Get to the Point — The High Point Networks Podcast

What CISA Actually Does and Why Your Organization Can't Afford to Ignore It (with Jim Edman)

High Point Networks Season 1 Episode 11

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 38:08

Most organizations in the Midwest don't have a dedicated cybersecurity team — and that's not a failure; it's just the reality. But that doesn't mean they're on their own. 

In this episode, Andy and Brandi sit down with Jim Edman, Cybersecurity Coordinator for CISA's Region 8, to talk about the free, taxpayer-funded resources available to cities, counties, schools, and small businesses — and why so few of them are actually being used.

From backup restore testing to business email compromise to cyber insurance, Jim brings a grounded, practical perspective on what organizations should be doing, what they're missing, and how to close the gap without a six-figure security budget.

Jim Edman is the Cybersecurity Coordinator for the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) in South Dakota, serving Region 8 — which covers North Dakota, South Dakota, Montana, Wyoming, Utah, and Colorado. In that role, Jim works with critical infrastructure sectors across the region on cyber risk management and security hygiene. Prior to joining CISA in 2021, Jim served as Chief Information Security Officer for South Dakota State Government for 13 years, where he built operational and strategic security platforms protecting constituent and government data. He also served as broadband manager for the Connect South Dakota Project, bringing high-speed internet to communities across the state.

 

0:00 — Introduction & cold open

2:00 — What CISA does and who it serves

5:20 — DSU partnerships: Boundary Fence, Secure SD, and Cyber SAFE

10:20 — The current threat landscape: what the 2026 Verizon DBIR says

13:55 — Business email compromise in South Dakota

18:40 — The backup restore gap

21:45 — Cyber insurance: what's changed, what it covers, and what it doesn't

34:30 — How to connect with CISA Region 8

 

🗨️ Mentioned in this episode: 

→ CISA — cisa.gov/about/regions/region-8  

→ Verizon Data Breach Investigations Report (DBIR) — annual industry benchmark on breach trends

→ Project Boundary Fence — DSU penetration testing program for SD cities and counties, funded through the SD Office of the Attorney General

→ Secure SD — SD Senate Bill 187 grant program helping cities and counties address security gaps

→ Cyber SAFE — DSU program extending similar services to small businesses

→ South Dakota Cyber Council — nonprofit connecting government, industry, and education around statewide cybersecurity — cybercouncilsd.org 

→ FBI InfraGard — FBI/private sector partnership for critical infrastructure protection; SD chapter at sdinfragard.net

📎 A note on sources:

The OPM breach Brandi references involved two related incidents. The commonly cited 22 million figure represents the total number of individuals affected across both; the 4.2 million figure reflects federal personnel records directly compromised. Both numbers appear in reporting on the breach depending on what's being measured.

 

Connect with Jim: 

CISARegion8@hq.dhs.gov | www.linkedin.com/in/jim-e-465a9a12 

_____


New episodes every other Wednesday.

Connect with us: 🌐 highpointnetworks.com 📱 LinkedIn, Instagram & Facebook: @highpointnetworks

Subscribe — Spotify | Apple Podcasts | YouTube | And wherever you listen.

Get to the Point is produced by High Point Networks for informational purposes only. Guests include High Point Networks professionals as well as subject matter experts from across the industry, each speaking from their own experience and expertise. Content shared is intended as general information and should be evaluated within the context of your specific organization and circumstances. Views expressed by outside guests are their own and do not necessarily reflect those of High Point Networks or its affiliates. High Point Networks assumes no liability for decisions or actions taken based on content discussed in this podcast.



Andy:

I think we should kick this thing off.

Brandi:

I think so too. It's good to be back with you, sir.

Andy:

Good to be back. Always a pleasure, and welcome to Jim, but we'll get to that in just a second. Yeah. So, um, I have a question to start off with. Brandi, from your perspective, in say, I don't know, the central US, which is kind of our footprint-

Brandi:

Yeah

Andy:

how many organizations do you think have a dedicated cybersecurity team on staff? Ooh, that's a great question. I'm, I'm guessing for small cities, county schools, or even midsize businesses, the answer's probably zero. and that's not really a failure, I think it's just reality. I think it's just, it's just reality. Absolutely. Right, I agree. So today, we're getting to the point of what can businesses do to protect themselves against cyber threats when maybe they don't have a sufficient budget or resources, or they don't have a dedicated cybersecurity team. Maybe they don't even have a roadmap on where to start. That's what we're digging into today. This is

Brandi:

get to the point.

Andy:

I'm Andy Middlemiss, and this is the Get to the Point podcast where we talk to real IT people about real IT stuff, and we try and dig in to the why behind the technology that's all around us all the time. Try to make it maybe a little bit more humor. I'll repeat myself. I'm Andy Middlemiss.

Brandi:

Well, I think you meant to say more human-

Andy:

More human

Brandi:

but we also make it more humor too. I love that you slipped it the-

Andy:

See, and last time I said more humid.

Brandi:

You did.

Andy:

Which that was also wrong.

Brandi:

Humid, humor. More human. Yeah, we're trying to make it… Yeah.

Andy:

We'll make it more human.

Brandi:

Well, hello, Andy Middlemiss. I'm Brandi Mentle, and joining us today is Jim Edman. Jim is the cybersecurity coordinator for the Department of Homeland Security's DHS Cyber and Infrastructure Security Agency, or CISA, in South Dakota. As cybersecurity coordinator, Jim works with critical industry sectors across the state on cyber risk management and improved cyber security hygiene. Prior to joining CISA in 2021, Jim worked with the South Dakota State Government and the Bureau of Information and Telecommunications, with experience in applications development, networking technologies for state government, K12, and higher education. Jim served as chief information security officer for the last 13 years, establishing operational, strategic, and collaborative platforms to successfully safeguard constituent and government data. He also served as the broadband manager for the Connect South Dakota Project to bring high-speed broadband to every South Dakotan. Other positions include deputy chief information officer and acting chief information officer. Woof. Jim, welcome to the show. Tell me something good.

Jim:

Well, thank you. Well, something good, uh, for today, it's, uh, election day.

Brandi:

Correct.

Jim:

So hopefully you're, uh, practicing your democratic right to, uh, vote. And, uh, tomorrow, hopefully no election ads. So how about that, you know?

Andy:

A fresh start.

Brandi:

Amen. Yes. Yes. Mm-hmm. I love that.

Jim:

Yeah. And then simply being the fact here, you know, that, uh- I'm gonna talk with Tom, and I think you should rename the show Andy and Brandi rather than Get to the Point. I think that would have a much better marketing ring to it there.

Brandi:

I don't know about that. I appreciate that. Jim, today, obviously we're digging into a powerful resource that kind of gets lost in the alphabet soup of government agencies, right? CISA. And I pulled some, what I think are facts, but, Jasmine's gonna fact-check me for sure. All right. CISA is the Cybersecurity and Infrastructure Security Agency. It was officially established on November 16th, 2018, when President Trump signed the Cybersecurity and Infrastructure Security Agency Act of 2018 into law. Before CISA, from my understanding and my research, the functions were handled by the National Protection and Programs Directorate, NPPD, and branch within the DHS in 2007. Following a massive office personnel management breach where 22 million federal records were stolen, it was evident that changes needed to be made. Is that all true?

Jim:

Yes. So far you're spot on.

Brandi:

Okay.

Jim:

Absolutely.

Brandi:

So my research… All right, good. Thumbs up on that. Jim, in plain terms, tell us what you do and what CISA does and kind of what the functions of your, that particular agency is meant to do.

Jim:

Our motto is defend today and secure tomorrow. And whether that's from a cybersecurity perspective or a physical security perspective, we work with critical infrastructure organizations to improve their resiliency against those types of attack, whether physical, again, or cybersecurity. And truly that in a nutshell, just to help folks get better. You know?

Brandi:

I love that. So, it's also my understanding that you guys work both on the private sector and the public sector. Is that correct? Yes. Okay. so tell me a little bit about what you do with, like, cities, counties, schools, small to mid-size organizations. Tell me a little bit about that.

Jim:

We work with folks from a strategic and a tactical perspective to get them better. We do risk assessments. We have ongoing technical assessments that we do for folks. We deliver presentations. We do education. You know, like I mentioned this morning, working with a small city doing an assessment for them, working with them and their IT provider, to improve their cybersecurity. We can do it in a lot of different ways, but that kinda summarizes it, technically, strategically. Making notifications if we see something from the internet. You know, everybody's connected to the internet these days. If we see vulnerable hardware or software, we'll pick up the phone and give them a call. Hopefully they'll take the call. Most folks will answer and listen to us sometimes. Folks just hang up on them. I'm gonna reference this next time. Say, "You know I'm a Homelander, okay?"

Brandi:

You should listen to me.

Jim:

So you know, just a variety of things. The price is right. All of our services are taxpayer-supported and what we can do to help folks get better. Mm, so that's it in a nutshell.

Brandi:

Awesome. All right. Well, we just had a pause, but I think I was saying it's very important that we continue to help organizations as they defend against the common threats and the ever-evolving threats that are out there. I also did a little bit of research on some partnerships that you have. One strategic partnership stuck out to me, because we're actually gonna be interviewing someone from this particular organization, but Dakota State University. I think you guys have a unique partnership with them. Can you describe what that partnership looks like?

Jim:

Yeah, absolutely. You know, as everyone knows, DSU's the premier cybersecurity university in the area-

Brandi:

Correct, yep.

Jim:

If not in the country. And they have some programs that our services just fit well into. one of them is something called Project Boundary Fence, which is a penetration testing service funded from the Office of the Attorney General to DSU to work with cities and counties to do penetration testing of their networks. We partner with them as we provide the strategic risk assessment as part of that, and then we have an ongoing free vulnerability scanning service that we do for thousands of organizations across the country, probably between two hundred and three hundred here in South Dakota. Do penetration testing every week, send them a report, and identify any vulnerabilities that may be within their hardware or software. So that's the Boundary Fence program. Secure SD program was funded by Senate Bill one eighty-seven from the legislature, two years ago, provide seven million dollars in funding for cities and counties to improve their cybersecurity. So between the Boundary Fence and our assessments, if we identify gaps or opportunities for improvement, Secure SD program can come through and fulfill those, fill those gaps. The last piece of the puzzle is their Cyber SAFE program, and that targets small businesses the same thing that, Boundary Fence does, and there are parts of it, of SecureSD that they can fund it also, where they will do penetration testing for small businesses. And so we've been fortunate. I've had a long-term relationship with Dakota State going back 25-plus years. And, as you know, relationships get things done here in South Dakota. And so just building on that history, these programs fit very well together to, again, help our critical infrastructure get better at protecting themselves.

Andy:

And all of that's-

Brandi:

Love that..

Andy:

kind of just available for the asking, basically for businesses.

Jim:

It's probably a two-minute sign-up on a website. You know, it's very easy, very straightforward to get registered for the programs.

Andy:

Yeah.

Brandi:

I love that.

Andy:

Very cool. Great, great service. So Brandi was kinda talking about just sort of this ever-evolving, you know, threat landscape in the whole, in the whole cyberspace. Obviously, AI is just this, you know, big behemoth thing that's going on right now and moving very, very quickly. But it also occurs to me that a lot of the breaches that we see really were just kinda old-fashioned, old-fashioned hacking kinds of stuff. what are you seeing, and how do you, how are you seeing this balance? Or is there a shift, toward AI as far as being a real practical tool for the, bad actors versus- social and phishing and vishing and all of the traditional stuff?

Jim:

Well, the timing of that's very good, Andy, in that, the Verizon Data Breach Inve- Investigations report just came out last week, which is kinda the gold standard in industry reporting. Yep. You know, there's lots of reports out there. the DBIR has been around the longest, okay? And a few of the interesting statistics that came out of that, for small and medium-sized businesses, the Most common method used in breaching is what they're calling, system intrusions or lack of patching, lack of software updates, you know, vulnerability management is a challenge, you know, when updates are coming out multiple times a week. Microsoft Patch Tuesday, you know, may end up being every Tuesday rather than once a month. system intrusion side from a small and medium-sized business perspective is really the biggest challenge. Now, you still have social engineering, okay? And you still have, you know, websites and web application attacks that occur. but that vulnerability management is really number one. Okay. Now, if you twist that and put, throw the AI angle in there, phishing is really the number one use of AI in eliminating those grammatical errors, those spelling errors, those things that are easy to spot in getting a message and looking at it and really making that Spidey sense of yours-

Andy:

make it more credible… Jim: more sensitive. Yeah. Mm-hmm. But AI in regards to phishing, and then simply the fact of what they can do from a system attack perspective is really where the, AI's being used at these days. Yeah. Probably volume and repetition, and it's a lot easier to do without-

Jim:

Well, it's human intervention, you know, you don't have to be a, geek anymore in order to generate a cyberattack, you know?

Brandi:

Yeah.

Jim:

You know, you used to be super smart, and then script kiddies came along, and now we have AI where it gen can generate an attack fairly easily.

Andy:

Yeah, crazy evolution of things. So what about just- Let's talk about the email stuff. You said that's obviously still very popular and people, tricking people into wiring money somewhere or changing an account number or things like that. How common is that? Is that still one of the main attack vectors, or is that kind of changing as well?

Jim:

That's what we see here in South Dakota.

Andy:

Okay.

Jim:

That's the, where we have most of our incidents is through business email compromise, phishing. You know, an account gets compromised, and so somebody begins impersonating Brandi, sending messages as her. Responses come back to Brandi, but in a folder that she's never gonna look at. so it's truly Brandi's email box, but it's not Brandi sending the messages. And Email compromise phishing is really the number one issue that we see here in the state these days.

Andy:

Yeah. Okay. Yeah. Very interesting. I'm curious because, we've been in the IT business, we, kinda sound like a broken record, right? I mean, we're saying the same things over and over and over and over and over, and it just, it feels like people still aren't acting. Companies still are leaving a lot of vulnerabilities out there. Why do you think the message just doesn't land?

Jim:

It's not gonna happen to me, you know?

Brandi:

Sure.

Jim:

you know, it might happen to those guys over there, but I don't think I'm smarter than that. nobody knows me. I'm too small. And really, it doesn't matter. I mean, whether you're a small city, county, or you're a large healthcare system or, state government, you're a target. And they don't care if they're gonna steal a few thousand or hundreds of thousands or millions. whatever they can steal, they're going to steal. And so you just have to, you have to change your mindset a bit. And if you're gonna use technology, in this century, you have to invest in it in a regular basis. You have to protect it. You have to understand that there are risks, and you have to take steps to mitigate those risks, understand what the threats are, okay? The glass isn't always half empty, but you have to understand what the threats are and how do you go about mitigating them.

Andy:

Yeah. Yeah. So I would imagine if you look at sort of just the population of businesses, you got the very large businesses. They probably have more resources. They probably take more care, but they're big targets also because of, potential bigger paydays versus, your small business probably doesn't have a lot of, things in place to take care of them, but they're a smaller target, but maybe it's a volume .Play there where do you see kind of the distribution of attacks across the very small to the very large business range?

Jim:

The small business, you'd be surprised how much money may roll out of a small business, small city, or small county. We had an example couple weeks ago of a school district, not in South Dakota, but a school district, suffered a business email compromise, three and a half million dollars.

Andy:

Ouch.

Brandi:

Oof.

Jim:

Okay? Three and a half million dollars, doesn't matter what size organization you are, that's gonna leave a mark.

Brandi:

Yeah.

Jim:

You know? So the size of the entity is not as important as what is the type of effort that it's going to take in order to scam them. Mm-hmm. And that effort really, with AI, with vulnerabilities, and those sorts of things, becomes easier on the cyber threat actor's end of it. Maybe a short, shorter game, right, than- Mm-hmm.

Andy:

Yeah. Makes sense. Okay. Yeah.

Brandi:

Wow. You know, coming back to just some of the blocking and tackling that you guys do, I think of this analogy of, like, I have a car, right? I take my car in for regular maintenance. Well, a lot of people just get in their car and they just drive it around, right? And until they have something go wrong and have to feel that financial sting and some other consequences, not being able to drive to work, those kinds of things I imagine that that's, you know … again, that analogy always sticks in my head when I think of, like, why you would want to continue to do vulnerability assessments and penetration tests and just, you know, just the checks and balances, right? Can you tell me, is there a gap between what organizations think they need versus what they actually need when it comes to security?

Jim:

Uh, absolutely. The, in a lot of ways, some of the things we do are just like a second opinion from a doctor, okay? Or a mechanic. Do I really need new tires? You know, do I really have to change spark plugs and those sorts of things? getting another opinion is always a good idea. Having somebody give a different perspective on occasion can go a long ways. I mean, you have your tools, your, expertise, your standards, your practices that you do things on a regular basis, and, you know, on occasion, we just need to have somebody come in and take another look at things and say, "Hey," you know?"Have you thought about maybe a different color?" Or, "Have you thought about maybe, "Do you do you really need… have you done gap analysis? Have you done risk assessments? when's your last penetration testing? When, have you tested your backups?" Everybody does backups. Okay? How do you know your backups work?

Brandi:

Oof. Just gave me chills. we do. We do know when our-

Andy:

A lot of people don't know that their backup's working.

Brandi:

Yeah, that's- Yeah.

Jim:

I mean, and everybody trusts their backups, you know? And there's a lot of very good backup products out there, okay? But one of the greatest gaps that I see is that folks don't do a restore test. your financial system may be the most important thing that you have in your office, and you back it up multiple times a day. Well, how do you know that that backup has the transactions that are working?'Cause if you get hit with ransomware, you're going to bank the restore of your business on that data being accurate. How do you know if you haven't tested it lately?

Andy:

So from a testing-

Brandi:

Oh, that's incredible… Andy: standpoint, as can restore as to, to the fact that you can store it.'Cause if you can't restore it- Sakes backing it up in the first place doesn't really matter, does it?

Jim:

No, it doesn't Yeah And, unfortunately we've come across instances where an organization's, "Nah, I'm not worried, I have a backup." Well, you're partially there, but let's finish the game and make sure that that backup is in great shape.

Andy:

Yeah.

Brandi:

Yeah. Wow. Incredible.

Andy:

And the rest of the story.

Brandi:

Yeah. I love that. That's, what great insight. Is there something that you wish leaders understood before the breach happened instead of after it?'Cause I imagine that you probably come in contact with people that have been breached and, you know, is there one thing there, one idea, concept, advice that you'd give to somebody to think about as a leader before that breach actually happens?

Jim:

You invest a lot of money in IT, okay? but it's not a one and done type of expense. It's an ongoing… You know, you mentioned your vehicle analogy earlier. You have to put fuel in it, you have to change the oil, you have to change the tires. If you have a electric vehicle, you gotta plug it in. Maintenance is expected, okay? And IT is no different. IT is an ongoing investment, and the threat landscape changes regularly, okay? So you have to be able to adapt to that, and that takes an investment of time, money, and expertise. And upfront you said that, most organizations, small and medium-sized organizations, don't have their own security people, and they rarely have their own IT people. So you have to build a good relationship, a good partnership with somebody that you trust that's going to be there and keep you well-protected. Mm. It's, that simple. You have to look at it as a regular investment and not an expense.

Brandi:

I love that. Yeah. I love that.

Andy:

Great insight. I've been excited about this episode because I think this really is something that's just a value add to our listeners and subscribers, and again, a free service that they can take advantage of, that adds, a lot just in the ongoing maintenance of their cyber approach.

Jim:

What we need to get people to understand is that when you go home at night, you close the garage door. You know, when you go to the store, you might lock your doors, roll your windows up. If we do those same fundamental best practices with our computers, with our networks, we're gonna be well-protected. I take the view that in cybersecurity, the glass is half full. You know? It's not a completely negative topic. Okay? If you do your best practices, you have your antivirus, you have your firewalls, you do your firewall audits, you do tabletop exercises. you go through the list of best practices, passwords, you're gonna protect yourself. Use multi-factor. there's a long list of best practices that are not complicated. if you do them, you're gonna protect yourself and your organization, you know? If you leave the garage door open, how come you're surprised when your tools are gone the next morning?

Brandi:

Right.

Jim:

Well, maybe I should have closed the garage door.

Andy:

Yep. I like that. Maybe I should have patched my software.

Jim:

Exactly. Mm-hmm.

Andy:

So let's, shift for a second because I think that's, actually a great segue into talking about the whole cyber insurance space. I think we've got a, we've got an upcoming episode on cyber insurance very specifically, but I wanted to, just dive into that a little bit, get your perspective on things. So, and I'm gonna throw a few, little bit of research stuff at you and see, if you validate it or, disagree with it. So I've heard that there for a while, cyber was getting really hard to get and really expensive, and I've heard that's for a variety of reasons, is becoming a little bit more affordable if you are well-prepared, and you have a plan, and you're well-protected. And some of the things that you just mentioned, MFA, endpoint protection,

Jim:

Training.

Andy:

Those kinds of things, that, if you don't have that, you're … It's probably hard to get, or it's gonna be very expensive. But if you're protecting yourself very well, it's an affordable thing, and I heard some stats that, you know, in, across the business sector, those who have it tend to budget, somewhere between a half percent and 1% of their annual revenue toward cybersecurity insurance. Curious if you have any perspective on that. And then I also read some stats around the small business space 'cause I kinda keep coming back to that. It just seems like they're a unprotected, area. And I read stats that say, anywhere from, well less than 50%, 35 to 40% of small business, depending how you define that, even have cyber insurance. Much more likely to see cyber insurance plans in the larger organizations. So there was a lot I just threw at you. So just commentary about that in general.

Jim:

It was 2016, and, the lieutenant governor at the time, Matt Michels, came to me and said, "Should we have cyber insurance?" And, so we did some research, and at that point in time, the questionnaire that came from the cyber insurance company, 25 questions, of which three, three questions had some semblance of cybersecurity related. Okay? The rest of it had nothing to do with cybersecurity. Interesting. Yeah. Today- And yet on a cyber insurance application. Exactly. Fascinating. And today, all of those things that you just mentioned, training, MFA, antivirus, those things are all mandatory requirements if you're going to get an, insurance policy. And if you don't have them in place, then your policy can be invalidated. So the industry has gotten much smarter in dealing with it, and as you mentioned, the price, it went from a bell curve up here, and now it is turning to come down a little bit, because organizations are getting better, at protecting themselves. The Verizon report ransomware, 69% of the ransomware incidents last year, the company did not pay the ransom.

Brandi:

Yep.

Andy:

That seems up from-

Brandi:

Read that too, yeah… Andy: prior years, right?

Jim:

Yes. That- Yeah. That's a much- Yeah improvement in that area. And the actual ransom amounts are going down a little bit, so people are getting better protected. Cyber insurance is like any other type of business insurance, you know? It's a good plan, okay? But you have to understand, you just don't sign up for it and forget about it. It's just like car insurance, home insurance, everything else. There are safeguards that you try to build into your business, so that you never have to make that call to your insurance agent and say, "Uh, I got an incident."

Andy:

Yeah. Well, and I guess that sort of, maybe answers to some degree kind of my next question, which was, you know, you've only got so much budget for this kind of thing. I've got to protect myself. I've got to have things in place. I've got to have processes, tools. On the other side, I've got to have insurance. I can't, really do one without the other, right? you gotta have a balance there. any advice- just for, you know, the small to medium businesses as far as how should they approach that from a budgetary standpoint and balancing protect myself versus insure myself?

Jim:

What's the risk to your business? That's a question you have to answer in regards to the, amount of IT that I have integrated into what I do. How long can I afford to be down? What's the value of my customer base and the information that I gather from my customers? Your CRM system, customer relationship management system, what do you store in that system? And what happens if it were to be stolen by, a threat actor, posted on the dark net, start, and being sold? you have to look internally and decide how valuable are those things, and is there a monetary value to put on them? And then do I need to go and get additional insurance to protect it? Obviously, you're gonna have deductibles with any insurance policy. You've, can you afford it on a annual basis? Those are not easy business decisions, but you really have to take an internal look at what you have. What is the gold in your vault that you're trying to protect? Do you have intellectual property, customer information, financial information? All of those things, play into your end decision whether you need insurance or not. It's another investment.

Andy:

And I know probably every policy's different, every company's a little bit different, so in general real high terms, what does cyber insurance cover and what does it not cover if I had cyber insurance policy?

Jim:

What do you want it to cover? I mean, it can cover as narrow as you want it to be or as wide as you want it to be. You can include phishing, you can include, vulnerability attacks, you can include ransomware. There's a wide variety of things other than, acts of war are not covered.

Andy:

Okay.

Jim:

Which gets into a complicated situation when you get some of our foreign nation actors and what's going on in the world these days, and that particular clause has been invoked-

Andy:

Interesting… Jim: by insurance companies So getting a policy is one thing, but again, just like our home, our auto insurance, et cetera, what does it cover? What doesn't it cover? And having that explicitly stated in there. I mean, you have all of your IT that you're using, okay? Is credit monitoring included? Is it gonna cover your customers? The spectrum of IT services is what you're gonna look at, and obviously there's a price to be paid for each one of those items. A phishing incident, business email compromise, software vulnerability, website, you know? Yeah.

Jim:

ransomware. All of those types of attacks have a price to be paid for.

Andy:

Sure. Yeah, a coverage and, you… Nothing's for free except for your services apparently. So how's that work with a with kind of a layered approach? I mean, it seems like it's just kind of one more tool I can put in my toolbox.

Jim:

Yeah, that's a g- You know, cybersecurity is all about layers of security, okay? And whether it's a weekly scanning of your firewall, monthly looking at your website for software vulnerabilities, strategic risk assessments that we do, presentations. There's a couple of groups here in South Dakota that we partner with. South Dakota Cyber Council and the FBI InfraGard are great organizations where you build relationships and you share information, what you're seeing, notifications. All of those tools in the toolbox are what we use to help folks get better to improve their resiliency. We don't wanna see any organizations in the state on the front page of the newspaper or the news leading with another cyber attack, another loss of funding.

Brandi:

Absolutely. Wow. Yeah, and we actually, you had connected us to a cyber insurance expert, so I'm excited to kinda dig more into that too in some future episodes. But, so, while I was doing digging, about CISA, I did notice that there are a lot of resources out on your website. So, before we kinda wrap up our episode here, there are free resources out on the website, correct? Yep. And people also can get connected to the services that you guys offer as well. So you wanna briefly touch on that, before we kinda wrap up here?

Jim:

Yeah, we've, got a lot of information on our website, cisa.gov, C-I-S-A dot gov. if you search for Region 8, that's the region that we're in, North Dakota, South Dakota, Montana, Wyoming, Utah, Colorado. just search for Region 8. At the very bottom there's an email address, and send a note to it, or make a phone call to Central, the phone number that's listed there. And, it'll end up in my inbox, and I'll give you a call, and we'll see what we can do. Give you some background, and hopefully come out and, help you get better through a variety of different things that we do.

Brandi:

Jim, you've always been somebody who I've admired, just w- your work at the State, your work here. You're passionate about cybersecurity. But I think the, thing that sticks out the most is your passion to help people. And, you've said it a bunch of times during this, of just helping you get better. And so thank you for your work. Thank you for just this commitment to helping people get better. We, genuinely appreciate it. We certainly appreciate you being here, and your time today. Th- this just stuff is so important, and if we can reach one person and, again, help them be better, I just, I feel like we're, passionate about that too. We're gonna have a little fun. So we've asked you a lot of serious questions, Jim. And you know Andy and I, especially Andy, is very unpredictable. But we have a golden wheel. I don't know if you've wondered what that is for. And so we kinda, we're gonna shake that up a little bit, and we're gonna pull out a question, and it's kind of a fun question. And-

Jim:

Maybe. We'll see.

Brandi:

Maybe, yeah. And so you get to choose. You can answer it just on your own, and if you want us to have to answer that question too so you're not the only one on the hot seat, we certainly can answer it as well. But we are gonna pull a question out of our fun little… Yeah. All right. And we're gonna just pass that over to you, and read it out loud and answer it.

Jim:

What do you hope for?

Brandi:

Yeah. What do you hope for? That's a great one.

Andy:

Short and sweet. I thought there was more to the question. No. Okay.

Jim:

I would hope for, in today's world, a civilized dialogue and communication. How about that? I

Brandi:

love that.

Jim:

I was listening to a podcast on the way up, Willie Geist, he's a NBC guy.

Brandi:

Yeah, yep.

Jim:

And he was doing a interview with Ryan Reynolds. You know Ryan Reynolds-

Brandi:

Yep.

Jim:

The famous Deadpool guy, along with everything else. And, Ryan Reynolds made the comment, and he owns a soccer team in Wrexham, and, he made the comment that when, fans come to you know, the soccer match, doesn't matter what their background may be, but they're both wearing the Wrexham jersey. Okay? I mean, we go to sporting events, and whether it's here in town, Minneapolis, Omaha, wherever, and we put on our, jerseys and go and cheer for our team. If I'm sitting next to Brandi or Andy, I don't know what your background is, but we have this commonality that, hey, we're here cheering for, you know, the Twins, or we're here cheering for the Stampede or whomever it may be, or our high school team. You know, we have 80, 90% commonalities of what we hope for here. And yeah, we have our differences, but, I would just hope we would understand that, we have far more in common than we do in differences. And, maybe we can get back to focusing on those positive aspects and, not so much on the negative, you know?

Brandi:

I love that.

Andy:

Wow. That was a fantastic answer.

Brandi:

I'm not gonna answer that question and i'm not gonna have you answer that one. That was a great way to end.

Andy:

Can't top that.

Brandi:

No. That was awesome. That's incredible.

Jim:

You put me on the spot.

Brandi:

I did. Well, that was our goal. That was our goal.

Jim:

That came out of nowhere.

Brandi:

I'm assuming people can find you LinkedIn or just maybe through the the website, okay?

Jim:

Yep.

Brandi:

All right. Well, if you wanna hear more from us, from Get to the Point, hit that subscribe button wherever you're listening from. Share with a friend, share with a colleague. Leave a review. If you have an idea about an episode that you wanna hear or a subject matter that you're, like, dying to know about, please, we would love to unpack it and dig into it. I'll let you-

Andy:

Well, thank you… Brandi: bring us home, sir. I appreciate that. Thank you again for being here. Always great to see you. And remember, we are always here to help you get to the point. Have a great day.