I recently had Brett Gailey on Marketing for SMEs. Brett is the Chief Information Security Officer and Senior Director of Security and Compliance at Tia, and he came on to clear up the biggest cybersecurity misconceptions small business owners have.
I wanted to bring him on because cybersecurity is one of those topics where you either get gated content trying to sell you something, or nothing useful at all. Brett gave us the opposite: straight, practical answers on what’s actually worth worrying about.
Meet Brett Gailey
Jeremy: All right guys, welcome back to another episode. I’m here with Brett Gailey. He is the Chief Information Security Officer and Senior Director of Security and Compliance at Tia. Welcome to the show, man.
Brett: Thank you for having me. I appreciate it.
Jeremy: I appreciate you coming on, dude. So you’re a friend of Akvile, who we had on only last week. Such a great guest, and I was like, man, do you know anyone in cybersecurity?
Because it’s a pretty hot topic, a lot of misconceptions, a lot of gated content, I’d say, because you don’t know what they’re selling. They might tell you half, then you’re gonna have to buy some stuff. And then you come up with someone like you, who already works for a big company and just knows a lot of stuff.
So if we take it back, because this show is more for small business and entrepreneurship, the purpose of this episode, if we’re gonna leave people with one takeaway, is how do we stop the misconceptions and what should people be focusing on instead?
Brett: Yeah, absolutely.
Jeremy: Okay cool, so if we go back to the history of it, how’d you get started in cybersecurity? Was it by chance?
Brett: It was a little bit by chance, but I started in the early 2000s in the United States military. And then transitioned in the mid to late 2000s into systems engineering and software development. Then in the mid 2010s transitioned back into cybersecurity, and since then I’ve been in cybersecurity, specifically in the healthcare space in the United States.
Jeremy: So was it a 9/11 thing? Was there a shift towards that kind of thing, or was it something else that was more triggering inside the whole world event?
Brett: I think at that time, the world and a lot of our efforts went towards the concept of terrorism in the United States. But since the late 2000s, we’ve had a transition into cyber crime and really kind of a renaissance in the information security and cybersecurity space.
Originally that might’ve been the concept of hackers and phreakers back in the 80s and 90s. Nowadays we see red teamers, blue teamers, purple teamers, these different roles in cybersecurity that are focused on enhancing cybersecurity capabilities within different organizations.
Jeremy: Never heard of that term. Is that real, is it common? Like red team, all that?
Brett: Yeah, Red Team is your more offensive type of people, the ones doing hacking or security research, finding vulnerabilities. Your Blue Teamers are your defensive individuals that are monitoring and preventing attacks from happening. They kind of work side by side in order to prevent attacks and discover new ones before they’re exploitable.
The Speed Problem: AI and Attackers
Jeremy: So my thing is always, the hackers are using AI to try to exploit, like, the speed of it. And the big security banks and everything is trying to outspeed that speed to prevent it from happening. Is there really a race like that?
Brett: There’s been a race since probably 1980. It’s always a race of, can you prevent an attack from happening? You’re always trying to catch up against attackers.
Attackers are going to be opportunistic. They’re going to find vulnerabilities that are easy for them to exploit. So any type of defense that just makes it more difficult, generally that is a good enough put-off for different attackers.
But ultimately your blue team, your people that are defensive minded, they’re always chasing what the bad actors are doing. So it’s always a bit of a cat and mouse type of game.
Attackers are going to be opportunistic. They’re going to find vulnerabilities that are easy for them to exploit.
BRETT GAILEY
CISO & Sr. Director of Security and Compliance, Tia
Jeremy: Let’s bring a practical example. When crypto first came, crypto wallets were like a Chrome extension. Was that just heaven for hackers?
Brett: It’s anything that’s sufficiently profitable, generally, for a lot of these cybercrime opportunists. They’re gonna find anything that’s going to fulfill whatever goal they have.
There’s lots of different goals from different bad-acting groups. There might be politically motivated, financially motivated, they might be nation-state sponsored, they might be a terrorist organization of some sort. There’s even things like environmental cyber crime.
If we take that to a small, micro business level, it’s probably ransomware. Like blackmail, leaking. Ransomware is the most common.
Jeremy: With ransomware, does AI fully accelerate what they can do?
Brett: Yes. Specifically when we talk about the power of AI in the context of cybersecurity, on the attacking side, what we think about is two specific angles.
One is the ability to generate an exploit quickly without a lot of skill. And then secondly is the ability to trigger agentic workflows to exploit those vulnerabilities and then potentially pivot to other exploits that might be available.
Jeremy: So as soon as they’re in, boom boom boom, the whole stack taken down.
Brett: Exactly. Whereas before it’s more manual, before you have someone more technologically advanced to be at that level, now it’s done. What would traditionally be a very senior research person spending hours, days, weeks, months on a specific issue.
Jeremy: Can’t stop it. That’s it, it’s done. Once they’re in, it’s in.
Brett: Well, you can make it difficult. You can make it really difficult.
What would traditionally take a very senior research person hours, days, weeks or months can now be done much faster.
BRETT GAILEY
CISO & Sr. Director of Security and Compliance, Tia
What’s Actually Preventable
Jeremy: So when you look at laymen like me and entrepreneurs just trying to make it work, we can’t really afford anything sophisticated. Do you see the things that happen to us hack-wise as fully preventable?
Brett: It’s actually pretty straightforward, to be honest. A lot of the hacking techniques that are used, those attack vectors, they’re the same ones that have existed for the last 30 years.
Is your password compromised? You can go check that for free on the internet. And two, is somebody impersonating the person you’re talking to? There’s a couple of different ways that comes up, but phishing, smishing, things like that.
Those are some of the most common techniques bad actors use because people are inherently trusting. They want to do well, they want to support other people, so they can unfortunately be manipulated or abused in that type of way.
So when we say what are the primary ways we can defend ourselves in these small business settings, it’s just being diligent. It’s just: verify. Trust, but verify.
That’s the most common theme I can tell folks to orient around. You can trust the person you’re talking to, but verify that the identity is who you suspect it is.
Jeremy: Because a lot of it has to be, in layman terms, multi-device authentication. Like you have to be a little bit social engineered to be giving them that code as well.
Brett: Correct. The concept of social engineering is violating someone’s trust. And that’s why I say: trust, but verify.
The concept of social engineering is violating someone’s trust. And that’s why I say: trust, but verify.
BRETT GAILEY
CISO & Sr. Director of Security and Compliance, Tia
Where AI Tools Fit for Small Businesses
Jeremy: In terms of the new tools coming out, in terms of AI and all that, there are people who are worrying about stuff they shouldn’t be worrying about, and people who aren’t worrying about the stuff they should be. Do you want to expand on that?
Brett: Yeah, so in the AI space, I think we see a lot of folks that lean in one direction or another, on two sides of a spectrum. I see a lot of folks orient on kind of black and white, which is either use all these AI tools explicitly without question and go for it, or don’t use them at all and stay far away.
In reality, for a small business, you want to look at how your risk profile exists with the types of organizations you’re working with. So you want to make sure the tools you’re using, whether it’s Claude or ChatGPT or Gemini or what have you, comply with your contractual obligations.
And you also want to really look at how you want to position yourself in terms of data privacy and the types of information you’re sharing.
The reason I flag that last one is: if you’re using these free accounts provided by Claude or Gemini or what have you, you’re sharing data with them to train on that data, and that can cause all kinds of downstream problems. We as a society have not solved that copyright problem, we’ve not solved that training problem. It’s a pretty large issue.
So one thing I constantly tell folks to reflect on is: what are your contractual obligations? Are you allowed to use these tools in whatever way you want based on the types of organizations you’re working with, and in what capacity are you using those tools?
Insurance, Vibe Coding, and Permissions
Jeremy: We touched on insurance before. You made it sound cut and dry: make sure you have indemnity insurance that covers what you have, and do the best you can to secure your own system.
Brett: Cybersecurity insurance is pretty straightforward. It allows for a lot of different bad events to happen, because sometimes a sufficiently motivated attacker is just going to compromise data. It’s not something you can specifically avoid, at least not with the general resources most people have.
But allowing those types of contracts you have with your partners, generally you want to carry cybersecurity insurance, that way if there’s an indemnification clause within that contract, you get a lot of protection and you’re not financially obligated to spend money out of your own corporate pocket.
Jeremy: With vibe coding, is that a heaven for hackers? Because once you give something like Zapier certain permissions, does that mean if they get into one thing, they can go crazy?
Brett: It gets a little more complicated than that. Your Zapier workflow has a lot of permissions and you have a lot of OAuth things. If that account is compromised, they do have a lot of access to resources and tools.
I don’t think vibe coding in and of itself is necessarily the problem, or these automation tools are necessarily the problem. But I do think there’s something to say about how permissive we give these tools, or how much permission we give them without really understanding the context of the information we’re sharing.
It’s so easy to do an OAuth exchange, which is like you clicking in and logging in with Gmail as an example. It’s so easy to do that, but it also grants the keys to the kingdom. So I constantly remind folks: it’s really just a risk versus reward scenario for you.
It’s really just a risk versus reward scenario for you.
BRETT GAILEY
CISO & Sr. Director of Security and Compliance, Tia
KEY TAKEAWAY
Use connected tools when their business value justifies the access and permissions they require.
Understanding Your Risk Profile
Jeremy: So what would be your advice, or something we haven’t covered today that smaller businesses, entrepreneurs, startups should know?
Brett: I think it’s really important to understand your risk profile as an organization. Who are the most likely people to attack you? Why are they the most likely people to attack you?
And what are the tools and processes you’ve put into place, big or small, that help prevent those types of attacks from happening?
You know, as simple as: a script kiddie wants to put ransomware on my device so I can pay them a Bitcoin. If you have a process that says, well, the most likely way that’s going to happen is somebody’s going to send me a bad email, so I’m just always going to double check the sender, that is more than enough for most small businesses.
There’s never anything that we can do to prevent all attacks, especially from the more sufficiently motivated attackers, the nation states, the really well-funded orgs, but you can get 99% of the way there.
Jeremy: What would be a higher risk profile versus a lower risk profile? Could you give an example?
Brett: A high-risk profile might be an organization in America, like the example I work at. We’re a women’s healthcare provider, which has some political motivations around that.
That might be treated as slightly higher risk, both for the healthcare ecosystem, which contains PHI (protected health information), and also some ideological perspectives. Whereas an organization that’s maybe manufacturing dolls might have a lower risk profile.
About Tia
Jeremy: If there’s anything else you want people to know about Tia?
Brett: Tia is a women’s healthcare, primary care provider in the United States. We provide care for women all over the United States. It’s something I’m really passionate about.
I’ve been here for the last six years, and I think what we’ve been building is really special and has meaningful value for women across the United States.
One of the most important things we’ve been focused on is trying to figure out how women can get the best care possible, considering that the primary source of research done in the United States and around the world is focused on men, specifically white men.
That is really undervalued when about 60 to 75% of all healthcare in the United States goes towards women and women’s decisions. There’s a massive imbalance there.
What we’re really trying to focus on is how do we give women the holistic care they deserve, because every woman is different.
Jeremy: Well, that’s a very meaningful place to be. Thanks again, man, for jumping on. The way you’ve answered it is very direct, very actionable, very practical. We know exactly what we have to go and do to prevent it.
Brett: Thank you so much, I appreciate you.
Key Takeaways
- The attack vectors haven’t changed in 30 years. Compromised passwords and impersonation (phishing, smishing) are still the two most common ways small businesses get hacked. The fix isn’t sophisticated, it’s diligence.
- AI didn’t create new vulnerabilities, it accelerated old ones. What used to take a senior researcher weeks can now happen much faster once an attacker gets in, so prevention matters more than ever.
- AI tool use comes down to risk versus reward, not black and white. Free accounts with Claude, ChatGPT, or Gemini can share your data for training, so check contractual obligations before using them for client work.
- Know your own risk profile before you build defenses. Who would attack you, and why, tells you exactly where to focus. Most small businesses can get 99% of the way there with basic diligence, not enterprise security budgets.
You can find Brett on LinkedIn, and learn more about Tia on LinkedIn or at asktia.com.
This conversation is from Marketing for SMEs with Jeremy Yang, exploring how Australian SMEs can use AI and digital marketing to grow. Available on your preferred podcast app, and YouTube.

