Ryan Tappis: Why Most Hackers Get In Through the Basics
About this episode
Ryan Tappis, Co-Founder of NR Labs, a pure-play cybersecurity firm that serves federal and commercial clients, says that after more than a thousand pen tests the same weaknesses keep letting attackers in: weak passwords, missing multi-factor authentication, and old software that never got patched. Good cyber hygiene, he argues, beats any Hollywood hacking scene. The conversation looks at how AI is changing both sides, from attackers finding zero-days faster to continuous AI red teaming on defense, and what a real moat looks like once anyone can vibe code.
Tappis also breaks down what separates a great CISO from an average one, and how NR Labs grew from 40 to 90 people while winning four prime contracts in a single year. He treats revenue as a byproduct of hiring the smartest people in the room. He closes on the myth he most wants gone: that cybersecurity is just hackers in hoodies.
In this conversation
- Why most attackers still get in through the basics: weak passwords, missing MFA, unpatched software
- How AI is changing both sides, from faster zero-days to continuous AI red teaming on defense
- What the new moat looks like when anyone can vibe code
- What separates a great CISO from an average one
- Growing NR Labs from 40 to 90 people and winning four prime contracts in a single year
- The myth he most wants gone: that cybersecurity is just hackers in hoodies
Full transcript
Welcome back to another episode of the Agentee Digital podcast. Today we're joined by Ryan Tappis. Ryan, it's a great to have you here.
First of all. And second of all, I would like to know what you're currently up to in the day-to-day. >> Appreciate you having me here.
Um it's it's a pleasure speaking with you. So, let me tell you a little bit about um where I came from personally and then I'll I'll dive in a little bit about NR Labs. So, I started my career at Booz Allen, um you know, learned all the stuff that you would expect to learn in a major world-renowned consulting company, right?
How to talk to people, how to deliver quality, um how to connect with clients, how to speak, all of that stuff. I left Booz Allen and I went to a bunch of small businesses throughout my career and then ended up founding NR Labs with my colleagues uh Brian and John. So, NR Labs is a is where a pure play cyber company, right?
That's it. We support federal, commercial clients and all we do is cyber. Um we don't you know, our whole idea is we don't want to be everything to everyone, right?
So, we made a very deliberate choice to really lock in only on cyber. Um that's where expertise lives and that's frankly where the stakes are highest um in the industry. So, the the agencies that we support are responsible for everything from financial regulation, um critical infrastructure, national security, and then our private sector clients, which I'm not allowed to name.
I'll just say it's a it's a very impressive uh a group of clients. Um so, you know, in terms of our journey as a company, um our last year has been remarkable. Um you know, I I think you know, you've heard of DoJ and kind of the impact that had on on the government sector um on our side.
Um but we built a firm from about 40 folks to about 90 over the past year. We won four large prime contracts supporting different government agencies. And you know, at the same time we we had to build out our leadership structure.
Ensure the culture remain the same. And all that stuff and and it was every bit as hard as you can imagine. >> Mhm.
Yeah, that's amazing. And your firm actually has run over a thousand penetration tests and assessments. And you know, after that much real-world exposure what what do you think is something that's uh most organizations still get wrong about you know, their own security?
>> Yeah. >> And uh what what would that be? And uh how would you correct them?
Or give them some advice. >> It's it's most of the time it is the basics. You know, we call it cyber hygiene, right?
It's just doing the basics. Not falling for social engineering, you know, the phishing emails that everybody gets, not clicking on them. Multi-factor authentication is by far the number one thing that I recommend to folks personally and in businesses.
If you have MFA turned on and the bad guy gets your password, there's nothing they can do about it cuz they don't have that second factor to authenticate. So again, at the end of the day, I folks are surprised, you know, they have this perception that hackers are you know, digging in and running in command line and things like that. But at the end of the day, the the most of the time the way the bad guys get in is through the most basic stuff.
Cyber hygiene, that's what we call it. >> Mhm. And are are are there any other parts of cyber hygiene that uh you think are worth mentioning?
>> Yeah, so I mean, so MFA uh is one that that we always talk about, system hardening and patching, right? You'd be surprised that folks sometimes are running very, very old versions of of Windows, for example. Windows XP, we see sometimes.
That hasn't been patched in years. There's vulnerabilities out there that the bad guys can exploit whenever they want. So, patching, vulnerability scanning MFA things like um uh protecting against phishing attacks, network security, right?
So, DLP, stopping stopping things from going out that shouldn't be going out, network segmentation, right? So, if there's a if there's a breach here, I can't move laterally here cuz the network is segmented. Again, none of these things are rocket science, but it's all of these things combined, you know, the bad guys it's like it's like a a robber walking down the street.
He wants to go into the easiest house it is to break into. If there's a house that's really secure, he's going to be like, "I'm I'm going to the next house that's way less protected." So, we want to make it that, you know, you can never be 100% protected, but we want to make it so they go to that next house. >> Mhm.
Yeah, that's that's great. And with with all of the AI things that are coming out, you know, Me Dos and all sort of things, what's what's your take on that? And I know that NR Labs has like a cyber innovation practice that's working on AI and zero trust.
Um where do you see AI you know, changing the day-to-day reality to for your customers uh security teams, and where do you think it's still kind of lacking? >> I mean, obviously, AI is changing the world as we know it, right? Across all sectors.
Cyber's no different. So, the way I look at it there's really there's two sides of the coin, right? The bad guys can leverage AI to do a lot more, a lot faster, and a lot better.
And then we on our side can use AI tools to both protect against that, and also build things faster that can stop the bad guys, right? So, you know, you talk about Mythos and Glasswing and things like that. Yeah, it's common and they're finding vulnerabilities and zero days way, way, way, way, way quicker.
And it's forcing us to kind of adapt how we do things. You know, there's a new there's a new concept um AI red teaming, right? So, instead again, like I said, instead of the bad guys having AI, it's like, okay, we're going to pretend we're the bad guys and we're going to use some of that AI to try to break in, and we'll and we'll see how well you guys do.
And it's almost like continuous Typically, we do penetration testing and it's like a one-and-done thing. AI pen testing allows you to do it almost continuously. So, you're constantly looking and constantly scanning for where you may be weak.
>> Mhm. Yeah and where do you actually see AI in, you know, the upcoming months? I don't want to say years because I feel like that you know, every there is AI there's new features coming out every week.
So, where do you kind of see it heading? >> I can't you know, I don't want to philosophize on my own personal opinions on AI cuz I I have a bunch. Um but I just see it I mean, it's obvious see it it's it's like Moore's law on steroids, right?
It's just not slowing down. It's just faster and faster and faster and faster. And I just see uh a lot of the the menial tasks.
Let me not say not menial task, but maybe more entry-level manual tasks are just going to continue to be to go away. Like I'm sure that you use some sort of AI either to come up with the interview questions or whatever. I mean, it's just everybody is using it for things now, and I only see that expanding.
Things like spreadsheets, developing PowerPoint decks, uh spell checking and grammar, all of that stuff is really a {quote} outsourced now to to AI, and that's only going to expand. And I personally worry about the societal impact of that. I don't know that that we as a world are ready for all of these white-collar jobs essentially that to potentially go away.
>> I feel like for most for most companies, it has always been the code, right? In in the past, it has been the technology itself. And now it's more or from my personal experience and opinion, it's it's more about the uh idea, because everyone can, you know, vibe code anything that they would like.
>> Yep. >> So, what's what's your take on that? >> Well, I think I mean, I think it goes that saying that that that businesses need to adapt or they will die.
I mean, that there's no getting around that, right? And and and the their the strategies and the approaches that businesses take to AI are going to dictate how successful they are, period. So, to your point, vibe coding has made it so that developers are I don't want to say less in demand, but but a lot more that they can do.
The vibe coding makes developers a little less um I don't want to say less needed, but but the whole vibe coding thing has just changed the game, right? So, I think that that whoever can embrace the AI tools the best will succeed. What that {quote} mold looks like, to your point earlier, I don't know.
It changes so fast, so fast, that I just don't I couldn't tell you what it's going to be like in 3 months. And I think anybody that does is being a little disingenuous, because it's just changing so fast. >> Mhm.
Yeah. Yeah, that's that's Yeah, that's what I what I also think about uh ba- based on kind of your your own experience, uh there must be some kind of common patterns that occur when when a new client comes into your door. Um what are what are sort of the common things that uh you see over and over on a repeated basis?
>> You mean from an AI perspective or or in general? >> Well, we could we could start with AI. >> Okay.
>> To to to begin with the same topic. >> the question that the question they always get is there's there is a I think a misunderstanding of AI in the cyber world and and what it can do. I mean, you get the things like Mythos out there and everybody kind of panics, right?
Like, am I am I going to be breached tomorrow? So the first thing we do is we we teach them a little bit about what is the impact. Let's take a deep breath.
It's going to be okay. But they always want to know one, what is the what is Mythos and what is that going to do to me? And then two, how can we as an organization better leverage AI?
So, you know, those are the those are the two things from an AI perspective. Now, from a more general standpoint, when we get a new client, and again, I think this is where we need to separate the the federal space and and the commercial space. It's two different completely different animals, right?
In the federal world, when we get a new client, frequently what they're asking it for is help with navigating the ton of frameworks that they need to that they need to go through. FISMA, uh in in the US, FISMA, zero trust security, um CDM, FedRAMP. There's all of these regulations and they're trying to navigate them all while at the same time, partially due to Dorsch, their their budgets are cut significantly.
So, they need help, they need a lot of help, and they need it cheap, right? So, that that's kind of the the public sector piece. The private sector piece is different.
And and based on what we do, we're we're pretty much strictly pen testing and red teaming. It's pretty basic. Where am I weak?
Break in, show me how you got in, show me that you got in, and show me what you're able to take out. And that is essentially the the the you know, what we do from a pen test perspective. Obviously, there's a lot more commercial sector services that are out there, you know, instant response and things like that.
We don't really do that. So, the ask for us is is strictly from a red team. Get in, show me how you got in, help me fix it.
>> What do what do you think is kind of the differentiator of NR Labs from from other cyber firms? >> That's a great question. So, so a couple things I would say there.
One, you know, I've been in the consulting the cyber consulting field for a long time and have seen a lot of the pluses and minuses. And what we try to do when we built NR Labs is hang on to those pluses and stay away from the minuses. So, a couple things that we that's woven into our culture, right?
One, we will never and this is a common practice. We will never promise you some senior person that will come in and help you, and then on day one it's some junior person that has never even done anything. That's a very common practice, right?
Two, we have world-renowned experts. The folks on the on the on the commercial pen test team, they are just way too smart for their own good. And I do think that, you know, we are a smaller business, so we don't have to charge those four $500 an hour rates.
You're getting these world-renowned experts at a at a discount. Um and we are three, I would say we're really really really constantly trying to push the envelope. So, we're making a big investment right now in a new concept we call GRC engineering, governance, risk, and compliance engineering.
And that's automating the compliance piece of security. So, SOC 2, um CMMC, things like that. We're trying to automate them and making them way more efficient, costly, and accurate.
Less costly, I should say, and accurate. >> Mhm. And what do what do you think kind of separates like a great CISO from an average one?
Be- besides the age, because you already you already you already mentioned that. >> So, I think that, um, you know, CISOs are all over the place. I I This is kind of a cliché answer, but they have to be balanced.
We see a lot of CISOs that are either incredibly technically savvy, right? And and can't speak to the board that they have to report to, or we see folks that that that are just they can speak to the board, but they don't understand what the heck is going on from a technical perspective. You know, we'll give them a pen test result, and they're like, "What does this mean?" Um, and then we'll have others that are like, you know, "I want to brief my board on the latest zero-day vulnerability, this CVE, talk to me about it." And we're like, "The board doesn't want to go into that level of detail, right?" So, a CISO really has to be balanced, has to be technically savvy, and able to talk at a high level to business leaders.
>> Looking back on your career, Ryan, right? Like you've you've probably seen a lot of things. I uh I imagine um, what do what do you think is like a belief about cybersecurity that uh you were convinced about when you were starting out your cyber cyber journey, and now maybe it uh has changed.
>> So, yeah, that's a great question. I have a couple things. If I can get on my soapbox for 1 second, this is strictly federal cybersecurity, federal employees in general.
When I started as a federal contractor or federal consultant, whatever you want to call it, I had this preconceived notion that all employees and and you know, I'm not sure if if you've heard this, but all federal employees are unqualified, lazy, um can't perform in the private sector, and that is so far from the truth. Some of the smartest people I've ever worked with work in the government sector, and that is a stereotype that just drives me crazy. So, I have to say that.
I get off my soap box. Um so, in general, um the thing that I thought when I started my career is I think everybody has in their head that you got these pen testers with their hoods on, and they're just hacking all day. And cyber is so much broader than just that.
I mean, that is such a small slice of it. I know it's a sexy piece. Trust me, I understand that.
But the governance, risk, and compliance piece, creating policies, security awareness and training, incident response, there is so much more to cyber than just hacking. And I think folks don't understand that, and they they really think I you know, I tell I tell them, "What are you doing for a living?" "Oh, I'm in cybersecurity." Guarantee what's in their head is always sitting behind a keyboard hacking. But that's not what I do, you know?
It it it's way broader than just that. I really think it's a it's a misunderstood industry. >> Mhm.
And so, my question to you is, what do you do? >> What do I do? >> Yes.
>> You mean on like a day-to-day basis? >> Yes. When it when it's not this hacking that you mentioned.
>> So, all right. So, so for example, my job within NnR Labs, uh we're a small business, so I wear a thousand different hats, right? From a cyber perspective, I have a client myself, and he's a CISO, and I sit with him, and I say, "All right.
FedRAMP just came out. What are we going to do about the new FedRAMP 20X program? How are we going to How are we going to implement that?
Or NIST SP 800-53 rev 5 came out." And I apologize I'm I'm in acronyms, but these are just examples. And I help them navigate the new requirements. And then I will help him, "Hey, we need to update our policies.
Hey, we need to update our awareness training. Hey, we need to ensure we're complying with this." And a part of that is the hacking, but it's a very small piece when all is said and done. We have to be compliant.
We have to do all of the things that will protect against the hacking. The hacking is the fun part, but without all the foundational stuff in place, the hacking will expose things that really just shouldn't even be there. >> Yeah, and now kind of uh wrapping this up, I would like to ask you like where where do you see NR Labs uh in the future?
What's kind of the goal that you guys are trying to achieve in the upcoming what we are we are almost halfway in the year? Uh so what's what's the main goal? >> The main goal and I tell my team this all the all the time.
It's not about revenue or anything like that. We just want to work with some just smart motivated cyber minds, period. That's what really inspires me to get up in the morning.
It's not that oh I made another million dollars in revenue. I want to work with people that are just ridiculously smart. And our goal is to assemble what we call the you know the the the greatest cybersecurity minds in the world in our company.
And I'll put our roster up against a lot of others. I mean that we are we have some really really smart folks that have been published, that have spoken at, you know, world-renowned conferences, that have written books, that have gone to Harvard. I mean this is just a really talented group that we work with, and that is what motivates me.
And where that takes us, ideally, I think it will take us to growth, but in the near term, we want to continue to work on our culture, we want to continue to foster our people, and we want to continue to build the company with really, really, really smart people. >> Yeah, that's great. And kind of the revenue part is like a byproduct of you focusing on that.
>> Exactly. I think if you put revenue first, I think everything kind of doesn't work out. It will be absolutely as a byproduct.
Getting all of these people that are just the smartest in the industry, customers are going to want to work with them, and then the revenue will flow. But that is to me I think a lot of companies do it backwards, and I don't know that that gives you a lot of staying power. >> Mhm.
Okay. Well, Ryan, it's it's great to have you here today. Uh and I will I will leave links so people can check you out if if they would like to, you know, discuss any cyber or just check out NRx Labs.
And thank you for taking the time and joining. >> Really appreciate the time. Great conversation.
Thank you.