{"id":5219,"date":"2024-09-10T08:54:39","date_gmt":"2024-09-10T13:54:39","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/dark-reading-confidential-pen-test-arrests-five-years-later"},"modified":"2024-09-10T08:54:39","modified_gmt":"2024-09-10T13:54:39","slug":"dark-reading-confidential-pen-test-arrests-five-years-later","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/09\/10\/dark-reading-confidential-pen-test-arrests-five-years-later\/","title":{"rendered":"Dark Reading Confidential: Pen Test Arrests, Five Years Later"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt0469f94bd17817ff\/6642699959fdc64aa5f9c5fa\/dark-reading-confidential-logo-sq.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/dark-reading-confidential-pen-test-arrests-five-years-later.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/dark-reading-confidential-pen-test-arrests-five-years-later.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Becky Bracken, Senior Editor, Dark Reading<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Hello and welcome to Dark Reading Confidential, a podcast from the editors of Dark Reading.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">My name is Becky Bracken. I&#8217;m an editor with Dark Reading and your host for today&#8217;s conversation, Pen Test Arrest: Looking Back Five Years Later. I&#8217;m joined by Kelly Jackson Higgins, Dark Reading&#8217;s editor-in -chief.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Five years ago on September 11th, 2019, a pair of cybersecurity pros named Gary De Mercurio and Justin Wynn were arrested while conducting an authorized pen test at a courthouse in Dallas County, Iowa. Following their arrest, what ensued was a heated years long battle between the two pen testers; their employer and company contracted to do the pen test Coalfire and its CEO, Tom McAndrew; and law enforcement; particularly Dallas County Sheriff Chad Leonard, who was seemingly bent on making an example of the pair.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Today, we are joined by Gary, Justin, and Tom to look back at the incident and how it affected them personally, professionally, as well as how the wider cybersecurity community conducts physical penetration tests. Welcome, Gary, Justin, and Tom. We are thrilled to have you here today.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Tom McAndrew, CEO, Coalfire<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Thanks, Becky.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Becky Bracken<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I would like to hand things over to Kelly who really was in the weeds with you on this as it happened as a reporter just to sort of walk us through the basics. Kelly.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Kelly Jackson Higgins, Editor-in-Chief, Dark Reading<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Thank you, Becky.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Justin, Gary, and Tom, it&#8217;s great to talk to you again. I&#8217;ve always wanted to circle back with you after we talked about what happened five years ago and kind of get a feel for how things have changed since then. I think this case, for those who don&#8217;t know much about it, really was sort of a game changer for the physical pen testing world.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For those that don&#8217;t know, physical pen testing really does rely on this pact between the client and the pen testing company that you, pen testers will be free from legal and physical peril when you do your job.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But this case really showed how things can go wrong sometimes. And I wanted to sort of go back to that night, Justin and Gary a little bit. I think it was after midnight, September 11, 2019, if I remember correctly.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">You were obviously in the final phase of the pen testing engagement for Iowa&#8217;s judicial branch, and you were breaking into the front door of the Dallas County courthouse with what I remember, a plastic cutting board that I think you bought at Walmart that had a, sort of had retrofitted it with a notch that you could kind of break into the door jam. Things kind of were going along at that point, right? And then things went in the other direction. So, kind of bring us back to that night. Justin, do you want to start just kind of where things went from there and how everything was going as planned for the most part.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Justin Wynn, Coalfire, former penetration tester and current director of cyber security services<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Sure. Yeah, just to catch up and recap on some of the other elements of the engagement, even in the months before we had been doing the virtual penetration testing for them, but then that week we&#8217;re on site assessing, with great success some of the other courthouses, the judicial branch, other facilities that were in scope. Nowhere along the way do we set off any alarms, just open access to pretty much everything with egregious vulnerabilities. We even ran into the state trooper while we were working on a door at the judicial branch. And then he Just kind of chatted and joked with us, went about his way, told him we&#8217;re working on contract, just kind of business as usual.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So, earlier that night, we&#8217;ll start on the 10th, since that&#8217;s when kind of everything started and went down. We&#8217;re working in another facility, got in using similar vulnerabilities, and then went over to the Dallas County Courthouse sometime probably around 11 pm on the night of the 10th.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And even before we had to employ that cutting board, just due to the positive air pressure in the building, we walked up, and that door was actually unlocked. So, you just pulled on it and opened right up. So that was the start of everything.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Once we got in, we kind of knew for all the places we tested, this was going to be the first place that had an alarm that would likely go off. It did. And then we sat around, waiting for the responding officers to show up as we kind of continued our work throughout the courthouse, just finding other vulnerabilities, getting a vantage point.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And then once officers showed up, took a little while. There&#8217;s probably about 20 minutes there while we&#8217;re trying to establish contact, wondering why they aren&#8217;t in the building yet. And then find out just some funny things afterwards about the security.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But we made contact with them, went down to the responding officers, know, kind of verified and went through the gambit for however long it was, 20 or 30 minutes. They verified us, talked to our point of contact and said, you guys are free to go. And that&#8217;s when the Sheriff (then-Dallas County Iowa Sheriff Chad Leonard) showed up and everything changed.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Kelly Jackson Higgins<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Gary, I know that there&#8217;s something called sort of like a \u201cget out of jail free card\u201d is the term for it, but something that you show to prove, okay, we&#8217;re here legitimately, you know, showing, proving who you were. How did that go when the first officers came in? It sounds like Justin was saying things were kind of going okay. What happened at that point?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Gary De Mercurio, former Coalfire pen tester, current founder, Kaiju Security<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yeah, it was going fine. It worked as intended, which was just to show them why we were on site, what we were doing, the name of the company, our names, which of course they verified by looking at our identification and then our contacts\u2019 names and numbers, which they called and they verified that we were working for iowastategov slash courts, I believe is what it was.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And yeah, from there it just it went really well. The entire interaction was very professional They just said, \u201cSit tight. Let us let us verify who you are. This is kind of strange It&#8217;s the middle of the night.\u201d And I made a joke something like, \u201cyou know, of course, It&#8217;s harder to break into a place when there&#8217;s a lot of people in the in the facility during the day.\u201d But yeah, for the most part everything went really really well. It was very professional, and the card worked just as its advertised, which is just to let them know what you&#8217;re doing and the information that they need to verify that you are who you are and you&#8217;re doing what you&#8217;re supposed to be doing.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Kelly Jackson Higgins<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I vaguely remember you guys talking, Justin, about what you had done before the police, before the deputies came. You had gotten through some of the actual pen testing, not physical, but regular digital pen testing process. Can you talk a little bit about how far you got there and some of the things that you had found at that point before they came?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Justin Wynn<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Officers responded quite quickly. I think the police department is literally across the street and then there&#8217;s just the audible alarm just blaring throughout downtown. So didn&#8217;t have too much time. we did find some other security vulnerabilities, obviously don&#8217;t want to go in and jeopardize and disclose things, that we shouldn&#8217;t that weren&#8217;t already made public. And it&#8217;s kind of Barbara Streisand effect. A lot of this we&#8217;re able to discuss because they brought so much notoriety into the case and a lot of the documents became public.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But yeah, found some other vulns. I think we ended up on the third floor of the courthouse, in a courtroom. And then we had a good vantage point overlooking that we could see officers arriving to the scene at that point, kind of put things on pause until we could make contact with them.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Kelly Jackson Higgins<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So pretty much everything was going as planned, like a typical engagement. So, then things got a little more heated when the sheriff showed up. Take us back to that scenario.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Justin Wynn<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">100%. Yep.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Well, it kind of paints a different picture now too, when you can see all the body cam footage, but we, we felt it as soon as he showed up, everyone&#8217;s demeanor changed reviewing body cam footage. You can hear some of the officers saying, \u201cThis ought to be good.\u201d And then turn off their body camera as soon as the Sheriff shows up. So, just a lot of implications there, I suppose you read into it, but, he showed up, already kind of immediately irate with the situation.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">You know, spouting off cursing that \u201cthe state can&#8217;t do this.\u201d You know, he needs to be notified. This is his courthouse. and just kind of the jurisdictional issues that come up thereafter. Gary, you to add more color to it?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Gary De Mercurio<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">They got uncomfortable. I think he said something in effect of \u201cDon&#8217;t you feel kind of stupid now?\u201d When he asked, he said, \u201cDon&#8217;t you know that the county owns this building?\u201d And I think we said something to the effect of, \u201cNo sir, we were hired by the state. We naturally assumed that the state and the court had jurisdiction over a courthouse.\u201d And he said, \u201cWell, they don&#8217;t. So I bet you feel pretty stupid now, don&#8217;t you boy,\u201d Something to that effect, if not, if not verbatim.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And he walked away and said, he said something, the effect of, \u201cHold them, they&#8217;re not going anywhere.\u201d And he walked away. Oddly enough though, when he walked away, even after that engagement with him, the deputies were still professional. was like, everybody&#8217;s like, \u201cOkay, yeah, well, that&#8217;s just the Sheriff, that&#8217;s how he is.\u201d And as soon as we walked away, we just continued to talk to them about how to better secure their courthouse, to figure out why the door was open, to figure out why they weren&#8217;t able to get into the courthouse even though we had gotten into the courthouse.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">We were answering questions. It was just basically another day for us even after the Sheriff had shown up, which made it all the more bothersome when he came back and obviously told them to and told them to arrest us.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Becky Bracken<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So what explanation, Gary, were you given about why you were being detained and eventually arrested? Or were you given any? Seems like things abruptly changed. What was the legal explanation for that?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Gary De Mercurio<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The legal explanation from the Sheriff was the state doesn&#8217;t own this courthouse. It wasn&#8217;t that we were burglarizing the courthouse. It wasn&#8217;t that he didn&#8217;t believe that we weren&#8217;t supposed to be there. It wasn&#8217;t that we had done anything wrong. His reasoning was simply that the state doesn&#8217;t own this courthouse. You can&#8217;t be here, which to me isn&#8217;t burglary. And that was one of the things that always bothered us.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">We&#8217;re not law enforcement, we&#8217;re not lawyers, but because of what we do, we at least have a rudimentary knowledge of what burglary is and burglary still requires intent. And they had the contract, they knew we were there, they knew that we weren&#8217;t trying to burglarize the facility, that we weren&#8217;t there to actually steal anything, that we were just two guys performing our jobs under contract. Now, whether or not the state and more specifically the court was able to give us access to that facility, that&#8217;s a different debate. If that would have been truly what we were in trouble for, that would have been something different. But that night they charged us for burglary, which means once you entered that building, you have intent to commit another felony, which was not the case.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Becky Bracken<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So, what appeared to be a simple administrative snafu resulted in your being arrested and held for how long, Justin?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Justin Wynn<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I think it was 20 hours before bail was posted and we were out the next day. You know, in between we&#8217;re dealing with quite a lot inside the jail cells with the officers trying to make phone calls. We were arraigned in the morning with the Magistrate. So, you know, quite a lot of action packed in those 20 hours.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Becky Bracken<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So, then Tom, that&#8217;s where you come in, correct? This is where you have to come up with the bail and come up with a game plan to get your guys out. Is that sort of how you received the news?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Tom McAndrew &nbsp;<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yeah, I think it&#8217;s not every day does the CEO get a call saying that you got to figure out how to bail employees out for doing their job. Much like Gary and Justin said, when I got the first call, I think it was like six in the morning. And I got the call that the two of them were, for lack of a better for term, caught and were in jail. My initial reaction was I laughed because I knew both of them. I knew about the engagement that we had going on. We kind of expect the unexpected in this. And so, when we do these engagements, everyone reacts a little bit differently, but usually that&#8217;s resolved in a couple of hours.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And so, by around 10 or so my time, which is around noon their time, when I heard that things were not resolved at that time, that was really when then I started kind of kicking into high gear. We started to understand what was going on. And this one&#8217;s unique because we&#8217;ve done 10,000-plus of these or so before, but we&#8217;ve never had any engagement that even today, Coalfire has never been part of this. All the charges and everything are actually against Gary and Justin as individuals, not anything against the company. So, it was kind of a weird thing where we said, well, we get our lawyers, we&#8217;ll protect ourselves, we&#8217;ll fight this, but we&#8217;re not in anything. We actually had to do it to kind of save the employees, which really, which is a little detail that I don&#8217;t think people really understand.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Becky Bracken<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So then litigation ensues. You all are out and so you have to then make your way from jail back home somehow.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">How did that work, Gary?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Gary De Mercurio<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Tom said, \u201cI don&#8217;t care how you get out of there, just get out of there first class, whatever you need to do, Greyhound bus.\u201d I agreed 100% and we got out of there as soon as we possibly could to get away from the situation. But not before having the worst pizza in the world. I will say that. If you want to know where the worst pizza ever is, let us know and it is in downtown.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It was pretty simple. I was gone the next day. I think Justin actually had a later flight just because he lives in a little town, Naples, Florida. So, it&#8217;s a little bit harder for him to get there. We were out there I think I was out the next morning. I don&#8217;t even think I lasted 12 hours<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Tom McAndrew<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yeah, I&#8217;ll just add maybe onto that one nuance of having bond, having lawyers getting that stuff in. was really, that was something that we had to do quickly. I&#8217;ve never done that. I&#8217;ve never gone out and posted bond through a company. We didn&#8217;t know what these things cost.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This is also a little town. And so, some of the questions we had initially of what&#8217;s the best way to tackle this, right? Do we get big, big New York lawyers to kind of come down and put pressure on or will that backfire because you know, they&#8217;re in a small town in Iowa and it&#8217;s better to kind of connect locally. So those are kind of the things on the back end that you know, we were trying to figure like how do we even, how do we post bond? What do we do for this stuff? And all that.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Kelly Jackson Higgins<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So, I think sort of the big thing to look at too is obviously, so firstly, this was a professional, you know, situation, but also affected you all personally too. Talk a little bit about sort of the fallout, like how you, you know, probably processed it. You probably were shocked that you were being walked to jail from a job you were actually doing legally. And then you had to deal with the overnight, you know, trying to get out of jail, trying to get all the legal stuff set up. What was kind of the aftermath like for you the first 24 hours?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Justin Wynn<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">First 24 hours, probably not as bad as it&#8217;s been in the last five years since. Gary&#8217;s got a lot of fallout that he can discuss and you know, I&#8217;m very mindful of it and it kind of affects my day to day, I approach career and everything else.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But those initial hours, I don&#8217;t think the full gravity had set in until we were arraigned in the morning. And it was clear that the Magistrate, the person who actually formally presses the charge against us, wasn&#8217;t keyed in on the situation. So, the Sheriff hadn&#8217;t talked to her and said, \u201cHey, you know, I did verify called that the state something&#8217;s fishy. You know, we&#8217;d still like to press charges,\u201d nothing like that. I mean, she was set up in front of against us saying, \u201cHey, these guys were arrested burglarizing the courthouse last night.\u201d And then she reads the documents as well in this courthouse and things got a little bit more personal from there.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And then, you know, the input from the county attorney saying these guys are a flight risk, who was working very closely with the Sheriff and he knew the situation. So, then they opted to heighten our bail, heighten the charges, everything they could.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So at that point, yeah, then we&#8217;re facing seven years of felony prison time. Again, all in the first 24 hours. And at that point, you still assume, you know, the company is going to take care of this. Things will be, you know, resolved pretty timely and without incident. And then, you know, the months started dragging on and things certainly change, but Gary, were the first 24 hours for you?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Gary De Mercurio<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Aside from the pizza, they are all right, I guess. Yeah, it was, I think the only thing that was rather nice, Tom, I can&#8217;t say enough about Tom. He handled it about as well as I think anybody could.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Tom McAndrew<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I&#8217;ll get you some free pizza, Gary.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Gary De Mercurio<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Just not from that place. Tom and I had known each other since you were a director, I think, when I came in as an associate. And so, I would like to think that Tom knew that I wasn&#8217;t a complete jackass and I wouldn&#8217;t be breaking into places I wasn&#8217;t supposed to be breaking into. So, I don&#8217;t know if that had anything to do with Tom&#8217;s help or not, but I&#8217;d like to think that it does. But the whole thing was handled, was handled really, really well.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I was a little upset and I think I went into his office later. I was like, \u201cWhat the hell took you so long to bail us out?\u201d I like shut the door, you know, and I was like, \u201cWith all due respect, what the hell is your problem? Then he explained everything. I was like, \u201cOkay, I get it. I understand. Yeah.\u201d<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Tom McAndrew<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I tried the best I could.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yeah, I will say that is one thing that this popped up, you know, and to your guys&#8217; credit, you know, when it did pop up, kind of by the noon, we knew it was serious. The first thing we did go through is go through all the contracts and everything, because, you know, when these things pop up, you have rules.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">You know what you&#8217;re supposed to do, but you&#8217;re always like, is this the one where we didn&#8217;t dot our I&#8217;s and cross our T&#8217;s? Is this the one where we didn&#8217;t, where we had a verbal instead of an email? And like, we&#8217;re, know, on one hand, think that Coalfire, we were very lucky that we had Gary and Justin, because had there been others with less experience or just others that didn&#8217;t have as good of a day, it would have been very different in the outcome.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And you kind of see that from all the everything that got posted, is why this bothers me so much. I mean, when people make mistakes, we get it. But in this case\u2014luck, skill, whatever\u2014the two of them did really everything by the letter of law.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And I think when people in power started realizing it, what really bothered me is they started spinning things politically into messaging. And if it wasn&#8217;t this, then this, then this, then this. And that was something that even today, when I was going back and looking at some of the news articles, you see this slant on it that two people arrested for burglary. And that&#8217;s real. That&#8217;s the sensationalism of this. The background of two people hired to do what they were going to do got in trouble is the big issue that I\u2019m worried about.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And even today, I was re-looking up the apology from the Supreme Court of Iowa apologizing for this. And they showed the contract on there and they say, \u201cWell, we never expected them to physically break in.\u201d<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But even on the screenshot they have of the contract, at the bottom it says, \u201cDo you authorize lockpicking?\u201d And it says, \u201cyes.\u201d But they cut that off halfway and they only highlight the other parts above of the building and the location because it matches their story. And so that&#8217;s, again, I think the part of this is people in power not doing the right thing is the thing that really bothers me.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Becky Bracken<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">How long did you have to live with this? I can only imagine the feeling of I didn&#8217;t do anything wrong and yet I am still, it must be a very powerless and anxiety inducing feeling. How long did this drag on? Where does it stand now? How long did it take you to get some sort of resolution?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Justin Wynn<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">About five years. Honestly still dealing with it just about every day that we&#8217;re in the public light and talking with people and having to set this story straight.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Because while this all went down, our lawyers were advising us that you guys are totally in the right, but the way things work for the law, you can&#8217;t make statements, you can&#8217;t go public. And meanwhile, the state&#8217;s just putting out all this misinformation. The Sheriff&#8217;s setting up meetings, responding to people, putting out all this misinformation. So, the narrative, if you read it in real time online, looks like we were out of scope. We did things wrong. Which can\u2019t be further from the truth.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And still today, there are people that we set straight on that story, let alone all the personal ramifications with employment now that we have an arrest record. It&#8217;s extremely frustrating. I mean, still today, it hasn&#8217;t ended for us.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Gary De Mercurio<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">More specifically, they waited until literally the last day to drop charges, which I think is one day short of six months, I believe is what it was. And I think I had to wait one less day because my charges were dropped. But they didn&#8217;t drop Justin&#8217;s. And I think we were talking to Brian Krebs at the time, I think it&#8217;s on video, where they actually dropped the charges for Justin finally. And we were like, okay. But they just drug everything out.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The dropping of the charges was this huge ridiculous rigmarole where the Sheriff, and please correct me if I&#8217;m wrong because I never was part of that conversation, Tom, but he, I remember having a conversation with the three of us, Tom and Justin and I, where the Sheriff was like, \u201cWe&#8217;ll drop charges, but I want to talk to Tom.\u201d And so, remember we&#8217;re like, \u201cThis was against us, not Coalifre. So why on earth would a Sheriff need to exact his pound of flesh from our CEO when it has nothing to do with Coalfire?\u201d<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">They were never brought up on any charges. Nobody was ever going after them for anything. It was just Justin and Gary, but it was almost like he was holding his hostage. Power play, I don&#8217;t know what it was. I&#8217;m gonna talk to Tom before we drop our charges. And we tried to tell Tom at the time, like, \u201cDon&#8217;t talk to him. Don&#8217;t give him the satisfaction.\u201d I think Tom&#8217;s reply was something like, \u201cWho cares? Let him yell at me as long as we get the charges dropped. Let&#8217;s go for it.\u201d<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Tom McAndrew<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yeah, think that so I think to your point, right, that in the system, because this was against you guys and wasn&#8217;t Coalfire, right? What I kind of told everybody at Coalfire, because everybody wanted to come to their defense, and even others around the security committee really wanted to jump in. But I said, \u201cHey, it&#8217;s less about the public appearance and more about like getting the charges dropped and make sure these guys don&#8217;t go to jail.\u201d So that was kind of priority number one.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But there was that point when nothing was really against Coalfire, right. And we take kind of our NDAs and, you know, our job is basically to find the problems with all these companies and to figure out how bad guys can cut into and make recommendations. So, we take that very seriously. And so, I had known kind of all the facts of exactly what had happened for a while. And we sat on it. And then finally it was that one day when I realized, think they had just, you guys had higher burglary charges, and they moved them down. So, you still had the charges, but they just downgraded them.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And at that point, that&#8217;s when I kind of got upset. So, I wrote a, I remember it was like 11 o &#8216;clock at night. I was just mad, and I wrote this like manifesto just saying, here&#8217;s what they did. They did all the right things. Here&#8217;s all the arguments for hearing the media. Here&#8217;s why it&#8217;s all wrong. People are assuming you don&#8217;t have a letter. You see, this is why you guys have to have this in contract. And I was like, this is, they just didn&#8217;t understand the situation and the nuances of it. And that, once that became public, people understood the difference.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yeah, we think of government as one thing, but know, state, local, they don&#8217;t necessarily like each other. Small towns, big towns, you know, they don&#8217;t like each other. Law enforcement, know, judicial, administrative branches\u2026. And the people that have actually spent time looking at the contracts and what we did and everything, that&#8217;s the scary part, is you walk away today and say, this exact same thing can still happen to anyone today, no matter what. And it doesn&#8217;t matter what the company does. On paper, on anything else, that risk still exists today for every single person that does any of these sorts of engagements.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">You have to realize you are on your own doing this. Hopefully you&#8217;ll have a company that&#8217;ll support you, but even if they do, it&#8217;s like I said, you guys are charged with burglary, not as Coalfire employees and not for doing work. And they don&#8217;t really care about what&#8217;s on the paperwork.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So maybe the analogies you think about it, digitally, people give us IP addresses and websites and every once in a while, people will mess up and they give us the wrong IP addresses or websites and we go after those, and we have to respond to them.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In this case, we do a lot of data center assessments and stuff and a lot of times when people give us those, we&#8217;re assuming those are the right data centers, but just like in this case, a lot of those data centers are actually owned by other corporations you may not know. So just because the company you&#8217;re working with specifically tells you, yes, you can go into these places, whether they&#8217;re physical or digital, does not mean that they necessarily have the authority and it&#8217;s very difficult to understand whether they do or they don&#8217;t before you&#8217;re doing the engagements.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Kelly Jackson Higgins<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This is a great segue to the question I wanted to ask you both five years later, how you&#8217;re approaching these engagements now differently, what you&#8217;re doing differently, what maybe sometimes gives you pause before you go into one.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Gary De Mercurio<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I think immediately when we got back into the physical pen testing, we&#8217;ll tell a war story here, I guess, but, but we started contacting the local police and the sheriff&#8217;s department both. And then we had the client contact the local police and the sheriff\u2019s department both just so there wouldn&#8217;t be some another overzealous sheriff or something saying, \u201cWell, well, you know, we didn&#8217;t hear from the company. Maybe these guys are not on the up and up and we should go check that out anyway.\u201d<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And we didn&#8217;t want him to get in another situation like that. So, we had the client call and then we would call. And it was probably our first or second engagement, we were doing a very large red team and we did that. We called the client called; we had verification before we went on site. We called the local police department, the sheriff\u2019s department said, we&#8217;re about to go on site. We just want to make sure that your dispatch understands that if you get a call that there will be security professionals on site testing the building. So please don&#8217;t come in guns blazing.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And sure enough, we were on site. We set an alarm off. We were actually on the phone with our contact trying ridiculous things to see if we can bypass the alarm. I think we even bought a shower curtain, like on the Karate Kid with the hoop and everything.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And we were trying to get past some of the rec sensors, it wasn&#8217;t a rec sensor, but a motion sensor. And we set the alarm off and he&#8217;s like, \u201cYeah, okay, yeah, the alarm went off. You&#8217;ve got about X amount of time before it&#8217;ll call the plant manager.\u201d<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And sure enough, a police officer showed up. It was his first response to a burglary. He had his weapon drawn and he was shaking. Luckily the plant manager was there with him, and she knew that there was some testing.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And she&#8217;s like, \u201cSon, you&#8217;re going to have to put that weapon away. Like we, we may have some security professionals here and I don&#8217;t want you to shoot them.\u201d And he&#8217;s like, \u201cI&#8217;m so sorry. It&#8217;s just my, it&#8217;s just my first response. I&#8217;m, a little bit nervous.\u201d<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So even after we take all those precautions, and even though we have changed the way that we do things, you still have issues where information still isn&#8217;t passed out. And I, and I believe, correct me if I&#8217;m wrong, Justin, but I think that, I think that Coalfire records most of those calls now. So, we don&#8217;t have the issue like we did before.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Justin Wynn<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That was kind of the big thing.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">All the stuff was on the phone. Yes, we want you to break in overnight. Here are the addresses. Just so explicit that there could be no confusion about what we were there to do. And that&#8217;s where they had leeway in the public lakes wasn&#8217;t in the documentation. We didn&#8217;t expect these guys to break in. So now that&#8217;s, that&#8217;s one thing we&#8217;ve changed, but kind of going back to Tom&#8217;s point, I find it an interesting question. What do you guys do different now when it never should have happened in the first place? And I think our, and I hope our situation is very unique and a one -off because there was a bad egg in law enforcement.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But we had, you know, two prior encounters both with the state trooper and then the responding officers who verified and let us go like happens on every other engagement where we get confronted. There are certainly things that we&#8217;ve adjusted and buttoned up. Some of the documentation I thought was a little outdated and we&#8217;ve done better there, but really in the first place never should have never should have taken place.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Becky Bracken<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I&#8217;m interested in picking up on something that you all were talking about and specifically about the reaction from the cybersecurity community. Tom mentioned it earlier that everybody was sort of rallying around your cause, but it sort of took a minute for that to kick in. Tom, can you walk us through a little bit about what the initial sort of schadenfreude felt like?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Tom McAndrew<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yeah, it totally sucked. We would deal with this all the time. We do audits and certifications and so, and maybe less so now, but five years ago, 10 years ago, anytime there was a breach, or something happened, you&#8217;d want to know who was part of that because they were part of the problem. If you guys audited that or you sign off that certification or someone did the pen test and application was breached, obviously the pen tester didn&#8217;t find that issue and they should.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So I&#8217;d say the community used to be, and maybe newer folks, used to be very reactive when they see something bad happening. They&#8217;re assuming that they were bad people that made mistakes. I think now with this assume breach and assume that you don&#8217;t know the details, the community, or at least I think the part of the community that most of us respect and the most, those are saying, \u201cHey, we never know all the details of everything. And instead, we assume that CISOs are doing their best. Security consultants are doing their best. And let&#8217;s kind of sit back and look.\u201d<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Like these are the questions you should ask. Was it in scope? Is it documented? Did they do it? These sorts of things. But unless you have firsthand knowledge, you really shouldn&#8217;t comment on them. So, I think that&#8217;s shifted a lot over the last several, maybe five years, maybe over the last decade. And the second part is then how do organizations react? Like I said, the comment I have that I made public on Iowa was that in 10 ,000 plus engagements, only one time have they ever publicly posted something like that. So it&#8217;s very unusual.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So, the time when something like this does happen that&#8217;s unusual or unique, it\u2019s a chance for leaders to step up. Like I get it. I get its initial reaction. I get the initial court judge and her reaction. And I get the initial reaction, but once you have the big picture as a leader, you need to come back and be public and say, \u201cHey, I messed up\u201d or, \u201cI didn&#8217;t have all the right information.\u201d And this should happen and that&#8217;s really what didn&#8217;t happen here.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I mean, we had like an employee that started last year. I remember he said, \u201cHey, Tom, just so know, like the only reason I interviewed here is because of how you guys treated those folks.\u201d And for me, it was kind of heartwarming to know that, but also to know that still today, it is one thing that a lot of folks really know about this onto it. And it&#8217;s a good story, right? You get to hear, you get to learn a lot of things.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But the part that makes it sad to me is there&#8217;s a lot of leadership failures out there in the greater community that could have done this. And ultimately, the two people still have lifelong repercussions of this.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There&#8217;s still a wrong in this world that has not been righted. And I don&#8217;t see that there is a path where that&#8217;s likely to be cleaned up. And that&#8217;s why you said, well, how long has it been? It&#8217;s been five years. How long will it go? I don&#8217;t know. To the best of my knowledge, Justin, Gary, there is no 12 more months and records are all clean or anything, right? It&#8217;s still, there is no path.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Kelly Jackson Higgins<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So does this kind of mean that the physical penetration testing job or profession is just not quite the same now? Because can you do the things you could do before with the element of surprise, for example? But you can&#8217;t do a lot of that now. The element of risk on your profession, your professional and personal lives. I&#8217;d love to get your thoughts on that, Gary, sort of where you see this field. Like is it going to change forever now, do you think?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Gary De Mercurio<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I don&#8217;t know that it&#8217;s changed necessarily in too much of a negative way. I think it was very unique in that we were trying to test courthouses for the court system, but the county is responsible for the security of said court system. There&#8217;s some gray area there. We still should have been able to be on site because we were hired by the courts and the courts are the one that run the courthouse, right?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So again, I think there was a whole lot of politicking going on there. In general, though, I don&#8217;t think it&#8217;s changed too much because if a private company hires us to test private property, there&#8217;s not really much the police can say outside of that unless they just don&#8217;t believe us. But again, you&#8217;re arresting somebody that would be the equivalent of a contractor working on private land and being an officer and showing up.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So, we haven&#8217;t had problems in the past and we haven&#8217;t had any problems from that point going forward other than some of the close calls. So, I don&#8217;t think it&#8217;s changed too much.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I think it does highlight, however, people&#8217;s fears of allowing a red team to go through their facility, especially when they hear stories like this or they remember a story like this, which is where, I think Justin was the one that came up with it was the, we called the whitelist walkthrough, where we perform the same function as the red team, just not testing the people, the policies and the procedures because we&#8217;re not doing it real time. We&#8217;re just testing the physical infrastructure of the facility and then going over their policies and procedures to make sure that they&#8217;re correct if people would follow them the right way.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I think so with the advent of that, making people feel a little bit better rather than having two guys breaking in the middle of the night. I hope it doesn&#8217;t change too much because the weaknesses that you find when you&#8217;re doing a physical penetration test are glaring and astounding. Come up with any big word that you want to think of that shows extreme value in that situation.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There are still vulnerabilities that we found four years later that we reported on to one of their facilities that are still there. And when we walked by they&#8217;re still there where somebody could just walk in the facility, kind of like we did with the air pressure in the front when we closed it for the courthouse that we were arrested in. Some of those vulnerabilities are still around because everybody was so worried about whether we should be in the facility, they completely forgot that maybe we should do something about all these things that they found.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Tom McAndrew<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I mean, I think it&#8217;s particularly important for state and local government, because I was actually going into my mind, all the states and counties and cities I&#8217;ve done, and most of corporate America, they outsource their data centers. when we look at what we have access to, physical, logical, administrative controls into it, a lot of governments, and you see it, right? Like you go to the DMV, it&#8217;s not the world&#8217;s best facility there. I was just at the post office here over the weekend. I couldn&#8217;t even tell if the building was open, I wasn&#8217;t totally sure if it was.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So a lot of times you have government and civil servants that are doing the best they can and they&#8217;re stuck with very old buildings that can&#8217;t be retrofitted securely. And then someone decides for money or for whatever reason, they&#8217;re going to stick, you know, Active Directory servers or sensitive things into these facilities. I&#8217;d say normal corporations generally don&#8217;t make those, but it&#8217;s very prevalent in state local government.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And one of the biggest benefits of these sorts of tests is you understand it and it can really help drive funding and fixing things. That&#8217;s been a big part that you&#8217;ll do these long engagements, and you&#8217;ll show all these technical risks and everything, but it just goes over everybody&#8217;s head. But you show them you can break into a door, or you show them that anybody can just go in here, or we had one where a homeless person was actually sleeping in a data center one time. Those things get funding allocated immediately.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One of the negatives of when you pull this out, it becomes very difficult for state, local, CISO security folks that know they have glaring physical holes to be able to show that to management to say this is why it&#8217;s so important. It&#8217;s just not the same as doing these, you know, whitelist walkthroughs. doesn&#8217;t have the same impact.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Gary De Mercurio<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And I want to piggyback on his piggyback, which is there&#8217;s the three-legged security stool, right, where you have logical security, physical security, and then the human element, usually through some sort of social engineering or something into that effect. And it doesn&#8217;t matter how good it is, it\u2019s almost like the stool has to be able to balance on three legs. If you take away one leg, it&#8217;ll balance for a while, but eventually it&#8217;s going to fall down.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When people neglect physical security or they neglect the human aspect and they focus everything on their external logical security, it doesn&#8217;t matter how good it is. If Justin and I can stick a stick through your door and wave it, which Justin has done multiple times, and open the door, and now we can walk into your facility and plug into one of your network jacks, it doesn&#8217;t matter how good your external security is.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And that&#8217;s one of the things that holistic idea of security that each leg is equally as important because they help the other one&#8217;s balance. And by taking this away, you take away one of those legs of that stool. Like Tom said, (we\u2019ve found) homeless people sleeping in a server room. It&#8217;s that easy. People just walk in and without it, you don&#8217;t know where those vulnerabilities are. And unfortunately, organizations, whether it&#8217;s local, state, or even companies, don&#8217;t test for those vulnerabilities and it makes them exceedingly insecure.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Justin Wynn<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Well, apparently that was a popular question, Kelly, because I also wanted to piggyback and tack on to that. But I know you also asked about whitelist, but let me, let me hit that real quick because you asked, \u201cDid this damage our industry or has it had me, has it made things more difficult?\u201d<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I think overall it&#8217;s certainly improved things because we&#8217;ve had conversations and discussions about it. There&#8217;s been proactive industry movements like Awareness-Con, that was held, in the town that arrested us, focused on just discussing this work that we do and how important it is. Documents were released by TrustedSec that show this is the letter of authorization, here&#8217;s the terminology and legal descriptions that we use to approve this type of work. And it also highlights the need of transcended industries, right? We usually operate in such a vacuum or a silo and nobody knows that red teaming and breaking in the buildings is a thing. And now pretty much the entire state of Iowa knows, and quite a few people across the world.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But look at how we got into these places and how trivial it was. There are glaring security issues that were never tackled to date for the decades that these buildings were in operation until red team was hired to do proactive offensive security testing. And I think that&#8217;s the main takeaway for us is how important this is.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And I was, I was a little different. So their reaction was a little bit negative. I think the industry improved, but Iowa did two funny things afterwards.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One: To appease the politics at play, they made the most boneheaded knee -jerk reaction they could make and said, we are never going to do this type of testing again. And now they are permanently in a degraded state of affairs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">All their buildings, like Gary said, we come on site and just walking by, you can see doors held open after hours because of the air pressure. And that stuff&#8217;s not going to be proactively tested. They said no afterhours testing. And look how important it is. And until they change that, they are still going to be in a giant hole and kind of set back from the rest of the industry.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A lot of the hackers, the community that rallied around us said we&#8217;re pulling out of Iowa. We&#8217;re not going to do jobs there if this is how they&#8217;re treating us. And so I think once, other parties at play realized that, Iowa was the second state after California, which tells you how progressive this is, that introduced a statewide VDP, a vulnerability disclosure program. So they did kind of come back and announce to the hackers\u2014and this was months after our arrest and all this case so I&#8217;m sure it had something to do with it\u2014but they basically made a statement to the community saying, \u201cHey, we recognize the importance of this. You know, things probably there weren&#8217;t handled great, but now we have a statewide VDP, second in the nation. If you find vulnerabilities on Iowa systems, please let us know.\u201d<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So that was one kind of positive change, but they still have a long ways to go. So now we can talk about whitelist if you want to get into it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Kelly Jackson Higgins<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yeah, tell us a little bit about the whitelist.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Justin Wynn<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Okay, so there&#8217;s generally two different types of engagements. The offensive, which was Iowa, which is what we&#8217;re all familiar with, and it can encompass social engineering, covert methods of entry. After this, we&#8217;ve unfurled a new offering called, \u201cphysical walkthroughs\u201d or \u201cwhitelist walkthroughs,\u201d which is fully comprehensive. So, some of the trade-offs, we&#8217;re not getting to test live responses. We&#8217;re not seeing if people can be tricked into letting us in.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Targets of opportunity while we&#8217;re there on site and really demonstrating the impact that Tom was talking about that man when you see that in a report that somebody can walk in your data center, that&#8217;s pretty impactful. But the whitelist lets us come in and do a comprehensive audit; so, a full 360, we test every door, every security appliance, we can sit down at the computers with them review the configurations. So, it&#8217;s a lot deeper touch and a lot safer. So, it lets multiple consultants come on site. You don&#8217;t have to worry about jurisdiction multi-tenant office buildings are notorious for this, you know, who do we need to notify? Who do we get buy -in on this? So, it&#8217;s enabled a lot more testing. It&#8217;s comprehensive.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Some trade -offs that you don&#8217;t get with that red team element, but it&#8217;s been hugely successful and something that a lot of our clients are opting for nowadays.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Gary De Mercurio<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There&#8217;s another thing that we implemented too that we did on one of our red teams, which was to invite a representative from the client with us. And so, they were actually on site going through us while we were doing the red team portion of it. We would explain what we were thinking, why we were doing it, the thought process. And that actually worked out. If there is a client there that is willing to do that and has the experience needed to understand what it is that we&#8217;re doing and how it affects their facility, that actually works out phenomenal.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The gentleman that we had with us was outstanding. At one point we had taken one of their yard semi-trucks\u2014we hotwired it, right? And then we moved the semi-truck, backed it up to one of the trailers on their loading dock and moved the trailer so we could try to get into one of their warehouses without breaking into anything because the doors were actually pretty secure.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And he was just like never in a million years would I have ever thought that that was something that we needed to protect. He&#8217;s like, never would have even entered my mind. So when you bring them on site with you, that&#8217;s like that middle step between a full red team and that that assessment is bringing them with you and having more of that purple team approach where they can actually get to see what we do, but they more importantly, they get to see how we think and the things that&#8217;s going through our mind when we&#8217;re trying to enter a facility.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Becky Bracken<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Unfortunately, we have reached the end of our time together. For our audience who wants to learn more about your work or find you, Justin, are still doing penetration testing with Coalfire, correct?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Justin Wynn<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Correct. Yeah, scared to apply elsewhere, but no great company can reach me here or red team wins is my handle.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Becky Bracken<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Gary, how about you? Where can we find you?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Gary De Mercurio<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Well, nobody will hire me anymore because of my arrest record. So, I had to start my own company. I&#8217;m at a company called Kaiju Security, which is which is my own.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Becky Bracken<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And Tom, course, CEO of Coalfire. Thank you so much for your time today. We very much appreciate it and for taking us back to those dark days five years ago. I learned a lot and I know our audience did as well. So thank you.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Tom McAndrew<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Thank you so much for having us.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Kelly Jackson Higgins<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yeah, thank you.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Becky Bracken<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I want to thank you again Justin and Gary. Thank you to our audience and to Kelly Jackson Higgins, Dark Reading&#8217;s editor-in-chief. We appreciate everybody joining our conversation today.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That&#8217;s been Dark Reading Confidential, a podcast from the editors of Dark Reading. We&#8217;ll see you next time.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/dark-reading-confidential-pen-test-arrests-five-years-later\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Becky Bracken, Senior Editor, Dark Reading Hello and welcome to<\/p>\n","protected":false},"author":12,"featured_media":5220,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5219","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/dark-reading-confidential-pen-test-arrests-five-years-later.jpg?fit=1920%2C1920&ssl=1",1920,1920,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/dark-reading-confidential-pen-test-arrests-five-years-later.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/dark-reading-confidential-pen-test-arrests-five-years-later.jpg?fit=300%2C300&ssl=1",300,300,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/dark-reading-confidential-pen-test-arrests-five-years-later.jpg?fit=640%2C640&ssl=1",640,640,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/dark-reading-confidential-pen-test-arrests-five-years-later.jpg?fit=640%2C640&ssl=1",640,640,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/dark-reading-confidential-pen-test-arrests-five-years-later.jpg?fit=1536%2C1536&ssl=1",1536,1536,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/dark-reading-confidential-pen-test-arrests-five-years-later.jpg?fit=1920%2C1920&ssl=1",1920,1920,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/dark-reading-confidential-pen-test-arrests-five-years-later.jpg?fit=1024%2C1024&ssl=1",1024,1024,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/dark-reading-confidential-pen-test-arrests-five-years-later.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/dark-reading-confidential-pen-test-arrests-five-years-later.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/dark-reading-confidential-pen-test-arrests-five-years-later.jpg?fit=1920%2C1920&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5219","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5219"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5219\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5220"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5219"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5219"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5219"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}