Hey, John. How you doing? Well, with the forty fourth annual NAFOA conference happening here towards the end of April, You know, definitely would like that opportunity to get out to the public. Mr. John Graham, principal with our cybersecurity department here at REDW. Hey, John. Hey, how are you? Doing good, doing good. Glad you had some time out of your busy schedule to sit down with us. I wanted to take this opportunity to really introduce you and you’re sitting on a pretty important panel on April twenty eighth with respect to cybersecurity. I think the title is, What Could Go Wrong? Cybersecurity Essentials for Tribal Governments. Alright, we’re gonna talk about, there’s kind of four main core concepts there, that’s gonna be around, kind of framing the issue, what actually can go wrong, stewardship and sovereignty lens, and then last is just, what do you hope leaders take away from NAFOA? All right, John. So the first question is gonna be, when tribal leaders hear cyber security, it often feels too technical or even overwhelming. How do you encourage leaders to think about this differently? Yeah, I do see that as well. A lot of times, the tribal leaders will just simply say, Well, our IT director takes care of that, or, Our third party IT service provider helps us with that, and they frame it in a technology way, and unfortunately, what we see happen is it’s a broader risk than just technology because if the tribal leaders look at it and understand how do they make decisions around a cybersecurity event when it occurs to minimize the impact, it’s not really a technology discussion at that point. And we also see areas where cyber attacks don’t necessarily take a technology direction. They may be a phone call. They may be, an email that becomes what’s called business email compromise where a financial process breaks down, and those cause the impact. If they would look at it as this is a decision flow and these are strategies that we have to look at as a leadership team, then you actually can bring the resilience in more to the tribe, and you can respond and recover from these events much quicker and in a better way. Yep. So basically, just really being proactive as opposed to reactive and not really having to panic when it happens. Yeah. Right. Good sense. Cool. Cool. Okay. No. The other thing is, you know, when it actually does go wrong, when those when those situations happen, you know, in your experience, when a cyber incident really starts to spiral, what disconnects are they usually prevalent at a government or leadership level that you tend to see? It tends to be similar to what we just sort of opened with, which is a technology team on their own can make a decision to shut down a firewall or turn off a server or stop a network. They can do those things. What then tends to happen is the tribal leadership then has to say, well, who do we engage to help us, or how do we recover, and what’s the priority of that recovery, and how do we think about when should we turn something back on and get the get the organization functioning again? And that’s where we see, again, a slow response time because they’ve never either done it before, they haven’t had training around how do we execute these decisions, and they haven’t gone through that process to build the muscle memory that allows the tribe to come together and say, wow, okay, this event occurred. Our IT team took XYZ action. Now we have to now make some decisions as a tribe to say, do we recover the government first? Do we recover the health care second? Or do we recover the casino first? How do we actually get back to an operational stance in a short amount of time? Again, looking at it from the muscle memory, how do we build that proactive posture and learning before an event occurs? Yeah. No, that’s definitely a good point. I really like your reference to muscle memory and just, you know, constantly at certain points in time, evaluate, you know, tweak, and then re implement, you know, kind of go forward with that. I think those are really some key points. Now with the speed at which technology is integrating with everyday life, you know, cybersecurity being one of them. And at times, you know, with tribal leaders, you know, they’re able to speak to people that voted them in. And then they speak to strategy moving forward. In the past, a lot of that was centered around, you know, hard asset building return on investments on that type of those type of assets, identifying which grant funding, you know, avenues there are. But now you have to really integrate and think about technology as an important part of it, especially now that financial systems, you know, the way people communicate now is all integrated around technology, whether or not it’s through, you know, phone, or tablet, and so forth. So as you talk to tribal leaders, you know, sometimes they may think that this cybersecurity issue is not their issue, and that’s for IT. You know? But I know sometimes you like to push back on that a little bit because, you know, it really does have to do with stewardship, which, you know, is core to being a leader within Indian Country, in this case, as we’re talking about just overall leadership. So what are your thoughts on that? I think your analogy is really good that historically the leadership in tribes have looked at things like a physical asset or a building or a school or a hospital, and they’ve said, Wow, okay, I can see and I can touch and I can feel that. And what we really need is to help educate that the data could be recordings or it could be the language that was stored, you know, in a computer for historical reasons. All of those things have value. Even though they can’t be seen or touched and felt, they are all, you know, elements of tribe overall, and they have to be seen as assets and they have to be dealt with around how do we manage the risk and the prioritization of protecting it, just like we would the building or the healthcare facility or the casino. And that is a change in sort of how to think about some of this, but when you look at the impact that happens in a cyber attack, whether it be ransomware where you have to start over, you know, basically rebuild your systems and things from scratch, and you may or may not have the data backed up appropriately. All those sound like technology things, the risk around how do we protect it and how do we think about it as a tribe are all really leadership discussions. They’re not just, oh, toss it to the technology team to try to figure out. No. That’s a good point. You know, it’s almost as if leadership sets the vision and the goal, you know, the tech team is basically charting going from a to b. Right? And then working together with that is definitely a must, if you will. Yeah. Now, you’re speaking at NAFOA, and you’re gonna be speaking to many different leaders, different people in different positions. And what do you really hope they take away from your topic and what you’re speaking on? I really hope that when the leadership returns to the tribes, that they ask some general questions and that they think about historically, like we’ve said, a lot of times the leaders will look to the IT organization or the IT director and just say, Okay, you own this and you have it. And the individual in that role always wants to do their best job, and they want to provide the best service. They may even be in a situation where they want to show that they own it and they have it, and so I would say ask them what help do they need. Most of the time, what we see is an individual in that role and maybe one other person working with them, and they’re supporting a vast amount of tribal assets from a logical and data perspective. And I think that, I would say lead with curiosity and ask them, you know, do they need help, or ask them, have they thought about how to recover and how can the leadership actually help them in those roles? I believe we see sort of a gap in that kind of a dialogue, more so we look at, you know, the IT team is chartered with doing something and they just say, Yes, we have it, we own it, we’ve got it, when it’s really a broader tribal event, and I would say you lead with curiosity and ask some of the questions. Yeah. That’s a good point. That’s a good point. Well, John, thank you so much. I know you’re a very busy guy. Be sure to stop by and say hello to John. He doesn’t bite. But, you know, you definitely have more than willing to answer any questions you have and more than willing to sit down, have a cup of coffee with you, or even just chat and talk about these important topics. Once again, thank you, John. Thank you, Wes. I look forward to it.