The Sound of Pursuit
This is the official podcast of Pursuit Magazine, an online community of private investigators, journalists, and truth-seekers of all stripes. In the podcast, we explore information sources, share tradecraft tips, and discuss ways to integrate new technology with old-school gumshoe know-how. We dig into myths about PI work and hear hard-won lessons from the field. And for the spy-curious outsider, we offer a behind-the-scenes glimpse into the lives of real spies and PIs. We CAN handle the truth.
The Sound of Pursuit
Cyberwarfare, Hunting Threats, and Why Companies Are Breached
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
How do you identify online threats before they turn into disasters?
Our guest Chris Nyhuis specializes in shielding clients from cyberattacks. As co-founder and CEO of Vigilant, a cybersecurity company in Cincinnati, he’s developed defenses for the food supply chain and telecom — protecting the kind of infrastructure that, when it gets hit, makes national news. Nyhuis teaches about cyberwarfare and holds multiple patents in threat analysis. And perhaps most impressive of all: The company gives 25% of their profit to organizations fighting child trafficking and supporting orphans around the world. It's built into their business model.
Listen to find out what's going on in the world of cybersecurity, who's getting hit, and how to take practical steps to keep yourself and your business safer.
Viligant's website: https://vigilantnow.com/
FInd Chris Nyhuis on LinkedIn.
Host: Hal Humphreys
Guest: Chris Nyhuis
"Blood Will Tell" podcast: On Apple | On Spotify | On Audible
Sponsored by: TLOxp®
Music provided by Jason White, who composed our theme.
Special thanks to Kim Green and Stephanie Mitchell, who produced this episode.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Pursuit Magazine and PI Education are part of StoryboardEMP, a media and education company in Nashville, TN. Pursuit, a free online magazine for private investigators, explores all things investigative, from gumshoe techniques and surveillance tech to industry news and crime in media. PI Education, its sister brand, provides online continuing education for licensed PIs. Pursuit and PIed are owned and edited by husband-wife team Hal Humphreys, a PI, and Kim Green, a writer and radio producer.
In this podcast, you'll find episodes that dive deep into the work and the business of private investigations. And at PI Education's YouTube channel, you can dive even deeper into the knowledge pool of this fascinating profession, with regular briefings and webinars. Subscribe to stay up to date!
Pursuit Magazine: https://pursuitmag.com/
PI Education: https://pieducation.com/
Our channel: https://www.youtube.com/c/PIEducation
Most trouble doesn't knock. It seeps in under the door, wipes its feet on your rug, and helps itself to your pantry. By the time it announces itself, the house is already on fire and the neighbors are calling the news. He works in the shadows where quiet failures turn into public disasters, building defenses for the food supply chain and the telecom systems that keep the lights on and the country talking. When those systems break, it's never a small story. We'll talk about how these attacks really happen, what they look like before they bloom into catastrophe, and what an ordinary person can do to avoid becoming the next cautionary tale. This company also carries a conscience, which is rarer than it should be. Stick around. This one might save you some trouble.
SPEAKER_00Ready to streamline your investigations? Find hidden connections and fresh leads that power successful cases with TLO XP from TransUnion. Replace manual searches with advanced analytics that examine 10,000 data sources and deliver actionable insights in seconds. Automatically uncover undetected links between individuals, assets, and organizations to keep your investigations moving. You'll build stronger cases and close them faster with TLO XP from TransUnion. For details, visit TLO.com.
SPEAKER_02Welcome back to the Sound of Pursuit. I'm Al Humphreys, your host. My guest today is Chris Nyheist, co-founder and CEO of Vigilant, a cybersecurity company in Cincinnati. Before founding Vigilant in 2009, Chris was Chief Information Security Officer at a national automotive data analytics company where he developed defenses against attacks that targeted big data sets. Now, this is a big deal. Chris speaks and teaches on cyber warfare and holds multiple patents and threat analysis. And here's the thing about vigilant that kind of struck me. They give 25% of their profits to organizations fighting child trafficking and supporting orphans around the world. That's built into the business model. I find that pretty interesting. Today we're talking about what's going on in the world of cybersecurity, who's getting hit and why, and practical steps that anyone can take to stay safe. Chris, thank you so much for taking the time to be with us today. Welcome to The Sound of Pursuit. Before we get started, just give us a real quick introduction of who is Chris Nyheis.
SPEAKER_01You know, um, Hal, it's great to be here. Thanks for having me on. I appreciate it. Um, you know, first and foremost, um, you know, I'm I'm a father, I'm a husband, um, I'm a Christian. Uh, I uh I care deeply about this world and the people in it. And it's what makes me tick every single day. Um, you know, outside of that, uh, you know, I'm a CEO, um, friend, um, and uh I love backpacking. I love flying air aircraft. I'm a private pilot um and just having fun. You know, I I think it we have to go outside of our our way sometimes uh to get adventure in our world. And uh and so I I try to do that. I've climbed Mount Rainier, um, you know, and love love love doing mountaineering and things like that. Um and uh and and ultimately I I just you know I love defending people and and and having them come along on that journey.
SPEAKER_02I love it. So um do you own an aircraft, Chris? I'm part so I do not yet.
SPEAKER_01One day. Um there there's been other things uh that are more important to spend our money on. Uh but I am part of an aircraft club. And so we have seven aircraft. Uh, I can rent those at any time I want to.
SPEAKER_02And then uh we just what's your what's your what's your go-to airframe?
SPEAKER_01My go-to airframe is an SR-22, it's a Cirrus. Uh but now our club doesn't have one of those, so I have to rent it when I go. So I do that for business travel. But uh outside of that, uh, we used to have a Piper uh arrow, love that aircraft. We we ended up selling that uh from the club, and and now um you know we have 182s and uh 172s.
SPEAKER_02So there's a planet 182 reminds me of driving a pickup truck sometimes. Yes, exactly right. I my Kim Green, my wife, had a Sestin 172 for years. Yeah, we we flew that thing all over the country. Uh 734 Papatango had had a stole kit on it. Yeah, uh oh, yes.
SPEAKER_01I almost scaled my check ride because of one.
SPEAKER_02Fantastic little airplane, but do things that other 172s wouldn't do. Um and I just I missed that airplane. It was destroyed um at BA here in Nashville in a uh straight-lined wind gust. I remember that. Kim Kim said uh she went flying on her own. She took out a king air and a limousine in the process.
SPEAKER_01Oh wow, that's crazy. So were you talking about the tornado that came through or just an actual wind?
SPEAKER_02This was probably, I might know a little over 20 years ago. Um just a real bad thunderstorm. There was a micro burst that that picked the picked the plane up, and yeah, she uh she came untethered and actually she wasn't even tied down. The the ramp had untied her to move her, and um she took a little, little, I don't know, 15-foot flight, hit a king air. The king air spun around, hit a limousine, did a lot of good damage.
SPEAKER_01Wow, that's crazy. That's crazy. Micro bursts are no joke. I I was I was flying into uh Martha's Vineyard with a buddy of mine in our in the in the Piper, and uh we uh full IMC were just coming to Mint's and uh we got hit by a micro burst right off the the the runway and we uh we got we got pushed about a mile off course.
SPEAKER_02Oh my god.
SPEAKER_01Scary thing, scariest thing ever. We had uh we had uh it was Peterborough came in uh over the radio and they uh they said, uh, are you flying uh a pipe or arrow? We said, yeah. And we said, Well, you you went pretty fast. You went faster than that airframe flies. And uh we told them what happened, and and they uh we did a uh we we let him know and he let the other pilots behind us coming into Martha's Vineyard know as well because that was that was scary.
SPEAKER_02That's terrifying. All right. So um today's today's sound of pursuit is aviation 101 for those of you listening. Um I did not know you were a pilot before you came on the show, Chris. This is exciting. Um we could we need to have another podcast where we do nothing but talk about um flying airplanes, that kind of business. Um, I am I am a certificated pilot as well, Kim. Uh when she bought the airplane, um, the guy who taught both of us to fly used owned the airplane, he offered it to me, and I just couldn't make sense of buying an airplane outright. But I thought, I've got to meet this woman who just bought that airplane. And yeah, that's amazing. 26 years later, we're married. Congratulations. Yeah, it's good stuff. Well, so all right, getting back to the topic at hand. Yes, um, and I don't want I don't want to go off into the the world of mountaineering and backpacking because we could do a whole podcast on that too. Um I think we'd be friends. Yeah, I think so. I mean when you when you said you did Mount Rainier, um, I've I've done several 14ers out in Colorado. Um one of the easy ones just to walk up Quandary Peak, probably, I don't know, 15 years ago, but back in the day, um, I worked for the Boy Scouts of America at Felmont um Scout Ranch. Yeah. And on days off, we would have 12 days on, three days off. We would drive up to Colorado and and climb Holy Cross, or um I remember Blanca Peak was one of my favorite peaks out there that we did. Um, so yeah, another podcast, another time we'll talk about those things. Chris, you started Villigent back in 2009. What were you seeing at the time that made you think something is broken here and nobody is fixing it?
SPEAKER_01Yeah, at first we thought a recession is a great time to start a company. Let's do that. Um, yeah, so that was that was then. Um, you know, what was interesting to me is when I was working, you know, when I first what really was my impetus moment in cyber was uh I was at a uh working for a food distribution organization. Basically all the food frozen food in the country goes through these warehouses, and they have ammonia control systems that compress ammonia uh SCADA control systems to create fast refrigeration and and freezing. And we had just switched from hubs to switches. We had uh put in the first firewall any of us had ever seen. Uh, and we popped that in and we started seeing weird traffic. And we thought, why would someone want to hit this place? Like, why would someone want to try to get in here? And as we thought more about the operations, it's ammonia. And you know, you had these Windows 95 systems connected up to you know the network, and anyone could pop on there, open a valve, and release ammonia and just literally melt people's lungs. And oh my gosh, that was the moment for me where I went, okay, because before that I'd worked at ISPs, I'd you know, and we had played around with malware that would open your drives and stuff. We'd do things to try to get into places, and uh, but it was never at that point, it hadn't it hadn't clicked that this was that bad of evil yet, because it was still hobbyist type stuff. And that was my moment. And as I everything I did going forward in cybersecurity, you know, it just takes me back to that moment still. And and so right before we started vigilant, what I was seeing in the market, in the marketplaces, you had organizations that weren't sharing threat data with each other, primarily because they were competitors and things like that. You had the industry was moving from uh distributed, uh more layered defense into UTM firewalls and trying to condense everything in, which sounds like a really good thing because you're like, oh, this is this advanced firewall. But in reality, what it was doing was it was benefiting the manufacturer because they only had to sell you one appliance now. Yeah, and it actually reduced a lot of your detection. So what I was seeing is the industry was reducing its footprint in the attack chain and their visibility, and it was negatively impacting the consumer and they had no idea. And you know, so we saw attacks hit us that none of the hundreds of thousands of dollars worth of gear that we bought would see first.
SPEAKER_02Yeah, yeah. Walk me through what it looks like when someone hacks into a network, not the movie version, but what really happens.
unknownYeah.
SPEAKER_01So when someone hacks into a network, you know, it starts months and months in advance. You know, they're doing recon on you, they're looking at um things like out of office. I hate out of office. Why? Because it helps the threat actor literally footprint your vacation schedule. It helps you footprint your organizational structure, who you who reports to who. You know, so they're doing all this recon up front. Uh, they're looking at your press releases, they're trying to figure out what hardware and software you use. They're trying to figure out if you're even a viable target for them. Uh, and then once they go through all of that, they start to test the exterior of your perimeter. And you know they try to see what triggers a block, what what triggers uh them to be detected. Uh and they test it and they keep going deeper and deeper in. And uh, and in most cases, what they're looking for is some piece of software or hardware you use that is either misconfigured or it has a vulnerability that no one knows about. Once they find those, then they then they exploit it. They'll either create a weaponized uh piece of software against it, or they'll manually go in and hit it. Now, all of that can take a few months, it could take a few days. Uh, but all of that combined, uh, when that really triggers, and once they finally get into your environment, the scary part about these threat actors is that once they're in your environment, on average, and you can see this in Verizon's report, you can see it in all these reports, on average, they're in an environment 287 days on average before they're detected. Right. And so when, yeah, so when your detection systems finally find them and you get the 15-minute guaranteed alert, it's 287 days plus 15 on average.
SPEAKER_02You know, most of the time. Most of us out here. Most of us out here think we're covered. You know, we've we've got antivirus software and IT personnel. Um, maybe we've even got our own firewall here at the office or whatever. Where does that thinking go wrong?
SPEAKER_01Well, the thinking goes wrong because what you what we think about those systems is that they cover everything. And cybersecurity is really a physics and a logic problem at its core. Uh, and you add in a little sprinkle of time. And when you look at that, uh, you know, think about antivirus, for instance. You remember Norton back in the day? Everybody loved Norton. I love Norton, it was awesome. And then all of a sudden, Norton was like really slow, it was bogging down, everybody was jumping ship, they're like, oh, we don't want this anymore. And then about three months later, it was like fast again. You're like, what the heck? Well, what Norton was doing was they were actually adding a lot more protection on it. Yeah, but people complained because their system slowed down.
SPEAKER_02Yeah.
SPEAKER_01Because the primary purpose of your desktop is to do Word and Excel and things like that for you to help you do business. The primary purpose isn't to stop threats, right? So you have to balance the processing that those systems have towards whatever you're using it for. And so unfortunately, security takes the backseat. And so what they had to do was they had to say, okay, well, you know what, we're gonna not load it with all of the detections that are out there. We're gonna start to look at what's trending, and then we're gonna load these systems with what's trending. And then we're gonna detect what hits it. The problem with that is if you always follow the trend, you're always behind what's really happening in real time. And firewalls are the same way, uh, laptops are the same way.
SPEAKER_02Well, and in fact, if if you know what the trends are, the bad actors know what the trends are too.
SPEAKER_01They know what they are too, and they're the ones driving it. So what's interesting is when they see the trend happen, it's opsec for them to realize that they need to change what they're doing because now they're being seen. So if it shows up in a best practice, you're too late. If you're doing best practices, you're too late. Um, the other thing too is they can buy the same firewalls, the same endpoints, the same everything you can. And so they just put it in their labs, and the moment their detection shows up in those systems, they pivot.
SPEAKER_02Fair point. Fair point. Yeah. All right. So, Chris, your company provides what what's called managed detection and response. Yeah. Forget the industry term for a second. What does Vigilant do on a Wednesday afternoon?
SPEAKER_01So what we do on a Wednesday afternoon is, you know, we are hunting for the unknown. We are looking for what hasn't been seen yet. You know, we are uh trying to find um that thing that a threat actor is doing now before there's detection for it. And, you know, that's been very successful for us. Um, you know, we have we have amazing clients, which is what helps make this this statement uh work as well, is that we in 16 years, we haven't had a client have a breach, no data loss. Um now the caveat there is, you know, that that has actually deployed what we do, right? You know, we've had some clients that haven't and and you know, fully, and we've said, hey, this is happening. And, you know, at that point, you know, if they haven't deployed those preventive controls that we could do, uh, we can't stop it. And it might take them a while to fix it and uh and then things happen. But we've never had a client that's deployed everything that's come out and and had a breach or data loss. And that's that's primarily because we try to hang out um before the attack happens, right? Like we're looking at what are these threat actors doing before this happens.
SPEAKER_02Now, your platform is called Cyber DNA. Where did that name come from? And what is the thinking behind that name?
SPEAKER_01Right. So cyber DNA is really based on this concept that you know security has to be directly intertwined in everything you do inside an organization, um, including the strategic decisions you make as a company, right? We have clients that will do a press release and they will dramatically have major attacks right after that, right? And so this aspect of looking at all the things that are happening with inside a company uh and then deriving the stance that you have to have to defend and even proactively defend against an attacker that might come at you. Um and so all the technology that we have that we've developed intertwines into that. There's the platform.
SPEAKER_02There's this, you mentioned this earlier, and and I'm really curious. Um, you know, the example of Norton that slowed your system down, trying to do too much. Yes. At the end of the day, we all have work to do. So how do you how do you approach this balance of we're gonna get you as secure as possible? We're gonna let you do the thing you do.
SPEAKER_01Yeah. Are you familiar with the kill chain or like the attack kill chain? No. Like how it okay. So uh attackers go through these stages where they're doing recon, they're uh you know, investigating how they might attack you, they create weaponized attacks, they deploy those attacks all the way through to getting the data that they want. Most cyber technology operates at the back end of that.
SPEAKER_02Yeah.
SPEAKER_01Uh and and that could be weeks or months after an attacker started doing something. The problem with that is, well, I'll say that the problem with that is you learn about attacks way too late. Um, and so if you're detecting an attack on an endpoint, right, um, in general, that's way too far down the kill chain, right? It's way too far down and it's way too late. And so we do identification across that entire swath of time. Um, so that that way when when a detect when a detection takes place, it's happening before it even gets to your endpoint, right?
SPEAKER_02You're trying to get to it before 285 days.
SPEAKER_01Before 285 days. In fact, we're under four hours as a company. Okay. Yeah. And so and the and the point there is that you know, when you look at your your desktop itself, you know, it cannot be loaded with every detection out there. It's like the flu shop, right? We have so many different variants to the flu, and we have to guess what flu might hit us this this month or this year. And if they're wrong, a lot of people get the flu. If they're right, it it's it's it's smaller. And it's the same thing with with the approach of antivirus software or even detections, is they try to guess what's there and they put it there. So at Vigilant, we try to not ever guess. You know, we want to we want to understand what's really happening.
SPEAKER_02So you're kind of explaining your process a little bit. And I think this is a great point place to just kind of point out to our listeners, um, Chris and his company um found a Microsoft exchange vulnerability before Microsoft even knew it existed. Um the first question is how did that feel? Second question is, you know, is continue with your your kind of discussion of how it is you guys do your work to get to it before the 285 days.
SPEAKER_01Right. So, you know, back then, that was that was a few years ago back, I think maybe five now, something like that. Uh it was in it was in February. Um, what what took place was, uh, and I'll I'll just talk about this in terms of placement. Security should always be placed as close to the threat actor as possible, uh, and it should collect as much information as possible. Now, most cyber technology out there wants to collect as little as possible unless your bill is based on storage. If your bill is based on storage, they want to collect as much as possible, right? So in that case, what we did was we were on the we sit on the outside of people's networks because what most people do with their firewalls is they'll do GOIP blocking, the block regions. Uh, they'll block things like ping and ICP, ICMP, just people that are trying to scan your network, they block those things. So the the defensive mechanisms you have in place never actually interact with the recon or the analysis, the pre-attack analysis that a threat actor is doing. So, what we do is we sit on the outside of your firewalls in a transparent way. No one knows we're there. The threat actor doesn't see we're there. And we're collecting all of that information across all of our clients globally. And we're we're evaluating what we see them doing, where they're coming from, what they're doing, how they're doing it. Uh, every single packet's important. And when you evaluate that, you can start to see how those attacks are forming because they're testing things. And then once you know how they test it, you can now start to do strategic decisions around where you think they're going. Okay. And that's what happened with Microsoft. So we we saw that. What was really frustrating to us is um when we we released that, we found out how they were doing it. We set up some uh some honey pots to collect what they were doing. Uh about three weeks later, uh, other security providers started seeing it uh and they started releasing those uh we call them indicators of compromise publicly. But what we saw was the moment they released those, within two hours, the threat actor changed what they were doing. And so Their IOCs didn't detect anymore. Right. That's crazy. Two hours. Two hours.
SPEAKER_02You know, a lot of the folks that listen to the show are investigators. Um, we have some intelligence and security professionals um that listen to us that work with clients of all sizes. Um, you know, small operations. And I would consider our company a small operation. Um are we as exposed as big operations? Who's getting hit right now?
SPEAKER_01So uh the smaller organizations are getting hit the most. Um now I would say uh the smaller organizations have a better opportunity to be a lot more secure than the larger organizations. It's a lot harder to secure uh, you know, a larger attack footprint, right? Uh when you look at the smaller organization, the biggest problem with the small organization is they just don't want to spend the time or the effort to put security in place. Um, the issue with that, though, is that 80% of the businesses in the United States are small and medium, and they are the first attack point, and they then are the pivot point for an attacker to get into their customers. And so sometimes you see, you know, someone's trying to get to a defense contractor, they're going through five or six different organizations to get there, you know. Yeah, yeah.
SPEAKER_02So um, for our listeners out there, yes, we should all be paying attention to this. Chris, you talk about um cyber warfare. You teach about cyber warfare. That's a word most people associate with governments and spy movies. How does it touch on a regular basis? On a regular business.
SPEAKER_01Oh, we are whether we like it or not, we are all in cyber warfare. You know, I mean, 100%. If you look, if you study warfare, uh, one of the things that's uh a common theme historically is this idea of concentric circles of protection. And so, you know, the outer circle used to be military, and then it goes all the way into the central financial system of an of an of a country. Prior to the 1990s, 1980s, you had to to attack the United States, you had to get in a boat or a plane, get across the Atlantic or the Pacific, come here, fight your way from coast to coast, red dawn it, if you remember that movie, you know, and fortunately I do. Yeah, right, right, right. And and I I have that memorized. But you know, you you have this this thing where physical kinetic warfare, you know, you know, physical warfare had to take place. When you know, when the internet started kicking off and attacks started happening, now one person on the other side of the world in their basement can take down the entire United States infrastructure. Yeah. Right. And you know, if you look at Stryker, are you familiar with the striker attack that just took place? Yeah. Yeah. With Stryker, you know, a lot of people thought, you know, and have been thinking. I did a post on LinkedIn on it, um, because what I looked at was what happened in the 48 hours before, what happened in the 48 hours after? Because these things are very coordinated. You know, these threat extra months and months and months to investigate this. And I got a lot of comments that were politically motivated on my on my post, uh, because people are like, well, if we hadn't attacked Iran, you know, they wouldn't have kicked this off. And the thing, what people don't realize is that they were in striker more than likely. Now, I don't, this isn't guaranteed. I haven't seen their threat reports, but statistically, looking at all the incidents I've worked at, worked on over my career, they they had to be in striker for months before that took place. So the real question is, why were they in striker before that? Or, you know, we have 250 known water districts in the United States with known threat actors in it that they can't get out. Why are they there?
SPEAKER_02Yeah. Yeah. Let me ask you this. What's one practical thing I and my listeners and your friends can do this week to improve their security beyond just update your passwords, which I know we all need to do, is there a small action that can make a big difference and help listeners get safer right away?
SPEAKER_01Yeah. I mean, the biggest thing is there it all comes down to the smallest unit you're part of, right? And that's going to be your family. And so that, you know, if our families are taken down, our our jobs are taken down, our cities are taken down, our states are taken down, because a lot of these attacks now are coming into a family first and then coming through you into your work and your personal systems. So the first thing I would say is, you know, we're in the world of AI, deep fakes, et cetera. Make sure you talk to your family about what you do and what you don't do, right? Uh talk to them and not not, and I'm not talking about what you do in terms of computer hygiene. I'm talking about in terms of, hey, I'm not, you know, I'm going out of town this weekend. This is where I'm going. So if you get a deep fake call and it says you're still in town, they know, right? So be very communicative to your family, but also have a safe word, right? You know, with your family so that that way if someone calls up and they say, Hey, I'm in jail, I need you to send me money, and it sounds like your voice, um, you know, I I can clone your voice, Alan, you know, in less than a minute, right? Because there's enough content out there. Um, if if someone says something with your voice, it can be very convincing. But if you say, hey, what's our safe word for the week? And I would change it that often, um, and they don't know it, then you know that you're you're fine.
SPEAKER_02Well, and inside the family, if you have kids, um, that becomes a fun thing to do inside the family, kind of have the safe word of the week. That's uh I like that. That's a good little tip. Chris, let me ask you about let me ask you about the giving side of vigilant. 25% of profits are going to fight child trafficking and child um support orphans. Um, that's not a small number. How did that become part of your company?
SPEAKER_01So from day one, and I'll actually say um the way that that came out was uh we we were starting vigilant. Uh, we knew that we didn't want to create a company that had private equity investment uh from the very beginning. Um, I had a lot of friends that were, you know, that started companies at the same time I was, I was talking to them about it and they're like, man, I would not do this again. Uh some of them that shot up, you know, they said, hey, we do it again in a second. Uh, but then later on they go, no, I would never do it again. And and the primary reason is that if you're in this industry, like I said, cyber warfare. Like this is not just cybersecurity. This is all of us are involved in an actual threat that wants to take down our way of living every single day. We are the best country in the world. We have uh we have an amazing ecosystem and people hate that. And uh, and so they want to take it down. The when it comes to um, you know, cybersecurity, we just said, look, if we take private equity, we're not going to be in control of our destiny. We're not gonna be able to do the sometimes. Vigilant does things that doesn't actually give us better margin, but it actually stops the threat. Where the 25% came in uh was we had just filed uh our our papers to to get our EI in. We were getting the bit the business going. Uh, I had just quit my job. Um, my uh I and I I had this dream and uh and the 25% was in there and I was praying about that. And I just heard God say, I want you to do this. And I didn't know what it would what the road ahead would look like with that. Um and I I I looked over at my wife because we had just both woke woken up and I said, Hey, I think we're supposed to do this. And she said, I had the same, the same dream and everything. And I went, okay, well, that's that confirms it for me. Um, you know, because that that was just such a such such a confirmation. And so we we said, okay, so literally the day, day one, we did it. Uh and uh what was interesting is uh we got tested on it. Uh we uh we you know we were net 90 then as a young business owner. I didn't know what net 90 meant, but it actually means net 180. Uh and we were about six months in, we were about out of all of our operating capital. And it came down to uh we had this opportunity where we either could pay, could donate this money to what we were doing with orphan care, or we could uh we could not and we could pay some of these bills. And that day all of our checks came in, but we we paid that that 25% first. So uh I'll say that's where it started. Now, where it's come, where it's come along the way is you know, we heavily got involved in organizations that do orphan care all over the world. Uh, we work in India, uh, you know, work with organizations in India, Nigeria, Haiti, Mexico, and the United States. Uh, it's led to uh developing 3D prosthetics, uh, you know, 3D printing prosthetics for kids in India. It's led to um, you know, babies living in Nigeria that wouldn't, uh, kids graduating from colleges. And we we come alongside these organizations and in and and just be part of their story. Uh back-to-back is is one of them that we work with, and and they're just phenomenal in the way that they care about these organizations. And human trafficking, uh, if you start doing stuff in orphan care, you start to see human trafficking, and and um, and I can tell you that that is um it's a really dark thing. And um and and so we're going after it.
SPEAKER_02I'm very interested in um this notion, you're you're one of uh three people that I've heard articulate this. Um my business partner and I being the other two that I've heard articulate this. Talking about venture capital, um our idea with building our company was we want to build something that is that is viable and that is useful and that we can it'll be bigger than us and that we can leave to you know children, legacy, that kind of business. Um we did not build it with the idea of an exit. Right, yeah, yeah. And I I think I I think there's an interesting thing about entrepreneurs that look at building a business that is an actual business and not building a business just to get VC and get an exit. Um I like that because it says we're here to do business. We're here to do um something long term. So Chris, thank you for taking the time to be here. I do have um a round of what um um Stephanie and Kim call rapid fire questions. Okay. I'm gonna ask you these real quick, give me a quick response. Number one, what's the biggest myth people have about staying safe online?
SPEAKER_01That uh fishing protection and antivirus work.
SPEAKER_02Strangest place an attack has ever originated.
SPEAKER_01Man, there's there's there's so many. I would there's so many. I would say um, and I and I love this country, so don't think negatively of it. Um, but and I've been there, so this is why it's so strange. A large technological attack from the middle of Nigeria in the middle of nowhere in in the in the bush, right? Like it's amazing. It it blew me when I finally went there. I was like, this is where this attack came from. Oh my gosh.
SPEAKER_02Something you always do before you close your laptop at night.
SPEAKER_01Uh I turn my Wi-Fi off. Yeah, I turn my Wi-Fi off. And um, you know, and the reason I do that uh is just because that the system can actually still continue to connect after that, right? Even when you shut your laptop down.
SPEAKER_02Okay. Uh favorite fictional hacker or spy movie, TV, or book? Oh, sneakers for sure.
SPEAKER_01I love it, I love it, I love it. Yeah. Chris, that would be your first one.
SPEAKER_02If you weren't doing this, what would you be doing?
SPEAKER_01If I wasn't doing this, um, I would be uh probably flying um uh Bush aircraft into uh remote jungles. Uh I think I I always wanted to do that when I was a little kid, and I thought that would be really cool. Uh Jim Elliott was uh guy that did that too.
SPEAKER_02Bonus rapid fire question Pilates or Cessna Caravan for that specific task.
SPEAKER_01Oh, a caravan for sure.
SPEAKER_02I love it. I love the high wing. I love it. All right, yeah. Chris, thank you so much for the time. You gotta be able to see below you. Yeah, yeah, yeah. Thanks so much for giving us an inside look at this. Many people hear these conversations and realize they're more at risk than they thought. Oh big time. It could be uncomfortable, but it's helpful. Um, if you want to learn more about what vigilant does, go to vigilantnow.com. Chris, where can people reach you directly if they want to get in touch?
SPEAKER_01You can hit me up on LinkedIn. Uh, I respond there pretty frequently. You won't get an AI about, I promise you. Uh and uh and actually there, uh we're I'm posting something today, Hal. Uh if you want to talk about it after we can. Uh, one of the uh I think the largest uh vulnerabilities that is at is coming out since solar winds. We figured it out over the last three weeks.
SPEAKER_02So okay, very interesting. Um Chris, again.
SPEAKER_01Check it out on my on my LinkedIn.
SPEAKER_02Thank you. Thank you so much for being here. Um folks, thank you for tuning in. Um again, thanks to Chris for being here with us today. I'm Hal Humphreys, and that is your Sound of Pursuit for this week.
SPEAKER_00You've been listening to the Sound of Pursuit, a podcast by Pursuit Magazine and PI Education.