Your Incident Response Plan Is Missing One Phone Number
Rajah & Tann Asia CISO Konrads Klints on why breaches start with budget decisions, and what a cheap firewall really signals.
Somewhere in your environment sits a control that nobody chose for security reasons, whether that is the firewall that won on price or the EDR that got bought without anyone being assigned to watch it. Both were settled years ago by somebody weighing a budget, and Konrads Klints thinks that is where breaches actually start.
Konrads is CISO at Rajah & Tann Asia, one of Southeast Asia's largest networks of law firms, with member firms in ten countries, and he spent years on the offensive side before crossing to defense.
On Episode 15 of the Full Metal Packet podcast, hosts Yegor Sak and Alex Paguis spend the episode testing his claim that attackers do not really hack your technology so much as they hack your org chart, your supplier relationships, and your budget.
TL;DR
- Treat your cheapest infrastructure decision as evidence. At-Bay found SonicWall appliances in 86% of Akira attacks in 2025, which Konrads reads as a budget signal and not a product flaw. The same philosophy set your patch cadence, your monitoring, and your hiring bar.
- Prove the controls you own are deployed everywhere before buying another. Coverage evidence is the only practical audit of what past budget decisions actually delivered.
- Record a named operational contact at every supplier your recovery depends on, and check whether their support structure has depth. One person deep is a reason to walk even when the product is better.
- Move admins to hardware-backed passwordless and disable the fallback. Konrads says any organization without hardware keys on anything important will not make it long term.
- Buy cyber insurance even at a small limit. Underwriting prices your exposure, the policy gives you an incident response panel on day one, and the broker reaches the managing partner directly.
The Org Chart Came First
The job Konrads holds barely exists, and the reason is structural. Most jurisdictions, Singapore included, require a law firm to be a partnership of individual practitioners instead of a company.
"Individuals doing their individual practices, banding together to share some costs."
Nobody assembles an advisory board on the way into a structure like that. Lawyers worked out that they needed someone to fix the computers, hired that person, and watched the remit grow year after year without anyone bringing in outside expertise. Konrads believes he was the first full-time security hire at a law firm in Asia, based on his own scan of LinkedIn, and his firm only got there because the partners saw what was heading toward them.
"They kind of saw the light coming at them, decided it's a locomotive and decided they need to get off those tracks."
The legal form of the business had set the security posture decades before anyone got as far as choosing a product.
Why Law Firms Almost Always Pay
That same structure makes law firms unusually easy to collect from. Akira hit the Singapore firm Shook Lin & Bok on 9 April 2024, the negotiation chat leaked, and SuspectFile reported a payment of 21.07 bitcoin, around USD 1.4 million, against an opening demand of USD 2 million. The firm never confirmed it and has said there was no evidence its client-data systems were affected.
The pressure Konrads describes is specific to the profession. Client confidentiality is not a preference, and once the files are public, legal privilege generally stops applying.
"If you don't do this, you're basically committing essentially almost like an act of professional negligence."
Being a known ransomware victim is survivable. Losing privilege is not. That is close to the opposite of the call Zach Lewis made in Episode 12, where a university CISO refused a $1.25M LockBit demand. Both calls follow from how the organization was built in the first place.
What actually punishes a breached firm is much quieter than a lawsuit. Institutional clients sit on three to five year contracts, and somebody inside the client vouched for you to get on the panel. After a breach, that person starts wondering whether continuing to vouch is good for their own career.
"You're still on the panel, you still have the contract, but you just don't get the briefs."
"Do Not Pay" Is a Position, Not a Plan
Alex asks why government bodies keep telling victims not to pay, and Konrads answers with an opinion he is happy to label as one.
"My own view is that it's political posturing and nothing else."
His reasoning is that any government genuinely convinced by the ecosystem argument could legislate a ban, and none has done so economy-wide, because a ban would push payments underground and force the victim to commit a crime in order to survive. Underneath that sits something harder to say out loud.
"It's very difficult for governments or the police to admit that they're essentially unable to protect you."
He is careful to add that this is not ignorance on the regulators' part, since people move between industry and government in both directions. "It's not for the lack of information, it's for the lack of a solution." Even the official advice, then, is an institutional posture more than an operational judgment. Jurisdiction constraining what a response can attempt is the same tension Alejandro Rivas-Vásquez worked through in Episode 4.
What a Cheap Firewall Signals
Yegor puts a statistic to him. At-Bay's 2026 InsurSec Report, built on more than 6,500 claims, found SonicWall appliances present in 86% of Akira attacks during 2025, with SonicWall the most targeted VPN across the whole book.
Konrads reads that as a budget signal instead of a product failure, and he is quick to say so. "I'm not saying SonicWalls are necessarily bad. SonicWall, don't sue me." The chain he describes runs like this.
| The decision | What it produces |
|---|---|
| Buy on lowest price | Thin vendor margins, less reinvested in the product |
| Thin internal budget | Limited resources to maintain the device |
| Limited resources | A lower hiring bar |
| A lower bar | Nobody buys or watches monitoring tools |
| No monitoring | No process that would catch an unpatched firewall |
The device itself never asks for attention. "If you log into the panel, maybe you see it, maybe you won't, but most of the time you're not logging into the panel anyway."
The usual mitigation is EDR, where the same pressure applies twice over. A pricey product is no guarantee of strength, and nobody is monitoring it, because monitoring means paying for a service. At-Bay's data backs him up on that second point. In its claims, the Akira victims that avoided full encryption had paired EDR with round-the-clock managed detection.
An appliance on the perimeter is the visible end of a decision taken years earlier by somebody who was not thinking about Akira.
The Decision Is Always Made Above You
Yegor tries the argument in reverse. Organizations that buy maxed-out appliances and the top CrowdStrike tier still get breached, so the price tag cannot be the variable that matters.
Konrads accepts that and sorts it into three tiers. Organizations that are small and poor are simply gapped out. Very large ones are defeated by sprawl, where contracts get signed and the coverage never actually reaches a particular server. The best odds belong to organizations with money that are still small enough for one person to hold in their head.
Then comes the sentence the whole episode rests on.
"That's a very big leadership question. That's not something you can answer from bottom up."
However capable you are, if you sit too far down the organization to change how it is structured, your purchasing decisions will not change the outcome. Ross Young reached the same place in Episode 11 from the money side, with a CFO who declined a $2M security program, absorbed a $4M breach, and still came out ahead.
For the organizations that can fund them, two investments pay off. The first is identity, because nearly everything eventually touches Active Directory or Entra or Okta, which makes it "a nice choke point that everybody has to go through." The second is incident response capacity, on the theory that if you cannot control everything you can at least get fast at stopping it.
What a Small Budget Buys, and Who Buys It
Alex asks the practical version of the question. If you cannot buy the best of everything, what comes first?
"You have to hire one or two really good people."
His examples of what those people then do are deliberately unglamorous. Windows Enterprise ships with Microsoft 365 E3 and includes AppLocker, which restricts what is allowed to execute. Turn it on and standard malware delivery becomes much harder, at no additional cost. After that comes basic access control, a free password manager, and, if you want to push further, Chromebooks or iPads.
Which turns the budget question into a hiring question, and hiring is governed by structure as well. Most organizations do not have a security team at all. They have an IT team carrying security responsibilities, and the labor market is unkind to them. "It is very rare that you're the top pick." An organization with real people management writes a job spec, works out how it would know a candidate is qualified, and ends up with a less variable result. An organization without one is relying on luck.
If you cannot hire that person, the fallback is to buy an advisor, which produces a distinction Konrads clearly enjoys making.
"A lot of organizations are split in two parts. Part number one is the one where the management has lunch with your big accounting and consulting firms. And others that don't."
Who your leadership eats lunch with ends up determining what your security team knows, which is not a technology variable either.
"How Do I Know I've Done This?"
Alex objects to the insurance advice on good grounds. If your security team is learning things from an insurer, the team is the problem.
Konrads takes the objection and reframes it. Basic advice is annoying and still fundamental, in the way that nobody is surprised to be told to drink less and lift more. What turns a basic tip into something worth acting on is the question you ask immediately afterward.
"Hold the one question back is how do I know I've done this? And if you're able to answer that question, you are now miles ahead of everybody else."
Install antivirus, sure. Now demonstrate coverage. Rajah & Tann runs Axonius to aggregate across its tools into a single view of what is covered by what, then takes the gaps to IT and asks why.
"I want this dashboard from the cherry pie to an apple pie. Please, please, make this go away."
That is a coverage argument, not a tooling argument, and it is the same demand for evidence over assurance that Maxime Lamothe-Brassard made in Episode 2. It is also the only practical way to audit what past budget decisions actually delivered.
The Same Problem, Pointed Outward
Everything so far concerns how your own organization is built. The two best stories in the episode apply the same argument to somebody else's.
A client in Ireland had been hit with ransomware, and the on-premises Exchange server was not coming back. The team migrated everyone to Office 365 instead, and it held for about a day. Then Microsoft restricted the new tenant on suspicion of compromise, because the client was sending a lot of email at once, which is what a community outreach program does. Support unlocked it. Four hours later it locked again.
KPMG's relationship with Microsoft was strong, but it ran through a relationship manager who does not work weekends, and what the situation needed was somebody operational who could intervene immediately. Then a contractor called Patty mentioned that he knew someone in Microsoft's Xbox division. That person knew someone else, who knew someone else again, and the tenant came unlocked.
"Our relationships were not good. But Patty's friend was exactly the right person."
The institutional relationship was worth nothing and an individual one worked, which is the org chart problem arriving from the supplier's side of the table.
The second story runs the same logic in reverse. A large Scandinavian client in the late 2010s needed software deployed across the estate at speed, and Konrads warned them how this kind of thing usually goes. What they had was a service delivery manager who owned the relationship with their outsourcer and called in a favor. Fifty engineers appeared overnight, working off a spreadsheet, screenshotting every changed system into a Word document as a human quality control layer. Work budgeted at three to five days landed inside 48 hours.
The exception was Brazil, which the outsourcer did not cover and which ran its own domain controller outside central management.
"Well, guess where the hackers are coming in from."
Yegor points out that no other guest on the show has raised this. Plenty of conversations have covered tabletops, contact sheets, and the first hour of an incident. Nobody has mentioned holding contacts at the vendors the recovery actually depends on.
Vet the Structure, Not the Product
Which turns vendor selection into an organizational assessment.
- Assess the local operation, not the global brand. A global company is never global at the point you deal with it.
- Check whether the structure is one person deep. Being handed a mobile number is not a support model. "Sometimes you see the structure is one layer deep." That is a reason to walk even when the product is better.
- Hold fewer vendors. Every supplier, even a silent one, costs roughly four hours a month in maintenance and calls. Ten vendors is a quarter of a full-time role spent keeping relationships alive.
- Use the coffee test. If they arrive with information and ideas, invest. If the agenda is buying more, "that's a person I really don't wanna invest any time at all talking to."
Alex pushes back on the consolidation advice, since concentrating vendors also concentrates risk. Konrads reaches for the Artemis program, whose two independently built redundant navigation systems ran on different hardware and a different operating system, so that one software fault could not take out both.
"I don't trust anyone. Not entirely."
So email runs redundantly across two providers with a two-hour tolerance, and almost everything else consolidates. He frames that as a question of feasibility more than budget. An in-house SOC needs six to eight people at a bare minimum, which he prices at two to four million Singapore dollars a year in Southeast Asia excluding tooling, and he says it will still be a bad SOC at that price. Alex offers a test worth stealing, which is to open a trial account and email support at 4am on a Saturday claiming to be locked out. Konrads refuses to choose between that and a named escalation path. "I think you probably need both of these things."
AI Does Not Fix Any of This
Konrads' first point about AI is that it raises the bar on people instead of lowering it. Junior staff struggle with it because they lack the judgment to direct it, while senior and mid-level people gain the most, "because they now have a team of five really great interns just cracking on with it."
His firm built one of those. They call it the intern, a bundle of skills, access, and APIs that lets an analyst type something like investigate ticket 9451. It pulls the ticket and runs the triage, and about eight times out of ten it has done what the analyst would have done, at roughly five dollars a run and around $200 a month. Those are his figures for his own setup. What it does not touch is the part this episode keeps returning to. "Tends not to help with interpersonal issues."
It does let you route around another organization's decisions, though. A niche vendor bridging the firm's practice management and document management systems refused to engage on security at all.
"These guys just didn't want to do security. They told us so."
So Konrads spent around $1,000 in AI tokens and rewrote their stack in his free time. He is careful not to oversell the result. There were no cost savings, since his own time was worth more than the annual fee, but the firm ended up with a better product and a platform it can build on.
Yegor asks whether a bespoke internal tool with unknown bugs is safer than well-known software where a CVE drops and everyone races to patch. Konrads answers by way of the panic that ran through July and August, when AI-driven vulnerability discovery pushed a wave of disclosures through widely deployed software.
"I make no assumption that any one piece of software is secure that I run."
Which makes the question exposure instead of obscurity. Put the tool behind something.
- Google Cloud customers, Identity-Aware Proxy
- Cloudflare customers, Access
- Microsoft customers, Easy Auth or an application proxy
- Anyone else, HTTP basic auth, so a scanner meets a 401 instead of your application
Alex redirects to what he thinks the real risk is. "The usefulness of a tool is only as good as the data within it. What data sources is this new tool consuming? Is it consuming your email?"
Konrads agrees and points at the data layer, which is another decision made years in advance. Financial services built one a long time ago, while law firms started a couple of years back at the earliest. His firm is building one now so that a person gets the data they are entitled to and nothing beyond it, which is what resolves the vibe coding question. "Go vibe-code something, point it over there. You're going to run it under your identity."
Passwordless, Android, and the Senior Conversation
Yegor calls scheduled password rotation one of the sillier ideas in security, since people run out of memorable passwords by the third cycle and start choosing weak ones. Konrads' firm sidestepped the problem entirely.
"I don't know what my password is. Haven't used it ever."
Hardware-backed keys are built into the machine, the machine authenticates to everything else, and a password manager covers whatever is left. His view is that any organization not using hardware keys on anything important is not going to make it long term, and he does not pretend the migration is easy. "Microsoft doesn't make it easy." It is the same conclusion Devon Ackerman argued toward in Episode 8, where one phone call to a help desk produced full network access.
Asked for a cheap habit with outsized impact, he says there are no free ones and offers trade-offs instead. The first will annoy people. "Don't support Android. If you can get away without supporting Android, don't support Android, you will have an easier life, hands down." His evidence is the passwordless rollout, where everyone on an iPhone simply got on with it, while Android produced devices too old to work and newer ones running Chinese app store variants. The firm ended up issuing phones it had not budgeted for.
Then Alex asks for the one thing every law firm should be doing and is not.
"Get insured. Get cyber insurance. It's your first rung to any security initiative."
Underwriting is the only process that reliably produces an outside number on your exposure. "Somebody out there is going to tell you how much they're willing to bet on you not getting hacked." Insurers then work that risk down because they are carrying it, and the policy hands you an incident response panel you can call on day one.
The reason he puts it first, though, is structural, and it lands back where the episode started. Insurance relationships are senior by default. A broker talks to the head of risk or the managing partner, so the argument arrives at leadership from the side instead of requiring somebody two levels down to push it upward for two years. For a firm with no CISO, that is the only channel that reaches the level where these decisions get made.
Proving the Control Is Actually On
Konrads' question, how do I know I've done this, is about evidence more than tooling. DNS is a narrow place to look for it, and it is at least inspectable. Control D provides two tools for that layer.
- The DNS Leak Test shows which resolver a device is actually using, which answers whether your policy reached that machine or is being bypassed.
- Admin Logs preserve every configuration change and who made it.
The Control D guide to DNS logging best practices covers what to keep and for how long.
That is one layer. It says nothing about whether the firewall is patched or whether anyone is watching your EDR, which are the controls Konrads actually cares about.
Continue the Argument
- Episode 12: How a University CISO Refused a $1.25M LockBit Ransom Demand shows the payment decision running the other way, where refusing held because recovery did not depend on paying.
- Episode 4: "Compliance Isn't Security" examines how jurisdiction constrains what an incident response can attempt.
- Episode 2: "Trust Me, Bro" Isn't a Security Strategy asks what security looks like when customers demand evidence instead of promises.
- Episode 11: Inside the Capital One Breach: The 1% Security Gap Nobody Fixed reaches the same leadership conclusion from the money side.
- Episode 8: Ex-FBI Agent: One Phone Call Gave Hackers Full Network Access shows what one help-desk interaction can hand over when identity checks are weak.
Browse the full Full Metal Packet series.
Common Questions Answered in Episode 15
Why do law firms pay ransomware demands?
Because payment often protects legal privilege, which generally stops applying once client files are public. Konrads' position is that for many firms this outweighs the reputational cost of being a known victim. Other sectors reach different conclusions from the same facts, which is why blanket advice on paying rarely survives contact with an industry.
Why do governments tell organizations not to pay?
Officially, because payment does not guarantee decryption, marks you as willing, and funds further attacks. Konrads' own view is that the position is largely political posturing, since any government convinced by that argument could legislate a ban and none has done so economy-wide. He notes North American law enforcement will privately help victims while the official line stays unchanged.
Does having EDR protect you from ransomware?
Not by itself. At-Bay's 2026 report found that the Akira victims who avoided full encryption had paired their EDR with 24/7 managed detection and response. Buying the tool without funding anyone to watch it produces the cost without the protection.
Should you consolidate security vendors or diversify?
Both, selectively. Consolidate broadly, because each relationship costs real time and consolidation buys standing with a supplier that will actually respond. Then deliberately diversify the one or two systems you cannot operate without. Konrads runs redundant email for this reason.
How do you evaluate a vendor's support before you need it?
Assess the local operation rather than the global brand, and check whether the support structure has depth or is one person deep. Alex's test is to open a trial account and email support at an unreasonable hour with an urgent problem. Konrads wants both a competent frontline and a named escalation path, since either alone will eventually fail.
Are internally built or AI-generated tools safer than commercial software?
Obscurity buys you something, and less than people assume, because you will still pull in dependencies that get exploited like everyone else's. Put the tool behind an identity-aware proxy, Cloudflare Access, a Microsoft app proxy, or plain HTTP basic auth. Then answer the harder question separately, which is what data the tool consumes and whose permissions it runs under.
Is cyber insurance worth it for a small organization?
Konrads argues it is the first thing to buy, before any other security initiative. Underwriting produces an external assessment of your exposure, the insurer has an incentive to keep you secure, and the policy gives you a pre-vetted incident response firm you can call immediately. For organizations without a security function, the broker relationship is also the only one senior enough to reach decision-makers.
Konrads Klints is CISO at Rajah & Tann Asia, one of Southeast Asia's largest networks of law firms, with member firms across ten Asian countries. He describes himself as the first dedicated law firm CISO in ASEAN, and in 2025 the firm's Singapore practice became the first law firm awarded the Cyber Security Agency of Singapore's Cyber Trustmark Advocate certification. Before crossing to defense he ran red team engagements and incident response, including telecoms work that produced a zero day in a widely used management platform, and he was previously at KPMG.
Full Metal Packet is hosted by Control D co-founders Yegor Sak and Alex Paguis. Watch Episode 15 on YouTube, or listen on Apple Podcasts and Spotify.