Video: Deepfake Defense May Become a Core MSP Service

Transcription

Hey channel insiders, welcome back to channel insider partner POV. I'm your host Katie Bavoso and my guest today is 100% real. He's Daniel Elliott, CEO of Delta Bear, a boutique cybersecurity MSP specializing in catching and stopping deep fake attacks. As AI continues to evolve, so does the cyber threat landscape. The bad actors have just as much access to the AI tools we rely on. That's why Daniel says legacy security solutions are no match for the human spoofing attacks.

Today we explore Delta Bear's deep fake fighting solutions, the opportunity this emerging threat vector offers channel providers, and why this kind of cybersecurity could be a standard layer in cybersecurity stacks in the very near future. Welcome Daniel. Thank you so much for being here. >> Thank you for having me Katie. Appreciate you. Love to give away what I'm getting into this afternoon. >> Very excited to dig into this conversation. We've been meeting a couple times leading up to this, so I've been chomping at the bit to get to talk to you about Delta Bear.

So why don't we first of all use that as kind of the introduction to dive in. Talk to me about Delta Bear. What is your core mission? Who are your typical customers and the verticals that you typically serve? >> So we're a modern security and intelligence operation that focuses on artificial intelligence solutions to basically displace security stacks. We're really for everyone. We're for the modern operator that wears too many hats and responsible for security ops and just doesn't have that ability to think outside the box in terms of what those solutions mean.

So we gear our audience towards those seats that are 20 to up to 500 seats, but we can go enterprise level. We do have POCs in those environments. And vertical, we kind of consider ourselves agnostic of all that because of who we serve in the security community. With ransomware being at the forefront of all things we do. Um, that's kind of where we start and then we we scope from there. >> That is the worst and best part about cybersecurity is that everyone needs cybersecurity because cyber risk is for everybody, unfortunately.

So, you're always going to see that. >> 100%. >> What is the bear in Delta Bear stand for? >> So, that's actually funny. So, because it it almost seems like the chicken and egg thing when I get that because I was like, "Oh, we love the name." But, um, with the Delta in Bridging Enterprise Architects and Resources. So, within Bridging Enterprise Architects and Resources, like what does that mean? Well, you're bridge gap conversations that lead you to new newer ways of thinking and new products that are out there in the market, um, obviously leads you to enterprise based solutions which you see within those of the Kaseya and other people and the manufacturers of the world um, that want to architect, um, certain resources that are in your environment.

So, we displace those stacks. So, where those and I say no those are our direct competitors. We could use that in a myriad of after mentioned, um, categories, but for the most part, um, we do that in a myriad of ways. It may it may even mean when we bridge enterprise architects and resources, we're not even doing that within offering you solution. It may be even just a conversation in regards to just giving you education that you may need for tomorrow. >> I love that.

Such a good answer there. So, Delta Bear, as we were talking about, offers solutions and hands-on expertise that help clients stop deep fake driven threats, those AI driven threats. But, before we dig into that, I want to talk about the risk. Deep fakes have been talked about for years. We've been seeing them. I think I joked with you about the the Tom Cruise deep fake that we see all over Instagram. But, we're now seeing them used in real-world attacks, like impersonation and vishing, that kind of new term that we have for fishing.

So, from what you're seeing in customer environments, what changed recently that makes the threat suddenly operational for attackers? >> Because it it's not just about spoofing you um, anymore. It's about pretty much controlling your environment and gaining that trust that we hold so dear as a part of the human element. And to be honest with you, once that happens, you can't trust anything else around you. So, you need solutions to be more forward-thinking in that approach because the person that you talked to today isn't the person of tomorrow.

And then how are you supposed to put an emphasis on that trust? It's just it's gotten so bad to where interoperability within your environment and being on the phone can't be trusted. Um, let alone the Zoom call that you were on with, you know, a counterpart. So, from a standpoint of an A to Z measurement, it's changed. The attack surface is so so much of changed. You have groups spending real-world money to make sure that their ability to basically encapsulate data, steal your data for nefarious actions is being done in cohorts.

And then from that standpoint, anything that they can or can't control they will control and manipulate. And for a small to medium-sized business, regardless of what their cybersecurity policy looks like, it just puts them behind the eight ball to basically just get washed. So, that's what you're currently looking at within deepfake. >> Scary stuff. So, tell me about your solution. It combines NetSec's deepfake detection technology with Delta Bravo services and expertise.

What does Delta Bravo add on top of that technology that customers wouldn't get from deploying the software alone? >> So, what we do is just a comprehensive deep dive in terms of what you're actually looking for because within utilizing the software like NetSec's to basically do proactive threat detection and response and helping organize organizations identify, contain, eliminate threats, we have to understand where does that start for you? And that's why we're boutique in our design.

And I don't believe it should be cookie-cutter. And within that is what your environment look like. Are you just in the 365 tenant? Are you Azure oriented? Are you Are you in a Mac OS environment where you know you're dealing with a lot of OT versus IT? I mean, it could be a myriad or gambit of things depending on the landscape and then we start from there. From an actionable item standpoint, from at least from what we see from a small to medium sizes that typically it's Windows Defender or base level EDR and and that's it.

And it's like, well, you're being reactive. You're not being proactive in your design. You're waiting for something to happen for then you to go that and try to figure out what that is and if they're just putting that up to your EDR in terms of compliant you're you're putting yourself behind. It's a gigantic issue that you're you won't see coming until it costs you real life money. And we start with kernel level telemetry. Just because it's a step lower before BIOS.

So from a stand of like Windows services and where we are, starting with the kernel is everything for us. Before we get into the operating system and what things do as a service and being able to stop a lot of our attackers upstream with proactive measurements and what we do in the in those environments is huge because then you then have something like a NetOps that we layer on top of that to basically protect you against it and eliminating threats before that just start to disrupt your container and start to deep fake, learn about your environments or even take over your web services and pretend that they're you.

So, it's interesting. It's an interesting way of doing it. I know it's very different in its design, but that's the reason why we are who we are and we're boutique in that manner. >> So in an earlier call that we had this week, you mentioned scenarios where a CFO receives what appears to be a legitimate call from a CEO authorizing a payment. How common are these impersonation attacks becoming and what kinds of financial or operational damage are you seeing organizations actually get hit with?

Because as you said right there, this is something that you're seeing in the environment and it does cost money. What kind of money are we talking about? >> Woo. Well, outside of the one that you probably transferred to who you thought was a vendor, um and you basically dumped that money into an account that transferred itself over to a crypto asset or whatever the case may be. Um you're looking at time. And being time being the most valuable commodity in the human element, that that's the first expense you're going to you're going to feel immediately.

Uh because you're going to be hustling backwards to kind of figure out how this happened, why this happened, and what you can do to control the situation. So, time is going to be very much spent trying to figure this out. The second in the financial aspect of it all is what does your policy tell you? What is your policy geared towards protecting you in case an event does happen where you have a data breach, and what does that mean to you? Typically for small to medium businesses, or at least what we see, it can be potentially catastrophic because their policy doesn't cover or insure up to that because if there's negligence that has been left not discussed, not dealt with, an an audit is ran which costs you a financial amount of money because the insurance company is going to tell you or give you a choice who they use in terms of basically running that audit.

You may find yourself in a compliance twirl that if you don't have the capital or the expenses to basically cover it that, you're fighting upstream and and you're guppy. And you're probably going to get washed out like I said earlier. And there's nothing you're going to be able to do about it because your customers entrusted you with that data. They entrusted you with the ability to protect that and privatize that. So, their expenses could be felt on that as well.

We pray that it doesn't happen that way, but it does. Um because that that in a sense that's why reason why we were so big with the ransomware pieces because it's a time oriented thing and it's random. Um once they figure it out and they realize that they have somebody that could potentially pay the ransom, they're going to do whatever they can to slow drag this along to get the money that they're looking for. And if they've encapsulated with else's data within there, you better believe that they're the next one to try to get breached.

So, from a financial perspective, it just puts you in a downward spiral. And then the trust, it costs you a ton of trust. You could be a company that's basically been around for 15 to 20 years and get a data breach and set you back. We see it all the time with bigger conglomerates, which I won't name them, but you can do your own research that have 900 gig extracted, 800 gigs extracted by these bigger RAS groups, which is ransomware as a service.

They pretty much deep dive, get get the information, sit on it, extract what they need to, and then next thing you know, it's a headline. And next thing you know, you're going to have to use LifeLock. And then you're getting things, and then all of a sudden some people just get a check in the mail because some class action lawsuit that's been taken care of because someone else realized the ramifications of what this cost them down that line. It's just a very slippery slope, and this especially within age of artificial intelligence, it's one that we live in.

So, you have to do your due diligence. You really have to think outside the box and stop relying on the tools and the skills of yesterday. >> You brought up insurance policies, and I'm actually very curious to know cyber insurance is something that I've seen more and more businesses getting because they understand the risk, they understand that this is something they need to protect themselves against. But have the cyber policies policies for the most part, in your opinion and your experience, caught up to the AI portion of that risk?

Like caught up to the deep fakes and the RAS and the things that we're seeing out there caused by AI? >> No. Um we're actually going to be doing um a segment on that all in together with um with a few friends that I have that are in that segment. So, I won't speak too out of pocket about that, but what I definitely know from being able to review insurance policies in the past um in the past, I'm talking a few months ago. Um that that are correlated within that, they're not geared for that because it's a gray area, right?

Um you don't know the 16-year-old that's in the basement that's conjuring up the next exploit and what that could potentially mean for the business and then what does that mean from a negligence standpoint from a security company because they're not trying to pay that out. Uh, that's just being honest. I mean, insurance is really only there until you really need it and then when you need it there typically clauses and gray manipulation of area to basically make sure that they're not being held left holding the bag that you are.

And if it's you being the small to medium business and cash flow being the most important thing that is keeping your business afloat to pay salaries, to do XYZ and vendors, you're done. And there's really nothing else to really do about that because once you start talking with an audit measures, you're going to find more issues. You're going to find that you weren't as secure or as vigilant in terms of your preparedness as you thought you were. That's the reason I love my company so much.

It's because being boutique in that design and being able to bring a solution like a network to be a beforefront thinking in terms of deep fake analytics and you know, how they interoperate with like blockchain and just being forward thinking in that measure just gives clients an ability to feel a little ease of comfort while they go ahead and they dig through the crate so to speak within these insurance policies. >> I also would venture a guess because you talk about you have to do your due diligence that I'm sure you've gone to talk to potential customers and they're like, "No, we're good.

We're covered. We have cyber insurance and it's a catch-all." And you go, "Did you dig through it? Did you really go through it to see?" And I'm very certain that you've probably spoken to to leaders who haven't seen the fine print and haven't dug through the insurance. >> I challenge them. I challenge them because I don't want to be the one that they rely on within the regards of reading all the black and white literature. I've had to read over 700 pages of documents before with being in the compliance in my own in in a company in the past and being one to recommend of services depending on what they are if it's cloud oriented because of certain things that we deal with in within data, you should go and talk to someone that lives and breathes this on a day-to-day basis that can give you a fair education and within that conversation, you should talk about deep fake.

You should talk about data manipulation. You should talk about ransomware. You should talk about artificial intelligence um that can be transmuted like you can do talk about all the things that make you uncomfortable to them and if they can't give you a response, run. Find someone who can because from a standpoint of where you are going tomorrow, everyone is using artificial intelligence. Everybody is leaning on it at a high clip and there's so many different ways that you can measure an attack and data breach that you want to make sure that you're fully educated underneath that umbrella.

Um not doing your due diligence is just negligence at that point. >> I'm curious to know because you're a business owner yourself and you're a business leader yourself, how much of that due diligence that the customer has to do impacts your business? So what I mean by that is how much of it impacts your decision to actually take on that customer if you realize that they're not necessarily doing their own part and pulling their own weight on that end. >> It's huge, but that's the value in what we do.

I mean, if we're bridging enterprise architects and resources, I'm not going to stand up a a proof of concept with you and offer you services that I know that are directly going to just basically put you behind the eight ball because you're not even covering yourself from a policy standpoint. I'd rather you just go do your own um due diligence um making sure where you are because it is one of the questions that we offer within the questionnaire in terms of security uh just to make sure that they're being measured appropriately for the environment that they have.

And and then we can we can discuss this in a slow burn version versus slow dancing in a burning room um cuz I don't I don't want that. I don't want that for you. I don't want that for my company, and then it turns around more than Delta parent sold us a product that basically assisted us with this, and you know, we're using artificial intelligence, so we're 100% good to go. Meanwhile, you're you're paying $40 a month with a cybersecurity insurance policy that doesn't even protect your environment in and of itself if something were to happen.

Cuz to say everything is 100% would just be very very very very dumb on my part. Like that that's never going to happen, but I it it just doesn't make sense. It wouldn't make sense for me. It It would be very negligent on my part. No, I won't do it. I just won't. >> I think it's so important to to highlight there still is no silver bullet, and as AI continues to evolve, we all continue to see ourselves try to like catch up as much as possible cuz the bad actors, as we're talking about today, have the same access to those tools.

Speaking of which, something really fun that you talked to me about is you mentioned actually running live demonstrations with a synthetic identity in which people on a call, prospective clients, can't tell that they're actually interacting with a fake person until your system flags it. So, what's the typical reaction when organizations see that in action? >> They kind of feel betrayed. Because like it it's not something that's like um an immediate thing.

Um I kind of like let it burn a little bit. I let it leak a little bit. I let it bleed a little bit, and then I'll get at least 10 to 15 minutes, and then they'll be like, "Hey, listen, guys." You know, and I'll take a screenshot. I'll drop it in the chat, and I'll show that, you know, the flirt, which is utilized by Netorks, is going crazy. Um I'm pretty much letting me know that this person that we brought on to the call, which is a localized LLM that we're utilizing mirror typically, is not real.

And we use a lot of demos, and and and we really try to kind of like push the narrative within a lot of what we do on LinkedIn and and giving people education because you just don't know. And it's only going to get better. So, from a standpoint of who you trust and how you're looking at trust, that can be manipulated. So, wouldn't you want to have someone that is on your side? Wouldn't you want to have a tool that's on your side to basically tell you like, "Hey, listen, in the very rudimentary way, this is good.

I'm not sure about this. Kill the call." You know, and then it just gives you a layer of trust that you can believe in. And you can hold yourself to an accord to say, and especially if you bring a guest onto a call or whatever the case may be, just another layer to say, "Hey, listen, this is what we have. This is what we're utilizing. We can trust this call." Because that's that's the biggest thing in it and that's the reason why I'm being able to layer services with networks is a huge deal.

It's trust. You you want to have trust. If you don't have trust, then then you're just worried too late until the aftereffect of it all. And nobody wants to be in that record. >> No, absolutely not. We talked about this earlier with legacy tools, but I think it's important to really double down on it because I want to name some some ones that I'm sure many people watching have already deployed in their organization. So, many organizations already have identity tools like MFA, endpoint security, IAM.

What do those traditional security controls fail to catch when it comes to deepfake-driven impersonation attacks? >> Biometrics. I mean, the fact of the matter is they can be manipulated, which some people will believe they'll they'll they'll they'll I'm pretty sure I'll get flamed for that. But, the fact of the matter is that's the truth, man. Like, what do you want to do if somebody basically puts all their time, energy, focus, resources into a collective to basically make sure that this is going to be impersonated at a high level.

This isn't like copying art. You're copying body mannerisms, body language, features, fingerprints, identity, eyes, how I move my hands, everything is is at a point where you're not going to the human eye is not going to capture it fast enough. Hell, the human eye can barely, you know, really understand 120 year gigahertz of refresh rate on the screen, let alone 240 or you know, or anything above that. So, from a standpoint of you giving all this trust in just 2FA, which I'm not saying that 2FA isn't the cat's meow.

I believe in 2FA across all policies, rather if it's Google Classroom or it's a Microsoft enterprise whatever the case may be. 100% do it. It is definitely a double check. There is another layer and aspect to it as we are gaining momentum in the artificial intelligence community to basically say that I could definitely impersonate you. In matter of fact, I'm pretty sure I can impersonate you better than you. Which is a very scary thought to think about and it makes you question everything from a standpoint that you see on video because imagine the patient that's sitting in there trusting in what they believe is their doctor and they're giving their PII just as a validation proof point and the call goes dead.

You just gave all this information >> Mhm. >> to basically authenticate yourself and where did it go? You don't know. You have no idea. You call back, you get in touch. Oh, well, we were on the call, we didn't see anything. How did that happen? Now you're asking more questions and you're like, well damn, well who did I give this information to? It's a little too late after that. Um So, so from a standpoint of being all things equal, 2FA is great, you know, different measurements of 2FA are off awesome, but there there's another level of authentication measure that's going to need to be educated on and rather quickly and I'm glad that you're having these conversations because we're here now because artificial intelligence isn't just spaghetti anymore.

It's not just whipping things up that that can't be um, you know, replicated. It can. >> And I'm assuming by this point your system has not flagged me as a deep fake or artificial intelligence, so it's it's working. I am a real person. >> Yeah. Yeah, Katie's super real. Yeah, and I'm real, too. This is a real baby Daniel and history. >> This is real. >> My nose is running. That's real. >> Oh, man. Well, Daniel, I'm curious to know do you have any success stories that maybe come to mind when you think about I love to hang my hat on this example.

This is really shows what we do as a company and exemplifies us at Delta Bear. With or without naming the customer, can you tell me one of those success stories that comes to mind? >> Yeah, I can I'll keep the customer off the books cuz but it's a charter school that's local lies to Pittsburgh. Actually two of them. It's kind of a similar feat to where, you know, budgetary concerns and especially within this day and this climate and this political landscape that we're in is just not readily available.

Finances are just hard to come by. And a lot of things are really gained through grants. We really kind of made our staple early on working with those two organizations helping helping them grant right to get where they needed to be from an I getting it from an ISP standpoint as a cost effective and then growing with them organically into implementing into their environment helping them gain global policies over their their students, their their faculty.

And then getting into a security aspect of what they're doing to basically take care of the problems of yesterday and looking for us the future. And within that, which I really love cuz I come from a place of understanding what a predatory contract looks like. I understand from a place from where that looks like and how hard that can be on a school that's just trying to basically stay open in urban environment and provide education to those who need it.

And being in the community we want to serve. We don't want to look for bleeding blood from, you know, pulling blood from a stone. That's that's not the way that we should be utilizing our schools that entrust in our youth. You know, we've helped them not only save funds, we've helped them reallocate funds to technology looking forward as they are esteemed school both are and within utilizing getting to a point to stand up their own privatized LLMs for their their kids.

And what that's going to do and what that helps out in their science departments, it just gives them an additional resource that they're going to be able to grow with and go to in terms of being able to assist these kids for tomorrow as they're looking towards artificial intelligence. So, we're help grooming these kids to be able to learn and be the next wave in terms of solutions. And at the end of the day, that just it makes me feel good. It just makes me realize what I'm really doing it for.

And I can lay my head on my pillow every night knowing that I'm going to be able to impact them. And we're And I'm sure you know, we have our businesses etc. but like that we're helping kids. Like I'm real big on kids and I love that. >> I love that too. I think that's so special to talk about and it's always so great to hear speaking to somebody and they go, "This is why I do it every day." Because obviously you love every customer but there's something really special about the ones like kids and and those other industries that perhaps they didn't have the budget or didn't have the know-how to get as far as they did and you come in and can help them.

So, I love that. And actually are there any other industries you mentioned schools but are there any other industries verticals where you see this kind of technology could really be applicable for? I know you said you're for everybody and we've already said cybersecurity is for everybody but are there any maybe regulated industries that you could see this really working for? >> Healthcare is huge. I think healthcare with telehealth and I think with you know, HIPAA compliance and you know, a lot of hospitals that use like Epic or whatever the case may be.

Um, and now especially with hospitals requesting to basically record you in your note-taking ability. And it's going to a privatized LLM to chart you. I mean, that data in of itself is so crucial. It's so crucial because it's it's you. It's your makeup. It's from the time you were born, you know, to the time you get a checkup, you get a shot, what's going on with you. And it's your profile. So, entrusting solutions that don't operate with the threats of tomorrow almost makes me like want to throw up.

Like I talked to my doctor. I'll just give you a little sidebar. But like I talked to my doctor um, cuz I had my checkup a month ago and and she's like, you know, do you give permission to record you? You know, this just helps me take notes faster. And I'm like, oh, that's super cool, you know. And I was just like, how are they protecting that? She's like, I don't know. And I was like, damn. Well, you know, this is going into a Windows machine. Um, like And then my brain start churning because I know the software and I'm very familiar with Epic and I know a few other softwares which I won't mention by name.

And I'm just thinking of the security protocols that live behind that and what's really protecting me and her in this private conversation that I'm entrusting with them. And when you really start to think about that and you don't have answers. And it's not like you can just go on a website and you can read do some type of privatized policy cuz those answers don't live there. I've looked. So, this is a help network. How what are we doing? You know, like where where's that where's that information going to live?

Is it going to live in my chart? Is it going to live in this software program that you guys are entrusted in and how are you guys protecting that to protect me? And that just makes me really uneasy um, thinking about how that goes. I was in the meeting for 2 hours. And I'll leave the potential client's name out because we're still trying to get a proof of concept up with them. 2 hours. It was a round table of this this is necessary. We have a sock.

We don't have to worry about this because we watch it with codes and in out. And we probably should pay attention. So, it was literally a triangle of division that I was doing my best to cut through. And it's like, well, you know, guys, we can get to a place where we can have a testing environment to really stand this up. And then we can kind of answer everyone's question in a water shed moment. And you know, I'm getting a little kickback about that.

But then I have advocates that are like, no, we definitely should do this. So, we'll see how that goes. But long story short, it really does have a real strong message behind it. And what NetOps is doing and what we're experiencing in this landscape of artificial intelligence and cybersecurity community, there just needs to be so many more questions. There needs to be so many more uncomfortable conversations with people that are entrusted in making these decisions, with the teams that entrusted them with good leadership.

Because I'll tell you right now, it's not happening. It's not. An acronym's getting thrown on something and it's like, well, that's enough. Well, good. We have oversight. We got a sock. We should be compliant. It's like, okay. >> Just ignore the last 2 hours that I've been telling you no, but >> Yeah, it's all right. >> Yeah. >> All right. Well, you know, I I I got to respect I got to respect where we're coming from. But the fact of the matter is is like, you know, the goal is simple.

The critical reduced dwell time. Like, we have to minimize impact. We have to keep operations uninterrupted. And you're not doing that with challenging something without evidence, without proof, without some type of validity. I don't want you to take my word for it. I don't. I definitely don't. I'm just some guy that could be just selling you anything cuz I got what they That's how it's perceived. But the fact of the matter is I want you guys to do your due diligence.

I want you to take what I'm giving you and then discredit it. And not only discredit it, put it through your paces in your environment and let's see what holds water and let's see what doesn't. And then, you know, maybe you don't. Maybe you are doing everything underneath the sun and God bless you. I hope you are. But from what I'm experiencing and especially what I know especially within my region in the Northeast region, we move slow. So from a standpoint of you taking care of the threats of tomorrow, I highly doubt it.

I do. >> Well, Daniel, speaking as an MSP yourself and speaking as an expert in this particular part of the industry, from a channel perspective, where do you see the biggest opportunities for MSPs here when I'm specifically talking about AI-driven deepfakes? Is deepfake detection becoming a new security service category that partners can build revenue around? >> 1,000% and this is a big one where I have with the gentleman. We were at Starbucks. He just recently left that company.

Still not going to say the company's name, but he knows who he is and I hope you're watching, brother, cuz you know that I'm right. Mobile phones, quite frankly, mobile phones, OT, devices that live in the environment that travel with you day-to-day, that you're responsible for, that you jump on to guess Wi-Fi after guess Wi-Fi after guess Wi-Fi. Like mobile phones. Dude, there's so much trust that goes unfortunately into mobile phones and there's so much of an asset risk back to into a company that most people don't even understand.

90% and we And it was 90% because I looked at it on this other LinkedIn article. It showed that most people don't take a proactive measure when flipping passwords. Most people don't care if something says compromised. I use that. There's no way someone has that password. Yeah? Oh, yeah? Okay, cool. You keep jumping from guest Wi-Fi and then you have somebody that's whacking in the background with a dolphin or whatever the case may be because there's so many different solutions to basically hijack Wi-Fi.

Um you're at a discredit and you're at a disservice and then next thing you know someone's getting man in the middle. Then you're going to get someone's getting a phone call for an authorization to send a a large sum of money that they're approving that is not real and it's not valid and they're giving the account number and you can have a 2FA measure where you have someone proof reading the first half of it and then you send it to them for a second line of authentication and they get it and it all looks valid and then all of a sudden you get a phone call from that vendor and they're saying, "Hey, listen, where's that payment at?" We sent it to you.

Go check. Okay, it's gone. And then it's like, "Okay, well, well, well, wait a minute." And next thing you know, you're on FBI's website, you're filling out a report, you're calling your local police, you're reaching out to that bank, and that that's when it starts. That's when the clock's ticking. And nine times out of 10, way too late. It's over. You just got man in the middle. And the relay server that's forwarding the calls off, you probably didn't kill it.

The threat landscape has really evolved. Um it is an old tactic, but it's one that's still being utilized. Um and with the age, once again, of artificial intelligence, it's only getting cleaner, better, smoother, transitional in those conversations and you're doing yourself a disservice. So, if I'm an MSP's perspective, why wouldn't you want to fill that gap? Why wouldn't you want to be able to go into an enterprise-based company or one of your own clients that you can educate in this standpoint and present a solution like Netwrx?

Evoke and just really focus on being proactive with defense measurements. Easy. >> This question might be a layup considering everything you just said, and you might just be like, "Hey, see all of the above." But, as I mentioned earlier, the bad actors also have access to AI-enabled tools to improve their attack success. What's the key to staying ahead of them these days? >> Staying in the conversation and staying curious. Um I don't think that there is no one that can clearly say that they know all.

And I'm And I love the people that ask like, "Well, I got my certainness. I got educated in this." That was invalidated the next day you woke up. Period. There's real money, real energy, real time, real resources, once again, being spent on making sure that these attacks are successful. Enterprise-based companies, Fortune 500 companies, they're not getting exploited for no reason. And it can't be done with just grassroots behavior. You're talking millions of dollars pe- grass-based companies and nefarious companies that are interested in where they're spending to get to you.

So, within encapsulated data and unpacking data, and they find these small-to-medium-sized companies, that's like low-hanging fruit for them. Um so, from a standpoint of being able to take those attacks and compound them to get little ransomware money back, why wouldn't you want to stay curious? Why wouldn't you want to stay educated? Why wouldn't you want to reach out to a company such as NetWorks within the solutions that they're providing to be able to provide to your client in terms of an education to fill a gap?

Cuz everyone's an expert until something happens in their environment. And then they're the first one that get looked to because they were the ones that were entrusted with the solutions. And not being curious is typically the issue. Like, I I can't tell you how many conversations I've had where like, once again, going back to my earlier statements to where they're like, "Oh, we're good. You know, we're straight." Month later, "We're not good. You know, we we we thought we had it figured out.

We thought we had measurements in place and all of a sudden we're being ransomware or, you know, we got man in the middle or whatever the case may be when there's solutions that cost you fractions per endpoint that would be able to take care of that. Just sounds like negligence to me, to be honest. >> Great advice. As we wrap up here, Daniel, I'm curious to know what you would think about the future when it comes to this kind of technology being implemented into the security stack.

Maybe even like 5 years from now, do you think what you're doing is going to be a typical layer inside the security stack just like we see endpoint protection today? >> I think it has to be. I think you have to combine the trust mechanisms um that we currently are putting all of our emphasis on and like like you mentioned within 2FA, within certain levels of tools that are in um the the security stack, so to speak. Do it almost behoove you not to do so and typically it will.

Deep fakes are real. They're here. Trust is big and it's not negotiable. You know, that's what makes being human awesome. Being able to talk to the person across from you via screen and utilize the technology we have. We figured that out through COVID, right? So, why wouldn't you want a layer of service that can make sure that that you can have that trusted call with the private data that you're sharing back and forth to be okay? So, you don't have to worry about what comes afterwards.

And a lot of people will put an emphasis on saying, "Well, what if that never comes?" Well, what if tomorrow never comes? We're human, right? So, that that just sounds like a comment made for someone who's worried about what they're going to eat for lunch versus about a environment they're trying to protect for tomorrow. So, with that being said, I think that all things being in combination, this will be become a requirement. That's why we're inviting the conversations and and our own hosted webinars, just to see what the threat scan landscape looks like 2 3 4 5 years from now.

Artificial intelligence is booming right now. People are doing amazing things with Open Claw. They're doing amazing things within API structures to be able to teach these LLMs how to maneuver, manipulate, and even some gain financial advantages. So, what do you think is going to happen to the groups that are doing ransomware, doing deep fakes, doing man-in-the-middle attacks, doing DDoS? I mean, you can go down your own gambit. You're only doing yourself a disservice by not being early, not challenging the thought process, and at least getting educated, creating your own little testing environment, standing up a proof of concept, and see if you're just being early, or maybe you're okay.

You're being early. You're being proactive. You're being measured. And And that's how it should be when you're being entrusted with um a business with a company. Just it beats being on the news. >> For all the wrong reasons, yeah. >> For all the wrong reasons. >> Well, Daniel, I could ask you a million more questions, but for those who have those questions and want to get to know you and want to learn more about DeltaBear and potentially even seek out your services, where can they go to learn more? >> Just go to deltabear.ai um and reach out.

Um we're always available. We do have Mira that does run live on the site. Uh so, she can answer a lot of the questions, even give you probably way more detailed answers than I can, cuz we always have her learning. And just reach out. Uh you can reach me d elliott two L's two T's at deltabear.ai. And um we'll be here for you today, tomorrow, and the day after. >> Daniel, thank you so much for your time today. This has been such a cool conversation and a scary one and I appreciate you. >> Appreciate you, Katie.

Thank you very much and talk soon. >> Thanks so much to Daniel for joining me today and thank you for watching or listening. You can check out every episode of Channel Insider Partner POV on channelinsider.com or watch us on YouTube at youtube.com/channelinsider_newsandtrends. You can also listen to us as a podcast wherever you get your podcasts from. Don't forget to like, subscribe and follow wherever possible so you never miss an episode. Come connect with Channel Insider and me on LinkedIn or X. Once again, I'm Katie Bavoso and I'll see you next time.

This transcript was generated automatically from the video's captions and may contain errors.

Delta Bear CEO Daniel Elliott joins Channel Insider: Partner POV to discuss deepfake attacks, AI impersonation risks, cyber insurance gaps, and MSP opportunities.

Written By
Katie Bavoso
Katie Bavoso
May 6, 2026
1 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Deepfakes are moving from viral novelty to real-world cyber threat. In this episode of Channel Insider: Partner POV, host Katie Boso speaks with Daniel Elliott, CEO of Delta Bear, about how AI-powered impersonation attacks are targeting businesses, why legacy security tools may fall short, and how MSPs and MSSPs can build new services around deepfake detection.

They discuss CFO fraud scenarios, cyber insurance gaps, synthetic identity demos, regulated industry risks, and why deepfake defense may soon become a standard layer in the cybersecurity stack.

Timestamps:
00:00 – Introduction to Delta Bear and deepfake cyber threats
01:01 – Delta Bear’s mission, customers, and cybersecurity focus
03:19 – Why deepfakes are becoming operational for attackers
05:02 – How Delta Bear combines detection technology with security expertise
07:18 – CEO/CFO impersonation scams and financial damage
10:45 – Cyber insurance gaps around AI and deepfake risk
12:47 – Why businesses need to read the fine print on coverage
14:20 – Customer due diligence and shared responsibility in cybersecurity
16:12 – Live synthetic identity demonstrations and customer reactions
18:09 – Why MFA, endpoint security, and IAM may miss deepfake attacks
21:25 – Delta Bear customer success stories
24:27 – Industries and regulated sectors where deepfake defense matters
29:24 – MSP opportunities around AI-driven deepfake detection
32:35 – How defenders can stay ahead of AI-enabled attackers
34:53 – Why deepfake detection may become a standard security layer
37:43 – Where to learn more about Delta Bear
38:17 – Closing remarks and where to watch or listen

Katie Bavoso

Katie Bavoso is a 2017 Regional New England Emmy-nominated broadcaster with over a decade of professional content creation, production, hosting, and interviewing experience. Starting her career off in TV news, she pivoted to the IT channel to help connect vendors, solutions and services providers, and IT buyers through exciting video content and storytelling. Katie is now the host of Channel Insider: Partner POV, a video and podcast series shining a light on the most innovative solution providers of the IT channel.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.