Speaker 0
0:00 – 0:43
A tech tip from VC3. If your municipality is still relying on traditional antivirus software, it may be time for an upgrade. Today's cyberattacks are designed to slip past basic defenses undetected. That's where endpoint detection and response, or EDR, comes in. EDR continuously monitors your devices for suspicious behavior and can automatically contain threats before they spread. It's not just about blocking known malware. It's about catching attacks in progress. For municipalities, EDR is an essential layer of protection that keeps your data safe, protects you from cyber threats, and detects attacks early so you can stop them faster. This tech tip from VC3.
Speaker 1
0:49 – 2:03
From the North Carolina League of Municipalities, this is Municipal Equation, a podcast about cities and towns. Hello, and thanks for being with us on this episode of Municipal Equation, the podcast of North Carolina League of Municipalities. My name is Ben Brown. And this episode, it's it's a recurring topic, cybersecurity today. But it's recurring because this is a topic that doesn't stop evolving. New threats, new things to be aware of all the time in the cyberspace. Since our last municipal cyber safety episode was at the end of twenty twenty four, it's about time we did a new one to address what's happening what's happening today, but also, how it's different from back when we thought that an antivirus program was all we needed. The mentality is different today, and it should be. To do that, we've got a great expert guest. His name is Suneel Rajan. He's the director of information technology here at the League of Municipalities. I've worked with Suneel for a long time, and I'm happy he can be with us on this episode. No need to wait. Let's just go ahead and jump into the conversation. K. So we are joined now by Sunil Rajan of the North Carolina League of Municipalities. Sunil, thank you so much for joining us. Before we get into the cybersecurity side of this, could you give us a little background on you and the perspective that you bring to this work?
Speaker 2
2:04 – 3:35
Well, thank you, Ben. And, it's a pleasure to be here. I wanted to start off by talking early early about in my career. I was working for an MSP, and MSP is a managed service provider providing IT services to a variety of clients. We had an incident where one of our clients got hit by ransomware. The network was down. Their systems were locked. Everything stopped. When we got there, the thing that stuck me the most wasn't the technical damage. It was how the attack happened. Someone's credentials got compromised and it escalated from there. What struck me most was the chaos. People didn't know who was in charge. Nobody had a clear next step. There was a lot of what do we do now and not a lot of answers. And here's the thing, the client wasn't complacent. They had internal IT resources. They had us. Technology was not the gap. The gap was nobody had ever thought through what happens when technology fails. No clear process, no defined rules, no plan for for when things go sideways. That's a moment when things clicked for me. Cybersecurity isn't just a technology problem. It's a people problem and a process problem. If you only invest in the technology piece, you're only partially protected. And that experience has shaped everything and how I approach this work today.
Speaker 1
3:36 – 3:55
Well, let's talk about the big threats today. When people hear about cybersecurity, you know, it's kinda baked in where people kinda think about viruses or malware. But for municipalities, you know, a lot of the real risks looks a lot more ordinary than that now. Could could you maybe explain what the threats are that you worry about most today?
Speaker 2
3:56 – 5:18
Yeah. It's interesting you use that word. The threat hasn't gotten more dramatic. It's gotten more ordinary, and that's what actually makes it more dangerous. Most of us most of what I worry about looks like a normal Tuesday, or in our case, a Thursday. Right? A phishing email, a fake invoice comes along, a request to update banking details. It seems completely routine. And that attack keeps me up at night because it's not anything sophisticated. It starts with someone in finance processing what looks like a normal payment. And here's the scenario that happens almost constantly. Finance team gets request of what looks like a no a normal request from a vendor, known vendor, to update banking details. The invoice looks right. The tone sounds right. The time and even timing makes sense. They process it. Later, the actual vendor calls asking where their money is. And then at that point, that's when the damage is already done. It didn't require even a single line of malicious code. And for municipalities, that ripple effect is immediate. One bad approval is sudden and suddenly payrolls have impacted. Vendor payments are redirected, and resident services could go down. It stops being a computer problem very fast.
Speaker 1
5:19 – 5:44
And that's scary because if something just looks ordinary, it just blends in with the natural things around you, what you screen every day. I mean, it kinda camouflages into, you know, just your natural flow of doing work. And so a virus can just kinda put itself into that flow. And a lot of this, you know, it comes down to exploiting trust. So fake invoices, compromised email, payment fraud. Who's doing this? Who's who's usually behind these kinds of attacks these days?
Speaker 2
5:45 – 6:37
Yeah. So organized crime, nation states, opportunists, it's really all of the above. It's almost everybody, you know but in particularly for municipalities, day to day, it's usually financially motivated. And here's what here's what people underestimate about local government as a target. Attackers don't have to work very hard. Staff name, job titles, email addresses, meeting schedules, a lot of that information is already public. This makes fishing and impersonation much easy easier to pull off convincingly. They don't have to go hunting for the perfect target. They're just looking for somebody who's visible, reachable, and busy. And municipalities, unfortunately, check every single box.
Speaker 1
6:38 – 6:44
Okay. Okay. So so talking maybe more about the the why with that. Municipalities, they're they're in this tough spot because
Speaker 2
6:45 – 7:44
they're public facing. Yeah. It's a uniquely difficult combination. High responsibility, real constraints. They're handling sensitive data. They're managing funds, delivering service people depend on with very lean teams, tight budgets, aiding systems, and a wide mix of vendors. And unlike a private company that consists simply takes systems offline and quietly figure it out, municipalities can't pause. If permitting goes down, residents feel it that day. If a finance system gets disrupted, payroll and payments get affected. If utilities are hit, now you're in a completely differently different category of a problem. And municipalities are so visible, and and and an incident doesn't stay in IT. It becomes a leadership issue, a public trust issue, and almost immediately, you're not just protecting systems. You're protecting the town's ability to function.
Speaker 1
7:45 – 7:53
Okay. So when a a town or a city does get targeted, what what are the attackers going for? What what are they after? What are they trying to get?
Speaker 2
7:53 – 8:29
Money, access, information, or even leverage, usually some sort of combination. But what people underestimate is the leverage piece. Attackers knew municipalities have to make decisions fast when critical services are affected. That urgency isn't accidental. They're counting on it. Lock up sys the lock up the right systems at the right moment, and suddenly, the town is making financial decisions under pressure without full information and on a clock. That's exactly the environment where mistakes happen the most.
Speaker 1
8:30 – 8:40
And so getting to the the bigger mindset piece, how do you think municipalities need to think about cybersecurity now compared to even just a few years ago?
Speaker 2
8:41 – 9:31
So we need to stop thinking, about it as an IT problem, especially when you deal with the breach. But after a breach, you have to start thinking about operation readiness. The question isn't whether a municipality will face a cyber incident. It's whether it can respond without chaos when it does. And that's a very different question because it means preparation matters just as much as prevention. So So those are two buckets we're talking about. If a town finds out Monday morning email is compromised, people shouldn't be inventing the basics in real time. They should already know who should call, who gets shut what gets shut down first, how decisions are made, and how to communicate, if communicate if email itself can't be trusted. A plan matters, and practicing it matters more.
Speaker 1
9:31 – 9:42
Well, then let's bring that into reality and make this real for the people listening or watching this podcast. What when something actually does happen, what is day one of that attack usually look like?
Speaker 2
9:43 – 10:43
Yeah. So it's usually uncertainty. Right? It that always where it starts. A file won't open. A system is down. A vendor is calling why they never got paid. And then leadership asks starts asking questions before anybody has the full picture. In fact, everybody is asking questions before anyone has the right picture. So that early window is where organization can organizations can either settle into a response or making things significantly worse. Unclear roles, department heads acting on partial information, people reacting without coordination. It compounds fast. So I'll say this, the chaos I described earlier in my career, I still see versions of that today. Organizations organizations that handle incidents well aren't necessarily the ones that with the best technology. They're the ones that have already decided how they're going to respond before something happens.
Speaker 1
10:45 – 11:11
And, you know, technology changes fast. Not everybody is so adept with, technology nowadays. It's hard to even be technically minded sometimes with the the way that, you know, technology kind of turns over. And, that that first stretch for someone who may not be, you know, technically adept might be really difficult, that first stretch. What should what should people be doing in these first hours maybe in, municipal leadership?
Speaker 2
11:12 – 12:29
Yeah. In the first hours, calm is more valuable than fast. Get the right people engaged quickly. Preserve evidence, use trusted communication channels, and resist the incident to fix everything immediately. Don't assume that the I issue is isolated, and don't pressure your team for certainty that they don't have. And lastly, don't make public statements before a response team understands what actually happened. Also, recognize early that this is just really an IT conversation. Depending on what happened, you're gonna need finance, legal, HR, communications, utilities, forensics, and insurance involved as well. So that's a whole group of people that you're gonna have to get involved, for this process. So get comfortable with that reality before you're in it. So have your process identified, do role play. Knowing that process and procedures really helps when you are in that, scenario. In IT, we like to do tabletop exercises, and this is an example of something that should have a tabletop exercise.
Speaker 1
12:30 – 12:44
And you you mentioned earlier that a lot of these attacks start with something that looks routine. This is a question that maybe people are waiting on me to ask about AI. I imagine AI has made all of this even harder. How has AI changed the the conversation?
Speaker 2
12:45 – 13:22
Yeah. So it's lowered the bar for attackers significantly. What used to require real skill, writing a convincing phishing email, impersonating somebody who's credible, producing a fake document, AI can now do in minutes. So this kills the old assumption that you can spot a scam because it looks sloppy. A fake message today can be completely polished, professional, and urgent. So the answer can't be trust your instincts. It has to be trust your process. Verification has to become the default, not the exception,
Speaker 1
13:23 – 13:55
because the visual cues that people used to rely on are now gone. Yeah. So thinking about going to a website and sometimes, you know, maybe back in the day, it looked like a fake website. This is a scam website. This is not the real Microsoft website or whatever it is, you know, PayPal or something like that. Sometimes they look like, you know, kinda put ons, and they're like, okay. That doesn't look legit to me. I'm gonna stay away. But if that's not really the the standard anymore, so to speak, you know, that that scam is easy to spot because, you know, it just looks sloppy. What does a modern scam actually look like now?
Speaker 2
13:56 – 15:08
Yeah. So that's the great question because the scariest part right now is when an attacker gets into an account, they actually do nothing. That's where that's the really scary part. They just watch. They learn how people communicate, the the who approves payments, how invoices move, and which pro projects are active. Then they step into an existing email thread and then send something that feels completely routine. Real account, real conversation, real vendor context. No red flags because it was designed not to have any. It looked normal, is not a defense anymore, and is exactly what a well executed attack looks like. So all of those pieces, about information, capturing it, and then using it against you is what a really good scam modern scam looks like. And then leveraging that with AI as well, you can literally send an email or even create a fake website that pulls the information and scrapes information without having the scammer lift a finger. So those are some common scams today.
Speaker 1
15:08 – 15:23
It's like spy intelligence or something. So so so if the message looks normal and it may even come through a legitimate threat, like, it checks enough boxes to look legit to where you feel, you know, you feel okay with it. What's the practical takeaway for municipalities?
Speaker 2
15:24 – 16:22
Yeah. This is gonna sound harsh, but, process has to win trust over trust every single time. There has to be no exceptions. So if someone's asking to change banking instructions or payment routing, the response should not depend on whether the message looks familiar or the name is recognized. The the same verification steps every single time that has to happen. Then it's process related, and it's not people using their judgment or making a decision on that. And building a culture where people report concerns quickly, that is really important. If someone clicked something suspicious or poo something they're second guessing, you want them to say something early and not hiding it out of embarrassment a week later. A phone call number that's already on file may might feel a little bit cautious, but it can help prevent a 6 figure mistake. Right?
Speaker 1
16:23 – 16:38
And so thinking about government and the operations and the business it does, you know, thinking about vendors, municipalities depend on third parties all the time for all kinds of things. How does a vendor issue turn into a municipal issue, in this context?
Speaker 2
16:39 – 17:59
Yeah. So you can do everything right, but then you can get still get hit through by a vendor. A compromised third party can reach out to you through a trusted email thread, remote access, shared system, software updates, payment flows, all completely normal channels. Sometimes the municipality was never breached directly. The attacker came through a trust. And we see this very con very often where, legal partners are compromised, and they send emails to the municipalities or even to us, and we see those emails, and that starts a chain of events. So it can happen because you're you have a trusted relationship with the third party. So what that means is that you have to periodically audit that trust, who has access, what to connect to, and whether any of that is outdated, or is it broader than that than it needs to be. So third party vendors that have access to systems, you should audit and see what systems they're accessing. Do that do they require that level of access? And so, and then restrict that as well. The vendor risk isn't a procurement issue. It's it becomes a security as well as a financial issue.
Speaker 1
18:01 – 18:17
And so thinking about the basic controls that we hear, you know, multifactor authentication is something that that does come up as a as a tip. Kind of it's becoming kind of a mainstream tip in terms of cybersecurity, but really important. Why does it so why does this matter so much in practice?
Speaker 2
18:18 – 19:11
Because passwords fail constantly. We reuse their phished, their guest, and they're stolen in other breezes because we've reused them. So MFA has a layer that can stop an attacker even if the password is already gone or compromised. Right? But not all MFA equals in practice. If a user gets repeated prompts and starts approving them without thinking, that's still a vulnerability. So it's not just about turning it on. People need to understand how to use it correctly. For email finance systems and especially remote access systems, it's one of the highest value protections available, and it's very straightforward to implement. There's very little reason not to have it in place.
Speaker 1
19:12 – 19:35
So it's kind of like having multiple locks on the door or multiple doors with locks, you know, before you get access to, to the big room. And thinking about access, you know, we think about at least traditionally, we think about cyber attacks and things like that with your desktop computer, your laptop or something like that. But what about your phones? Are are mobile devices, just as much of a target these days?
Speaker 2
19:36 – 20:32
Completely. Phones are where fast mistakes happen. People use them for email, MFA approvals, work apps, password resets. Attackers know that. Right? So a text that looks like it came from a bank or a software vendor, it's very easy to click that button, and, you know, the the phones create that conditions where someone clicks it before they can even think about it. So when you're thinking about protecting accounts, you have to think about every device, people use and axe and access them. So phones are included. In a lot of organizations as well as in our organization, we've restricted what apps are allowed to access our organization, so that we can have controls on that. And in order to access, our network and our infrastructure, you have to use our certain policies as well. So, that is a requirement now to safeguard your phones.
Speaker 1
20:34 – 20:40
And you've mentioned remote access a few times now, both with staff and vendors. Why does that deserve special attention?
Speaker 2
20:41 – 21:24
Yes. Because it's one of the clearest entry points into an environment, especially when it's not managed correctly. Every municipality should be able to answer three questions. Who can still get in remotely? How are they getting in? And is that access still necessary? And that includes employees, vendors, third parties. You should be looking at old accounts that nobody's reviewed, tools set up years ago. All that creates exposure that is easy to miss because it's not actively causing problems yet. We talked about doors, but too many doors open and eventually somebody tries one.
Speaker 1
21:25 – 21:34
That makes sense. And and once somebody gets in, it seems the next question is how much access they actually have. How important is privileged access in all of this?
Speaker 2
21:35 – 22:21
A lot of incidents get significantly worse because compromised accounts had more access than they actually needed. The fix is very straightforward. People should only have access the required access to do their jobs, not more because it's convenient and not more because nobody got around to cleaning it up. When account gets taken over, how bad the damage depends on directly on how much that account can reach. So to put it shortly, if you limit the reach, you also limit the damage. So it's highly recommended to audit all your accounts on a regular basis and see what level that they have and give them the least privilege that they need to do to successfully perform their jobs.
Speaker 1
22:22 – 22:41
So convenience is is not the best trade off for for that sort of thing. So we you know, we we've talked a lot about office systems and email accounts, vendors, but municipalities also have operational environments that they may not get the same visibility. You know, are are there risks that don't always show up in a normal IT review?
Speaker 2
22:43 – 23:43
Yeah. This is one of the most underestimated areas in local government. There's two terms worth knowing, SCADA and PLC. So SCADA stands for super supervisory control and data acquisition. This monitors and controls operations like wastewater, water, and utilities. And then you have PLCs, the programmable logic controllers. They're devices that actually run the equipment, the pumps, the valves, the motors, and alarms. So these systems often sit outside of normal IT visibility. They're older remote access methods. Their vendors connect to them, and equipments nobody's really mapped recently. And the fundamental problem is very simple. You can't secure what you don't know what you have. So municipality can feel confident about its general IT environment, but then still have significant operational technology exposure it fully hasn't fully accounted for.
Speaker 1
23:44 – 23:52
And so this raises the stakes pretty quickly because now you're talking about more than just email or files. Why is that such a serious concern?
Speaker 2
23:54 – 24:24
Because at that point, you're not talking about data anymore. You're talking about operations. A compromised email account is serious. A compromised system involving water treatment, pumping, utility operations, that's a completely different category. Now you're dealing with service delivery, public safety, regulatory exposure, and decisions that go well beyond IT. That's where a cyber incident stops being an IT problem and then starts becoming a public public crisis.
Speaker 1
24:25 – 24:33
And so if those systems are so important and sensitive, why are they often harder to patch or secure the same way other systems are?
Speaker 2
24:34 – 25:49
Yeah. It's not because, you know, they're being ignored or forgotten or complacent. It's it's just the nature of the environment, and this is really unfortunate. Those systems require a lot of uptime, and not cybersecurity is not the focus when they're really when they're designed and built. They're often older and then patching them isn't really simple. They require the vendors to get involved. They require downtime. There's a lot of testing. So there's a lot of coordination that needs to happen before anything can change. If you do it wrong, then you create service disruption, which nobody wants to hear. So they often another area that they have is they often sit across multiple owners. You have their are they are they utilities? Are they facilities? Are they outside integrators? Are they vendor managed? So that creates some confusion as well as who owns it. So the challenge isn't knowing what good security looks like. It's applying it without breaking something essential in the process. That takes coordination, clean ownership, clear ownership, and organizations really haven't fully worked that out yet.
Speaker 1
25:51 – 26:02
You mentioned incident response. So disaster recovery, business continuity, these terms get used together a lot. Could could you break down the difference in a in a practical way?
Speaker 2
26:04 – 26:56
Those are three different problems. They're often confused. So incident response is your immediate playbook, your first actions, who gets notified, how you contain and investigate, and how you communicate while it's happening. Disaster recovery is about getting the systems back, servers, applications, data, and backups. Business continuity and is like the broader question. How does a municipality or organization keep delivering critical services while systems are down? So the shorthand, I would say, is incident response is how you react, disaster recovery helps you restore, and business continuity keeps you operating. All of these matter because the getting the technology back and keeping the town running is not the same problem.
Speaker 1
26:57 – 27:10
Okay. And you you mentioned backups. Good place to talk about that because a lot of organizations feel better just knowing they have backups. What should municipalities really understand about backups?
Speaker 2
27:11 – 28:17
Yeah. So it's really important to understand that having backups and being able to recover are two very different things that need to be understood. A backup only helps if it can be restored in the time frame that the organization can survive. In in today's businesses, some businesses are not able to recover their data in time. And as a result, they go out of business because their day their backups took too long to recover or their backups are out of date, and it's no longer relevant. So that means testing matters so much as the storage. So just not knowing that back just knowing that backups exist and is not enough. You should know how they work, how they're protected, and then the how the right and that the right people understand how to how to recover that data when something actually happens under pressure and not just the theory of it. A lot of organizations feel secure because they have backups, but the real question is whether they can actually use them when it counts.
Speaker 1
28:18 – 28:24
Okay. So so if you had to bring all this down to practical practical next steps, what should municipalities be doing right now?
Speaker 2
28:26 – 29:53
Start with what reduces real risk. So we have MFA on email, finance systems, and remote access. Backup testing, not just backup storage. Review remote access and then clean it up. Clean up what's outdated. Remove or reduce admin rights to what is actually necessary. Train staff on verification, especially around payments, and require, independent confirmation for any banking or routing changes every single time. No exceptions. On the patching side, let's be you be practical. Focus first on interface Internet facing systems, remote access tools, and critical vulnerabilities. And don't leave operational systems out of the conversation. Water, wastewater, and connected control environments need to be a part of it. Most importantly, build the incident response plan before you need it. Know in advance who you should call outside the organization, Insurance, legal, forensic, law enforcement. Have that in your playbook. Organizations that handle incidents well aren't the ones with the most resources. They're the ones with the clearest processes.
Speaker 1
29:55 – 30:09
Now not every city or town in North Carolina is a Raleigh or a Charlotte with maybe in house teams that can do this kind of thing, IT teams, security teams. For smaller municipalities, where do they start with something like this?
Speaker 2
30:09 – 30:39
You so you don't need a perfect program. You need to know where you're exposed and start there. For smaller municipalities, that means MFA, backup testing, secure remote access, payment verification, and a clear answer to one question. If something happened tomorrow, who would we call, and what would we do first? Start there and then build from there. You don't have to fix everything at once. You just have to stop being the easiest target in the room.
Speaker 1
30:40 – 30:49
And what about compliance? Organizations can fall into the trap of thinking they're compliant. They are secure. What do we have to keep in mind with this?
Speaker 2
30:49 – 31:42
Yeah. So great question. Compliance is just the floor. That that's the baseline. It's not the ceiling. So we can't get them confused because that could be very dangerous. Compliance creates structure, baseline expectations, get us ready, audit and audit readiness, and all of that's valuable. But a policy on paper only matters if people can follow it under pressure. So checking a box doesn't mean you're prepared for an actual incident. So for municipalities, the stakes is much higher because accountability isn't just just internal. It affects public trust. So, yes, compliance matters, but the real goal is to reduce risk. And being able to respond to something when it goes wrong is is key, not just passing the audit.
Speaker 1
31:43 – 32:12
So a takeaway for me from all this is, you know, I can't just download an antivirus package and have that be it. It's more about, well, it's it's it's more about behavior, and it's about, you know, maybe knowing what the site even in something that may camouflage very well in plain view. Bringing it back to the league and the kind of work we do here, what do you see the league's role is in this conversation?
Speaker 2
32:14 – 33:01
Yeah. So most towns don't need more theory. Right? They need to see they need help seeing the actual risk clearly and then what to do next. And that's where the league cybersecurity's work has been being being done with the ARPA related initiatives, and that's what it's focused on. It's really helping municipalities identify what gaps matter the most and then taking practical steps forward and then improving their readiness over time. It's not abstract frameworks. It's actually we're actually seeing progress. It's concrete progress that we're helping these municipalities because awareness without action, it doesn't protect anybody. So the this program is actually making steps to help cities and towns in North Carolina.
Speaker 1
33:02 – 33:11
Wrapping up, what is the one thing you wanna leave listeners with? If you could just just kinda wrap it up for us, what's what's the one thing to leave listeners with?
Speaker 2
33:13 – 34:08
So cybersecurity is not about stopping bad actors. It's a product of it's about protecting the account's ability to function. Payroll going out, utilities running, vendors paid correctly, and residents served, which also helps public trust which also keeps public trust intact. So if you want a a place to start, pick three things this quarter. Confirm MFAs on all your critical systems, review who has access to remote or elevated access, and make sure your incident response contacts and escalation packs and escalation paths are actually current and not from years ago or never updated. Just make sure they're updated. If you're prepared, if if you're prepared, a bad day stays as a bad day. But if you're not, the same day becomes a public crisis.
Speaker 1
34:09 – 35:06
So, I mean, there's been a wealth of information shared here. And, you know, I guess the good thing about this podcast is this is not just like a a live meeting. This is something maybe you could listen to or pass around to people. There's a lot of good stuff here. And we also have a lot of resources, that are available to our member cities and towns. So, you know, just just really wanna thank you for coming on and and sharing this with us and having the main takeaway be that it's it's you know, these things keep changing. These things keep evolving. And if I'm a cybercriminal, maybe the first thing on my mind is staying ahead of what people are, you know, know to be prepared for. But, but but there there are plenty of rules of thumb, and there's lots of resources that people can, can can adhere to to stay safe. And if something does happen, there's also a a plan and a procedure. And these are good things to, you know, kinda know in advance so you're not just scrambling the day of when it actually happens. So I I this is just a great thing to keep in mind, Sunil. So we really wanna thank you for,
Speaker 2
35:07 – 35:11
for joining us here on this episode. Well, thank you, Ben, for having me.
Speaker 1
35:14 – 36:07
Thanks for being with us. And thanks to Sunil Rajan from the North Carolina League of Municipalities for his expertise and insights on these threats we face online and how it's changed over time. We know it's gonna continue evolving. These threats that we face in the cyber world, which is why we'll continue to bring these episodes, with all the timely expertise on it, reach out to us. Is there something we didn't address here? Maybe something that you'd like to know more about? Is there a follow-up question based on something we did talk about on this episode? Please let us know. You can find my contact info on the people directory at n c l m dot o r g. Just hover your cursor over the about us tab at the top of the website, and you'll see people directory. Just click that. Enter my name in the field. My name is Ben Brown. Send me also any episode topics that you would like us to tackle here on the podcast or anything else. I'd love to hear from you. Thank you again for being with us today, and we will see you on the next one.