Interview with Tony Anscombe is the Chief Security Evangelist for ESET

This post was originally published on this site.

[embedded content]

Cybersecurity has become a growing challenge for small businesses, particularly as cybercriminals adopt more sophisticated tools and artificial intelligence accelerates both attacks and the discovery of new vulnerabilities. For businesses with limited IT resources, keeping systems protected around the clock while managing patches, employee security, compliance requirements and emerging AI risks can quickly become overwhelming.

To explore what small businesses should be doing to strengthen their defenses, I spoke with Tony Anscombe, Chief Security Evangelist at ESET. Anscombe has spent roughly 30 years in the technology and cybersecurity industry and works with organizations, technology partners and the media to help explain the constantly changing threat landscape.

During our conversation, Anscombe discussed why small businesses should stop viewing cybersecurity strictly as an IT problem and instead consider it a broader business risk. We also talked about the challenges of 24/7 threat monitoring, the difference between traditional IT expertise and specialized cybersecurity expertise, when businesses should consider outside help, and how artificial intelligence is changing the threat landscape.

Anscombe also explained what small businesses should expect from managed detection and response services and managed service providers, as well as the responsibilities that should remain inside the business even when cybersecurity is partially outsourced.

Here is our conversation.

Leland McFarland: Hello, Small Business crew! I have a special interview for you. Got Tony Anscombe, the Chief Security Evangelist of ESET. Tony, great to have you on.

Tony Anscombe: Hey, good to be here, Leland.

Leland McFarland: Great. All right, why don’t we start off by having you tell the audience a little bit about yourself and a little bit about what you do at ESET?

Tony Anscombe: Okay. Well, as you said, I’m Tony, Chief Security Evangelist at ESET. So what does that actually entail? Well, you know, I go around talking about cybersecurity and the current threat landscapes and things like that at conferences and to the media, but I also work with a number of technology partners as well. So, some of the underlying companies that we all rely on from cybersecurity perspectives and in generally our day-to-day lives, I try and look after some of those relationships, find out what they’re doing and stuff as well. So, pretty interesting stuff. And just to give you the snippet of where did I come from: well, I’ve been in the business 30 years, and I started life as a COBOL and FORTRAN programmer. Now poor old Leland here is going to have to look that up.

Leland McFarland: No, I learned about FORTRAN back in… My career started out with a computer programming degree at Oregon State University, so I actually studied it a little bit. Not a lot, but I know where you’re coming from.

Tony Anscombe: Well, it was on punch cards if that if that rings any bells. So, yeah, going back a bit.

Leland McFarland: Great. All right, so when you look at small IT teams today, what are the absolute biggest hurdles they face trying to lock down a small business?

Tony Anscombe: Well, it is challenging, and I think AI has added some elements to this that probably is drawing—not confusion, I think there’s an element of unknown in there when you start talking about AI. Are we talking about threats? Are we talking about the deployment of AI, etc., etc.? And I know we’re going to get to some of that in the interview, but if you overlay that then on my questions, you’ve got the whole issue of cybercriminals don’t come when you expect them to come. They don’t work 9 to 5, they’re not in your time zone, unfortunately. So, you know, the big challenges out there are 24/7 monitoring. So realistically, today, to protect a business, you’ve got to be protecting it day and night, every day of the week, because at 3:00 on a Sunday morning, that’s when the cybercriminal’s going to come knocking on the door. And are your teams there?

The other big one I think in there at the moment—and this is kind of on that AI-related—is vulnerability and patch management. You know, if you look over the last 12 months, in fact, to the start of this year, the first three months of this year—and I’ll just use this as an indication—you know, Microsoft’s Patch Tuesday, that fateful day where your machine turns around and says it’s updating… At the start of the year, they used to patch for the first three months between 150 and 200 fixes per Patch Tuesday. September was 974. And that’s because AI is being used to find the vulnerabilities at a scale that we’ve never seen. So I think as a small business trying to keep pace with some of that—and you know, the Patch Tuesday one is a fairly automated process, but you think of all the different components, all the different software, all the different hardware you’ve got in a business—keeping up at that scale, I think, is virtually impossible.

Leland McFarland: Right. Small businesses sometimes assume that they aren’t large or valuable enough to be a serious target. I’ve heard stories otherwise, but why is that mindset very dangerous today?

Tony Anscombe: Well, it certainly is dangerous, and one of the reasons is because small businesses are a conduit. They’ve got partnerships with bigger businesses, so they could be the weakness in the chain. I’m going to use an example here because actually, I think it was on such a mass scale that I think it’s important to understand the learnings from it. Jaguar Land Rover, JLR, had that cyber incident. It was fairly well-published across the world. Shut down production of their entire car plants in multiple countries, and it cost around just under £2 billion for the cyber incident. I can’t even start to fathom how you recover from that.

The importance here, though, is there were 5,000 small businesses involved. They had to lay off nearly 300,000 people between them. So when you start thinking about that, now, obviously that incident was JLR, so it’s the primary, it’s the hub of all things, and that doesn’t really answer your question. But it was actually a small business in amongst that mix that caused the issue. It was a service provider that was compromised, and thus JLR was compromised. So there you go. That’s why you’ve probably got information that somebody wants.

And even if you’re not in what I’d define as the service chain—i.e., maybe you’ve got credentials or maybe you’ve got access to their systems or whatever—if you were a service provider that you made the magic screw that held the gearbox together, and as a cybercriminal I can work out that supply chain and I can come and take you offline, and I can bring JLR’s production line to a halt because they can no longer get the magic screw, then you’re holding a really influential part of that supply chain for them. So my point here is, however small your business is, you’re probably critical to someone. And it’s when a cybercriminal realizes that, then actually you just made yourself a target.

Leland McFarland: Right. Is there a point where SMBs should recognize that managing cybersecurity entirely in-house is no longer realistic, and what warning signs should an owner or IT manager be looking for?

Tony Anscombe: Well, firstly, I’d like to suggest that owners and IT managers in small businesses stop thinking of this as cyber risk, because I think we historically all think about, “Yeah, the computer’s down,” or this—it’s blamed on IT; it’s blamed on cyber connectivity. This is about business risk. And you need to approach cyber with a business risk hat on.

So, you know, can your business survive? Can you be realistic about being able to do 24/7 monitoring, because we know that cybercriminals come at those weird times of day? Do you have trained security analysts on staff? If you don’t, do you have access to them in a fairly free way? I.e., can you access them when you need them, or are you on a long list of customers that are in the line for them?

My point here is I think you need to ask yourself the question of, “Can my business survive a cyber incident? If a cyber incident unfolds today, how resilient am I?” If I’m not resilient enough, then I need to be going to get some help. Can I keep my business operational? And you see even big companies don’t do this very well. There’s incidents around the globe where you see a big company go offline for two, three days if they have a big cyber incident—the JLR one as we just talked about is a good example for weeks. But then you see a small business down the street switch to paper, and, you know, they turn their business around and keep it going. So, could you keep going? And I think that to me would be the telling time of: if I can keep going, then maybe I don’t need the outside help; if I can’t, then I do.

Leland McFarland: All right. A lot of small companies have an IT person or a small IT team, but not a dedicated security team. What is the difference between being good at IT and having the expertise needed to detect and respond to modern cyberattacks?

Tony Anscombe: I heard somebody put this in such a beautiful way recently. So, you have a family practitioner, and the family practitioner is pretty good at telling you whether you’ve got flu or whether you’ve got something that needs a specialized doctor to look at it. Would you trust your family practitioner to do the neurosurgery? Therein is—I think we just answered the question, didn’t we? That’s why you need security experts.

When you look at the sophistication of a cyberattack today, it can be really complicated, because cybercriminals don’t just deploy a piece of malware and carry on. They infiltrate, they move laterally around networks, they exfiltrate data, there may never be any malware. They might have persistence in the network—i.e., they may have left themselves multiple methods in, so even if you lock one… So you need that specialized doctor. You need the security analyst, that expert, to help you out. And I thank whoever it was that I heard use the medical analogy. I thank them for it because everybody smiles when you use it, and it’s like, “Oh yeah, okay.”

Leland McFarland: That is a great example. It really kind of hits home how important the difference is between the average guy who’s good with technology and the person who has dedicated their life towards actually stopping cyberattacks. All right. Cybersecurity increasingly requires round-the-clock monitoring. What can happen if an attack begins at 2:00 AM on a Saturday and no one is actively watching the environment until Monday morning?

Tony Anscombe: Well, as you roll out of the nightclub at 2:00 AM on a Saturday morning and your phone goes off saying you’ve got a security alert… No. You know, and I say that with jest because at my age I’m not going to a nightclub anymore, certainly not at 2:00 AM in the morning.

But my point here is if a cybercriminal can gain access at 2:00 AM on a Saturday morning, then basically, if your business is a Monday to Friday business, realistically they’ve got two days to sit there and move around, work out what data is important, exfiltrate it, and by the time you come in on Monday morning, you’re either facing a data breach or you’re facing a system that’s completely non-operational. So, I can’t express enough that actually you need that continual monitoring. And even if you’re a small business and you don’t have that 24/7 response, or you haven’t got systems that can respond automatically, then you’re not going to be in a good shape in today’s world, unfortunately.

And I think most companies are starting to understand that. I think more sophisticated cybersecurity solutions are being either implemented, are implemented, or are thought about within the next 12 months, so I think we are starting to see that change from the business side.

Leland McFarland: Great. All right, enterprise-managed services usually come with an enterprise-grade price tag. What realistic options are there out there for small and mid-sized businesses that still need robust security?

Tony Anscombe: Well, firstly, I’ll say that you can’t think of cybersecurity… It’s about the value of keeping your business running, so can you afford to be without it? And yes, there’s an element of risk in here that you have to then calculate, i.e., if this happens and I lose my business for the next two weeks, does my business actually survive? So therefore, then you’ve got to calculate what it is that you’re willing to spend or what I need to spend to make sure that my business will continue or will recover in a good time frame. So you have to think about your appetite for risk, so to speak, as a business owner.

Now, the second part of that question is: actually, no, it doesn’t necessarily need to be expensive. It’s about finding the right partner, and actually at ESET, we have recently repackaged our MDR. Obviously when we bring out product releases, there’s new features and all those sorts of things, but we’ve kind of repackaged it and taken the view that actually, MDR should be available to everyone. It should be, and there should be a price option that all businesses could take advantage of. And I’d recommend come talk to us or come talk to an MSP and actually find out what it would cost to have the right protection and the different levels of protection being offered, so that you can then work out where your appetite for risk is or what your business can actually afford to implement.

Leland McFarland: So AI is giving attackers new ways to automate phishing, reconnaissance, and other parts of an attack, while businesses themselves are rapidly adopting tools like generative AI and AI agents. How is that changing the security challenge for small businesses?

Tony Anscombe: Well, we’re all doomed, aren’t we, Leland? You know, AI’s coming and it’s… No, I kind of say that tongue-in-cheek, because we’re not. I think there are lots of things coming that are a problem. So, in a business, if you’re a small or medium business—and in fact, I’d say even a lot of bigger businesses still don’t have a handle on this—you potentially have got data leakage. I’d ask you the question, Leland: do you ever actually look anything up using an LLM? Have you crafted a piece of text? And you’re smiling on the video stream, so I know…

Leland McFarland: Yeah, a couple times.

Tony Anscombe: Yeah, right. Have you ever uploaded something that could become company-sensitive? Hmm. You have to think about that.

Leland McFarland: I try not to. I try not to.

Tony Anscombe: Yeah. But the problem is, you and I probably know very well because we’re in the industry that we shouldn’t be doing this, but we step down into industries where actually the people aren’t as aware as we are—I think is a better term for that. They may well upload data; they could be uploading IP; they could be asking a system to rewrite their emails or rewrite some text. But actually, if they’re doing that on a public system, then obviously that data leakage, that information is going into the training of the next version of the model. So potentially it could be resurfaced at some stage to somebody else.

Then you’ve got agent activity, and that’s kind of where my tongue-in-cheek bit was: “We’re all doomed, the rogue agents are coming.” No, no, you know… If you run it, but I think there’s two sides to that. If you’re running agents internally, so an employee might be running an agent—I saw some AI skills recently, some pretty cool skills actually, that teach an agent how to create PowerPoint presentations. You upload a couple of pages of text, it creates the slides and the speaker notes for you. You know, that could be a useful tool to a lot of people, at least to get your presentation started, etc. But again, you’re expanding the entire attack surface using this type of thing. And AI skills—we recently published some research that showed they can be malicious. Bad actors have realized this and are infiltrating them and putting bad code in them.

AI-generated content: when an AI agent does give you that text back, creates that presentation, are you verifying what it tells you? Are you actually verifying the output from the agent, or are you using it for business purposes? I think a lot of people would just trust it: “Well, the AI told me that, it must be right.” And put it in the email and send it to a customer, and people aren’t looking at it. So you’ve got this lack of general visibility as well.

But on the other side of that, attacks are unfolding faster, deception’s easier, you’ve got this extended attack surface. It’s a challenge. Look, AI is a challenge, and right up front I said it’s the unknown, because you’re seeing this unfold at a pace where I think it’s challenging for anybody to keep up.

Leland McFarland: So when an SMB brings in an MSP or managed security provider, what responsibilities should still remain inside the business? In other words, what parts of cybersecurity shouldn’t simply be handed off and forgotten about?

Tony Anscombe: Well, firstly, you’re partnering. You’re not handing off; you’re partnering. You’re doing this with somebody. So there are certain things that should remain internal. Governance and policy remain an internal issue. So the service provider is providing something to within the policies that you want to have in your company, and you need to make sure the service matches your policy and continues to make you compliant. There may be regulatory issues, there might be legislation that requires you to do certain things, especially if you’re in healthcare or you’re in critical infrastructure or such like, or you’ve just as a business got to adhere to privacy legislation depending on where you might be doing business around the world. So some of these things need to stay within your organization.

Training is a good example; training of your own employees on cybersecurity awareness, that’s definitely something that remains on your internal side. And business resilience planning—cyber, the bit that you’re outsourcing, is a part of the puzzle. Can your business manage if you did have an incident? And bear in mind incidents aren’t always cyberattacks; could be a power outage, it could be an internet outage, who knows? But will your business survive? Business resilience planning definitely belongs internal, and a large element of that is cybersecurity.

The other one I’d add in there is crisis management. Crisis management is part of a cybersecurity plan, but these days that might be handed off to an insurer, so there you go, you might have another third party involved here doing your crisis management as well. So then it’s about being the director of the play and keeping all the acts on the stage at the right time and making sure they’re all doing the right things for your business.

Leland McFarland: So we hear a lot about detection, but detection is only useful when someone actually responds. What should a small business expect to happen after a managed security service identifies a serious threat?

Tony Anscombe: Well, firstly, if they’ve identified a serious threat, hopefully they’ve isolated, disconnected, blocked it, and responded accordingly. Now, most solutions, if it’s a serious threat and they see something like this, should respond to this automatically, so there should be automation in here. But if not, if it does require a security analyst and you’re using an MSP and they’ve got an MDR service running behind them, then that security analyst should be taking that off, and the time to respond should be relatively quick—I’m talking minutes or tens of minutes, not hours, and certainly not days.

But what should happen after that? Well, you’re then looking at service restoration and notification. You come in on a Monday morning and there’s a workstation down the hallway that doesn’t work, well, maybe that’s because that’s where the threat unfolded and it’s been isolated and is no longer on the network. So the service provider should be presenting the facts, in effect the evidence board, back to the company, giving them the summary of, “Look, this incident happened over the weekend, here’s the incident, here’s what the resolution was, and here’s the action and recommendation going forward,” and of course looking at the root cause. So I often think when you watch the detective dramas on TV and they have the evidence board, that’s kind of what you want, isn’t it? You want somebody to draw you the picture and say, “This is what unfolded, and this is how we got to a resolution.”

Leland McFarland: So if you were giving advice to a business owner right now, what key things should they look for when vetting a cybersecurity vendor or MSP?

Tony Anscombe: Well, that’s an interesting one, because it’s a balance of… There’s a number of things you should look for. It’s a partnership, and I think I already said that, and you’ve got to look at that partnership. If I was a small business owner, I’d look for the MSP that wants to understand my business. And the reason I say that is because if they try to understand my business and they appreciate what my business is actually doing, then the services they provide me will be geared towards my business. I shouldn’t just be a number, i.e., another customer that’s an MDR customer down the path.

Understand what compliance I need, understand what legislation I need to comply with, how can they help me with that. Maybe I’ve got something very specific, maybe I’ve got operational technology segmented in my network; they should have an understanding of what other parts or what other threats I should be concerned about. My point here is that it’s not just sign up, get a service from a managed service provider; it’s actually partnering with a service provider. And I think some of those things would be incredibly important to me. I’d also include them in table top exercises as well, by the way, to make sure that actually in a crisis, they’re going to perform.

Leland McFarland: All right. So for the audience, why don’t you tell them a little bit about the kind of services that ESET can offer for small business owners, and where’s the best spot for them to learn what they can get done for them and how they can get protected?

Tony Anscombe: So we have a range of services all the way from what I’d define as basic services all the way through to hand-holding, white-glove type treatment where you’ve got access to security analysts, threat researchers, and such like. And beyond even that, we can provide threat intelligence either in report format or threat intelligence feeds as well. So all the way from what I define as the small business down the street all the way up to the large enterprise—in fact, for that type of threat intelligence on APT groups, you’re talking about governments and such like.

So depending on where somebody wants to sit, and some of those packages are all-encompassing, so multi-factor authentication, encryption, MDR… There’s lots of different parts of the package that then become important. And having one vendor be able to provide or tick off a lot of the boxes that are requirements within a cybersecurity framework makes it much, much simpler because you’re putting unified management, one provider, and getting it all in one place.

So if people want to learn more, come talk to us, look us up at eset.com. I mentioned our research; we publish a lot of our research on our blogs, so look at our blogs as well. I say that because that research helps people secure things and understand what’s going on out there in the world as well—what current threats are, etc., etc. So I’d subscribe to our blogs and come and find out what we do at eset.com.

Leland McFarland: All right, great. Well, thank you for coming on and sharing the glimpse of information, your knowledge, your expertise with my audience.

Tony Anscombe: My pleasure. And the one thing I’d say is cybersecurity shouldn’t be that challenge that you’re directed or scared of overcoming. You know, there’s the right experts out there, and all these things are very achievable to stay safe.

Leland McFarland: Great. Well, thank you so much.

One of the clearest takeaways from my conversation with Anscombe is that cybersecurity for small businesses is no longer simply about installing security software and hoping it stops an attack. Businesses need to think about how quickly they could detect and respond to a threat, whether they could continue operating during an incident, and how well prepared they are to recover afterward.

That becomes particularly important as attacks become faster and AI introduces additional risks on both sides of the cybersecurity equation. Businesses are adopting AI tools and agents that can increase productivity, but those same technologies can create new opportunities for data leakage, malicious software and an expanded attack surface.

For small businesses without dedicated security teams, outside expertise may increasingly become part of the solution. But Anscombe emphasized that working with an MSP or managed security provider should be viewed as a partnership rather than simply handing cybersecurity responsibilities to someone else. Governance, employee training, business continuity planning and decisions about acceptable risk still belong with the business.

Perhaps the most important point for small business owners is that size does not necessarily provide protection. A small company can possess valuable data, credentials or access to larger organizations—or simply represent an important part of a supply chain. That can make even a relatively small business valuable to an attacker.

At the same time, Anscombe stressed that business owners shouldn’t view cybersecurity as an impossible challenge. With the right combination of preparation, technology and expertise, businesses can significantly improve their ability to prevent, detect and respond to cyber threats.

For small business owners, the question may no longer be whether cybersecurity deserves more attention, but whether their business is prepared to keep operating when the next incident occurs.


More in:


Hot this week

Canada suspends plans to expand assisted dying to people with mental illness

People with mental illness alone were to be eligible for assisted dying in Canada in March 2027, but that has now been paused indefinitely.

Spanish pensioner whose eviction sparked nationwide protests dies, union says

Maricarmen Abascal, 87, was forcibly removed on a stretcher from her apartment of more than 70 years in September.

Ex-Spurs player Vega set to run for Fifa president

Former Tottenham defender Ramon Vega says he intends to run in next year's Fifa presidential election - becoming the first person to confirm they want to challenge Gianni Infantino.

Survey Finds People Prefer Human Support Over AI in Therapy Settings

In an era where mental health support is becoming...

Topics

Canada suspends plans to expand assisted dying to people with mental illness

People with mental illness alone were to be eligible for assisted dying in Canada in March 2027, but that has now been paused indefinitely.

Spanish pensioner whose eviction sparked nationwide protests dies, union says

Maricarmen Abascal, 87, was forcibly removed on a stretcher from her apartment of more than 70 years in September.

Ex-Spurs player Vega set to run for Fifa president

Former Tottenham defender Ramon Vega says he intends to run in next year's Fifa presidential election - becoming the first person to confirm they want to challenge Gianni Infantino.

Survey Finds People Prefer Human Support Over AI in Therapy Settings

In an era where mental health support is becoming...

Western civilisation at risk of ‘atrophy, servitude and decline’, Rubio says

In a speech overlooking the Acropolis, the US Secretary of State also said the US believes Europe "can awaken from its long slumber".
spot_img

Related Articles

Popular Categories

spot_imgspot_img