined procedures. An incident can actually be declared without activating the full IR plan. I got it for example. So for example If you have like a minor malware infection that might be handled through routine security operations and and it's not spreading like Ebola, the IR plan is is usually only activated in cases not like that. Like it's when the incident is severe or it's widespread or legally sensitive and requires coordination across several teams. Glitch: Alright, so so what you're telling me in short is that declaring identifies and classifies the incident while activating the IR plan mobilizes the formal response, right? Okay. Cypher: Yeah. Yeah. Yeah. Yeah. That's when you fall back on your IRP and follow the engagement matrix. So you know who to notify, when to notify them, and what authority they actually have once they arrive. Severity severity drives the engagement and the authority. not curiosity, not seniority, and not whoever happens to have insomnia at two thirteen in the morning. Glitch: Okay. I think I I'm picking up what you're laying down. So you're you're saying that the team can handle Ebola as a declared incident, but measles means we activate the IRP. Cypher: Measles? Really? Glitch: Look, come on, measles is so contagious that one infected person can spread it to most unprotected people around them and it can hang in the air for up to two hours after they leave. That is basically lateral movement with excellent persistence. Cypher: I hate how well that analogy actually works. All right, okay, fine, fine. Okay, so Glitch: I'm surprised how well that worked. Cypher: w now we're picking up what you're laying down, so I will go with that and say yes. Glitch: And if the IRP is activated, that's when it's like, Welcome to the Thunderdome. Cypher: You know, I'd I'd actually like to prefer to think that it's more like the Shatter Dome from Pacific Rim since we're all the good guys and we're holed up working to save the world. But but I'll just go with a passive yes on this one and pretend that we have super cool Jaegers. Glitch: Very nice, very nice. I like the Shatter Dome reference, by the way. Cypher: Mm-hmm. I love Pacific Rim. Glitch: It is is quite quite the movie. If any of our listeners haven't seen it, you have to see it. A Cypher: For sure. Glitch: hundred percent. Okay, so Cypher, what happens when we activate the IRP? Cypher: Oi, aha. That Glitch: Huh. Cypher: that is a loaded question. Glitch: Yeah, that's I I'm full of those too. Cypher: Okay. So I'd say the IRP is really more about solid orchestration. You know, a good plan tells us who's in command, who leads the technical investigation, who owns the business decisions, who handles legal and communications, how we classify severity, where we communicate, how we document decisions, and then how the authority changes if one of your people is not available, you know, like Usually do that by by roles, by the way, 'cause names change, but roles, those are are pretty static. Glitch: Okay, so from that I've got two very important questions. Is half the orchestra on fire? And do we need to call John Williams? Cypher: I would say it definitely feels like it sometimes. Glitch: Okay. Cypher: yeah. Somebody though I mean, even if the orchestra is on fire, somebody still has to conduct, you know, so that's why you need a clearly named incident commander who really is that conductor for your orchestra. Otherwise you've got ten people giving technically reasonable but mm mutually incompatible directions while the cello section is wiping the server. Glitch: right. But seriously, what what is what are the hardest parts about going through an incident? Cypher: Wow, that's God, you're like full of tough questions today. Glitch: I I told you I was plenty full of it today. Cypher: Wow. Okay, look at you being the underachiever and just kind Glitch: Yeah. Cypher: of limiting that to this one time that we're talking. But anyway, Glitch: Yeah. Cypher: seriously though. I'll tell you what, let's break that into two sections, shall we? Glitch: The breakaway, my dear. Cypher: Okay, okay. So for starters, let's talk about the visibility issues we have when we're trying to investigate during the initial phases, but that'll probably come up later too. Glitch: Yeah, because no one ever logs everything or retains things for long enough, right? Okay. Cypher: Correct. You know, way too often we are caught with our proverbial pants down because either logging for a specific system wasn't on or inevitably the logs that you needed rolled off yesterday. Glitch: yes, this brings back memories. even as recent as an hour ago. The most reliable log entry is evidence not found. Cypher: Your lips to God's earbud. Like and that makes that makes the early urge to just like it's an incident. Just shut it down. That makes that urge very dangerous. But if we wipe a system, disable account, or start blocking infrastructure before we really understand what we're looking at, we're really gonna take a chance because we can destroy evidence, we could tip off the attacker, or we could interrupt a critical service without actually containing the threat. Glitch: So what you're saying is and this kind of hurts my heart, so no panic yanking the power cord like it's a haunted toaster. Cypher: Correct. On a toaster. All right. No. containment should definitely be deliberate. Like you have to preserve that volatile evidence when it matters. We have to, we have to record what we do. And we have to pick the least disruptive action that meaningfully reduces that threat to us. Sometimes, yeah, immediate isolation is absolutely right. But you know, it needs to be a decision, a cognizant decision and not a reflex, especially like you know, an involuntary gag reflex with haunted toasters. but that's where the other problematic part is with our visibility. We get so consumed with doing it right now that we forget to document decisions or, you know, what we did, when we did it, why we did it, you know, all that stuff. And that everybody always gets like pissy 'cause they're always like, gosh, documentation is just stupid. There's no reason for it. That is the only thing that we have later. That helps to justify our actions. And those actions post incident are almost always scrutinized. So it's it's not just stupid documentation stuff, you know. It's ugh, it it's irritating to me. But anyway, but then there's the far more kind of problematic part of the incident response. And that ironically has nothing to do with the systems. Glitch: okay. I think I know this one. we we say it all the time, technology's easy, but people are the hard part. Cypher: I'm just really surprised you don't have one of those sound effects yet that scream like, Yes, that that that that that. Glitch: Well I got this one. Cypher: The hell What what do it again Glitch: No, no Cypher: What is that? Glitch: You don't know you don't recognize that. Okay? Cypher: Do it again. Glitch: It's the minions. Cypher: Is it just like the first start of the doo doo doo doo, like dean or nean or Glitch: No. Yeah. Cypher: Okay. All right. So let's just move on and Glitch: Yeah. Cypher: not give that any kind of additional validation through acknowledgement. Yeah. Totally. But okay, but to answer the actual question, Glitch: sad face. Okay. Buzzkill. Cypher: yes, it is the people. Well, it's actually more like the people sprawl that seems to happen during an incident, which for the record may need to actually be limited and very carefully structured as part of like that engagement. Because of a thing we call legal privilege. Glitch: Privilege. That sounds entitled. And maybe maybe we'll talk about that later, but yes, let's set the scene. All right. It's two thirteen AM on a Saturday. Ha Cypher: Huh? Glitch: hazy, foggy morning. And your Microsoft Teams app makes the drive me alcoholism sound. And I wish I could put a sound here, but I don't have a good sound for this. I know. Cypher: I I almost feel like it's in my head all the time. Yeah, the teams Glitch: That's why that's why I didn't play it. I figured that's gonna trigger both of us. We would all we would both keel over or start throwing things. So I figured y yeah. Cypher: Like legit. Yeah. But yes, the the dreaded team's call sound. I got it. All right. Glitch: Yes, yeah. And your sock is like, Hey, you busy? You wake? Yeah, you know, hey Cypher: Okay, okay. Carry on. You've set your stage. Glitch: All right. I know you're likely wanting to ignore it, like many of us, as would I, but you're a glutton for punishment, as I am too. And so you answer, just sleeping. What's up? You know, nothing big. Then they're like, we We may have something suspicious like, I don't know, PowerShell activity on three servers and we validated it's not us. Cypher: that yeah, that'll wake me up for sure. I think at that point I would probably declare an incident, preserve what evidence we can, start a timeline, bring in the right SMEs based on severity and what systems were involved. But for the record though, I would not actually be the first one they would call if they followed our IRP because I'm actually more like a midway through person. Glitch: Okay, so they actually would have been walking or waking someone else up duly noted. I'm being hypothetical again, so let's just roll with it, because you Cypher: No. Okay. Glitch: know how I am. So let's add to the that timeline that four minutes later it's affecting three more servers. well let's do let's do four. I why not? We'll make it seven. And their business critical systems running on those. Cypher: Okay, so yeah, at that point, going with your hypothetical, yes, I am likely gonna follow my IRP and we are going to actually activate that. So you notice that we declared an incident when we validated a thing happening, but now we're actually activating the IRP because the expanding scope of that you just mentioned, that's gonna change my criticality. Cause number one, it's obviously not limited and contained, and number two, it's about to hit the business critical systems that you mentioned. So that right there is when we methodically start to escalate. We name an incident commander, we open up an approved incident channel for communications, we assign a a person, a scribe, whatever you decide to call them, to make sure that we've got our documentation, P's and Q's done, and then we're gonna just launch the right work streams. But just for the record, that's also where things can go sideways on the people front if we're not careful. Glitch: Amen. I've been an incident commander on so many different types of operations, whether technology related or otherwise, and that is one of the biggest mistakes that I see an organization make is assuming more people on the IR equals a better response. Cypher: God, yes, yes. And you know, we still get people who want to inject themselves into the process, you know. I would love to say they're always trying to help, but it's more like sometimes they're trying to help. Sometimes they're just being anxious because there's a thing going on. and sometimes the title that they carry has convinced them that every single call is improved merely by their presence. but the engagement matrix exists for a reason and it should identify the core response team, the conditional participants, and what conditions are needed for those folks to actually be present. the executive decision makers and their alternates and then people who receive scheduled updates without even joining the working call. Glitch: Wait, whoa, whoa, whoa, whoa, whoa. Are you telling me there's an option where I get an update without joining and asking seventeen questions? Cypher: Revolutionary, isn't it? Yeah. Yeah. Glitch: My God. I I yeah. Cypher: Yeah. A a good incident commander actually protects the responder's focus, you know, because those those hands on the keyboard, those are the most critical staff at this moment. So it is one hundred percent a need to protect their focus and let them do their damn jobs. So yes, we have we have one working call, clear rolls, we have a regular briefing cadence, and we have a separate path. for those executive questions so we can prevent the investigating team from getting like pegged all the time with those six hour, you know, retelling of its own origin story kind of of events going on in our call. Glitch: Cipher, I think so you're you're telling me, I mean, you you're telling me not to join the call after it's been running for six hours and immediately ask for a breakdown from the top. Cypher: Exactly. Glitch: I am appalled. Cypher: But you know what? But I'd be equally upset if you join two minutes into the call and you're immediately demanding to know who got in, what did they access, and how did they get in? You know, like it's it's early in the incident. So a lot of people don't like it, but we don't know yet is usually at that point the most accurate answer. And the worst thing when people are just they start speculating and jumping to things, premature theories. It's amazing how those hardened effects and then the whole investigation can get bent around proving that first guess right rather than following what we need to follow. Glitch: So this is really as simple as not to jump to conclusions and don't be naming the threat actor or estimate the bre breach population and draft the movie adaptation before breakfast, in essence. Cypher: Correct. Yeah. I I would say that is strongly discouraged. We need to separate out the confirmed facts, the with working hypotheses and the unknowns. You know, scump the the scope of the thing is something that you're continually testing. It is not something that you declare complete just because the first dashboard that you saw looked a little comforting. Glitch: Okay, well let's jump back a few minutes 'cause you mentioned something about legal privilege earlier. Is that just Cypher: Mm-hmm. Glitch: corporate speak for no one gets to see our homework? Or what what what is that? Or th or I hate if the dog ate it too, but Cypher: No, no. No, no. And it's not like the the equivalent of the magic invisibility cloak either. But so legal counsel, and this this is one like low and slow. Legal Glitch: All right. Cypher: counsel needs to be engaged according to the incident response plan, especially when sensitive data, regulatory duties, litigation risk, or law enforcement may be involved. Your legal counsel Determines whether and how an investigation is directed for legal advice and what communications may be privileged. The team still has to operate carefully, right? But we have to keep factual business records factual. And we have to use our approved channels. We have to limit the distribution of the knowledge and the things. And we we cannot casually label everything as privileged and then just assume that the problem disappears. Like it is not just a label that we slap on there. It's so much more. Glitch: All right, so legal privilege is a is a legal structure. It's you're telling me it's not a subject line decoration. There's actually a purpose to it. Cypher: Exactly. And I cannot tell you how many fights I've had over that distinction. Like, it's a lot. It's a lot, a lot. And for the record, like the details vary by jurisdiction. So that playbook or the run books, those need to be designed with actual counsel before the incident, not invented by our exhausted engineer at three o'clock in the morning. Glitch: Well, speaking of communication channels, are we all just talking about this in the normal group chat title? Definitely not a breach. 'Cause Cypher: It's no. Glitch: breach did not happen here. No. Okay. Cypher: Right. No breach here. Okay. No, please do not. if if identity email or collaboration systems might be compromised, the plan, the IR plan, it actually needs to have an approved out of band communication option. And I've seen some really creative things there, but you know, definitely something that's out of band. And it should also state who can communicate with employees, with customers, regulators, insurance, law enforcement, and and even the general public. Otherwise, otherwise sensitive data leaks into a compromise system. Or you have five leaders publishing five different versions of their reality based on how well they broke down the geek speak that we may accidentally use if they heard us talking about it. Glitch: And I've I've witnessed this myself and I can completely see where that would get frustrating. 'Cause here's all right, so here's another question for you. When you're doing all of that, how do you weigh the business needing to function against things you may have to do to contain the incident? Cypher: And doesn't every single security leader in the entire world wish that they had that answer? Glitch: What there's that you can't flip to page fifty two in your little magic pocketbook and no, no, okay. Cypher: No. No. No. no. Honestly, containment versus continuity is I hate to feel like I'm using buzzwords here, but it is a risk trade-off. You have to actually figure out how much damage can spread if we stay online versus how much business impact are we gonna create by shutting it all down. and for the record, this is you've heard me so many times. This is why I preach. that we need bid like really, really good business continuity plans because the best DR in the entire world is probably not gonna help if we have a widespread issue, right? So we may have to actually go to the business and recommend it that they activate their business continuity plan. anyway, back to your your actual question. We our tenant, right, we protect safety of people and critical assets first. And then we make an effort to choose the least disruptive action that is still gonna stop the threat. And then we hope to God that it feels like a rational and defensible decision when everybody on the planet is looking at it with that wonderful twenty twenty rear view vision. Glitch: Okay. So from all of that, who makes that call? Security? Or who d who makes that call? Cypher: I mean security makes the recommendations about the threat, but security should not silently accept the business risk on behalf of the entire organization. You know? The IRP should actually say who has the authority to isolate a system, to shut down a service, to activate continuity plans, notify external parties, or accept the risk of remaining online if that's the decision that's made. But the important part again, go on back to it's just stupid documentation, right? Like Your scribe, they have to record what we knew at the time that we knew it, the options that we considered and like the approved action and the why. Glitch: the decision log you sorta mentioned earlier, also known as the CYA receipts for future us. Cypher: Precisely, definitely CYA receipts for future us. It you know, a good log should capture timestamps, facts, hypotheses, evidence, actions, owners, approvers, and then the next step. Because let's be honest with with ourselves. And and I say this to you because I know that you have a phenomenal amount of recall and memory. But six weeks after that incident, that high pressure, fast paced, doing a lot all at the same time. Six weeks after the incident, human memory, it's more like fan fiction. Glitch: And just to add to that, just from some of the other things that I've dealt with, whether it's from a an a technology type incident or something unrelated, the higher the stress level, and it's also dependent on the person and their personality of how they can deal with the stress, even after a few minutes, you start losing very important details. So one hundred percent getting that information accurate from a scribe, recording it at that time is cr crucial for all of that. Cypher: Yeah. I mean, as much as people like to and I I hate it that they do this, but as much as people make efforts to devalue the that position and what it's there for, it is the second most important I would say it's it's up there with the second or third most important position. You know, you've got your incident response commander. That's important because it's the conductor for your orchestra. And then you've got your entire you know, your woodwinds and your your strings and your your you know brass section that's the engineers doing the work and all of that shit will fall apart if you don't have the percussion doing the right beats in the background. And Glitch: Amen. Cypher: they are definitely extraordinarily important to your incident. Glitch: Amen. All right. So earlier you mentioned multiple work streams. Is that just a fancy term for everybody panicking in smaller groups? Or wha what are we what are we talking about here? Cypher: mean ideally ideally no, right? Like Glitch: Okay. Cypher: so a strong response runs several coordinated tracks in parallel. so you've got your your your track one, right? That's the the investigation to figure out what happened and determine the scope of what's going on. You've got your track two and these are the folks that are responsible for containing and eradicating the threat. You've got your track three, which is keeping those business critical operations function, functional. And then you've got your track four, which is managing like the legal privacy, insurance, regulatory, and communications obligations. So three of those are kind of technical. They have to talk with each other. They're not, you know, again, they're working in parallel together with with feeding off of each other's information. Track four is more of a summary kind of level, but we have to understand that that's also a big time money. generator right there. If you don't do those things, that's where you can really get a lot of punitive things going on as well. But they all share kind of a same or common operating picture, but they don't all actually have to occupy the same call at every minute. Glitch: Right. I'm gonna ask a question. I already have a feeling I know the answer to this, but this is or we're educating our audience. So on the technical side, is cleaning the infected servers the finish line? Cypher: Not even close. Glitch: Yeah. Cypher: yeah. Teams get overly endpoint focused, you know, like if the attacker compromised identity or the control plane, you can clean every laptop why they, you know, they the bad guy retain access through like a cloud account or tokens or service principles, federation, management tools. Like there's so many freaking things all the way down to your like your backup environment. You might back them up right to where they needed you to, you know, where they still had access. So you you have to investigate the systems that grant and govern the access, not just the machines where the malware or whatever was making the noise. Glitch: All right, so what you're saying is the burglar may be gone from the house, but still has the master key and it controls the alarm comp. Cypher: Exactly. Right? Like and that's why recovery is not the same as eradication. You know, restoring a server quickly, again, that can just restore the attacker's persistence right along with it. And you see this happen all the time when you track the news. You know, they thought that they had the system clean, they put in the backups and bada boom, bada bang. Guess who was already there with their back door? You know? So recovery criteria should really require evidence that the threat was actually removed, credentials and trust relationships have been addressed, the restored systems are clean, monitoring is heightened, and then the business owner needs to be the one who accepts the residual risk of all of that. Glitch: Alright, so that sounds like a whole lot. Cypher: Mm-hmm. Glitch: I feel this is a I I feel this nagging urge to ask how we really prep for these type of events though. Cypher: Ooh, you know what? It's almost like that was a bullet point that we wrote down because we needed to be sure that we hit it, doesn't it? Glitch: Yeah, well I'm I'm I'm I'm a nager, so nag. Nag nag nag. Nag nag. Very much like that. So what's the secret sauce cipher? Who say that three times fast? Sauce cipher. Cypher: What's the secret sauce cipher? Okay, so the fun answer that no one wants to hear to answer your question is incident response tabletop exercises. Glitch: I like this 'cause that's kinda like corporate D and D for cyber, right? Cypher: I mean it's it's probably not that fun, but essentially yes. You know, because it's literally presenting your fictional cyber crisis and then the team plays through it, you know, like the network is down, customer data may be stolen. What are you gonna do? admittedly though, there are no dice, no dragons, but we do get like surprise twists with things that we call injects. you know, there's difficult decisions, lots of debate over who has the authority to act half the time, but Honestly, it's the the goal is to practice together and find the gaps in the response plan before the attacker does. Glitch: And I'm guessing together means more than the cyber team congratulating itself in a conference room. Cypher: Very much so. you need to bring in your executives, your IT, your cloud and identity teams, your business owners, definitely legal and privacy, communications, continuity. Honestly, even any vendors that you actually would expect to call during that, like you know, like your your forensics retaining team and firm. But Really, you have to test your contact list. You have to test the alternates. You have to test the decision authority, the engagement matrix, any out of band communications. they need to understand evidence handling, the insurance requirements, which are a thing. And then what happens when the person that was named in that plan is like on a plane going somewhere and not accessible or maybe they don't work there anymore? Like all of that is part of the testing. Glitch: But but Cypher, we wrote such a beautiful plan last year. It had colours and everything. Cypher: Yeah, but a plan that hasn't been exercised is like a theory with page numbers. Yeah. Yeah. And Glitch: I like that. Cypher: after an exercise or sadly a real incident, the lessons learned need owners and they need funding and due dates and then you need to retest because otherwise all you've done is you've produced like a tasteful PDF describing the same failure that you're gonna enjoy again the next quarter. Glitch: Yeah, okay. Well that feels like a logical place to stop. I wanna circle back to something you said earlier about words mattering. I seem to be circling back a lot in this episode. Cypher: It's okay. Glitch: because th there's a late night call both of us got got that I know freaked you out from the start. I was a little freaked out too, and I and I think it's a good example of why those IRPs provide good guidance. Cypher: which call was that? Glitch: We lost control of our domain. Cypher: my god, yes. Glitch: Yeah. Cypher: Yeah, yeah. Okay, so let me set let me set the scene for everybody listening. Glitch: Yeah, please do. Cypher: All right. So I answer the phone hours after my bedtime. And it's someone with a a pretty big title. And those are the words that came through the phone. We've lost control of our domain. So I'm immediately then I am up and I am out of bed and I am stumbling towards the computer. And I'm asking all of these probing questions because keeping in mind, regardless of what the IRP may say, I'm the first call that was being made. So it's not a call to my SOC or even to my engineers. It was direct to me. Glitch: yes, and I remember this so well because your tone changed from I'm on to something well let's just say less pressing. And anyhow, when he explained what he was seeing, what was your response? Cypher: hey, did did you did you pay the bill? Glitch: Yeah. Yeah. Fun times when people do stuff like that, right? I I literally knew all the cuss words going through your head. I could hear them and I'm sure I was having just as many. It's so fun. Fun, fun, fun. Cypher: Dude, like we seriously need to talk about your interpretation of fun. But but it does prove the point, right? Like words matter. Validation matters. And the engagement path that you take matters. you know, the domain expired and a threat actor controls active directory are both domain problems, but only one of those should actually summon the cyber cavalry. Glitch: honestly, Cypher, I just thought it would be fun to get you all annoyed before we signed off. Cypher: How deeply magnanimous of you, sir. Glitch: well thank you. I I I thought so too. that's how I roll. And speaking of rolling, I think that get us right to a rolling stop. so I'm your host, Glitch. Cypher: And I am Cypher, the now annoyed and vexed. Glitch: And we will see you next time.