18 September 2026 · Cybersecurity
Stephen Phillips: Protecting Businesses from Cyber Threats
Paul Spain speaks with Stephen Phillips, Chief Technology Officer and Chief Information Security Officer at Gorilla Technology, about the risks facing New Zealand organisations, from identity theft and convincing phishing messages to deepfakes and vulnerabilities in software.
Host Paul Spain speaks with Stephen Phillips, Chief Technology Officer and Chief Information Security Officer at Gorilla Technology, about the risks facing New Zealand organisations, from identity theft and convincing phishing messages to deepfakes and vulnerabilities in software. Stephen shares lessons from telecommunications, banking and cloud technology. He explains why every organisation needs to understand its risk appetite, prioritise resilience and recovery and protect identities. They also discuss how smaller businesses can access effective security protections without the budgets of large enterprises, and why security awareness, careful technology selection and regular testing matter more than ever.
Hosted by Paul Spain, CEO and Futurist at Gorilla Technology.
Watch the conversation
Play video
Transcript is computer-generated and may contain errors.
Paul Spain:
Hi, I'm Paul Spain, futurist and chief executive at Gorilla Technology. I love helping individuals and their organisations to achieve their best. The New Zealand Business Podcast is really all about this by helping you learn from some of our highest achievers. Today on the New Zealand Business Podcast, we're tackling one of the most important issues facing organisations right now, cybersecurity in the age of artificial intelligence. Joining me, I'm very privileged to say, from Gorilla Technology is Stephen Phillips, our Chief Technology Officer and Chief Information Security Officer. Stephen brings decades of experience across cybersecurity, technology leadership, telecommunications, cloud services, software, and digital transformation. His career includes serving as Chief Technology Officer at CorePlus, now 2degrees, through a long period with Hewlett-Packard, including technology consulting and senior commercial leadership, to roles with Micro Focus and Sumo Logic. He later became Chief Information Security Officer at Westpac New Zealand, where his focus included strengthening cyber resilience, compliance, and cloud security.
Paul Spain:
Stephen then worked with application security company Snyk, helping organisations improve governance and manage risk as they embraced cloud-native software development. Today at Gorilla Technology, Stephen helps New Zealand organisations achieve great outcomes from technology enablement whilst proactively understanding and addressing cyber risk, all from a perspective grounded in business outcomes and each organisation's actual risk profile. In this conversation, we're going beyond the headlines and the hype. We'll look at how AI is changing the cybersecurity threat landscape and what remains fundamentally the same but should not be ignored, along with plenty of lessons Stephen has learned from real incidents and major technology environments and the practical steps that you as a business leader should be taking right now. New Zealand Business Podcast is proudly brought to you by One New Zealand alongside Gorilla Technology, making tech enablement and cybersecurity easy for midsize and smaller organisations. And by Outrun Global, remote staffing to help your local teams work smarter, not harder. All right, let's jump in. Stephen, welcome along to the New Zealand Business Podcast.
Paul Spain:
How are you?
Stephen Phillips:
Great to be here, Paul.
Paul Spain:
Thanks for joining us. Well, lots to delve into today, but always nice to start a little bit at the, at the beginning. So, you know, maybe you can, you know, tell us where your first interests in sort of technology and engineering came from. Was that something from your Earliest years?
Stephen Phillips:
Yeah, probably at around age 10, I was playing around with Morse code and set up a Morse code system between me and the neighbour. And yeah, found it fascinating that we could communicate without using a telephone or shouting over the fence. And that's really where it all started. And I got into telecommunications at a very, very early age. radio, telegraph type work, because this is well before the internet, and telephony. So yeah.
Paul Spain:
So Stephen, what were the first roles that you took? How did you get started in your career and into telecommunications technology and cyber?
Stephen Phillips:
With the telecommunications, it was starting off actually as a technician, moving into engineering, product development, and then sort of marketing and sales, and then into governance.
Paul Spain:
What was that journey in terms of, you know, the organisations that you, you worked with during, during that, that period?
Stephen Phillips:
Yeah, so it was started off with Telecom New Zealand, then joined a company called Netway Communications. Netway ended up becoming part of the Spark group. So it was all of the advanced sort of networking communications side of that. And after Netway, I went and joined another company which was CallPlus, and that's now turned into 2degrees Mobile, 2degrees that we, that we see today.
Paul Spain:
You know, you worked through what was Telecom at the day, CallPlus, you, you ended up there as their Chief Technology Officer. So How did you kind of wiggle your way through into such a senior position at a reasonably young age, right?
Stephen Phillips:
Yeah, it was quite young, sort of mid-late 20s I think was when I was in that position. I started off in engineering because with all technology you've got to have a good engineering basis. But then it turned into how do we bring new innovation and bring services. So got involved in product development and understanding the economics and the utility of the services. we're providing, and then sort of moved from there sort of more into actually governance and how do you make sure that you actually deliver the outcomes for these products and services that you're delivering to your customers.
Paul Spain:
And when was it that cybersecurity really started taking your attention in that journey?
Stephen Phillips:
Really, there wasn't a huge amount of cyber incidents back in those early days. It was sort of like security through obscurity because systems were so unique and special snowflakes, there wasn't a lot of uniformity, and a lot of things actually weren't sort of online and connected to the internet like they are today. So really those sort of things started coming in the late 1990s through into the early 2000s is where the pace and the cadence of attacks affecting New Zealand businesses were really starting to take effect.
Paul Spain:
Yeah. And you did a period with country manager for across Hewlett-Packard's software side there, working with some pretty big businesses and transformations. Was that a time you kind of got to see things through maybe a different lens than you had done before?
Stephen Phillips:
Absolutely. So the time with Hewlett-Packard was very much, not so much specifically around cybersecurity, but the precursors basically to making sure that systems fit for purpose. And that was probably the big learning there was start with the business requirements, start with the outcomes that you're looking for, make sure that you have a plan to test that those outcomes can be delivered, and iterate. Don't try and bite off everything sort of all in one go, or you end up with very large, expensive projects.
Paul Spain:
And I saw quite a number of those across my tenure at Is that something that applies kind of across, from your experience, across all manner of organisations at every scale?
Stephen Phillips:
Absolutely. So you can be a one-person sort of business. If you get yourself into a technology system that looks good, you maybe fell for it, had a great brochure and people were raving about it. Don't peer back to the fundamentals of what does this need to do for me and what information is it processing for me and how do I need to keep that safe, things can go incredibly wrong. And as a sole trader, that can end your business. As a medium-small business, it can be a huge burden on the organisation. At a large enterprise level, you might be able to cope with one or two of those, but if it becomes a repeated pattern at scale, it can also take you out of business.
Paul Spain:
I know from our prior conversations, you have sort of seen, I guess, a variety of different impacts at varying scales. When you look at these things through a cybersecurity lens, how important is that part of the picture versus just getting this, picking technology and software that will deliver and meet the kind of core needs of an organisation?
Stephen Phillips:
I think you should always start with what is the business outcome? Is it aligned to the business strategy? Should always be right up there, probably the first thing you consider. But you shouldn't ever make a selection of something without considering, can the system be secure enough for my organisation for the type of data that you're processing? So you should never do the, make the decision without considering both of those things. Is it fit for purpose and can it be secured?
Paul Spain:
Right.
Paul Spain:
And often, you know, we come across the scenario where we talk to somebody who's in a similar business or a similar field and they say, oh, we're using XYZ. And that sort of becomes like a gold recommendation because someone else is using the software. Have you found that's a good approach to follow?
Stephen Phillips:
No, sometimes going with the crowd is a good thing, but you always need to do your due diligence, make sure that the fundamentals are sound. Something that looks good on brochure or good in a demo can turn out to be operationally a disaster for you.
Paul Spain:
In terms of the key lessons that you were picking up, In those years, what really stood out to you? I mean, it seems from looking at your career that there's always been this sort of crossover between the technical and the business outcomes and those two very closely linked. And you've kind of had a foot in sort of the business camp, but always keeping well connected with the technical side as well.
Stephen Phillips:
Yeah. Probably some of the biggest learnings in all the time at probably the CorePlus Group in the CTO role was you've got to look at external risk and you've got to look at internal risk. The internal risk is you need to be auditing how the use of your assets are happening on a regular basis, because sometimes they are misused. And you also need to look at external risks. What types of external threat could take the business out. And we had a situation, one of the early, what's called a worm, which is an attack from the internet against a particular technology. It happened to be attacking database technology. But what it did was completely took the internet service provider business out.
Stephen Phillips:
We were offline for multiple days. And it was a really interesting lesson in resilience. So, you know, for the want of not having 2 ways to connect to the internet, all of our customers were out. So, you know, resilience basically was required basically to make sure that we actually delivered, delivered on our promise basically to the customer.
Paul Spain:
Yeah. And I guess in those, in those early, earlier days, you know, there would have been a lot of lessons to learn. that no one had really probably thought of so much at that point. And as time's gone on, we've got to a point where things like having internet connectivity, access to databases and technology systems is an imperative because you can't operate when those things stop.
Stephen Phillips:
Yeah. And it turned out that the common advice, you have to patch your systems, was absolutely vital. Nobody can be exempt from that because it was the most senior leader in the business that let basically the threat in. And then it pretty much took the business out for a couple of days and we were starting to lose customers hand over fist. So really, patching is an indisputable thing. You just can't not do it.
Paul Spain:
Yeah, yeah. Great advice. Now, you took, during sort of early COVID, you took on the role at Westpac Bank of Chief Information Officer. security officer there becoming accountable for, I guess, cyber risk over a large portion of the funds that were flowing around New Zealand. What was sort of the big changes that you've seen in more recent years when it comes to cybersecurity and the takeaways from that?
Stephen Phillips:
Well, the reason I joined Westpac was it was an interesting role to do a bit of a transformation. All banks are required by the regulators in both New Zealand and Australia to uplift their control environments. So that was an opportunity for investment and an opportunity to actually build out a large team, build a culture of security. So that's really why I joined. And as a large organisation, you're talking many tens of millions of dollars going into this. So there's not often a lack of funding, but there is seasons of funding. And so it was a really, really great opportunity to do that.
Paul Spain:
The transformation that you did at Westpac, obviously on a bigger scale than you know, probably would be relevant for most listeners and their organisations. But from what you see in the market, do most organisations need to go through some sort of transformation as it relates to their cybersecurity, or are we in a reasonably good state in New Zealand?
Stephen Phillips:
Yeah, I think the answer there is pretty obvious. Certainly understanding what your risks, understanding what the threats are to your business, both technology availability and reputation type threats, all need to be considered. And you can do a reasonable job at any scale. The reason it costs to run a program at large scale for a bank is mostly driven by how many people are in the bank. So if you've got 6,000 people, protecting 6,000 identities is going to cost you a lot more than protecting 10 identities. So those aspects sort of drive the scale, but you should never not protect your identity, not protect your endpoints, and not take a threat-based sort of approach to understanding sort of what your risk is to your particular data.
Paul Spain:
And so, you know, what does that look like from a high-level perspective when you talk about identities and so on? You know, what should a business leader be thinking about to ensure those things are looked after appropriately?
Stephen Phillips:
Yeah, so the big one with identity is breaching the trust of identity is what all of these bad actors and all are looking for.
Paul Spain:
Um, so they're trying to be able to log in as, as someone within your organisation without being that person.
Stephen Phillips:
Yeah. And as soon as you're reliant just on passwords to do that, humans are fallible. They like to use the same password everywhere or all of those types of things. So getting your bill, your, your business basically off passwords wherever possible. And when you do have to keep them, use a password manager. Those, those types of things, absolutely critical. So. Today, if you're not managing your identity, it's only a matter of time until you're going to be breached.
Stephen Phillips:
It's that simple.
Paul Spain:
Yeah. Yeah. And there's increasingly more use of AI and extra layers to help protect the identities now, isn't there?
Stephen Phillips:
Yeah, absolutely. So when you're doing things sort of at scale, like some of these big cloud providers, they're able to detect that some sort of behavior is going wrong within 20 seconds to a couple of minutes using AI-enabled defense strategies. So having something like that that's protecting your business 24/7 is a great investment. The other factor is a lot of organisations might be, everything that I'm doing is with Google or is with Microsoft. the bad actors out there have figured out that if I actually look at all of the Microsoft systems, I can find my way around that and bypass. So sometimes having a backstop protection is a good idea as well.
Paul Spain:
Yeah, great. So following Westpac, you worked with Snyk. Maybe you could just give us a little bit of insight of what you learned there and how technologies like what Snyk offer are an important sort of part of the the mix to bring security to an organisation?
Stephen Phillips:
Yeah, so what Snyk does is it's a cloud platform that sits beside a developer, and it is, you know, AI-enabled, and it looks at all of the code that they're actually writing themselves, and it looks at also all of the code that they're bringing in from third-party open source or commercial closed source, and it looks at all of the risks. So it builds you a, like, a bill of materials of Is the code I wrote and the code I'm using, is it secure? And what it does for the developer is actually provides alternatives and it provides fixes that a developer can actually roll back in so that what they end up building is secure. You know, the reason I joined Snyk was it was an area of interest and it was a, you know, gap in my knowledge. So I wanted to go and find a company that was, you know, a world leader in that sort of space. But what I found at Snyk is more and more companies are relying on software development to create their unique advantage. And software developers are being pushed to actually write software faster and faster.
Paul Spain:
Especially in the AI era, right?
Stephen Phillips:
And in the area of AI, the amount of coding that a developer has to do is probably It's dropped to maybe only 10% to 20% of actually what it used to take. But you've got to now do the planning, and you've got to do the testing and the iteration side of things. But AI has certainly sped that up. But what it's also done is actually sped up how much external software from third parties is being brought into actually what's being built. And it's also bringing in code that on the surface might look pretty good, but it is bringing in vulnerabilities and risk to the business. So really what it comes down to is if you're trying to build out a system, or even if you're choosing a third-party vendor, you've got to have the assurance that application security is being consistently applied and tested. So just letting a developer build at the speed they want to build is going to be a bad outcome. Just buying a piece of cloud software off the internet without checking that they also do those checks is very high-risk appetite sort of behavior today.
Stephen Phillips:
So what you should be looking for is tools that can help your development practices so that they're continuously able to make sure that they're building secure code. And you should be working when you're looking at bringing in new software as part of your cloud stack or your operating system of how you want to run the company. Every decision on who you bring in, you should be doing the due diligence to make sure that have they been pen tested? Are they continuously pen testing? It used to be okay to not check these things for a year. Today, really, you can't be not checking these things for a week. So AI has actually changed the cadence that these types of risks evolve and actually get compromised. What used to be a 3-month cycle for vulnerabilities being compromised is now down, in some cases, to minutes.
Paul Spain:
How does that journey connect to what you're focused on now at Gorilla today?
Stephen Phillips:
Yeah, so what I'm focused on at Gorilla today is ensuring that small, medium sort of businesses, organisations on a mission can also have the same degree of security outcomes that a large organisation can have, but at an affordable scale for a small, medium business. So what we're doing is making sure we've got all of those layered protections in place, you know, all around your productivity suite, whether that be Microsoft or whether that be Google, making sure that those are configured and hardened and locked down so that they can't be compromised by third parties, making sure that the identities are being protected, making sure the devices are being protected, making sure that all of the software is being updated all of the time so the vulnerabilities aren't there. Because what happens today is AI-enabled vulnerabilities can be found in minutes, and then you can use the AI to actually put in place an attack sort of scenario where you can automate attacking hundreds, if not thousands, of organisations, and they only need to find one that's vulnerable and they're in. So we're trying to avoid those types of risks for our customers by protecting their identities, protecting their assets, protecting their devices, and protecting the network paths that allow people to actually get into the systems.
Paul Spain:
So now we are in this AI era. Is it just the pace that's really sped up when it comes to cyberattacks? What are the, you know, what are the other things that you would say have really sort of stood out, you know, to you in terms of what's changed now where we're in this new era?
Stephen Phillips:
It all comes down to trust. Humans naturally want to trust communications from other humans, and bad actors actually try to take advantage of that. In the era before AI, If somebody had sent an email, it arrived basically on your desk in your computer, and you could see that the language was not quite right. It was full of spelling mistakes, and you know that this company would be better at their grammar than they are. It's pretty easy to actually pick it up. You could detect it with your eye. In the AI world now, you can no longer detect it with your eye, because if something's been well-crafted by AI, all of the Domain names are going to look good. It's going to look pixel perfect compared to the real organisation.
Stephen Phillips:
So, you know, you might be expecting to get a proposal from someone expecting to DocuSign a contract. You could get something that comes in that looks exactly like it's from DocuSign with the right context and all those types of things, because they've done a bit of reconnaissance and they've, they've used that reconnaissance information to actually, you know, come up with, yeah, we think they're expecting this contract and they're expecting it from this organisation, maybe from this person. And it'll come in exactly like that, but it won't be the real DocuSign. It'll be somewhere that actually takes you off to put your password in that will look like DocuSign, but what it's really doing is actually grabbing your identity. And those types of breach of trust type things, AI is actually making it really, really hard to detect. Right.
Paul Spain:
Now we've also heard about deepfakes being used in the AI era as well. That seems like it's in a, in a very similar category, probably still not something that we see a lot of, but, you know, is that quite a big game changer, do you think?
Stephen Phillips:
Yeah, absolutely. It's only happening in large-scale, large organisations at the moment. But the barrier to entry to actually achieve this is actually getting lower and lower and lower as the AI models get better and better. So less than 2 years ago, there was a British UK, very large-scale engineering firm that does massive infrastructure projects and the likes. They had the situation where A financial controller was in a board meeting with the chief executive officer and the chief financial officer, and they were working through payments basically for a large program. And the financial officer was urged by the CFO to make those payments and transactions occur. What transpired was that whilst they thought they were on a normal sort of, you know, web conference, the CEO and the CFO were both fake. They weren't real people.
Stephen Phillips:
They were somebody mimicking the real people. And the chief financial controller didn't pick that up in the meeting, acted off what they were being instructed. Their boss and their boss's boss were instructing, make the payments, and ended up making a series of payments of about $25 million.
Paul Spain:
With there being a raft of new AI-related threats and things really speeding up when it comes to the landscape, because of course the attackers have got access to the same AI tools as everybody else, there is also a positive flip side to that, isn't there, in terms of new AI mechanisms being able to be used to defend and protect? our organisations, whether it's a very small organisation up to a large enterprise. What are you seeing there that you feel is super helpful?
Stephen Phillips:
Yeah, a couple of things. One of them is around the endpoint management, so managing your compute systems, whether they be phones or Apple computers or Windows computers. Having a system that is defending those, that's actually using AI-enhanced sort of ability to detect and understand dependencies and the likes. And the same with your identities. So making sure that those are protected, and then you've also got a backstop. So if somebody, if a bad actor is focusing on that whole, you know, I wanna bypass Microsoft because that's what, you know, 60, 70% of computers, you know, they really focus on, they buy the software themselves, they test their AI generation, can they actually bypass Microsoft? As soon as they bypass Microsoft, they can actually go out and attack, you know, 60%, 70% of the market. So having that backstop, pretty important. At the same time, also using AI systems to actually look at your organisation from the outside in and making sure that you haven't left the door open, the windows open, those types of things.
Stephen Phillips:
So that's called reducing your attack surface. So using AI tools that are constantly checking that. So instead of it being found a month later. You're finding it and then you're remediating that or fixing it within a couple of minutes.
Paul Spain:
Is there any risk that New Zealand companies maybe become overconfident that, you know, hey, you know, the IT team or the IT provider, you know, they're using some AI, so, you know, everything should be fine?
Stephen Phillips:
No company can ever say that they're secure. You know, whether you're a small company or whether you're a large company spending tens of millions of dollars, you can never be secure. It's a matter of how much risk appetite have you got to actually put enough controls in the place to slow down or to stop basically particular types of attack. Yeah, it's pretty important these days to just not trust that everything's going to be okay. You need to evidence that. You need to be doing periodic audits to make sure that the service that is being delivered has been delivered in a secure way. To not do that is just inviting risk.
Paul Spain:
Yeah, maybe we can come back to that a little bit more because I think it is important to understand how an organisation decides what their risk appetite should be. But I'm curious to hear your thoughts on what remains true when it comes to existing cybersecurity standards and approaches in an AI world.
Stephen Phillips:
Yeah, what remains the same is you still need to be fixing the vulnerabilities in your system, and you need to be fixing them faster than ever. The volume of vulnerabilities over the past few months, every month we see almost a doubling in the number of vulnerabilities, say, in a particular ecosystem. So Microsoft last month might have had 2,000 vulnerabilities in it. This month it might have 4,000. So you can't basically not take action to actually keep on top of those things because the AI systems are actually generating vulnerabilities faster than humans can keep up. So the humans can only keep up by actually using AI to solve and remediate the problems.
Paul Spain:
So I think one of the big challenges for organisations, probably of any scale, is knowing what should their approach to cybersecurity be, right? You're a one-person business. You naturally have only got so much time in the day. And that same extrapolates out to any organisation in terms of available time and resources and investment. And one of the things that we'll probably often see In some environments, there's the sort of Kiwi attitude of, she'll be right, mate, when it comes to kind of cybersecurity. There are others who sort of believe that we should just completely lock everything down. But there's a balancing act, and you need to ensure that actually technology is an enabler that's helping an organisation to achieve their best. But yeah, you still need to have cybersecurity and data privacy mechanisms in place. But what I often see is a lack of clarity around what and how much.
Paul Spain:
So how should organisations be looking to get their head around that and understanding what is an appropriate risk appetite for an organisation?
Stephen Phillips:
Yeah, the first thing is most businesses actually don't understand the risks. So starting by understanding the risks, and when you're trying to understand the risk, think about the data and the business processes that data and system use, and identifying from a business continuity, from a business resilience perspective, ask yourself the question, what would happen if I can no longer access or trust that data, and for how long could I actually run my business without this? So take that approach. Think about maybe the top 5 business processes that create value in your business and look at the data and the systems processing involved in those. and focus first on, if those weren't there, how do I actually recover from that? So business resilience, so making sure that you've got a really strong backup and recovery capability that's actually proven on a regular cadence, probably the key thing. Once you've got that, you know you're going to be able to recover the business within maybe 24 or 48 hours. Beyond that, you probably want to start looking at the other risks that maybe an audit would pick up. Risks around risky sort of use of identity, people using shared passwords, using guessable passwords, or people that are prone to clicking on phishing links and all those types of things. Start shutting those ones down, but always start with business resilience.
Stephen Phillips:
And the ability to be able to recover your data, then protect your identity, then protect ingresses into your business and protect your devices.
Paul Spain:
Now, these areas can be quite complex for someone who's just, you know, wants to know that it's sorted, but maybe doesn't have the time or the expertise to delve in too quickly. Now, this is an area that Gorilla's involved in and helps organisations with, but How do you think that leaders should be looking at how to get the right sort of external help or bringing internal help in? Because that's going to vary from organisation to organisation, isn't it?
Stephen Phillips:
Yeah, you want to look at getting some credible advisory help, or you start with an audit to understand current state. The first thing I did when I joined Westpac was had an audit basically done of all of the people, the systems, things to understand actually where the risks and the gaps are, compared that to what the regulators thought, and then devised a strategy to actually come and solve that. Now that can be scaled down to a business of any size, from a single sort of sole Sole trader up to the largest sort of enterprise. Always start by understanding your risk and then pick off those risks one by one on the basis of how material they are basically to the operation of your business.
Paul Spain:
Right, because these things are going to change over time, aren't they? And you can't solve everything, you know, overnight. You never get to that 100%, you know, perfection, but you want to be, you know, at an appropriate level and as new things come along, addressing them accordingly.
Stephen Phillips:
Yeah. Most businesses that we see, when we actually look at their security posture, how well placed they are to be resilient if something happened, they might only be 40% prepared. To get that preparedness basically up to maybe 60% is not a huge investment. To get it up to 80%, yeah, there's a bit of investment there, but no one, you know, you can spend tens of millions and you won't get it to 100%.
Paul Spain:
Mm-hmm.
Stephen Phillips:
this marginal sort of return with the spend sort of after a certain point.
Paul Spain:
One thing that I find, you know, really helpful when looking at cybersecurity is to actually hear some of the real-world stories. And I think these are, you know, they're always, you know, fascinating to hear and to learn from situations that have come up and help us make, you know, good decisions. So maybe we could walk through, you know, some of the learnings and situations that that you've seen in the telecommunications side of your career? Any lessons that really stand out from that time or stories that you can share?
Stephen Phillips:
Having internal audit controls is pretty important. We're in a position where the business had significant resources, data centers, connectivity to the internet, and all those types of things. And we weren't really sort of looking at how that was being used very well. And at some point, I was wanting to launch a new product, and I went to determine the costing for using some of the resources. I wanted to do a hosting— website hosting business. And I went and looked for the data. The team gave me the data. But when I looked at the data, it kind of didn't make sense.
Stephen Phillips:
But what ended up happening is we found out that there was misuse of internal resources at a very large scale because we weren't actually looking after how we were actually using those resources. So by not measuring things, we found that there was a lot of it was being wasted. That turned into a very, very expensive exercise to rectify the situation. And I won't go into the details because probably a lot of that's still very confidential. But by not keeping your own shop in check can lead to some disastrous outcomes. We've all heard about businesses and organisations where staff defrauding and skimming money off on the expenses. That can happen from a very small business to a very large business. So keeping on top of your costs as well as basically your revenues to make sure that all of the numbers are adding up, a very important thing to do.
Stephen Phillips:
Always be auditing.
Paul Spain:
It probably becomes even more relevant today with increasing AI usage and the cost of AI tokens. You know, if a business is, you know, say spending a lot on cloud services, AI capabilities, but those are maybe getting, you know, utilized not actually for the core business, but for somebody else's own side hustle or something else, you know, that's not particularly helpful to the success of an organisation.
Stephen Phillips:
Correct. And people, you know, these days are encouraged to explore and find new ways to solve problems. But you've gotta be measuring, is this providing value?
Paul Spain:
In the banking world, what would be, you know, a story or something you could share from that time?
Stephen Phillips:
Yeah, cast your mind back to around 2021. There was a whole raft of attacks that were happening across the New Zealand Stock Exchange and the banks when, you know, the first—
Paul Spain:
Systems were going offline, weren't they?
Stephen Phillips:
Yeah, and when a bank gets attacked, and doesn't defend well in this, what happens is people can be at a supermarket and try to pay for their groceries and they can't, which can lead to some very bad reputation outcomes. So banks want to avoid these types of problems at all costs. But what had happened across the banking sector, and the bad actors had figured this out, is banks hadn't modernized how they protect against things like like that. And it comes down to risk appetite. The money to invest in actually those types of protections hadn't happened. But the risk basically was also not really well documented and understood by the banks. So there was about a couple of month period where there was some very rapid investment that happened. Because for the want of a couple of hundred thousand dollars, Banks could avoid actually really significant reputation damage.
Stephen Phillips:
And if you saw what happened with the NZX, the NZX basically had a lot of change in senior personnel and all those types of things. So fortunately, the banks in that first round got away with actually only fairly minor impacts. But behind the scenes, you had teams of hundreds of people working huge hours to actually keep on top of this and actually stop the disruption to the banking sector. The good news is today, if you move to AI-enabled, cloud-enabled approaches to defending against that, you're not talking hundreds of thousands of dollars, you're talking hundreds of dollars. And you can get those same level of protections for even your small-medium business. But for small-medium businesses, that's about protecting your presence on the internet. It's about protecting your website. It's about protecting the portals that your customers use to interact with you.
Stephen Phillips:
So it's about, for the want of maybe $1,000 a month, keeping the reputation and keeping your website or your commerce basically ticking. That's what risk appetite's about. understanding that we do have risk here and this amount of investment will actually remediate or solve that risk.
Paul Spain:
Yeah, that's helpful. Now, I often hear, especially amongst New Zealand sort of mid-sized down to sort of small business and startups, that, look, no one's going to target, you know, target us, you know, we're too small, we're not relevant. They're going after the banks and the NZX, not us. What's the reality from that perspective?
Stephen Phillips:
The reality is that there's now tens of millions of commercial crime, cybercrime parties. They're now enabled with AI, so their reach and the scope now allows them to target any individual or business that could be processing funds. So if your business is processing funds, if your business has any type of an internet presence or uses the internet to communicate, it's only a matter of time until you're going to be tested on these fronts.
Paul Spain:
Yeah. So it's just a reality, isn't it? Because every business has to have a digital presence in some form, has to communicate, has to be moving money around. So we're really all at risk, aren't we?
Stephen Phillips:
Yeah. And if you look at the figures from the GCSB, the government's computer security bureau, that they put out, it's getting into the hundreds of millions of dollars every year, basically, that New Zealand businesses are being defrauded out of.
Paul Spain:
And that's just the ones that actually are reported. And most folks are actually embarrassed and don't want to talk about or report what's going on, right?
Stephen Phillips:
Yeah, that's the tip of the iceberg because there's no mandatory reporting. reporting obligations in New Zealand. You do have to let the Privacy Commissioner know, but other than that, not a lot of consequences.
Paul Spain:
Now, one thing that we've seen many times, folks have made a decision, they feel like they've got enough information to make a great decision around some technology that they really believe is going to give them a lift, help their productivity, help move them forward. But somewhere along the way, actually, the wheels come off in varying ways where there were sort of steps that were missed. Now, this crosses into the thing that we're all looking for from our technology, which is to get an uplift, to get that transformation through technology as well as into cybersecurity. Um, you know, have you got an example that maybe you can, you know, you can share that will, you know, help listeners, you know, under— understand, um, maybe, you know, the, the best way to go through these processes of, of, you know, picking their next product, whether it's a CRM system or, you know, whatever it is within their, their organisation, because, you know, I think in reality, Most organisations don't have perfection when it comes to technology and quite regularly are on the lookout for a new piece of technology to bring some, to help bring some transformation into the business. And obviously the transformation doesn't just come through the technology, it's through what you do with it and putting it into action.
Stephen Phillips:
Yeah, yeah. So probably the best place to start is Don't get excited and listen to someone else saying, this was great for me. You need to take a very planned approach. Start from the outcome, the business outcome that you're looking to achieve. Understand actually what is required to make that outcome come into fruition. And then sort of also look at how do I make this process that is going to be fixed resilient? How do I ensure that if it is disrupted, it can be recovered? And then look at how could the use of this process, whether that be a customer relationship system, whether that be an HR system, it could be an e-commerce system, it could be anything that's doing something of value to your business. How do I then make sure that its use is not going to be interrupted? What are the risks to interruption for this service? And what controls or what mitigations can I put in place to minimize that? What resilience can I build into my business to do that? And the best thing to do there is actually to have a plan for sourcing that you write into the policy of your organisation saying, when we source something, these are the steps that we go through. What are the outcomes? How do I assure resilience? How do I assure availability? How do I assure basically that I'm also going to not spend a whole lot of money getting people to adopt this technology? So you've got to look at all of those factors when you're making a technology decision because It might only be $500 a month, but investing in that $500 a month could cost your business hundreds of thousands of dollars through business disruption, through rework, through having to change to a different system because something didn't work.
Stephen Phillips:
You always want to pilot things and make sure that it does deliver those outcomes, does deliver those processes. So never, never sign on the dotted line first. Make sure that it actually delivers what it says on the can. And make sure that if it goes out, you can get it back.
Paul Spain:
Yep. And of course, there's all the security aspects in there as well. And I think, you know, probably everyone, you know, listening is aware of a technology, you know, system and whether it's in their current workplace or somewhere, you know, prior where it hasn't gone according to plan or, you know, it might've looked really good. They thought it was going to be really good. But somewhere, you know, in the, in the, you know, implementation, it never quite got to, you know, got to where it, where it should be. And, and, you know, that can be a big issue too, right? We, you pick some software that seems pretty good, but you never ever really get the full, the full capability out of it because there wasn't an appropriate kind of oversight and, and understanding on what the true goals needed to be to get that, that superb result, right?
Stephen Phillips:
Yeah. Yep. Plan, test, train, iterate.
Paul Spain:
Yeah, yeah, yeah. And that iteration's key too, isn't it? Because the business, our businesses, our organisations keep changing and the technology keeps changing. And of course, threat landscapes and so on keep changing as well. So we can't really sit still.
Stephen Phillips:
Yeah.
Paul Spain:
So let's talk about the practicalities. We've chatted around a broad range of things, and I think some really good insights. What would you say for listeners that they should be putting in place when it comes to moving the needle from a cybersecurity perspective? If we look at, say, the next 30 days, what would be the sorts of things that should be taking place even the next 24 hours? What would be the right point to start at?
Stephen Phillips:
Probably first point is understand your risks would be the place, basically, any organisation, and get an expert organisation to do that. Generalists who cover sort of all sorts of different things, they can provide absolutely everything, may not be able to do that. So work with an organisation that really sort of is focused. on making sure that you're making good decisions to actually uplift the value that your technology investments can provide.
Paul Spain:
On top of that sort of insight, what would be the typical type of actions that then need to be made?
Stephen Phillips:
Normally when you look at the current sort of threat, the current risks that an organisation has, Then you prioritize those based on what's going to be the most impactful so that you can protect against the most impactful thing to your organisation first. So prioritize those.
Paul Spain:
One of the challenges that all organisations have is there is only so much resource in different areas to go around. What is the the approach to being able to stay on the proactive front when it comes to cybersecurity, particularly in this AI era, but in a manner that is cost-effective and doesn't mean that the organisation is really having to overinvest when it comes to cybersecurity. Because you go out and get an audit, you might come back with a huge list of things, And if you go for that 100%, which of course is never achieved, as you've mentioned, that is probably a very expensive exercise. So what are the approaches to keeping that balance right when it comes to resourcing an investment?
Stephen Phillips:
Put your first dollar into resilience and recovery. Understand the prioritisation of those business sort of processes. The most important ones, make sure you're investing in the ability to recover should the data or the system actually be lost or corrupted. That's probably the first place to start. Start with recovery. Then start also looking at the process of recovery. How can I recover from an incident? Making sure that that is very well understood by your partners. Make sure it's a very well understood by your senior executives who might need to make decisions around that.
Stephen Phillips:
So the incident response and the incident recovery part's probably the next thing to look at. That would be the second thing. The third thing would be looking at what are the highest risk ways that your security could be compromised. And it's generally today your identities. So protect your identities. The next part after identities is protect basically your compute systems. So the computers that you have and the third-party cloud services that you're using, make sure those are protected and all is well. The next thing would be looking at your vulnerabilities.
Stephen Phillips:
So making sure that you've got a partner that will patch and keep all of your software systems safe and up to speed, and that you've got backups for those as well. So making sure that there aren't gaps basically in the vulnerability management, and making sure that your applications are being patched, that your systems are being patched, that your networks are being patched, and that your cloud services are constantly being looked at as well to make sure that they don't have vulnerabilities.
Paul Spain:
There is a, I'm not sure I quite call it a silver lining to all of this, but there is a positive in the AI era, especially for smaller, less complex organisations, is that the technologies to assist with this keep getting better.
Paul Spain:
Yeah.
Paul Spain:
A smaller organisation is able to actually get itself into a good state without having horrendous overhead when it comes to staying on top of cyber, unless they're in a very unique kind of field where they need really extreme security mechanisms in place. This is not something that's out of the reach of most New Zealand organisations, is it?
Stephen Phillips:
Yeah, correct. So a lot of the software suites that businesses use, whether that be Microsoft or Google, can be very well secured.
Paul Spain:
But often they're not though, are they?
Stephen Phillips:
Straight out of the box, when you buy them, they are not secured. They might only be 20 or 30% out of 100 secured. But by having the right partner who knows how to operate those things and can harden those systems correctly, it's not going to cost too much more than the actual licensing that you have to pay for to actually get it to the point where it's actually pretty secure. So that's definitely worth investing in, in a security partner who really does that. A lot of organisations will say, yes, we're security first, we take security very seriously. Always ask them to prove that.
Paul Spain:
Excellent.
Paul Spain:
Anything else you'd like to add, Stephen?
Stephen Phillips:
Probably the other part we haven't really focused on is the human impact. Humans As we've mentioned, like to trust communications from other humans. So what's really required is an ongoing security awareness program, campaign that can actually help your people to understand when something comes across your desk that looks like you should do something urgently, is that in itself is usually an indicator that something might not be quite right there. But educate yourself. Make sure that everyone in your organisation, from your directors down to your contractors and staff, are all being educated on cyber awareness on an ongoing basis. It's getting harder and harder to actually detect these things. So also look at, is there some extra control that I can put in place to help My staff, myself understand that, you know, when something is presented to me on a browser and it looks good, are there hidden things behind the scenes that would let me know that this isn't actually what it says it is? So that there are controls that allow you to protect when you're browsing and protect when you're using email to detect these things, because you can no longer do it with your human eye. It requires almost like an AI-based companion to help you make those decisions.
Paul Spain:
And of course, the reality is that there are cyber incidents going on all the time around New Zealand on a daily basis. We don't hear about most of them because it's not the sort of thing people like to wave a flag and talk about. So yeah, this is really timely and particularly As AI has very much sort of accelerated the pace. So thank you very much for being on the New Zealand Business Podcast today. Super insightful. Cheers.
Stephen Phillips:
Wonderful. Thanks, Paul.
Paul Spain:
I trust this conversation with Stephen Phillips will help you to consider what next steps are needed to help your organisation be secure and resilient while you innovate with AI and other business enablement technologies. New Zealand Business Podcast is brought to you by One New Zealand alongside Gorilla Technology, making tech enablement and cybersecurity easy for mid-size and smaller businesses, and by Outrun Global remote staffing to help your local teams work smarter, not harder. Now be sure to listen in to our other episodes featuring many of New Zealand's most successful leaders, including Brooke Roberts of Sharesies, Sir Peter Beck of Rocket Lab, Cecilia and James Robinson of My Food Bag and Tend, Sir Stephen Tyndall of The Warehouse and K1W1, and of course, many more. And be sure to share this episode with a friend or a colleague who you know will benefit from it. All right, that's Paul Spain signing out. I'll catch you on the next episode.
Paul Spain:
See you then.
More episodes
Part of the Podcasts NZ network.