1653 – What Saves A Company in Cyber Security with Carbide Secure’s Darren Gallop

31 Aug 2023 · 21 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Podcast Episode Summary: The Thoughtful Entrepreneur - Episode 1653

Episode Title What Saves A Company in Cyber Security with Carbide Secure’s Darren Gallop

Host Josh Elledge

Guest Darren Gallop - CEO & Co-Founder of [Carbide](https://carbidesecure.com/)

Episode Description In this episode, Josh Elledge speaks with Darren Gallop about the pressing issues of cybersecurity, the evolution of compliance requirements, and how Carbide offers innovative solutions for small- to medium-sized companies navigating the complex landscape of data privacy and information security.

---

Key Points from the Episode

Cybercrime Landscape

  • Black Market Growth: The proceeds from cybercrime have surpassed those of illicit drugs globally.
  • Involvement of Organized Crime: Criminal groups are increasingly engaging in cybercrime, enhancing the sophistication of attacks.

Importance of Cybersecurity

  • Human Error: A significant portion of data breaches is attributed to human error, emphasizing the need for robust training and compliance programs.
  • Compliance Requirements: Companies face growing regulatory pressures, especially if they operate internationally or engage with government entities.

Carbide's Solution

  • Compliance Platform: Carbide helps businesses manage and report on their security posture, ensuring they meet various compliance standards.
  • Cost-Effective Tools: The platform leverages intelligent technology and cloud solutions to help companies develop security and privacy programs efficiently.

Target Market

  • Primarily serves B2B Software-as-a-Service (SaaS) companies that need to comply with stringent security requirements from larger enterprises and insurance companies.

Customer Acquisition

  • Initial Customers: Obtained through networking and existing relationships; relied heavily on referrals and personal connections in the early stages.
  • Growth Strategy: Focus on building a sales team, enhancing marketing efforts, and implementing a structured go-to-market strategy to support ongoing growth.

Future Trends

  • Rising Cybersecurity Awareness: Companies are increasingly aware of the risks, often prompted by competitors' breaches.
  • Regulatory Complexity: The need for compliance becomes more complex with varying regulations across states and countries, underscoring the need for tools like Carbide.

---

About Darren Gallop

  • Experience: Over 15 years in information security, including roles as CEO and Chief Information Security Officer (CISO).
  • Previous Ventures: Co-founded Marcato, a platform for event management used by major festivals worldwide.
  • Funding: Raised over $7 million for Carbide, focusing on regulated sectors such as e-commerce and healthcare.

---

Additional Insights

  • Human Element: Emphasizes the necessity of ongoing education and awareness training for employees to mitigate risks associated with human error.
  • Layered Defense Strategy: Suggests a comprehensive approach that includes training, technical safeguards, and compliance programs to enhance organizational security.
  • Call to Action: Interested parties can explore Carbide's offerings through a trial on their website or schedule conversations with sales representatives for personalized assistance.

---

Conclusion The episode underscores the critical nature of cybersecurity in today's business environment, particularly for smaller companies. Carbide positions itself as a valuable partner in navigating the complexities of compliance and security, enabling businesses to not only protect their assets but also leverage security as a competitive advantage.

For further information, visit [Carbide's website](https://carbidesecure.com/) or listen to the full episode for deeper insights into cybersecurity best practices and compliance strategies.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:28Hey there, thoughtful listener. million in revenue. Just head to upmyinfluence.com and watch my free class on how to create endless high-ticket sales appointments. You can even chat with me live and I'll see and reply to your messages. Also, don't forget, the thoughtful entrepreneur is always looking for guests. Go to upmyinfluence.com and click on podcast. We'd love to have you.

0:59with us right now it's the ceo and co-founder of carbide it's darren gallup darren thank you so much for joining us thanks for having me your website is carbide secure.com and and would you mind maybe just kind of giving us just a quick 101 on what carbide is absolutely um so carbide is a platform for information security and data privacy compliance. So basically what we do is we help small to medium-sized companies build, manage, and report on their information security and data privacy posture. So that may be for their board, for their investors, more often than not for customers. And just to be able to do what you're supposed to be doing, follow the regulations, and to comply with what your customers need you to comply with.

1:46Yeah. So obviously there's the, you know, just kind of staying within the good graces of regulations and laws. I mean, that's mandatory. But, you know, those regulations and laws are there for a reason. And that is, is that, you know, cybersecurity risk can be incredibly painful. It can put a company out of business. Would you mind maybe just kind of talking about the whole kind of risk versus, you know, just complying just because you have to because it's the law? Yeah, I mean, look, I am a big fan of cybersecurity. I've become very interested in all the concepts around it, probably about 10 years ago.

2:26I have a brother, my older brother, who ran a leadership role with the RCMP and involved in cybersecurity. So I've just had it around me. I've dealt with it on my last company. We've been very close to breaches. We've had incidents. We've been part of breaches that were very scary. You know, so a lot of exposure and, you know, seeing the stats, seeing the, just the revenue that the criminal environment is making. So, yeah, I'm all in for cybersecurity versus doing it because you have to. We get a lot of customers, though, that are not quite as aware of the risks and really taking the security side.

3:04You know, we see prospects come to us. They're coming to us because they're trying to close a big deal and they need to meet certain requirements. But, yeah, the reason the requirements are there is because companies haven't been really jumping on and really thinking about it properly because it is a cost center. You're paying to protect yourself. And it's not it's so so it is really important. And so, you know, the way I look at it is, yeah, companies should follow best practices because that's what's going to save them. If you have a major data breach, if you're a SaaS company, say you've got a couple of million records in your platform and you get a data breach, you can have a whole kind, all kinds of problems.

3:41You're going to have the embarrassment. You're going to lose customers. You may get sued in class action. You may get sued from other businesses you work with. You may get fines from privacy regulations. You'll destroy your brand. And so I think a lot of people forget just how damaging that can be to a company. Yeah. And I would imagine in your tenure, you've likely, are you typically coming in when there's already a problem or hopefully most of your clients are coming in because I just, I went to prevention, right? What do you typically see? There are those cases, but I'd be honest to say that most organizations are coming to us with a need to meet the growing stringency that we see in supply chain.

4:30So if you're selling to government or if you're selling to enterprise, even mid-market or smaller businesses now are starting to mandate various different requirements. Some of them are regulatory or some of them are dialed into standards. Some of them are just doing due diligence to make sure that the organizations they work with are following best practices. And we're also seeing pressures like insurance. So we're seeing insurance companies not be willing to give an insurance policy, certainly not a cyber insurance policy, unless they have some affirmation that the organization is following due care and due diligence in the way they approach cybersecurity in the organization.

5:06So it is in fact, you know, I would say if I was to estimate, I would say 20 % of the people that come for it come to us are like, hey, we just want to do what's best to be preventative and the rest are like, oh wow we're getting, we're getting asked to meet this and we need to put this in place and we need to put a formal risk program in place and, you know, we need to have pen testing and we need to have all these things in place so it is, it is, is more coming in the small to medium sized businesses. it's more coming from them being required to do it in order to do something else that's in their strategic roadmap whether it's being sales goals moving up market raising rounds of capital or insurance plans things like that yeah so without carbide how do we do this well or how have we been forced to do this another way to ask is how have we been forced to do this before carbide came on the scene i'll tell you how i did it in my last company and how i got into this and got the idea in the first place so my last place was it was the company that did festival management it was a sas platform all the back end logistics so not your tickets not your mobile app that the the people that go to the concerts or the events go to all the back and stuff the artists what they're getting paid when they're playing who they're playing with their phone numbers what gates are coming in what flights are coming on what hotel they're staying in all this logistics and we were working with some of the biggest festivals in the world by 2014 2015 we had Coachella Bonnaroo Burning Man just for last festivals.

6:24We're in 20 something different countries. And we were just getting hit by all kinds of challenges around that we were getting, you know, so when we went in to do it, what we did is we hired a consultant to come in and do an analysis and assessment. We hired an auditing company to do an audit. We discovered that there was a lot of things we weren't doing. We had consultants help us with certain aspects. I did a lot of reading because this became a very big problem in the business. We had a bunch of our festivals getting hacked through other technology partners where lineups for Coachella and lineups for Bonnaroo are being leaked and things like that.

7:01So there's a lot of heat around the security problem. And yeah, I dove in a hundred percent. Like I was literally working on this very diligently, my CTO for about, I'd say six to eight months, eating up a lot of my time and his time. And we had consultants in, we had auditors in, we were reading, we were downloading templates. We were taking online courses even just to try to figure out, you know, how do we talk about this stuff? What do we really need to do? And that's the way people did it. You either did some sort of combination of doing it internally with some outside assistance, or you just pay a premium to a cybersecurity consultant firm to come in and really sit in your business and do the work for you.

7:42So, you know, big, big cost items there. And so the new way of doing it is having tools that leverage more intelligent technology and cloud-based tools and some AI stuff in there to really help organizations get a pretty significant way in this success in building a security program, a privacy program quickly and spending significantly less dollars. Yeah. And so today, what would be examples of companies that are working with carbide right now? And, you know, I'm just kind of thinking of like, you know, there are probably folks that need to have a conversation post haste. But who today do you find yourself working with most often?

8:29Like specifically, you don't have to name names unless you're able to. Yeah, you know, I usually like to, what I would say is the majority of our customers are B2B software as a service companies. So they're selling, they're selling to enterprise more often than not or government. and they are being met by very strict security questionnaires, security requirements. They are in their contracts before working with these organizations, signing security and data privacy addendums where they're basically confirming their commitment to follow several pages of best practices or comply with some standard or framework or frameworks.

9:14that is and they range this on the smaller side yeah we have companies that are small as 11 10 12 20 people i would say on average it's more like 80 to 100 um and and then we have you know starting to see a lot more companies as our product evolves and becomes more sophisticated we're doing a lot more business with companies 250 400 500 even a thousand employees um and and in that realm which is fascinating we're actually getting into different uh different companies we have a company called Protocase that does, they do custom enclosures and it's just effectively it's manufacturing, right? We have another organization, 45 Drives, that makes actual hardware for on-site servers and data clustering.

9:59And, you know, so we're starting to broaden out as we're seeing the demand for sophisticated security tools evolve and we're starting to move out America with our own technology. Yeah. And how did, so kind of thinking about like when you launched Carbide, what was go-to-market? Like how did you acquire your first batch of customers? You know, to be honest, it was a lot of like friends and family and network, right? Like, you know, I'd already had a couple of different companies in the past. I knew a bunch of different investors. My co-founder and myself, we went through the Techstars program in Boston.

10:35So we were, you know, had a bunch of connections to the Techstars network. And yeah, that's really how we started it, right? It was just like knocking on doors. We, you know, when you launch, you're usually pretty MVP and, and a little rough around the edges, not necessarily ready for prime time, which, you know, certainly was our case when we, in the early days when we originally launched. So yeah, we went to, we went through our network at first and that was probably our first 25 or 30 customers paying customers and really helpful and sort of validating the product and getting great product feedback and getting feedback on pricing and different things like that.

11:08Yeah. And so today, Carbide, you've got an impressive client roster. You've got a great size company. What do you do for growth? And where is Carbide going from just like a growth perspective now? Yeah. So we're very growth focused. We have a phenomenal VP of sales and marketing, Michelle Russell, who has come on board, I guess, not just a little over a year ago now. And so really starting to build out that sales motion. She's come in and put in a sales team. So we have a sales team with business development reps and account representatives, account executives. We have a channel, a personal leads channel partners.

11:51We're starting to build out a channel network for go-to-market purposes. We're starting to build out our marketing department now as well, starting to do things like paid advertising, content, marketing, things like that. So, you know, really just sort of firing up the jets from a go to market strategy. A lot of it, you know, in the early days, it went from sort of friends and family network to word of mouth to an inbound content strategy. And, you know, now we're really starting to fire up the jets. We've been looking at averaging just a little over 100 % growth year over year. And of course, as the number gets bigger, the requirements, the new customer requirement to meet that same percentage becomes heavier and heavier.

12:32So, you know, the friends and family founder led approach is not, you know, might've got us there the first couple of flips, but you know, we've definitely brought things up from a sophistication level. Well, that's exciting. And it seems like trends are only going to move in your favor, right? The laws are going to get more and more tight because every time, just from a PR standpoint, every time there's some sort of a hack, there's data, some sort of a leak or something like that, those headlines generally evoke the ire of those who set regulations. And, you know, so companies are going to listen, you know, either you kind of stay ahead of this or, you know, you become a statistic in a headline and you don't want to be that sort of a statistic or headline.

13:24So it's better to a little ounce of prevention. Well, the black market from a cybercrime for profit perspective has been explosive in growth. And in fact, it was 2017 Interpol estimated that the proceeds from cybercrime in the black market exceeded all of the illicit drugs globally. So just to put it in perspective, and that growth continues. And we're even seeing now the organized crime groups, we're seeing cartels getting involved. And the toolage keeps getting better. Now you have AI being a very helpful set of tools coming from the AI world to help hackers be better at what they do. And so it's a money, it's a profit game.

14:10It's very hard for law enforcement to catch a lot of these folks. And depending on where they're out of, where they're conducting their quote unquote business from, it can be very difficult to prosecute people as well. So there's that element. So yeah, you're definitely, and we see we're hearing more and more companies being hacked. We do get customers more now that are like, oh God, two other competitors of ours just had major breaches. And we're fearing we're next. And there is that, but yeah, to your point, what happens is what's happening and has been happening is the regulatory environment has stepped in very aggressively.

14:45The challenge with this is, You know, this is some of the pain point that we focus on in Curbide in addition to best practices in securing your business. The problem is if you're an international company or even a national company and you're selling in multiple different regions, the problem we're running into now is that you have, for example, in the United States, each state is pretty much coming up with its own privacy regulations. Some of them have cybersecurity regulations. Various industries have their own certifications from a cybersecurity perspective. You have things like the GDPR in Europe, then Canada has its own federal law, plus the provinces have regulations.

15:20So the red tape complexity for an international business or even a smaller SaaS company that sells to a big international business, the amount of things that they may need to comply with becomes very complex. So it's, you know, you have your security requirements, best practices, securing data, but you also have to make sure that you are, you're, you're, you're carving that out in a way where you're complying with all the requirements that you're going to be met with as you're selling to your customer base. How are you able to, and I'm just curious about leaks that are the result of maybe a little bit of carelessness with data internally.

15:58So someone clicking on a bad email, someone mishandling information, they leave a terminal unsecure, just those sorts of human error. Like that seems more like educational. Are there any ways to enforce that or how is Carbuy involved in that side of it? Yeah, so we would be very involved in our platform we use in the prescriptive side of determining what are the risks associated to your business? What are the threat vectors that would be very prominent for your business? And in most businesses, I can't think of any businesses that don't fall into the bucket of human error and user side error is a huge weakness.

16:45And so, you know, think about it through layers of defense. And what I mean by that is you want to have the awareness and the training because your humans are your front line. So then just having a proper appropriate training program, awareness training, making a personal, making it real. Don't make it just like some BS that people have to go through to check a box, but actually actually train them, make them aware of what the threats are to the business. That's a big one. And then testing how that awareness is working. So you're seeing a lot of uptick out there and phishing simulators out in the marketplace where, you know, you're kind of testing your employees to see if they're really capturing the knowledge and putting it to practice.

17:23And then also on the technical side, there's a ton of different function tools, depending on the environment and the certain risks of your business that can also help spam filtering, anomaly detections, different things like that. So, you know, it's really you really look at every business. There's a there's a look at what tools are using, look at what the risks are to the business, what those threats are and building a program. And that's really where we come in. We will likely bring in other partners from our network, other tools that we either white label or partner with. And the organization will implement things like endpoint detection, phishing simulators, vulnerability assessors, things like that.

18:01So you really want to think layers of defense. You're never going to be able to get to a point with a business where every human being is never going to make a mistake and never going to accidentally click on things. So you want to have those layers in place that make sure that when they do, there's still other lines of defense and other mechanisms in there. Arbide offers a seven-day trial. There's a self-guided demo. Can you talk about someone that's maybe they're listening to this podcast because they're familiar or they're searching this because they know that they need help. Where do they go from here?

18:36What would you recommend their next steps be? You just go to our website and you can click on the try it for free. Or if you want to talk to a sales rep, you can just click right there, either in the chat window in the bottom right-hand corner of the website or on their contact information. There'll be somebody happy to have a quick chat and understand what you're trying, what is it that you're looking for? What's the pain? What's the challenge? And then finding the experts within our business that can most appropriately look at your situation and share how we can help solve those problems. Yeah, the website carbidesecure.com.

19:14We've got a link to it in the show notes. And again, Darren Gallup, your CEO, co-founder, it's been great having you. Thank you so much for joining us. Thanks for having me.

19:29Thanks for listening to the Thoughtful Entrepreneur Show. If you are a thoughtful business owner or professional who would like to be on this daily program, please visit upmyinfluence.com slash guest. If you're a listener, I'd love to shout out your business to our whole audience for free. You can do that by leaving a review on Apple Podcasts or join our listener Facebook group. Just search for The Thoughtful Entrepreneur in Facebook. I'd love even if you just stop by to say hi. I'd love to meet you. We believe that every person has a message that can positively impact the world. We love our community who listens and shares our program every day.

20:14Together, we are empowering one another as thoughtful entrepreneurs. Hit subscribe so that tomorrow morning, that's right, seven days a week, you are going to be inspired and motivated to succeed. I promise to bring positivity and inspiration to you for around 15 minutes each day. Thanks for listening and thank you for being a part of the Thoughtful Entrepreneur Movement.

From the publisher
In this episode of the Thoughtful Entrepreneur, your host Josh Elledge speaks with the CEO & Co-Founder of Carbide, Darren Gallop. Darren explained that the black market for cybercrime has surpassed the proceeds from illicit drugs globally, and organized crime groups are becoming more involved. With the regulatory environment becoming more aggressive, companies face complex compliance requirements, primarily if they operate internationally. One of Darren's key points was the importance of addressing human error in data breaches. Carbide offers a platform that helps companies mitigate this risk. Carbide is a company that is making waves in the cybersecurity industry. They provide a unique service that helps small- to medium-sized companies comply with information security and data privacy. Darren emphasized the importance of cybersecurity and the risks associated with not following best practices. Many companies approach Carbide because they must meet specific security requirements to do business with government agencies, enterprises, or insurance companies. Previously, companies would handle security internally with outside assistance or hire expensive cybersecurity consulting firms. Carbide, however, offers a new way of doing things. They provide tools that leverage intelligent technology and cloud-based solutions to help organizations build security and privacy programs more efficiently and cost-effectively.

Key Points from the Episode:

  • Emphasis on the importance of cybersecurity and the risks of not following best practices
  • Explanation of why companies come to Carbide, often due to security requirements from government agencies, enterprises, or insurance companies
  • Description of Carbide's approach, leveraging intelligent technology and cloud-based solutions to build security and privacy programs efficiently and cost-effectively
  • Focus on Carbide's target market, primarily B2B software-as-a-service companies
  • Discussion of how Carbide acquired their first customers through their network and connections
  • Growth of Carbide, including sales and marketing efforts, building a sales team, and implementing a go-to-market strategy
  • Highlighting the growing threat of cybercrime and the need for companies to prioritize cybersecurity
  • Mention of the increasing complexity of compliance requirements, especially for companies operating internationally

About Darren Gallop: Darren Gallop is the Co-Founder and CEO of Carbide, a leading cybersecurity firm that equips businesses of all sizes with tools to establish robust cybersecurity and privacy measures. His company helps clients protect their data from cybercriminals, transform security into a competitive advantage, and foster accelerated growth. With Carbide, Darren has raised over $7 million in funding and witnessed a rapid expansion of their clientele, especially in regulated markets such as e-commerce, FinTech, healthcare, and Insurtech. Darren has over 15 years of experience as a CEO and Chief Information Security Officer (CISO) for various businesses handling sensitive data. This experience has enabled him to develop a keen understanding of evaluating and managing risks in alignment with organizational goals while fostering growth. Before Carbide, he co-founded Marcato, an innovative event management platform utilized by 300+ music and cultural events worldwide, including renowned events like Burning Man and Coachella. After a decade of successful leadership as CEO and CISO, Darren decided to focus entirely on the cybersecurity industry. He holds certifications as a Certified Information Privacy Manager (CIPM)...

More from The Thoughtful Entrepreneur

All 987 episodes
1653 – What Saves A Company in Cyber Security with Carbide Secure’s Darren GallopThe Thoughtful Entrepreneur · 21 min
Listen in VO