In short
Podcast Summary: The Thoughtful Entrepreneur Episode 2235
Episode Title
Navigating the Cybersecurity Maze
Essential Insights from Aethon Security's Derek Kernus
Episode Description In this episode, host Josh Elledge talks with Derek Kernus, CEO of Aethon Security, about the evolving landscape of cybersecurity and its importance for all businesses. They discuss critical cybersecurity threats, compliance requirements, and actionable steps that business leaders can take to protect their organizations.
---
Key Points
Understanding Cybersecurity Threats
- Current Threat Landscape:
- Nation-state actors from countries like China and Russia are increasingly targeting U.S. government networks and contractors.
- Attackers aim to steal sensitive data or disrupt critical infrastructures (energy grid, water systems, healthcare).
- Proliferation of Attack Points: As businesses digitize more operations, potential vulnerabilities increase.
Importance of Compliance
- Compliance Standards:
- Government contractors must meet standards such as the Cybersecurity Maturity Model Certification (CMMC).
- Non-compliance can lead to lost contracts, legal penalties, and reputational damage.
- Adoption in Private Sector: Companies are expected to adopt rigorous cybersecurity measures regardless of their government dealings.
Real-World Cyber Threats
- Case Studies:
- The Colonial Pipeline attack exemplified the risk to critical infrastructure.
- Disruptions of municipal water systems highlight vulnerabilities in public utilities.
---
Actionable Cybersecurity Tips
- Implement Multi-Factor Authentication (MFA):
- Essential for critical accounts to reduce unauthorized access risks.
- Train employees on its usage, especially for administrative and remote access accounts.
- Conduct Regular Vulnerability Scans:
- Identify system weaknesses before exploitation.
- Automate scans, prioritize high-risk vulnerabilities, and document efforts for compliance.
- Keep Software Updated:
- Apply patches and updates promptly to close security gaps.
- Leverage Federal Frameworks:
- Utilize resources like NIST and CMMC for structured guidelines on cybersecurity measures.
---
About Derek Kernus Derek Kernus is the CEO of Aethon Security, a cybersecurity consulting firm that assists organizations in navigating compliance requirements and protecting against cyber threats. His experience includes working with government contractors to help them maintain a strong cybersecurity posture.
---
Conclusion Derek Kernus emphasizes that all organizations, regardless of size, should treat cybersecurity as a core business risk. By understanding current threats and implementing actionable steps, business leaders can improve their cybersecurity defenses.
Contact Information
- Aethon Security Website: [aethonsecurity.com](https://aethonsecurity.com)
- Email: info@aethonsecurity.com
---
Final Thoughts The episode underscores the necessity for businesses to stay informed about cybersecurity threats and comply with standards that protect sensitive information. As cyber threats grow in complexity and frequency, leaders must prioritize cybersecurity as a fundamental aspect of their operational strategy.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:05Hey there, thoughtful listener. Are you looking for introductions to partners, investors, influencers, influencers, influencers, and clients? Well, I've had private conversations with over 2 ,000 leaders asking them where their best business comes from. I've got a free video you can watch with no opt-in required where I'll share the exact steps necessary to be 100 % inbound in your industry over the next six to eight months with no spam, no ads, and no sales. What I teach has worked for me for over 15 years and has helped me create eight figures in revenue for my own companies. Just head to upmyinfluence.com and watch my free class on how to create endless high-ticket sales appointments.
0:51Also, don't forget, the thoughtful entrepreneur is always looking for great guests. Go to upmyinfluence.com and click on podcast. I'd love to have you.
1:05With us right now, it's Derek Kernis. Derek, you are the CEO of Athon Security. You're found on the web at athonsecurity.com. Derek, it's great to have you. It's great to be here. Thanks for having me on, Josh. Yeah. And listen, hey, before we get going, by the way, I shared your website, athonsecurity.com. We're going to be talking about that in just a second. Before we do, I always love finding, you know, just like hobbies or passions or, you know, things that maybe you're playing a game right now or watching a show with your kids or your family or whatever that you really like. What have you been into lately on the side?
1:42Well, I'm very much into theme parks, so I'm really excited that summer's here. I'm very jealous that you're in Orlando. It's like the theme park capitals of the world. Truly. Big Disney fan. Love Universal. uh gone to cedar fair quite a few times uh cedar park run by cedar fair entertainment uh i love love that theme park because i'm a big roller coaster fan and uh the game that i've been playing recently is monster jam showdown uh my boys and i i have six four and three year old and we love monster trucks and monster jam so we have been geeking out on that the past couple of weeks making sure we get every little truck in that game it's been been a good time monster jam showdown and I'm looking it up right now.
2:24I see it. This looks like a lot of fun. Have you gone up to Cedar Point? You're talking about Cedar Fair parks. Yeah, yeah. Cedar Point, Cedar Fair is the entertainment company. I was now there for Kings Dominion and a couple of other theme parks. But yeah, before pre-kid days, my wife and I used to go out there once a year in the middle of the summer and enjoy all those roller coasters. It's an amazing theme park for that. Yeah. Do you like G-Forces, Cedar Point? I'm originally from Michigan growing up, so we'd go out there. It's funny, living down here in Orlando, my kids, as you can imagine, have become theme park fans as well.
3:06As they were getting a little older, they were getting a little bored with Disney, and they were like, yeah, take us up to Cedar Point. Yeah, ramp it up. Ramp it up. Go to the next level. Yeah, now I will say Universal's definitely put in some pretty behemoth coasters over the past handful of years. I can't wait to go to Epic Universe. I think that's happening for us, the new park, as of when I'm recording this, in about a week or two. We're going to go check it out. It opened last week, May 22nd. I had my eye on it. We couldn't go down there, but we checked out the Nintendo World when we took the boys to California last summer.
3:46And it was cool, but I think that the Epic Universe Nintendo World is going to be way better. Maybe the next time I come down to Orlando, you and I can hook up. We can get the families together and go. There we go. There we go. Well, let's talk about what is 8th on Security. Tell me about the work that you do in the world. Yeah, we're an MSP and an MSSP, so managed service provider and a managed security service provider that supports federal government contractors. We primarily work with defense contractors that have cybersecurity requirements for protecting what's called controlled unclassified information.
4:19So we help companies become compliant with those requirements and then help them maintain those ongoing requirements for a strong cybersecurity posture and maintain their IT environment. Yeah. Well, I would imagine that. Well, here's what I'd love to hear, Derek, is if you could give us take a few moments and just give us a little bit of the State of the Union as it as it pertains to security. What have been the major headlines that you've been seeing in your world? For those of us who don't spend our time in cybersecurity and IT security, what has been all of the buzz in your world over the past maybe six months or so?
5:02So it's been the same story for about what's the story's been for the past six months, been the story for about five or six years now. What we're seeing in the government space, especially with the United States government, is that a lot of nation state actors, so organizations that are backed by primarily China and Russia, they are trying to infiltrate or breach our IT environments for both our government networks and our government contractor networks and steal information for a multitude of purposes. So it could be anything from stealing proprietary IP to help build weapon systems more efficiently and faster to just disrupting our way of life, disrupting critical infrastructure, things like energy systems, water systems, our hospital networks.
5:49We've seen that as well. So it's a new battleground. It's a way where by disrupting our way of life and the way that we operate day to day as a civilization, these nation states think that they can disrupt our way to defend ourselves. So specifically what the Department of Defense has done is they have found that the contracting base wasn't fully meeting all of the requirements for their contracts to protect the government's controlled unclassified information. So they have now instituted a third party mechanism to verify those existing requirements that were finalized about eight or nine years ago now.
6:24And what we do is we help contractors and we help any critical infrastructure organization subject to those requirements become compliant with them so that we can protect this information and protect our way of life. Yeah. So when you talked about kind of, you know, nation supported cybersecurity violations for someone who's not aware, could you mind maybe just sharing some examples or just put a little meat on the bones there? because it sounds like that's quite a claim. And I think not all of us hear what might be going on. And I think a lot of us, if you were to ask, where are our greatest vulnerabilities from a national security standpoint or certainly from an international conflict standpoint, those battles are all going to be fought on the web through our IT systems, not likely having a war in Topeka, Kansas.
7:29Yeah, you're exactly right, Josh. The battleground is changing. I mean, we're always going to have our physical battlefield. But some of the bigger events that we've seen in the past few years are the colonial pipeline attack that brought down a fuel network basically along the East Coast, where we all may remember that people on the East Coast were going to gas stations for four or five days and putting gas in trash bags because gasoline cannot be delivered on the rail system. We've also started seeing many attacks on water systems. And, you know, ironically, you know, when I looked at that first, I was like, why are they attacking water systems?
8:10I spoke with somebody at DARPA and found they have found through cyber war gaming that attacking our water systems significantly threatens our way of life. because one, of course, we all need water to survive, clean water, right, as human beings. But also there are a lot of things that power our nation through water. Think of hydroelectric dams affecting those, getting in those systems, and many other things that we do day to day. So we've actually seen that more frequently where it appears that a nation state is already in those systems and they're just sitting waiting and they've been testing out periodically what will happen here if we take this water system down.
8:48Energy grids are another major concern. I can't say anything definitively, but there have been quite a few blackouts and brownouts recently that I know that some people in the United States government have suggested that those are due to nation states, again, testing what will happen if they try to take down sections of our critical infrastructure. So I think that we might see these things in the news pretty regularly, but we're not thinking about them in that context. So it's certainly something that I think all Americans should be conscious of moving forward when watching these events in the news that, you know, I don't want to be a tinfoil hat guy, but they all might be related in some way, shape or form.
9:26Wow. Wow. All right. Well, as leaders, what can we do to protect ourselves? I may not be running the city municipal water system, but I have sensitive systems. I'm handling sensitive information. Certainly don't want to make any mistakes. Certainly not. And I mean, there's quite a few repercussions of not meeting these requirements, but the government does have, for government contractors specifically, they do have cybersecurity requirements in place for every department and agency, and they vary. Meeting those requirements can go a long way in protecting an organization as a whole, even for their own proprietary information.
10:05But what I I urge business leaders in general, if you don't work with the government, you're in private industry. I think that the federal government actually has great resources to provide frameworks and guidelines for basic cybersecurity controls and an organization to implement. These are things like multi-factor authentication, commonly referred to as MFA or two-factor authentication, all of their systems. Doing vulnerability scanning and basic network monitoring. There are tools out there where you can scan the network on a regular basis for very low cost just to see where your vulnerabilities are and then where you need to patch or basically provide updates to your operating systems or to your software applications.
10:44Because these things make it very easy for bad actors to infiltrate a network, whether it's they send a phishing email, we click on a link, and it accesses a vulnerability in software or in our operating system. or even if we're using a web application, something that we've published ourselves, there might be vulnerabilities in the code in the web browser, believe it or not, where they can open that up in the developer tools. They can modify that code to break into the web app. So making sure that we're constantly updating those if we're hosting them ourselves is very important. Yeah. Well, Derek, where does Athan step in?
11:22Like, so who are your tips? I know you mentioned a little bit this at the top of the interview, But just so I have clarity over someone that potentially should be reaching out, do you mind maybe sharing an example of someone that you've worked with? Or, you know, again, if you have to change names to protect the innocent or whatever, you're welcome to. But help me understand where Athan steps in and, you know, really as just kind of an example for, you know, if you're just doing this on your own, trying to follow your own best practices, that's an option. However, you might want to bring in the big guns.
11:59Do you mind kind of finishing that thought? So this is a great opportunity for private industry and government contractors, because a lot of times what I find is that organizations were not taking cybersecurity as seriously as maybe they should have been. And I find kind of going back to actually the previous question you asked, I encourage business leaders to really take the leap of faith and, you know, maybe you're religious, maybe you're not. But in religion, a lot of times we have faith that something is there, even though we can't see it. To me, having a strong cybersecurity posture is the same thing.
12:31Just because we're we may be a small dog or a small fish in a big pond. That doesn't mean that we're immune to potential cyber attack, because what these bad actors will do is they will just send out they will spray send phishing emails. They'll get your email. They'll just spray it out and see who clicks. And many times it could be one uninformed or untrained individual that doesn't know the things to look for. They click on it and it can take the whole organization down. So where we come in is we can help any organization understand what their current cybersecurity posture is by doing a quick gap analysis or gap assessment and help them understand this is where you're currently at right now.
13:08These are your most critical vulnerabilities and then provide recommendations to them to say, hey, these are the tools or these are the procedures that you can put into place to help improve your security posture and mitigate this risk that currently exists to your organization. Now, from a compliance standpoint, if we start talking about working in a government space, or even potentially there are some private organizations that they have cybersecurity requirements in order to work with them. For us, like one of the well-known ones is Microsoft. They have their own basically Microsoft certification that vendors have to have in order to work with them.
13:41But when working with a lot of those frameworks, and we primarily work with CMMC and ISO 27001, we help organizations build compliant cybersecurity programs or information security programs to meet those requirements and then get certified. So that's where the business side of this comes into is because that becomes a business risk by not being compliant. And now for CMMC not being certified because contractors will start to lose work because they don't have that cybersecurity certification for their IT networks. And we come in and help on that side of the street, too. Yeah. And 8th on Security as a company, tell me about your growth plan or how you've grown or gotten to do the kind of work that you do today.
14:29I mean, it looks like this is actually a relatively new venture. Yes, it is. So I originally got into this government contracting cybersecurity compliance space in 2019. I was in an MBA program, a full-time MBA program, and had earned an internship at a government contractor. And the president's CEO had asked me to help the client or help the organization come compliant with NIST 800-171. And I had no idea what that meant at the time. And then in a webinar I watched about it in the first 10 minutes, a lady named Katie Arrington with the DOD had mentioned the CMMC program for the first time. And when I'm hearing about the program, I thought to myself with my business, I said, this is going to be a big deal.
15:16This actually happens. and it's going to be a great business opportunity, but it's also going to be a great way to help small businesses with these requirements, because I knew that there were going to be vendors out there that were not being truthful or taking advantage of the situation. Because prior to that, you know, in another life, I was a sales manager for a managed network service company, and I knew what it was like selling to this. So it was not so much a thing of, do we have to do, can we convince them that they need to do this? It was more of, can we convince them that we're the best partner to do it, right?
15:50So I ended up building a compliance program for this contractor and started offering services to other contractors. And then about nine months ago, I decided to start my own firm and our reputation for my team preceded us. So we've been very fortunate to get a lot of referrals from our colleagues in the ecosystem and have started doing some more outbound promotion and marketing. And it's been going really well. Yeah. And then, Derek, when you're working with someone, so let's say our friend that's listening to us right now, and they're interested in having a conversation, what do you recommend they do next, like from here?
16:33So if you're interested in speaking with Aethon Security, you can go to our website that you mentioned earlier, aethonsecurity.com. And we do have a contact form there that you can fill out. and one of our team members will reach out to you and schedule a meeting. You can also send an email to info at aethonsecurity.com. That's also monitored by our accounts team. And we'll follow up with you and schedule a meeting to discuss what your needs are and you'll help identify the best path ahead. Yeah, aethonsecurity, A-E-T-H-O-N, security.com. Derek Kernis, CEO, it's been a great conversation. Thank you so much for joining us.
17:09Yeah, my pleasure, Josh. Thanks again for having me.
17:16Thanks for listening to the Thoughtful Entrepreneur Show. If you are a thoughtful business owner or professional who would like to be on this daily program, please visit upmyinfluence.com and click on podcast. We believe that every person has a message that can positively impact the world. We love our community who listens and shares our program every day. Together, we are empowering one another as thoughtful leaders. And as I mentioned at the beginning of this program, if you're looking for introductions to partners, investors, influencers, and clients, I have had private conversations with over 2 ,000 leaders asking them where their best business comes from.
17:58I've got a free video that you can watch right now with no opt-in or email required where I'm going to share the exact steps necessary to be 100 % inbound in your industry over the next six to eight months with no spam, no ads, and no sales. What I teach has worked for me for more than 15 years and has helped me create eight figures in revenue for my own companies. Just head to upmyinfluence.com and watch my free class on how to create endless high-ticket sales appointments. Make sure to hit subscribe so that tomorrow morning, that's right, seven days a week, you are going to be inspired and motivated to succeed.
18:40I promise to bring positivity and inspiration to you for around 15 minutes every single day. Thanks for listening and thank you for being a part of the Thoughtful Entrepreneur Movement.
From the publisher
In today鈥檚 rapidly evolving digital world, cybersecurity is no longer just a concern for large enterprises鈥攊t's a critical part of every organization鈥檚 strategy. In this recent episode of The Thoughtful Entrepreneur, host Josh Elledge sat down with Derek Kernus, CEO of Aethon Security, to discuss how business leaders can protect their organizations from the growing wave of cyber threats. The conversation dives deep into the importance of cybersecurity, compliance, and practical steps that leaders can take to stay ahead of the curve in an increasingly complex landscape.
Understanding Cybersecurity and Compliance in Today's Business World
Derek Kernus opens the conversation by highlighting the current cybersecurity threats faced by businesses today. Nation-state actors from China and Russia are increasingly targeting U.S. government networks and contractors, aiming to steal sensitive information or disrupt critical infrastructures like energy grids, water systems, and healthcare. As businesses digitize more of their operations, the number of potential attack points expands, making it essential for leaders to treat cybersecurity as a core business risk.
Derek emphasizes the importance of compliance, particularly for government contractors who must meet cybersecurity standards like the Cybersecurity Maturity Model Certification (CMMC). Failure to comply with these requirements can result in lost contracts, legal penalties, and reputational damage. Even in the private sector, companies are increasingly expected to adopt rigorous cybersecurity measures. By understanding and implementing these frameworks, businesses can ensure that they are protected and ready to meet both governmental and industry-specific standards.
The episode also addresses real-world cyber threats, including the Colonial Pipeline attack and attempts to disrupt municipal water systems, underscoring the need for proactive security measures. Derek offers actionable cybersecurity tips for business leaders to improve their organizational defenses and protect sensitive data.
Actionable Cybersecurity Tips for Business Leaders
Derek shares several practical, actionable cybersecurity steps that leaders can implement immediately to enhance their company鈥檚 security posture. One of the most essential steps is implementing Multi-Factor Authentication (MFA) across all critical accounts. MFA significantly reduces the risk of unauthorized access, even if passwords are compromised. Derek advises prioritizing MFA for administrative and remote access accounts and training employees on how to use it.
Another key recommendation is to conduct regular vulnerability scans. These scans help identify system weaknesses before they can be exploited. Derek stresses the importance of automating these scans, prioritizing high-risk vulnerabilities, and keeping records of the scans and remediation efforts for compliance purposes. Additionally, keeping software and systems up to date is crucial. Outdated software often serves as a gateway for cybercriminals, so applying patches and updates promptly can close those security gaps.
Finally, Derek encourages business leaders to leverage federal cybersecurity frameworks like NIST and CMMC to better manage risks and ensure compliance. These frameworks offer structured, proven guidelines to assess and improve cybersecurity defenses, making them invaluable tools for organizations of all sizes. Derek advises that even non-government contractors benefit from adopting these best practices.
About Derek Kernus
Derek Kernus is the CEO of Aethon Security, a cybersecurity consulting firm that helps organizations navigate complex compliance requirements and protect their data from cyber threats. Derek brings years of...

