Cybersecurity – Protecting your Business and Yourself with Paul Laudanski of Onapsis

11 Nov 2025 · 33 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Podcast Episode Notes: Cybersecurity – Protecting Your Business and Yourself with Paul Laudanski

Episode Overview In this episode of the Builders podcast, host John Busby interviews Paul Laudanski, Director of Security Research at Onapsis. The discussion centers around the evolving landscape of cybersecurity, including key vulnerabilities, the impact of artificial intelligence (AI), and practical advice for both businesses and individuals on strengthening their cybersecurity posture.

Key Topics Discussed

Definition of Key Concepts

  • Zero-Day Vulnerability:
  • A software or hardware vulnerability that is unknown to the vendor.
  • Malicious actors can exploit these vulnerabilities to gain unauthorized access.
  • Offensive Security Research:
  • Conducting research to discover vulnerabilities for the purpose of responsible disclosure and remediation.
  • Involves testing software, reporting findings to vendors, and aiding in the patch creation process.

Current State of Cybersecurity

  • Rise in ERP Attacks:
  • Increased attacks on Enterprise Resource Planning (ERP) systems, specifically targeting applications like SAP.
  • Attackers have shifted from inquiring about ERP systems to actively exploiting them, resulting in significant breaches.
  • Threat Landscape:
  • A notable surge in zero-day attacks has been observed, with hundreds of companies experiencing breaches due to vulnerabilities in ERP systems.
  • Criminals are increasingly sophisticated, leveraging critical business information for ransom or sale.

Why Vulnerabilities Exist

  • The complexity of software development, combined with numerous integrations and dependencies, makes it challenging to eliminate vulnerabilities.
  • Continuous maintenance and monitoring are required to manage software security effectively.

Impact of Artificial Intelligence

  • AI can enhance efficiency in identifying vulnerabilities and understanding software use cases.
  • However, malicious actors can also leverage AI to exploit vulnerabilities more effectively.

Cybersecurity Investment and ROI

  • Investing in cybersecurity can have positive returns, such as:
  • Lower insurance premiums.
  • Enhanced brand reputation and recognition.
  • Avoiding regulatory fines as compliance becomes more stringent.

Practical Cybersecurity Tips for Individuals

  • Patching: Regularly update all software and devices.
  • Password Management: Use unique passwords for different accounts and consider using a password manager.
  • Mind Social Media Sharing: Be cautious about sharing personal information that could aid attackers.
  • Multi-Factor Authentication: While beneficial, remain vigilant as attackers have found ways to exploit MFA systems.

Career Insights in Cybersecurity

  • Advice for Newcomers:
  • Cultivate passion, curiosity, and a proactive attitude towards learning.
  • Engage in hands-on learning, such as self-driven research and experimentation.
  • Key Attributes:
  • Three A's: Attitude, Aptitude, Approach – essential traits for success in the field.

Cultural References

  • Paul draws a parallel between cybersecurity and The Lord of the Rings, emphasizing themes of trust, cooperation, and the importance of community efforts in achieving positive outcomes.

Conclusion The conversation highlights the urgent need for robust cybersecurity measures in today's digital landscape. Organizations and individuals alike must remain vigilant and proactive to navigate the complexities of cybersecurity threats effectively.

Additional Resources

  • Business.com+: A free membership program for small business decision-makers that provides access to expert advice, pricing negotiations, and vetted solutions.

---

Listen to more episodes: [Builders Podcast](https://plinkhq.com/i/1608075598?to=page)

Watch on YouTube: [Builders Podcast Channel](https://www.youtube.com/@builderspodcast)

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00On Builders, I speak with leaders and entrepreneurs about building your business and career. and today I speak with Paul Ledansky. He is the Director of Security Research at Anapsis and we talk about cybersecurity. We discuss the risk to businesses and how to protect yourself as a business as well as tips if you're a consumer or if you wanna get into the profession. Paul also gives me an unexpected and very thoughtful answer to a pop culture question I ask at the end. Thanks for listening.

0:35Hi, Paul. How are you? Good to see you. Hi, John. I'm doing pretty good. How are you? I'm doing good. And for those that are watching on video, you can see when we're recording this right around Halloween season, although you'll probably be listening to this in November. Is the spooky season a fun one for you, Paul? It always is. We've got a lot of families in the neighborhood that put up a lot of Halloween decorations. And so we have a lot of trick-or-treaters. it's always fun and interesting to kind of dress up and to participate when the kids are coming up to the door. Yeah, no doubt. And we were talking off camera prior to starting.

1:13We're both in the Seattle area and Halloween's, it's a really good season because it's usually a little wet. It's dark. It's kind of spooky outside. The leaves are falling. So it's a good place to live for Halloween. Especially today with all the rain coming for the next week. Yeah, yeah, totally, Totally. Well, we're going to delve into cybersecurity today. And I want to start with a few definitions because we haven't talked about this subject recently on the pod. So I'm going to ask for a couple of things that are right in your wheelhouse. What is a zero day cybersecurity vulnerability? And also, what is offensive security research?

1:50Maybe let's start with those two things. Sure. Sounds good. And again, thanks for having me here, John. I can be able to join you today. So I've been practicing cybersecurity for a long time, and there's been a lot of changes throughout that time. Today, there's certainly a lot more words, there's a lot more processes, there's a lot more things in place, because we've been learning and iterating throughout the years. When we take a look at answering that question, what is a zero day in cyber, cybersecurity. It happens to deal with either software or hardware that there's some type of particular vulnerability that that vendor doesn't know about.

2:30And so in that particular case, if a malicious actor actually finds that zero day and doesn't warn the software or the hardware vendor or anyone that's using that application or that hardware, that malicious actor can go ahead and use that vulnerability to gain access into a system. Now, offensive security. So that's something that we do in my wheelhouse recently. We conduct those types of behaviors, essentially, for the purpose of a positive outcome. So we will work with software and try and understand what particular zero days might exist in that application. And then once we discover those zero days, we go ahead and do a coordinated responsible disclosure with that software vendor and say, hey, here's what we found.

3:21Here's the mechanics. Here might be a proof of concept so that we can help them try and find what's the actual source of this zero day that they can go ahead and explore. Hopefully find where the bug is or try and find a way to remediate the vulnerability. and then that's what sets them to eventually create a patch and that patch gets released. Once that patch gets released, there's usually a score that's assigned to that that helps cybersecurity organizations understand the severity. Like, is it critical? Is it high? Is it a low priority? And that helps them to prioritize how quickly they need to potentially release that patch.

4:03Did you know that Builders is sponsored by business.com? I'd love to tell you about a new free membership from business.com for small business decision makers. It's called business.com plus, and it's designed to address the pain in selecting new products and services. What is the pain you might ask? It's things like knowing which vendor is best for your specific business, negotiating pricing, having access to someone who can answer questions for you. The new membership, Business.com Plus, handles all of that with a dedicated advisor, pre-negotiated pricing, and solutions tested and reviewed by experts.

4:40Check it out at business.com slash plus. That's business.com slash P-L-U-S. You know, I'm going to ask you about a pop culture later, but it reminds me of the movie Sneakers where Robert Redford's team, they're like hackers, you know, hackers for good. trying to solve vulnerability. And that's a 30-year-old movie. I know things have evolved a bunch. Your company focuses in the world of ERP and SAP. When it comes to things like zero-day attacks and just attacks in general on companies, has this been a big year for that? Is this problem increasing? How many attacks are there? Curious if you could sort of give a state of the union for the audience on this.

5:24Yeah, thanks for that opportunity. Over the past couple of years, we've been doing some additional research into the threat landscape and into what the threat actors are doing. And what we found a couple of years ago was that they were understanding there's this thing called ERP, which is enterprise resource planning. It's essentially applications that contain business critical information for any business. It can contain your HR information. It can contain your financials. It can contain information for your supply chain management, so on and so forth. But it's that information that threat actors over the past couple of years have found as they've been getting access to it is what is this they've been asking?

6:10and they've been understanding, wow, this is vital information for companies. And if they can hijack this information, either hold it as a ransom to these companies or potentially sell it to other criminal entities that can use that information, that's essentially what we found is that they're very much interested in that information. But this year in particular has shown that these threat actors have gone from, what is this to now we're gonna take advantage of it. So this year, what we saw at the beginning of the year was there was threat actors that had essentially executed a zero day attack against this application in the ERP, which is called SAP.

6:55and there's a lot of companies that use SAP globally, but essentially this zero day allowed for threat actors to gain access into these companies that were running a compromised SAP server. SAP was not able to go ahead and issue the patch because SAP did not know about this attack, right? This is that true use, malicious use of a zero day that happened earlier this year. and the zero day allowed these threat actors to gain a foothold into these servers. They're able to install web shells. They're able to go ahead and run remote code execution. And that led to essentially companies were breached, right?

7:39Their applications, their tools that they had in place, it was unable to detect the zero day. So what we found throughout the course of the next few months after the zero-day attack started against all these companies, we partnered with incident response companies who had their customers that they were servicing and responding to these incidents found that there were literally hundreds of companies that were targeted by the zero-day. So it was a pretty big year. It was probably the biggest year ever in terms of attacks against ERP for a zero-day. And it's interesting, right? We've gone from a time period of these nation state actors, these advanced attackers did not know about ERP to a couple of years ago, they started to understand, hey, what is this?

8:31Oh, this is business critical to this year. The cat's out of the bag. We've gone beyond the crux. There's no going back. These criminals know and they've taken advantage of these companies and they're still doing that today. We're seeing companies that are being targeted and it's shutting down a whole supply chain. It's shutting down whole industries because companies are being targeted through this zero day. I think it begs the question, at least for the non-technical or non-expert hosts like me, why are there so many vulnerabilities? like um why are there so many ways you could you know uh you know i could figure out a way to access access the systems of another company like and like why hasn't that been figured out by engineers and then kind of a second second part of it it's an obligatory question about you know generative ai and agentic processes given where we are in today's today's world it strikes me that so many more people have access to code and have access to systems that can do stuff on top of HR software, for example.

9:40And how does that impact your line of work? And does it increase the risk of cybersecurity incidents, in your opinion? Well, the first question is an interesting one. I think we can just take a look at physics in general. In physics, we see a lot of things that just get broken down over time, whether it's through our own mitochondria, right? That's aging. Aging is the breaking down of cells. It's the breaking down of just the cells within our body. And we see that just in general in the universe. And the same thing applies to the software. You can write software with a particular business use case or a particular goal because there's so many different interactions, there's so many dependencies with libraries and integrations.

10:30It's difficult for one particular developer to account for a whole mesh of integrations and software. You've got an operating system that it runs on, you've got the cloud that the code might be running on. You might have these integrations that aren't patched necessarily. So there's just this huge complex universe. And, and that's difficult, right, to, to kind of control. So it's important to have processes in place, right, just like in regular life, when in our lives, you have the maintenance of cars, right, you don't want your car to break down. So you take it into a mechanic, you want to have a strong heart.

11:11So you, you know, you may run, you may eat healthy, you may drink a lot of water, and the same applies to software to hardware, you want to go ahead and make sure that you're patching, that you have processes in place that are monitoring for potential misuse of an application that you might have installed. But you also want to make sure that you're going in for those doctor checkups, right? You want to make sure that you've got an expert that's coming in and checking your installation. You want to make sure that you not only create that code and deploy, but you're testing that you are bringing in penetration testing services.

11:49You're doing code audits. It's not a one and done type situation. So software development as in life requires continual maintenance and continual monitoring. And so far as AI is concerned, I think that there's lots of different use cases, right? So because there's a lot of demand for features and for code and for updates and for patching vulnerabilities, we look at using the tools that we have in order to create efficiencies, right? Right. And part of the use of the AI tools can help with those efficiencies to be able to find those bugs. Right. To be able to take a look at the use case, to be able to take a look at how it's actually being used.

12:39Is it being used in the way that it was intended? And can AI help us to see the other side, which is how can that code be used in ways that we didn't think? Right. So you've got AI that you can use for that. But you also have people that you can use for that, too, right? And we get back to the penetration testing. Now, let's go over the other side of the fence to the malicious actors. Same type of scenario. They can go ahead and use those AIs to take a look at the code, right? They can access the code. They can put AI use cases against it to be able to help them find and locate bugs in the kernel.

13:20Bugs that could potentially be hard for software vendors to patch quickly. And so that bug can be maintained for a long period of time. So there's good and bad with any type of technology. And it's always that push and pull between the white hats and the black hats. Totally. And, you know, I like how you phrase this as like maintenance. That makes a lot of sense to me because, you know, investing in cybersecurity costs money. Are there other ways that businesses can look at new investments in cybersecurity as positive ROI? Such as like reducing, you know, maybe you do more proactive cybersecurity stuff, your insurance goes down, that kind of thing.

14:03Absolutely. A long time ago, it seems that people knew about the business if there was something negative, potentially, and it went up on the news. Or there might be something positive and the stock is going up and there's a lot of celebration around it. today because of social media, it's very easy for an organization to be plastered out there and then everyone's going to know about it, whether for good or for ill. And so that speaks to brand recognition, brand protection. So when you have cybersecurity investment, that's another positive ROI is that you can get ahead and put yourself in a position where if something does happen, you can position yourself hopefully from a positive brand recognition.

14:51And part of that is that maintenance concept, right? So you want to make sure that you're monitoring brand domain. You want to make sure that your domain is not being maliciously used by threat actors in a phishing campaign or in a social campaign. Certainly last year, we were talking about the use of deep fakes. Now we're seeing the rise of generative AI being able to produce pretty realistic videos, pretty realistic content that makes you potentially question what's being said. And so I think it's more important than ever now for companies to continue to invest in cybersecurity because not only does it help with insurance, not only can it help with brand recognition, but it can also help with staving off fines.

15:39There's a lot of regulation now that if you don't have that investment, a company can have a lot of fines. And the officers of the company too can be personally held liable if cybersecurity is not taken into serious consideration. So that's just a couple extra that kind of come to mind. You certainly don't want to go to bed at night and then wake up in the morning and find that the company that you run has exploded because you didn't have the proper cybersecurity practice or the technology or the processes in place. And you certainly don't want to be fined by an organization because your reporting, your financial reporting has been skewed because a threat actor used a zero day to come into the system and to manipulate the numbers.

16:27And then therefore you have lost the integrity to be able to do accurate financial reporting. No doubt. No doubt about that. You're focused right now and you have been for several years on B2B scenarios. But I know looking back over your background, you spent time working on crimes impacting consumers, citizens, digital crimes, those sorts of things. I imagine among your family, you're the go-to guy when people say, what should I do? What are you telling your friends and families when it comes to tips for protecting yourself? What should people be doing in 2025 right now if they haven't already?

17:08You know, when I first started out on this, when we go back to the length of the career that I've had, there were a few key things, but I don't think that patching was top of mind. back when I first started. It was kind of like the Wild West when I first got into it. But today, certainly, patching is a big deal for anybody. It's important to patch, patch early, patch often, and patch everything that you have. And I would say password management. Do not use the same password for everything. I would say have a trusted password manager so that you can put your most complex passwords in there. And I would say that your most complex passwords are probably going to be something that is like your retirement account or your banking account, your financial account, anything that if it were compromised, it would bring a bad, a bad day for you.

18:08So I would say that those are pretty important. Um, and, and be mindful too of the information that you share. I think it's so important for people to not overshare in social media. So if you're planning on going out this weekend to a trip to, uh, to Alaska, right, we can just hop on Alaska air and, or sorry, go to Hawaii or to Alaska. Um, It's important to not put that out there because there's a lot of local threat actors that are looking for when you're not going to be home. And then they can pretty easily go on to a website, a government website that they might be able to try and find where you live and try and target your home if you're going to be gone.

18:59So I think that those key takeaways are important, right? Be careful about posting if you're going to be leaving for an extended period of time. By all means, do it, right? But after you get back, right? Share your photos if you want to. But then again, I do caution about the types of photos that you share, right? We see threat actors taking those videos, those photos, your audio, and then repurposing that for their social engineering. Scary stuff. um i think that like like uh over the last five or ten years multi-factor authentication has has been a peace of mind for me at at least are there ways that you feel like people are trying to exploit that or is there any any things we should be thinking about when it comes to two factor multi-factor authentication 100 um so years ago when i was definitely in this space I was investigating a lot of phishing attempts that criminals took advantage of the multi-factor authentication.

20:02So there was a particular overlay JavaScript application called Leprechaun that was bundled with a lot of advanced persistent malware threats at that time. And that had gone on for years and years. I was investigating these crimes for years. It was very difficult to get a handle on by AV companies, by cybersecurity companies, because essentially what would happen was that the mechanics of the attack was, and this is an actual example, there was one particular threat actor that got a hold of a financial director. And it was, you know, those late night infomercials a long time ago, you're sitting on the couch watching late night infomercial and you have to buy now, buy now, buy now because the price kept dropping.

20:47Well, it's that kind of same concept that was used during that period and it still is used today. And if you let down your guard, as the case happened with this particular example, the finance director got an email that said, hey, you owe this bill. You need to pay it right now. So the finance director opened up the email, opened up the PDF. The PDF was armed. There was no security application that told it that it was armed because this was part of the zero day, right? There's no detection of this attack at the time. And so that PDF, once it was opened, it executed another type of an attack, which caused it to go to a malicious threat actor owned website, downloaded some additional malicious files.

21:34those files executed, installed a specific JavaScript code onto the browser, and then waited for this finance director to connect into the payroll website that was used to pay everybody at the company. And so once this finance director was connecting into this payroll site, that information was no longer being sent. The login information was no longer being sent to the threat actor site because the browser that was now owned by the threat actor, unbeknownst to the victim, the victim was now, instead of being connected to the payroll site, was now connected to a site owned by the threat actor. And what have we learned, right?

22:20We have taught people when you connect to a website, when you look at the address bar, you're looking for the secure lock, right? Well, this particular attack took advantage of that. So you would go to the site, you would see that it's locked, you completely believe you're safe. But the threat actor took advantage of that was able to go ahead and get the victim's credentials. As the victim was trying to connect in, the victim is expecting a multi-factor out of band message, right? So The victim is getting this message and then inputting the message into what the victim believes is a legitimate location, but that's going to the threat actor.

23:02I've seen these attacks unfold in real time. The reason why that multi-factor information is being sent to the victim is because the threat actor is logging into that site at that same time. So the threat actor is obtaining the victim credentials, logging in, is getting the out-of-band multi-factor, putting it in, and is now logged in and is successfully moved off millions of dollars. Wow. That's a crazy story and a scary one. Just to make sure the audience is understanding what you mean by patching, that means every time your computer, every time your iPhone, anytime anyone wants to do a software update, you do it?

23:45Is that what you mean? Yes, exactly. So when you get the message from your operating system, or you get your message on your phone, or you get your message wherever as a consumer, right, and it says, hey, there's updates to your system, right? The recommendation that I always tell friends and family and everybody is go ahead and accept it and let it run its update. A lot of leaders on this podcast, guests are entrepreneurs, non-technical backgrounds. We talk about the tips, the keys, the things that got someone to advance in one's career. I'm curious about your case, analytics, intelligence, security, technical roles.

24:21What are maybe one or two things that were real big accelerants for you in your career? And what advice would you give someone who's just starting out in your field? So it took me some time, I think, to understand this. As someone who has been hiring people now for a while, I've translated my understanding into that hiring process. And so from my own journey, what I've come to understand and from similar practitioners, it's all about the attitude, the aptitude and the approach for anybody. So I've certainly not been a unicorn. A lot of practitioners that I know throughout the years, none of us have really been unicorns.

25:03Um, sure. There, there are unicorns for sure, but the majority of us, uh, we've just had the passion. We've had the curiosity and how did I show that to prior employers, to prior interviews? Um, when I wanted to get into a particular role, well, I researched it, right? So if I see a particular role, I research what it's about. What about it is interesting to me. Um, and, and I look at the company that the role is at and I do some research about that company. So A, it's showing that passion. It's showing that curiosity. If I want to get into a malware researcher role, then I'm going to want to see, can I do something like that at home?

25:43I'm going to start to research out there and see, okay, if I want to understand more about malware, oh, I see. I need to get this type of tool. I need to set up this type of system. So let me see what I can do. I might go to a retailer. I might go online and try and find commodity hardware, commodity software to get that stuff installed. And then it's a process of going to some sites where I might be able to go ahead and access some software, some malicious software for testing purposes. So there's definitely places that you can go where you can get proof of concept code or potentially the malicious code itself.

26:22And from that perspective, I would go ahead. I would get it installed. I would use the tools to try and understand what's happening. Right. So I would start teaching myself. I think that's part and parcel being the recipe to show the hiring manager and to show the recruiters that although you might not have the education or you might not have the experience, you do have something that I think has been very important in their industry, which is the grit, which is the curiosity and the ability to show that you're going to jump right in and to try and understand it, right? Because we're dealing with years and years of new technology, new solutions, new advances.

27:07And a lot of times this is much faster than what is able to be educated. So that's where I come back to, how did I get to all the positions that I've been at? I've gotten to all the positions that I've been at, I believe, because I've just jumped in, right? I didn't wait to be taught. I just jumped in to try and understand what was happening. And in doing that, I started to collaborate with new people. I started to be able to write about the things. And that helped me to better understand and to better articulate solutions and approaches. So we go back again to the three A's. I think it's important for people to have that ambition, to be able to show their approach and to show that they have the aptitude to just jump into something new and to be able to understand it and to be able to help translate how to use it, how to protect against it, or to create new tools to help create a safer environment.

28:11I love that alliteration and the three A's. And it's true. Two of those is really good. three of those is like a killer killer combination i teased a pop culture question at the beginning of our of our talk and i'll i'll end here is there a show or a movie that you think is an accurate portrayal of your industry i'll put industry in quotes whether it's hacking or digital crimes or conversely is there one that you'd call out as being patently ridiculous or impossible? Uh, you know, when I saw that question, um, I had to think about that, right? I got that yesterday and I thought about that overnight and, and I figured I'd answer in this manner.

28:51So I, I volunteered in a lot of different aspects of my life to give back to the community. And, uh, and, and for several years, I used to be a, uh, a volunteer firefighter, a volunteer EMT. At one point, I was looking to go down into law enforcement, and I was at a crossroads, and I decided I'm going to go down the cybersecurity path. But at that time, a lot of my friends in law enforcement didn't watch the cop shows. And I didn't understand why. But eventually, there were shows on EMT, on ambulance, on medical emergency, and on fire, and I just couldn't watch them. And there were reasons for that, right?

29:35I had experienced it. There was a lot of human connection through all of that. You're in people's lives during tragedies. And you're the source of balance potentially and stability for them during such an emergency situation. So when I tried watching those types of shows, it was too much drama for me. Way more drama than my own experience. Interesting. And similarly, in my industry, it's been very difficult for me to watch those types of shows. When I've tried, it's like, okay, sometimes it doesn't seem grounded in reality. So based on that, I put myself out of the box and I wanted to get back to some of the ideas that I've been talking about.

Read the full transcript

30:24So I'm going to call out Lord of the Rings. Okay. And I call out Lord of the Rings because for a few different reasons. First off, it's about trust, right? Everyone's got to trust one another in cybersecurity. You got to trust that your fellow practitioners are going to do what they're supposed to be doing, right? Lord of the Rings isn't about micromanaging. It's about your... And it's not even about picking out a unicorn to do the ultimate doom, right? It's it's you've got a hobbit that that is taking the ring and throwing it into the fire, right into the fires of Mount Doom. But he's not a unicorn.

31:06Right. And it's and it's all about cooperation. It's all about that grit. It's all about that attitude, that aptitude, that approach. This particular hobbit was curious, wanted to embark on this and had a tremendous amount of resilience and grit. Right. And ultimately ended up getting the job done, got the job done because there was a lot of other people on the team that went and did the jobs that they had to do. Right. So there's there's all that trust. And but there was a plan that was put together in the beginning and everyone set out to embark on that plan. Now, do we have unicorns in there?

31:45You know, you might call Gandalf a unicorn, right? You've got the Valor. Literally, maybe no. Yeah. Gamaya. But Gandalf didn't, you know, it wasn't the unicorn that did that thing. It was regular people. It was people that might have not prepared for it, but that had that passion, right? That had that interest, that had that desire to do good, to help the rest of the community around them, people that they didn't know and the people that would never know them, right? It's to seek a positive outcome with positive goals, positive return of investment, essentially. So for me, I like that tie-in to The Lord of the Rings because it was all about this good thing that a lot of people are involved in and everyone's trusting each other to do the function that they were hired to do.

32:39Unexpected answer, Paul, but I love it and really appreciate our conversation today. Thanks so much for being on the podcast. I appreciate you and have a happy Halloween. You too. Thank you.

32:56Did you know that more than 20 million professionals and business owners visit business.com and business news daily? Why? It's the best place for resources, advice, and information about how to grow your business. And if your goal is to reach our audience, you should become one of our lead partners, sponsor a section of the site, or sponsor even this podcast. Reach us at business.com slash connect. That's business.com slash connect.

From the publisher
On this episode of the builders podcast, John Busby sits down with Paul Laudanski, Director of Security Research at Onapsis and a leading cybersecurity expert, to explore the evolving world of digital security, from zero day vulnerabilities and ERP attacks to the growing impact of AI and offensive research. Paul shares insights from his extensive career, discussing how both businesses and individuals can strengthen their defenses, make smart cybersecurity investments, and stay ahead of increasingly sophisticated threats.

Thanks for listening, and if you liked this episode, be sure to share it with someone that you want to see leveled-up with you. 🚀

🚀 Join business.com+: https://bit.ly/business-com-plus Business.com+ is a free membership program for SMBs that takes the pain out of choosing new business services with 1:1 help from an advisor + exclusive deals on the best solutions.

🎧 Listen and subscribe to the builders podcast: https://plinkhq.com/i/1608075598?to=page

📺 Watch more from the builders podcast: https://www.youtube.com/@builderspodcast

More from builders from business.com

All 82 episodes
Cybersecurity – Protecting your Business and Yourself with Paul Laudanski of Onapsisbuilders from business.com · 33 min
Listen in VO