Transcript

Manoj Tandon:
Hello everyone, and welcome to another episode of Dark Rhiino Security: Security Confidential. I’m your host, Manoj Tandon. Before we get started, I need to remind you to please hit the like and subscribe button. It doesn’t cost you anything, but it helps us tremendously and allows us to keep bringing you great content and amazing guests. We truly appreciate your support.
Today we have a fabulous guest joining us to talk about ransomware. Without further delay, I’d like to introduce Matthew Waddell. Matthew is an incident response and digital forensics expert with over 25 years of experience. He has helped governments, global enterprises, and small businesses, and has supported the U.S. government in counterintelligence investigations and frontline overseas operations. He also has an upcoming book titled Survive Ransomware, which we’ll discuss later. Matthew, thank you so much for joining us. It’s an honor to have you on the show.

Matthew Waddell:
Thank you. I’m thrilled to be here.

Manoj Tandon:
Tell us a little bit about your background. How did you get into cybersecurity? Were you formally trained as a computer scientist?

Matthew Waddell:
I fell in love with cybersecurity at a very early age. When I was in college, I wasn’t sure what I wanted to do. A cousin of mine who worked at AOL back in the 1990s told me there would always be people trying to break into computers. Around the same time, James Bond was on TV, and something clicked in my head. I realized this could be a career, and I absolutely fell in love with it.
I finished college with degrees in computer science and business management, and my first job out of school was at NASA, working on their incident response team in the SOC. From there, my career took off, and it’s been quite a ride ever since.
At that time, we didn’t have the tools we have today. When I mentor younger incident responders now, they have push-button solutions for many things. Back then, we were writing custom scripts just to sort data, identify incidents, and understand what was happening across such a massive and geographically distributed environment.

Manoj Tandon:
I imagine there were different levels of data—public, secret, top secret. Were those systems segmented?

Matthew Waddell:
They were, and they should be. After NASA, I went on to work with nearly all of the major three-letter government agencies. Government organizations generally do a very good job with network and data segmentation. Classified systems are heavily isolated and don’t touch the open internet.
Unfortunately, small and medium-sized businesses—and even many enterprises—do a poor job of data classification and segmentation. That’s one of the first things organizations should address.

Manoj Tandon:
Many businesses still believe segmentation is expensive and complex.

Matthew Waddell:
It doesn’t cost money anymore. It costs time and knowledge. On my home router, my IoT devices—security cameras, weather stations—are all on a separate network. That took minutes to configure and didn’t cost me a dime. Most modern business networking equipment supports segmentation.
Finance systems should absolutely be segmented. If you’re in business, money is involved, and that makes you a target. Segmentation limits blast radius and reduces risk significantly.

Manoj Tandon:
People push back on that. They complain about printers or convenience.

Matthew Waddell:
They do, and security is about understanding consequences. If you want everything flat and open, you’re making a tradeoff. Security introduces friction, but the benefits far outweigh the inconvenience.
My house would be more convenient without a front door, but that wouldn’t be very secure. Security works the same way. Once people understand why passwords, segmentation, and controls exist, they’re more likely to accept them.

Manoj Tandon:
If you had to give a short list of basic hygiene items everyone should do, what would they be?

Matthew Waddell:
Password hygiene is number one. Long, unique passwords—at least 12 characters. Anything shorter can often be cracked in under an hour using modern techniques. Complex passwords aren’t enough if they’re reused. If one password is compromised, attackers will try it everywhere.
Everything else—encryption, segmentation, classification—comes after preventing that initial access.

Manoj Tandon:
What are your thoughts on passkeys and password managers?

Matthew Waddell:
I’m a big fan of both. I use hardware keys like YubiKeys, which provide extremely strong authentication. Password managers are excellent because they generate and store long, random passwords. You only need to protect one strong master password, ideally with MFA. Tools like Bitwarden are affordable and effective.

Manoj Tandon:
Let’s talk ransomware. Walk us through how a ransomware attack actually begins.

Matthew Waddell:
Every ransomware attack starts with reconnaissance. Attackers research the organization—vendors, employees, LinkedIn profiles, who works in finance, who might have access to critical systems. They craft a targeted phishing attack, often personalized using social media information.
Once the phishing email is delivered and someone clicks, malware establishes a foothold, creates backdoors, and escalates privileges. From there, attackers move laterally across the network, searching for valuable data and backups. Only after they’ve exfiltrated data do they encrypt systems and demand ransom.

Manoj Tandon:
Execution times are getting faster. How is that possible?

Matthew Waddell:
Attackers practice on small and medium-sized businesses with little security. Those organizations are used as training grounds to refine tools and techniques. By the time attackers target larger organizations, their process is highly optimized.

Manoj Tandon:
Wouldn’t EDR detect much of this?

Matthew Waddell:
If it’s installed, configured correctly, and monitored—yes. But many organizations rely on basic antivirus, which doesn’t catch behavior-based attacks. EDR looks for abnormal behavior, like mass file encryption, but it only works if people are paying attention.

Manoj Tandon:
Is AI accelerating ransomware?

Matthew Waddell:
Absolutely, on both sides. Attackers use AI to write convincing phishing emails and generate malware. Defenders use AI to filter alerts and reduce noise. Security has always been reactive, and AI just accelerates the ladder-and-wall dynamic.

Manoj Tandon:
Could employee education make a real difference?

Matthew Waddell:
It’s the most effective lever organizations have. Educated employees are frontline defenders. Security should be an enabler, not the department of “no.” When employees understand why controls exist, they become assets rather than vulnerabilities.
Unfortunately, fewer than 10% of organizations truly succeed at this mindset shift.

Manoj Tandon:
Have you ever seen a system that couldn’t be breached?

Matthew Waddell:
If I can physically touch your system, all bets are off. Physical security is often overlooked. Most serious attackers exploit trust—name badges, confidence, social engineering—not technical vulnerabilities.

Manoj Tandon:
What should companies do before an incident happens?

Matthew Waddell:
Have a plan. Even a bad plan is better than no plan. Teams don’t rise to the occasion—they fall to their level of training. Incident response plans should be written calmly, practiced regularly, and tested through tabletop exercises.

Manoj Tandon:
Tell us about your book, Survive Ransomware.

Matthew Waddell:
It’s written for small and medium-sized businesses that don’t have security teams. It walks through the ransomware lifecycle in plain language and provides a clear response path from “I think I have ransomware” to recovery. I wrote it because this information needs to exist in an accessible form.

Manoj Tandon:
That’s an incredible contribution. Anything you’d like to leave our audience with?

Matthew Waddell:
If you think you might have ransomware or need guidance, visit surviveransomware.com for updates on the book, or tacticallysecure.com for consulting. I’m happy to talk with anyone and help point them in the right direction.

Manoj Tandon:
Matthew, thank you so much for your time and insight. Please don’t be a stranger.

Matthew Waddell:
Thank you. I really enjoyed this.

Manoj Tandon:
Take care.