Built By and For

EP09 - Cybersecurity as a moat, not a cost

Founders Financial Season 1 Episode 9

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 41:16

Bridges don't break at their strong points. They break at the weak ones. In our industry, the weak point is usually the advisor — and the actual target is usually the client. 

In this episode, Steven Watts sits down with Justin Neria, Chief Technology Officer at Founders Financial, and Jane Maccubbin, Senior Compliance Officer, to unpack why cybersecurity has become the defining infrastructure question for independent advisors. They explore why post-COVID networks demand a zero-trust architecture, why most advisors radically underestimate the threat (6,000+ attempted attacks per user, per day), and how Reg SP is raising the regulatory bar. The closing thesis: when cyber is built into the platform, it stops being a cost center and becomes a quiet growth enabler.

More from Founders Financial: 

TRU Enterprise OS: (cybersecurity is built into the platform): https://foundersfinancial.com/tru-enterprise-os/

LinkedIn: https://linkedin.com/company/founders-financial

© 2014-2026 Founders Financial. Member FINRA/SIPC and Registered Investment Adviser. All Rights Reserved.

SPEAKER_00

From Founders Financial, this is the Built By and For Podcast. Partner-to-partner conversations for independent financial advisors. Today, host Stephen Watts, Chief Growth Officer at Founders Financial, sits down with Justin Naria, Chief Technology Officer, and Jane McCubbin, Senior Compliance Officer at Founders Financial to discuss zero trust architecture and turning cyber into a competitive advantage. Bridges don't break at their strong points, they break at the weak ones. In our industry, the weak point is usually the advisor. Here's the conversation.

SPEAKER_04

So, Justin, I'm curious from your perspective, why is cybersecurity no longer just an IT issue for advisors?

SPEAKER_02

Well, it's always been that like the first line of defense is those who are on the front line, right? Which is in this case the advisors. They're the ones who are targeted and trying to be manipulated by malicious attackers all the time. We see it every day. Thousands and thousands of attacks. And more recently, we've had spoofing attempts where people are getting emails. And the the point is that you are, it means the advisors, the first line of defense. So if you see something suspicious or something odd, the IT team there is to support you, but it's also needs to be um well known and they need to be educated on how it is to spot and identify these malicious attacks, is what we do as part of uh our cybersecurity platform, right? So yeah.

SPEAKER_04

So I remember when I um first joined the industry uh with another firm. This was twenty-six years ago. Um and and that firm had just gotten a website. And so there really wasn't a huge infrastructure with with things in place, and we just kind of approach things as no matter what I do is gonna be okay, because there's an IT team over in the corner that's that's keeping us safe. And I don't even think we thought about it that to that lens. We thought I I would I wouldn't be able to do it if it wasn't safe to do. And I think the world has definitely changed that.

SPEAKER_01

And what's your Yeah, I I I would say I I think Justin Hits is is right. I I'm gonna say it through a different lens. Um the the the bad actors of our world are gonna try to find the the point of weakness, the weakest point. Um, you know, bridges don't break because of the strong points, they break because of the weak points. Uh and so in the independent uh uh uh broker dealer RIA space, um unless a firm has a comprehensive they're in control, they do it all program, platform, uh which you know most don't. It's it's ad hoc in our industry. Right. Uh the bad actors realize that the advisor is the path of least resistance. They're the least educated, to your point, they're the least trained. Um they to some degree probably, and maybe this isn't fair, you know, kind of take it for granted a little bit that what they've been told by their partner firms enough. Uh and I frankly, I just don't think they take it seriously enough. And so um, you know, regulators are are making hard pushes towards these points, and I think that's the right thing to do candidly.

SPEAKER_03

Yeah.

SPEAKER_01

Um, you know, the I mean, this will sound odd coming for me, but uh this is something like probably the wire houses are doing better than the independence when you have control of everything, and this is a focal point uh because it's just that important. Um yeah, I mean we we read about uh attacks, malicious attacks, you know, data breaks every single day. And what do you want to spend your time doing? Cleaning up this mess that was that was mostly and probably preventable because um you haven't taken it seriously, or or you want to go the other way. Yeah.

SPEAKER_04

So well, and the truth is there are tools out there that anyone can go and record your voice, take your your picture, and FaceTime, you know, FaceTime their advisor or call their advisor and and present themselves as a client. And that's not something I think an IT team could detect. I mean, uh I'm I'm assuming I'm I'm assuming that you can't.

SPEAKER_01

We can't, you you're not gonna be very Jane, you'd be very surprised what what Justin, our guy here, can do.

SPEAKER_04

It's pretty yeah, he pulls a lot a lot of rabbits out of his hat. But but I feel like, you know, are you look you know, can you listen to a phone call and detect that, oh, this this voice has some type of uh overlay on it? I don't even know that we're that we're there. And so to that end, I feel like the only person who can do that is the advisor to weed that out because they know that relationship, they know who that person is, they can ask questions to affirm identity.

SPEAKER_02

Um, you hit the you hit you hit the the nail right on the head, right? It's the relationship. Thank you. So a lot of the time when we're getting calls, um, the IT team, we can pretty much identify because we have that relationship, that rapport with all of our members. We know who they are, we know how they act, we know the questions they would ask. Um and when they ask odd questions or they send us emails of certain requests, we know it's not them. That's just because we know they would never ask for this. Right. Or they would they wouldn't even know how to ask for this kind of questions. So uh we we try to do our best to make sure we educate, but that's the first line of offense again, is all of our we call them in IT the end users, yeah, but it's our relationships and um how we focus on helping them grow and understand that way they can identify it, bring it to us. They have a lot of confidence in our IT team now, so they they do rely on us quite often for that kind of stuff. But it's it's better that they send it to us, we review it, and then we educate them on the process. Yeah.

SPEAKER_01

I'm I'm curious, you know, for both of you, one from a regulatory lens and one from just a year entry experience. Do you think advisors take this seriously enough?

unknown

No.

SPEAKER_02

Not really. There are some that do, and most of the time it's because they were affected at one point in time by some sort of uh experience that happened. You learn the hard way kind of thing, right? They did. So we have quite a few who have learned the hard way, but we're always there to support them.

SPEAKER_04

So yeah, I think if you it's it's kind of like um, you know, having your identity stolen. If you if it's never happened to you, you think, oh, the the odds that my I'm I'm I'm safe online. I don't put my you know my credit card out wherever. And then once it happens to you and you and you're you can't figure out how it happened, then all of a sudden your you know your guard goes up a little bit more.

SPEAKER_01

And it's jarring. Yeah. It's jarring. So imagine you're an advisor, you serve however many households, and you come to learn that somehow, some way, the you you gotta look in the mirror and be honest with you, as the weakest link, have not paid attention to something well enough. Yep. And and while it's not your fault per se, it kind of is. That's jarring. Yeah. And the and the reputational risk, the issues you then go deal with, uh, the time, the money, uh, it's it's it's significant and serious. Um and you know, I I don't personally believe, like all the advisors we talk to that are considering learning about founders, when we get to this point in the conversation, explain um what we've done under Justin's leadership to build an incredible infrastructure to protect there they're they have in many cases we're talking about because even the firms are with aren't talking to them about these things. It's not a conscious conversation, it's it's patchwork. It's yeah, we have done enough in theory to maybe check uh a regulator's box that we can show we've done something. Um because you know, Cannon, maybe I'm wrong. The regulars don't have a A, B, C, D, E. They have, as anything, based on your firm, its size, its mix of business, it's this, it's that, yeah, what's the best approach? There's some standard to it. And and so again, it's it's complicated in the independent space when you're when you're trying to solve this problem collectively across uh our industry. Yeah. You know, a a lot's changed since COVID, right? Um, and so in the context of us being forced out of our offices, which were our you know, from a cyber perspective, uh and as a cybersecurity professional, uh the a preference, because we got we got one thing to protect, and now we go to to many, you know, what what have you seen? How how have things changed and what are what are the things advisors in this new world post-COVID um are should be thinking about, aren't thinking about? Um Yeah.

SPEAKER_02

So the old mantra was to build the castle, build the gate, build the moat, right? Um, and then keep everything inside of it. Right. When COVID happened, you had multiple castles everywhere. So then the entire idea of having to secure all that completely flipped. Right. So and it had to be done in an urgency because of the fact that everyone was everywhere. Right. Now the best part was is that for the most part, technologists already worked in that sort of multiple site accesses and restricting access and so forth because all of the internet is set up at different locations all over the world, across the globe, so all that segmentation. And from being a network engineer in the past, that's what we're comfortable with. So the difficulty came into place when you have like multiple branch offices like we do. You have to control them, but also keep allowing them to you know do their day-to-day operations and to run their business.

SPEAKER_01

Um is control the right word or is protect the right word?

SPEAKER_02

Aaron Powell So it is protect, but we do put controls in place.

SPEAKER_01

But think about controls, and it's an important point here in the independent space, right? So it's one thing to control them, it's another thing to put controls in place so that they're protected and they can feel you know great about the work they're doing, that they don't have to worry about it.

SPEAKER_02

Aaron Powell No, that's true. And one of the uh best and positive feedbacks we've ever gotten is typically when it comes to security, it makes it inconvenient. Right. But when we implemented our zero trust system, it made it more secure and more convenient.

SPEAKER_03

Yeah.

SPEAKER_02

Because we have a system in place that authorizes everyone by you know doing checks and balances during their entire access process. Right. Yeah. So typically before you let them in the door and they do whatever they want. Now, as they go through different data structures, they access different files, they access different things, it checks along the way and lets our IT team know if there's any inconspicuous items happening.

SPEAKER_04

And I have to compliment you on that rollout because I was talking to a friend the other day who works in a different industry, but um, she's in healthcare. And so also highly regulated, you know, lots of security. And she was just ranting about all of the authenticators that she has to use. And I said, Yeah, we don't we we our our our system is set up in such a way that we don't we don't need that because we have other controls in place. And I'm like, yeah, I forgot how inconvenient that was and those those stops.

SPEAKER_02

So yeah, if you think about it, we actually have a castle, a moat that's visible to all the malicious attackers at every every location. But then we also have the crocodiles, the sharks, uh, dolphins with lasers on their head. We have multiple layers of security in that moat before they even get to knock on the door. Yeah.

SPEAKER_01

So it's it's interesting. The the experience in founders on this talk is has been very interesting. Um, founders chose a very different path than what the industry's functionally chosen. Um and and candidly at the time, it was the the the harder path. It wasn't the path of least resistance, it wasn't the path to just check a box. Um, we understood that it was our our purpose, our almost obligation requirement to do for our member partners candidly, and Justin, see if you'd agree with this, that which they really can't do for themselves, right? Um it's not uncommon, and I we always make the the cousin Vinny joke, but you know, how many advisors run small independent practices and it's their brother, it's their cousin, it's somebody, you know, putting the malware on their computer, you know, whatever, you know, Comcast business protection walls, you know, those the basics, right? But the basics are easily worked around in in the modern world with hackers and those kinds of things. And so we made a very difficult decision. Um, we said that um we need to bring everybody into one platform. And um, and it was it was hard. We we brought every single member partner in for personal one-on-one meetings. We helped them understand and candidly at first it felt like an invasion of independence. Uh, and I get that, right? You know, they own their own practices, they own their own business and enterprises, and it felt like that to them. But as they as they began to listen, and as you guys know, we have a really high trust uh proposition with our member partners. They know we're not doing this to them, we're doing this with them and for them. Yep. And they got to begin to listen and they got to hear what what was being built, what you were the castles, the moats, um, alligators and sharks and all those all those amazing things. They realized that what was something that was an afterthought that shouldn't have been, that was weak for them that shouldn't have been, that was undervalued and shouldn't have been, something got solved for them like that. And and that, and that yet they were still spending money on it too, without any understanding of was even money well spent or not. It's it's like you don't know you're in trouble when you don't know you're in trouble, right? And so is ignorance. Ignorance is blitz a little bit. And so once we got through their understanding, as you guys know, everything we do with founders will help them understand why we're gonna do it on our in pursuit of our built by and for culture, our shared resources, shared values culture. And so this was probably the the grandest of those experiments because it it it honored and it was the true embodiment of interdependence. And and because you could make the argument that, and you probably did use the right term there, controls were put in place. And how does that how is that meaning you're independent then, right? Um, and our and looking back now, our members cherish this. They are nothing but thankful for it. It's been game-changing for them as business owners, something they need to think about. Um, and they know that you, our team, our are what you've built is something that they don't have to worry about anymore. It's been an incredible positive experience in founders. And when I talk to recruits, they're thinking about founders. They've never talked about it with their firms. And then when they see what how differentiated it is, it's a powerful uh attractor.

SPEAKER_04

Well, and the truth is the independent space is really hard to implement this in because if you're at a at a wire house, you've got, you know, five systems that you work in and and you can control those. And in the you know, in the independent space, we're agnostic to a lot of the the systems and technology. And so we need to make sure that all of those are good. And I think your team does a great job vetting those those tools. And you know, what uh one of the the phrases that I hold on to is, you know, we need to be right every single time a hacker only needs to be right once. And I think we've built a platform in such a way that allows people to still be independent and and the freedom of choice when it comes to to different platforms, but also protecting all that that information that's inside because I think a lot of people don't think about just truly how valuable the data that they have in their offices is.

SPEAKER_02

Yeah. I think one of the best parts that I see out of the outcome of this entire process is one, the trust and um the comfort that our member partners receive and how they um you know explain that to us and the fact that they are like, I don't have to care about any of this stuff. You guys handle it for me. Right. And we we love the fact that they have that confidence in us. So we're the the marines on the wall, as uh one of my old colleagues used to say.

SPEAKER_01

Yeah, it makes it makes a huge difference. So that so then what does it produce? Peace of mind. And what does peace of mind produce? They can stay focused on the things that are most important, the things that actually make an impact to their clients, grow their enterprises, and help them live up to their missions at the end of the day. Yeah. Yeah. Do you think advisors they're do you think they're prepared? And we just painted a picture of the disjointed nature of our industry in contrast to how founders just tackled this very important issue. What what's your experience, Justin, and and how do you think advisors are are or aren't prepared for for this?

SPEAKER_02

So it's very difficult to be prepared for this because it evolves every day. Yeah. Which is why they appreciate the fact that they have a team that our managed IT team that's there for them.

SPEAKER_03

Right.

SPEAKER_02

Um over the last year, we've had several onboards, and during each of them, they had no understanding of what their cyber footprint actually was. Um we had some join who were actually being attacked on a day-to-day basis and they weren't even aware.

SPEAKER_01

Wow.

SPEAKER_02

Um luckily, you know, they didn't have any incidents occur. Um and usually when they join, we do an entire But it is luckily, right? It is luckily. Yeah, right. Because they were using certain platforms that had certain minimal safeguards put in place. Yeah. But the check-the box minimal standards, right? Yeah. And uh they're never really understanding what it actually means to be attacked every day. Um we've had member partners who didn't know that they get 6,000 somewhat attacks on them just themselves every day. Right. Right. Um, because they don't understand what it is about data posture and data footprint. Right. So to answer the question, no, they're not really prepared for it. Uh we do educate them when certain circumstances come up. And the best part is that we have our member partner virtual office that allows us to let everyone know, hey, there's certain cyber attacks that are occurring right now. Keep an eye out for them. And things like that.

SPEAKER_01

I mean, just this weekend, um, you communicated to our entire community of advisors and team that you were ratcheting up some some I don't know exactly what you did. You're the you make the magic, man. But yeah, it's just even this late weekend, um you you you caught or it caught something that was going on and twist the dial and we're we're that much more safe.

unknown

Yep.

SPEAKER_04

Well, and I I think s a lot of organizations they they look at cybersecurity as as an expense, that it's a it's a line item cost, and as long as it's good enough and it meets the regulatory need, we're we're we're fine. And so they want to they want to check the box and they wanna keep costs low. But I don't think anybody's ever outside of us. I don't I don't think I don't think people generally sit down and think about what is the impact to my organization if I if I was breached? What's the impact to my relationship? What is the the impact to the confidence that all of my relationships have in me if their data were to be breached? I mean, we're we are protecting what people have worked their entire lives for. And you know, I used to always reflect on when I was with a a different firm, like people would literally put their life savings in an envelope, mail it across the country to someone that they never met before and hope they did the right thing. Like that level of trust is insane. Yeah. Now, granted, we have relationships, so it's a little bit better, but the truth, but it's still the truth. It's everything that they've ever ever worked for. And and honestly, you know, I used to hear from my dad, you know, I can't, I can't give you much, but I give you, I gave you your name. Well, in the world of cyber threat, you can lose that too.

SPEAKER_03

Right, sure.

SPEAKER_04

Um, and so I think organizations really need to set back and reflect on not just what is the line item cost to to check the box and to meet what what everybody else is doing, but really of what is the cost of the organization, the the actual dollar cost, the cost in confidence, the cost in in damage control if one of those threats happen get like gets through.

SPEAKER_01

Yeah, why do you think advisors fight this so hard? Independent advisors, why do you think they fight this so hard? The cybersecurity aspect of it. Yeah, like why, you know, it because again, we've we talk to advisors all the time, and uh this is, you know, their the general sense is this is not something that I want you to do for me, firm that I'm partnered with. Uh it tends to be more cont you know, controversial and and um you know, it's it's not warm fuzzy for them. Why why do you think that is?

SPEAKER_02

So the biggest conundrum that's always been in IT and cybersecurity is it's kind of like insurance. No one really cares about it until something happens. Until you need it. And then when it does happen and you needed it, now you regret not having it. Right. So and then it's hard to have a value proposition with something is just to protect you from something that hasn't happened yet. Right. Like insurance.

SPEAKER_01

Especially if you don't know the degree to which it's actually a real risk.

SPEAKER_02

Correct. And then if you have no actual live metrics, nothing's ever happened to you, you have nothing to compare it to, and then they don't really think about it often until the day it happens.

SPEAKER_01

Right. You're not happy you have car insurance until you got until the day you get in a car accident.

SPEAKER_02

And you might say, I haven't had a car accident for six years, I've been paying for this, why do I need it?

SPEAKER_01

And I'm a good driver and I do all things safely, and but you just don't, which you know, you don't know. And and it's and it's accelerating, right? With AI, it's getting harder, right? And so and so I you know what what advice would you tell an independent financial advisor about this in in the context of its importance and what they should be thinking about?

SPEAKER_02

Aaron Powell Well the the important thing is making sure you understand the risk that you bring to your enterprise, right? So cybersecurity is a large risk. You lose your data. Data is now more value and money than actual currency. Um with that data you can do all kinds of things. You can manipulate credit reports, you can manipulate uh your client base, you can manipulate people to think that you're interacting they're interacting with a specific individual with how AI is advancing. Right, right. Um we have Brad Shepherd Netic, that's pretty much Brad, but not so much Brad. Yeah. We're not letting that guy out, that's for sure. But you know, the amount of technology we have and how advanced how much it is advancing on a day-to-day basis makes it more difficult. So it is important for them to understand the risk they take every time they you know send a PDF with maybe someone's sensitive information in it.

SPEAKER_01

Yeah. So And to your point about expense, um I'm gonna say most, maybe it's not right, many, you pick the term. Firms or industry kind of see it that way. Totally. And what's the what's the minimum viable product? Yeah, it's not revenue. Yeah, it's not revenue. It's a cost, it's it's yeah, and so and because you're independent, it where's the where's the boundary between my responsibilities as your partner, quote unquote, versus your responsibilities as the independent advisor owner of your own business and practice, and where does that crash into each other? Yeah. Um, and uh, you know, at least our experience is that, well, as you know, we chose to blend that into one, but as we talk, advisors are becoming aware um they really are understanding of value and and and stuff, yeah.

SPEAKER_04

So and I want to go back because my brain is spinning right now to what you said six thousand times a day that one person was getting attacked. You could have told me six thousand times a year, and I still wouldn't be just as shocked.

SPEAKER_01

And so what's the number for for our organization on a daily basis?

SPEAKER_02

So for twenty twenty five, the average was six thousand like two hundred and something attacks a day. Right. Yeah. Um that has subsequentially increased with AI now being able to run data pools against all these black markets. Market data is um unfortunately the the difficulty is is it's not typically advisor is the original target. It's a client of the advisor. Right. Yeah. And because they are their financial advisor, they then become the target. Yeah.

SPEAKER_04

So it it's it's interesting. And I I wonder one, how many advisors know how many times that they're getting attacked and and can put that, you know, because because if you would have asked me, I probably would have said, oh, once a day. A handful, you know, a handful a day. And so it's shocking.

SPEAKER_01

You know, things shocking.

SPEAKER_02

Yeah, like nobody actually knows. Yeah. Yeah. I mean, uh Brad is constantly attacked every day. Yeah. At least 30 or 40 times every hour. So but we have systems in place that protects his accounts.

SPEAKER_01

And so you you made an interesting point though that we've not talked about, uh, and that is the role of the the client in this, right? Uh and you know, we said the advisor is the weakest link. They're actually probably the second weakest link. Yeah. The weakest link is is is the client, right? The person who does literally doesn't know what they don't know. They have a Yahoo email or they have a this or that or whatever. And and um and so, you know, talk about if you would, from a compliance lens, what do you think advisors should be doing in in the context of educating their clients around this as a priority in what they deliver as a as value add. Yeah. And then Justin, what advice would you give those same advisors on on things they should be you know not just educate, but teaching their clients about?

SPEAKER_04

Yeah. So I think it's it's twofold. It's it's teaching their clients about being safe with their information and then also uh being aware of what the threats that are out there. So the safety piece is don't let your client email you their statement. That's stupid.

SPEAKER_01

You know, but giving it from their unprotected internal email.

SPEAKER_04

If you don't have a vault, there's other secure ways that you can you can share share information, but just don't so don't don't encourage bad behavior. But then the second piece is around informing them of the risks. And I would say it's at least once a week that I'm talking to an advisor where one of their clients has been um the the subject of some type of of hack.

SPEAKER_01

And sophisticated at times.

SPEAKER_04

Oh, yeah. And and the thing, and actually hack is a bad term because it's no impersonations and yeah, exactly. They are actively participating in it and sending money to them. Right. And and the the sad thing is the one that I talked to most recently, the the advisor's like, no, I kept asking this person where the money was going, and they kept telling me oh, it was going to my son, it's going here, it's going there. And he's like, and I and I knew that that they weren't being truthful, but I also didn't know how I could get them to open up. And right. And and that's the that's the hardest thing.

SPEAKER_01

So what would you tell them?

SPEAKER_04

Yeah, so it so it's really about establishing yourself early on in the relationship and repeatedly of I am a, you know, use me as a sounding board to talk through things. Um if things seem like they're too good to be true, they probably are, you know, and and putting that information out there and having those conversations with people because some once somebody realizes that they've been um that they've fallen for it, and you hit on it earlier, like you you feel a lot of shame. And then it's how am I going to rebuild from this? Whether because it's not like somebody gave $50. I'm seeing 10,000, 20,000, 800,000 is the most recent one that I saw. And it's wild to me that these people who are otherwise.

SPEAKER_01

Tell me please that that was an effort and not a success.

SPEAKER_04

Um, and thought they were paying their taxes.

SPEAKER_03

Wow.

SPEAKER_04

And they they were not in in either in either case. And it and it but it happens all the time. And so if you look at the if you look at the numbers, it's billions of dollars a year. It's a very, very fruitful.

SPEAKER_01

Yeah, as I say, if it wasn't good for the bad guys, the bad guys wouldn't do it, right?

SPEAKER_04

Exactly. And so so this is a case of you can't wait to talk to your clients about it when it happens. Um but we also need to present it to our clients from the lens of this is not a matter of if but when. Yeah. Because all of our information is out there.

SPEAKER_01

Um I think so, as a value proposition, you know, as a value add, uh, I, independent financial advisor, should be explaining to our relationships how we, why we, what we, and so it it it's I'm sorry it can't be that easy, Mr. and Mrs. Client. Yeah. Here's the reasons for that. And you need to know what we're doing to make sure that you're in you're in good stead.

SPEAKER_04

Well, and and and beyond that, it's even, you know, let's talk about how to be safe on the internet. Don't accept friend requests from people you've never met before if you don't know their name.

SPEAKER_01

Because I'm Are you suggesting we should parent our clients?

SPEAKER_04

But it's it's wild when you when you start to unravel about how did that person, how did that bad actor first get their foot in the door?

SPEAKER_03

Yeah, right.

SPEAKER_04

And it's literally, oh, I sent them a fr, you know, I got a f a friend request from someone and we were in the same Facebook group or whatever it was. And you know, and and when the person looks back on it, they're like, gosh, how can I be so foolish? But but these people are sophisticated. They are they've got it down. And so maybe not parenting's the bad word, but but if you are, you know, when you are engaging your relationships, whether it's through through seminars or one-on-one, it's not just let me talk to you about how we save for retirement, but it's also let's just talk about good day-to-day habits, things that you probably don't think about that unknowingly introduce risk to your lives. Because ultimately, I am here to help you reduce risk across the board, whether it's in a diversified portfolio or in protecting your information.

SPEAKER_02

Right. Yeah, fair. I mean, it's all about data footprint. Um a lot of the more recent conversations I've had is because we have members who are sending secured emails to a client, and then the client's trying to forward that to you know their CPA, whoever it might be. Yeah. And then they're like, well, I can't send it to them. And that's because they're not part of the original chain. And it's designed intentionally to stop people from getting access to it or aren't supposed to. Right. Um, and then we'll get complaints about it. And I tell the advisors that that's actually an opportunity for you to open up a discussion to say you need to be more cognizant and careful of your data posture rather than saying, oh, I'm sorry, we'll do something else. Right. Right. Right. It's an opportunity to show them that you're here for them and you're doing your best to safeguard all their information because you care not just about them, but their entire household.

SPEAKER_04

Absolutely.

SPEAKER_01

Yeah, it's it's a it's a leadership conversation, right? And I think you said it both very well. Leadership isn't just about their financial plan, their investments, how they're gonna protect their family with insurance, all these kinds of things. It's more than that. Uh it's deeper and richer than that. And um, the most capable, successful advisors are gonna lean into this as a strength of their firm, celebrate it as a differentiator ultimately. Aaron Powell Yeah, I agree.

SPEAKER_02

There's been a lot of talk about AI and the use of it rate recently in cybersecurity. Um one of the best examples I've seen was at um so they have a thing called DEF CON. It's out of California. It's uh like a hacking convention. Yeah. And they were demonstrating one. It is. You should never bring your own real phone. Okay, fair enough.

SPEAKER_04

Um ethical hacking or all hacking?

SPEAKER_02

It's uh a little bit of both. Okay. Okay. So um unfortunately, actually, there are malicious actors at those conferences. Of course there are. Trying to gather data. That's the honey pot, right? Right. So um one of the examples they gave there was they took a photo of a child that was on social media that parents posted. They aged it. They gave it a voice, they found their social security number, their address, date of birth, opened up accounts with it. Now, again, this is all a simulation. Yeah, sure. But it was an actual person's photos that they aged up. Right. And uh, you know, provide all information, uh, you know, doctor documentation. It's all about data. Right. Because everyone, there's no paper anymore. It's what does the zeros and ones say to me on this computer screen? Yeah, sure. Oh, this is a valid person. Let me issue them a new credit card and go on from there.

SPEAKER_01

So from your lens, I'm just curious. Do you think the um the protectors of cybersecurity, the the big companies that have built the products that you then deploy, have they built really good? Like do we have good castles and good boats and good sharks and good alligators? Um, or do we need do we need more from those? And what should we be doing on that front?

SPEAKER_02

Aaron Powell Well, the beauty of the stack that we've built is that we've catered it to our specific needs and our needs to offset certain risks.

SPEAKER_01

Okay.

SPEAKER_02

Um it's out of the box, a lot of them are good for, you know, not just the bare minimum for what we're utilizing, but it meets certain standards because we, you know, we tell them, hey, when we work with our vendor partners that, hey, this is what we need this for, and this is the kind of risks that we need to offset. And then we work with them to figure out the best applicable tools. Um, but it's up to us to understand what it is business purpose-wise and application-wise. So we bring it to them. Now we do have a largely Microsoft stack. Um, I typically don't talk about what's actually in the stack, but most people have Microsoft enterprise stacks nowadays. Right. Um, and because of that, they have a lot of tools for us to use and we have adapted them in ways that many others in our industry have not. Right.

SPEAKER_01

Um kind of our secret sauce, right?

SPEAKER_02

It is. And that's why I pride myself on having an identity score of 100.

SPEAKER_01

Uh-huh. There you go.

SPEAKER_02

I mean, every once in a while it does go down a little bit, but that's because there's new recommendations based on new attack vectors. Sure. Yeah. Um, and we make adjustments and we try to keep it at the 100 scores. Yeah, right.

SPEAKER_04

Yeah. Well, and I think, you know, the the question really is there is no piece of technology that is going to be good enough today, tomorrow, and indefinitely in the future. And so it it's not just is is the technology good enough today, but what is their what is their plan? How are they forward-looking? Sure. How quickly can they adapt to they being the technology company to evolving threats? Because that's what that's what you need. And I imagine standing up one of those structures is is rather complicated. So it's not like a, oh, they they drop the ball, so I'm going to switch. Yeah. And if you decide to do that, that's that's a pretty heavy lift, too.

SPEAKER_02

I mean, one of the best things that are I think our relationships are getting out of this, not just our members, but our vendors, is the fact that we apply what we're utilizing to safeguard our systems to them. And then they start utilizing it themselves. They uh we identify issues where they need to, you know, adjust for the industry or whatnot. Yeah. Um, and uh like to say like we like to bless all of our vendors with that education and knowledge. Sure. Yeah. Yeah. That's awesome.

SPEAKER_04

So, you know, it's interesting, we've been seeing uh the regulators really increasing their their focus on cybersecurity. And if you look at every every year the SEC and FENRA publish, what are their what are their top priorities? And for at least the last five years, cybersecurity has has been up there and it and and it absolutely it it evolves. Um and the you know, the standards can continually being um being raised. But you know, ultimately the reason that they care is, you know, what's their purpose here? What's why is why does Finnra and the SEC exist? It's to protect investors. And so we're they're protecting investors, their m their money while it's here, but also back to the earlier conversation about the end clients of how do we how do we protect their data getting out? And and and my guess is that when FINRA and the SEC started thinking about cybersecurity probably 10, 20, 30 years ago, they probably didn't have that perspective. It was truly how do we protect what's in those four walls. But the truth is is that all of the things that they've brought forward have helped um helped protect people beyond just their their their individual investments.

SPEAKER_01

Well, and correct me if I'm wrong, but have they not taken the lens that cyber is kind of intertwined and and brought through the lens of reg SP uh and the collection of the privacy and the and the protection of client data? And so it's not just it's a best practice. Um and I'm personally for me, I'm I'm thrilled that they that they're making it this important. Yeah. That's not a bad thing in my mind. That's a really good thing. Um, but by by putting it through like actual documented regulation, um, they're they're setting firms and advisors up for accountability.

SPEAKER_04

Absolutely.

SPEAKER_01

Um and you know, we can all debate to the degree we think that's good or bad. Um, but you know, if I'm an independent advisor, uh I'm I'm taking this seriously. Uh our experience with the regulators on this topic has been really constructive and positive because of the zero trust footprint and platform that that's been built by Justin and his team to do you know some of the things we've talked about today. Um and while they'll never endorse, you know, they're they're satisfied that you know we've built something of substance. Absolutely. Of the material substance. Um and advisors, they again, they don't know what they don't know, but the regulators, this is an everyday ongoing and it's low-hanging fruit.

SPEAKER_04

Yeah.

SPEAKER_01

These these things can be figured out quickly and easily.

SPEAKER_04

It is an absolute expectation. And and you you raise an inch or a good point with with Reg SP and there's Reg S and S ID, and that's all related to protecting client data. And so today it's cybersecurity, but before, I think we, you know, when advisors are thinking about this in their office, they need to think, how am I protecting my clients' data broadly? Because, you know, I've seen things in my my career of people they they print off a tax, uh tax form from the printer and they print them off for a couple of clients, and they just happen to grab the top one for somebody else, shove it in an envelope, mail it off. They don't realize it, but by the when the client opens it, they've they've you know they've compromised their their data. I had a situation um at at home where someone down the street did worked as a CPA out of their office and they threw away their trash and their trash got torn into by an animal and I found somebody's information sitting on my front lawn. And so it's all of those things. And I think advisors need to think back to on themselves of how I should be leading my relationships with the same level of care that I lead myself. And so, how would I feel if my my parent or my own or my my child's information was was compromised, either because somebody inadvertently mailed my information to the wrong person, they they left it out, or they didn't take cybersecurity seriously enough to put, they said, nope, this is good enough. Well, what else, you know, my my lens would be, well, if you thought that was good enough, what else are you thinking is good enough that really isn't?

SPEAKER_01

Yeah, I'm I'm entering your perspective on this. Do you feel that the regulatory bodies, SEC Fedora, are right-minded around this topic? Uh and and how then do you feel in the founders' world, we've we've not just checked the box. We we've like we we've built the box.

SPEAKER_02

Yeah. So um in comparison, five to ten years ago, during audits, I had they had no idea what they were doing. They didn't know what to focus on, they didn't know what actually a part of cybersecurity actually meant. In more recent ones, they actually are they're bringing in CISPs, so those are very highly it's a CISP, it's a certification that was given to certain individuals who know pretty much all aspects of cybersecurity. Okay. Whether it be physical security, actual data security, all the different postures, encouragement security. Um, they're bringing those individual specialists to be able to do that. So they work for the regulators now. They do. Okay. Um and actually at their last meeting, I specifically knew there was a CISP in there, and I was looking for his responses in mannerisms. Gotcha. And during that entire meeting, to go on to the second part of your question, he was just like nodding his head, asking the uh the auditor was asking questions. He was nodding his head, nodding his head. I was looking for responses. By the time we got to the last question, he said, I don't have any questions. Wow. You guys are, you know.

SPEAKER_01

To the degree to which we can say, right? Yeah, yeah.

SPEAKER_02

You know, to everything that we're covering, everything that we need, you guys have already been doing. Um and that's because we designed our system with the thought of in 10 years, we need to be able to make sure that we're still adapting and overcoming all these securities. Right.

SPEAKER_01

So in in many ways, I apologize to interrupting, in many ways, because we've built what we built, we actually empower advisors to be independent and able to own something and not and and not have to worry if that makes sense. Trevor Burrus, Jr.

SPEAKER_02

It does. And that's where I was saying earlier is like typically when you enforce higher levels of security, it's more difficult. But because of the way we've implemented our zero trust system, it allows them to continue doing their business. They don't have to they don't have to think about their IT anymore. Right. Unless you know something breaks, and they'll just give us a call and we get it situated for.

SPEAKER_04

And and so what what I was going to wanted to or what I wanted to give kudos to to you and your team is I feel like the industry often says, I need a cybersecurity solution, what does the regulator require? And they build to that. And you took a different perspective and you said, We need a cybersecurity solution. What it what does the cybersecurity world expect and require? Right. And so you took the perspective of how does healthcare do it, how does defense do it, how do these other organizations that have really important information to protect, how do they do it? And because of that, we've built something that is far superior and and and has stood the test of time and is ready to evolve because as we evolve, you know, we're evolving to the cybersecurity standard, not to the industry standard.

SPEAKER_02

Yeah. Yeah. A lot of the times the questions, and this has been brought up before, is my my avenue of approaching these sort of things isn't a what do you need us to do? We'll do it. It's uh come at me, I've already designed the system the way I think it's best to serve and protect our people. Yeah.

SPEAKER_01

So it's and it's a it's a wonderful point. And I think it's the difference to kind of just bring this full circle and summarize, it is the fundamental difference between founders and and uh the industry. It's the difference between independence and alone and interdependent, built by and force, shared resources, shared values. And you know, again, what is our simple purpose in life? It's to empower advisors to do great work for their clients. Yep. We are the means to their end, so they can be a means to their clients' end. If this isn't something they ever have to worry about, the the peacefulness that brings, and then the ability to go focus more on what's most important. Yeah. So it's it is actually in many ways, and it's not an expense in our world. It is a it is an enhancer of if we're gonna get to the bottom line of economics, it's a revenue enhancer because you're free to actually go serve and grow and not worry about this stuff. And and so it's an interesting way to think about it. But uh cyber in our world and what we've built is a promoter of growth, not a deterrent to growth. Absolutely. Yeah.

SPEAKER_00

Thanks for spending time with us on the Built By and For podcast. If this conversation resonated, follow the show on Apple Podcasts, Spotify, or YouTube, and share it with an advisor in your circle who's thinking about what comes next. To learn more about Founders Financial and our solutions for independent advisors, visit Foundersfinancial.com. The Built Buy and For podcast is produced by Founders Financial. The opinions expressed by hosts and guests are their own and do not necessarily reflect the views of Founders Financial. Content is for informational purposes only and is not intended as investment, legal, or tax advice. Securities offered through Founders Financial Securities, LLC, member FINRA, and SIPC, registered investment advisor. Copyright Founders Financial, all rights reserved.