Behind The Stack

Hackers Don’t Hack You Anymore… They Log In | Matthew Templeton, Xpand IT

Jade Terence Barter Season 1 Episode 7

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 19:43

Send us Fan Mail

Cybersecurity has changed. The question is: has your business changed with it?

In this episode of Behind the Stack, Matthew Templeton from Xpand IT breaks down how cyber threats are evolving, where businesses are most exposed, and why protecting your organisation goes far beyond firewalls and antivirus.

We unpack the real-world risks facing businesses, the growing importance of identity and access security, the human element behind cyber attacks, and what organisations should be doing to stay ahead.

If you run a business, manage IT, or make technology decisions, this is a conversation you need to hear.

Featuring Matthew Templeton from Xpand IT.

#Cybersecurity #XpandIT #BehindTheStack #ITSecurity #CyberRisk #Technology #BusinessTechnology #SouthAfrica

SPEAKER_01

If your business depends on technology, this could be one of the most valuable conversations you hear this year. We consistently hear of more cyber attacks and breaches. Why, when businesses are investing in more security, is there more cyber attacks?

SPEAKER_00

More money, more spend on security doesn't equal more security. It's about spending the money on the right tools and then implementing those tools correctly. You gotta go back to those.

SPEAKER_01

Matt, we consistently hear of more cyber attacks and breaches and stuff in today's world, despite seeing so much money and budget of different businesses going towards it. Why, when businesses are investing in more security, is there more cyber attacks than ever?

SPEAKER_00

100%. We we see it all the time. I think the the reality of it is that more money, more spend on security doesn't equal more security. It's about spending the money on the right tools and then implementing those tools correctly. And the the amount of businesses that have overlapping tools is scary. It's like you got to go back to basics.

SPEAKER_01

And so I assume there's a lot of wasted spend, like you're saying, overlapping tools, there's tools that could be done away with. Do you see that often? And and why do you think it's the case for a lot of businesses?

SPEAKER_00

You know, sometimes people are pressed for time. Often, you know, the the budget's not available until something happens. So there's almost this rush to purchase something. You know, companies are going on the wrong advice. You know, it's taking advice to plug a hole that isn't a hole yet. Right. Maybe that does form part of the strategy, but like understand the tools that are in place already and you know, spend the money on improving on those tools versus just you know swapping and changing and taking the latest and the greatest.

SPEAKER_01

And so would you say part of the problem is businesses and individuals who make this these types of decisions are not researching or or maybe taking the time to understand the tools that maybe they already have or the tools that they're wanting to get? How do they how do someone listening who wants the opposite? How do they prevent that?

SPEAKER_00

I think like we we all press for time. You know, we we're in a world where business owners are running the business. You know, you don't have the time to sit and look at all the tools. So you're hiring people to, you know, do the research and you know find the right tools for your business. Right. But it it needs to almost become a collective approach towards understanding what the tools are, how those tools get implemented across different departments.

SPEAKER_01

And what would you say is the biggest kind of false sense of security that you see in businesses where they think, man, we we're covered, but in reality, there's there's a lot at risk.

SPEAKER_00

We we've spent the money, we've got something in place, we we're happy with it. It works. But it's you know, you you gotta be dynamic, you've got to be ever changing, you know, the world changes at a fast pace, and you know the the pace increases every year. And if you've got a tool that's outdated or hasn't been, you know, tested to the latest threats, you you're opening your your business up to vulnerabilities.

SPEAKER_01

And so if you were to walk into a business tomorrow, what is the the vulnerability that you look for first?

SPEAKER_00

It's a funny one. So we we all sit on email all the time. Um, you know, you get inundated on emails, you you almost suffer from email fatigue. Um, I I want to say that's the first aspect. I I'd always look and see, you know, what are you using as your your email security? Are you using a proper domain for your business or are you using a public domain that doesn't have the the the right tools in place, that doesn't have the layers in place to protect it. I think a second thing is you know, go going back to the the fact that people are always busy nowadays, you know, short on time, attention span is also there. People don't focus. So if you use a little bit of social engineering with with you know a weak email, it's a weak point in most businesses. So I think a a big thing for for businesses is you know two-prong approach. When you look at that, you should be securing your email and you should be having proper awareness training in place so that your staff are prepared for when these things happen. I mean your your staff is a big expense to your business, but it can also be a weak point to your business.

SPEAKER_01

Yeah. With that, would you say employees and businesses are are the ones making more mistakes or or hackers are just getting so much smarter in in their craft?

SPEAKER_00

That's a good question. I I think it's it's easy to sit and put the blame on humans, to put the blame on people. The reality of it is you know, we are distracted. We we're in a world where we're chasing perfection. You know, when you chase imperfection, you you can make mistakes because there's the urgency attached to that perfection as well. So you know, I think businesses should be focusing on prevention. Um, I I like the saying prevention's better than the cure. So you know, have the right tools in place to protect your staff, you know, that that need to access these systems. Don't put the blame on on people. Cyber attacks have have been happening in the 20th century. It's it's it's not like it's all of a sudden happening now. I think it's just a lot more targeted now, it's a lot more frequent now.

SPEAKER_01

It's a topic that, like we know, is overly hyped and big at the moment. And uh the way I'd like to bring it in, obviously that topic being AI, how is it efficiently or effectively helping cybersecurity? What are the tangible ways that it is uh preventing more of these these attacks?

SPEAKER_00

We're reaching our limited capacity as humans. Companies are are trying to do more with less. And the only way you can do that is by you know either employing someone who knows how to use the systems and the tools to to fight the cyber attacks, or you know, setting up you know, agentic AR, setting up agents to combat these threats. The reality is that what we have as employees, as business owners, the the tools that we have, you know, the the criminals have access to those exact same tools. Right. You know, it's it's two sides of a coin. You know, one side's playing for the good, the other side's playing for the bad. It's a constant war to, you know, you got to protect your environment just as much as people are trying to get in your environment.

SPEAKER_01

And the the potential uh weaknesses of of AI and these technologies being part of uh like your cybersecurity solution, uh, if any, what are they?

SPEAKER_00

People are always after things that are free. Um, you know, that there's a lot of free offers everywhere. If if you look at adverts everywhere, uh it's it captures people, you know, it's a trap. So people start using free tools and they don't know how to use the tools. So company data gets leaked. There's no streamline of what AI gets used in a business. So it forms part of an AI policy. I think that's the first step, having a proper AI policy, setting up an AI council within your business so that you know the the leadership can effectively lead the AI journey within the business instead of having the staff lead the AI, you know, journey. You you want to have the right tools, be prepared with those tools and know how to use those tools. That's how you find the efficiencies, that's how you find the improvements. With great power comes great responsibility. As business leaders, as business owners, you've got to, you've got that responsibility to have the right tools in place for your staff. But equally, you can't just expect everyone to understand how the tools work. There needs to be a guided implementation, there needs to be an understanding. And also, you know, like there's so many different AI tools out there across different systems, and you got to find the right tool for the right system, also the right departments, you know. AI in a finance world, you know, without education on it, can be disastrous for a company.

SPEAKER_01

In an environment, are there ways that you can ring fence or protect or ensure as a as a business leader or in a business that there's your employees can't do certain things? I mean, guys are putting proposals and different documents and stuff to refine. Are there ways to protect that?

SPEAKER_00

Definitely. So, you know, in your security policy, or I want to go back to having an AI policy in place. When you have the AI policy, a fundamental part of that is to understand where your data sits and how people access that data. Most businesses have that locked down, but you know, how locked down is it? A weak point could be you know someone who actually sits in a position of power, doesn't know how to use the AI tool correctly, and then leaks sensitive information. So, you know, it's almost like having a fact check against a fact check. Lock it down that there's you know permissions, that that there's a process to get something implemented. Um and also, you know, stay away from the free stuff. It's not a sales pitch. It's just you know, when you pay for something, there's generally a guaranteed SOA behind it. When something's free, there's no guaranteed SOA behind it. So, you know, the the companies that have these free tools, they pretty much can do whatever they want with that data.

SPEAKER_01

Uh what do modern changing topic a bit uh phishing attacks look like? 2026, what what are you seeing out there in different businesses or clients of yours?

SPEAKER_00

I love this question because I think you know, we we get asked it often. Um, I've seen, you know, the I've I've been with Expandati for about eight eight years now, and through the years, you we've always had the right tools in place to to combat these. And I have these you know conversations with business leaders, you know, business owners, C-suite execs that are sitting to, you know, they might have been exposed to something like this because they typically targeted in most scenarios. And the the criminals are smart, you know, they they're using the AI tools that you know the businesses are using, so they're able to copy and mimic and you know use Photoshop and you know things like that, and you have developers in place that can sit and build you know front-end systems that look exactly the same as what Microsoft does as an example. I think a big point for for looking and trying to find these things is you know, number one, you've got to rely on your gut, but it's also being educated to see what those latest you know trends are, what those latest phishing attempts look like. Typically, a phishing attempt is you know, like an internal email. Um, you know, maybe it's you know JG sending me uh an email saying, Matt, here's an invoice from our latest conversation that we've had or you know, business that we we've transacted in, you know, it's hot, it's there. But normally when something like that happens, it's you know, someone's already got visibility of what's happening or what was intercepted. And you got to have the right tools in place. You know, we we also we live in a world where we're trying to prevent risk as much as possible, but we also want to do as much business as possible. So, you know, there's a risk on your clients and there's a risk on your end. Um, but there's a shared responsibility on you know how that data transacts.

SPEAKER_01

And now ransomware compared to years ago, again, what what are you seeing in in today's market and world and clients?

SPEAKER_00

A few years ago, it was always a big bang approach, it was a shotgun approach. It was target the biggest companies that are out there, the companies are publicly facing. And maybe you know, from thousands of attempts, there's one weak point, and you get this massive payout. Um, a lot of the bigger companies have matured in their security understanding, they've implemented the tools correctly, and they've traditionally had bigger budget. Um, they've also been the first to feel the pain of uh a ransomware attack. So the the criminals have you know obviously tried to do that, but they've become a lot more sophisticated. So now it's all about using their AI tools to try to do targeted uh attempts. Uh uh a lot of the the ransomware nowadays, it's the the guys are are doing their research. You know, I like to use it like a you know, in a sales you know, perspective, you're doing your research on your prospect before you're trying to sell them the right tools. It's equally the same thing on the criminal side, they're going doing research into the the business. I've seen some websites where you know you you've got the leadership of a company listed on a website with their cell phone number and an email address. That's a big no-no. As much as you want to get it out there, you you want people to be able to get a hold of you. It's it's it's what these criminals are preying on. They're preying on someone going and doing something like that. We we talk about a SIM card fraud that happens in South Africa. Uh typically people phone in that can be seen as a ransomware attack. You know, it's it's it's just a different perspective, different view of it, but it's still targeted. It's you know, a small business still has money going through it. And you know, if if if you look at a smaller business, they don't have the budget or the tools or the education and the maturity to be able to make those decisions on the right tools.

SPEAKER_01

And what cyber security conversations are you seeing maybe businesses or or clients are not having enough of or stuff that people are maybe blindsided by?

SPEAKER_00

I I see companies looking at risk, looking at governance, looking at compliance, um, trying to get ISO certified. Um a scary reality is that in South Africa we don't actually have a proper AR policy or that's that's agenda or you know set as a scope of which businesses can can can work off of. I think what what companies are doing is they're looking more at the risk, the governance, the compliance. Instead of saying, let's go back to basics, I like going back to basics. You you set a foundation, a strong foundation is off what you could build. So businesses that are you know trying to take the latest and the greatest, you know, trying to adopt AR, you know, instead of you just going ahead and jumping into bed with AR, you know, take a look at it and say, what tools do we have in place? How will it work with AR? Um, and those are conversations that that companies need to have. You know, you you almost need to sit and do a drill down and uh I want to say uh internal audits of the tools and systems that you have in place, go back to basics on how those tools were set up. How many times in a business, you know, someone inherits a system that was developed, or and you know, there's this person that could have been with the company for 10 years that managed the system, now they've just done a quick handover in their notice, and you know you've got all this legacy stuff. So I think it's about taking a look at those systems, seeing how integrated they are in the business first, and then you know, improving on it, you know, locking it down as much as what is possible without obviously affecting you know operational efficiency.

SPEAKER_01

With that, five years from now or in the next five years, what do you see cybersecurity looking like more and more?

SPEAKER_00

So AI is a buzzword now. Five years' time, it's people training AR better than what we're training AI currently. We spoke about you know people being burnt out because you know it's a world where everyone's trying to find perfection on urgency, it just becomes too much. People need time to rest. You know, cyber criminals AI doesn't rest. It's it's a server pushing out data somewhere in the world running 24 by 7. The only way that you can uh effectively run for you know future protection would be to have the right AI tools that you know fight against the cyber threats that are happening, the attack vectors that are happening, but then constantly improving on it. So it's like almost you need to adopt an AR tool now that starts learning for the future, and then having someone you know run those tools in the future, manage those tools in the future, built in Copilot is encrypted security where your your data resides in your Microsoft tenant, knowing that is a critical aspect before you know building out your security further around it. So yeah, I think you know, five five years from now, it's gonna be a very different world.

SPEAKER_01

The CEO, business owner, or or someone listening who's wanting to improve where their security is at now, uh, what are the the biggest things you would tell them, the simplest things for them to go away and say, Let me let me focus on this?

SPEAKER_00

Taking a look at your security as a layered approach. So break it down into layers and also understand where your business sits. If your business is sitting online, you know, that's a big point where you you have to protect, you know, it's it's public, it's visible. Um, you know, people that have access to that aren't necessarily always the best of people. The cyber criminals have access to the same online platforms. So secure your platform where you're trading in business. Um, you know, if everything's online, obviously protect your online presence, but also understand the the responsibility that you have. If you've got online servers that customers are are accessing, you know, you're equally responsible for having that online presence. You know, make sure that you've got the right security layers in place to protect clients interacting with your business, but then also like understand your your main points of contact. How does information leave and you know come into your business? Those are points of you know protection. You need to look at those things and say, you know, data is what the the next you know criminal wants. That they don't want the money, they want the data so they can get the money. Um that they want to use that data against your business. So secure your data as much as possible. If you take a look at your business and think of it like your home, how you're securing your home, do the same thing from understanding your your applications and you know how you communicate within the business.

SPEAKER_01

Matthew, super insightful. Thank you for for your time. I think the audience, anyone listening, could benefit a lot from this, but also from reaching out to yourself and and expand IT. I think, like you said, there's there's too much. We feel like we should know everything in today's world, but this reality is there's too many components and and things to understand in just this the world of cybersecurity. So thank you for your insights. And yeah, I encourage people to reach out to you, lean on guys like you who can provide insights and real world examples. And yeah, I look forward to to hearing more and seeing more of what you do in the future.

SPEAKER_00

I appreciate the opportunity, Jade. Thank you. Thanks for the time.