In this episode of Cyber Security Inside, panelists from the 2022 RSA Conference share their thoughts about collaboration against some of the biggest cybersecurity threats. Camille Morhardt talks with Tom Garrison (VP & GM Client Security Strategy & Initiatives at Intel Corporation), Abhilasha Bhargav-Spantzel (Partner Security Architect, Microsoft Corporation), Aanchal Gupta (VP Microsoft Security Response Center, Microsoft), and Dr. Diane Janosek (Director, Commandant , National Cryptologic School, NSA).

The conversation covers:

  • Why our panelists think collaboration across the private and public sectors is the only way forward in cybersecurity.

  • What the panelists think about threats to the supply chain.

  • Why it’s true that as we develop more complex technology, protecting gets more difficult.

  • What our panelists think are the most urgent things to be thinking about in the world of cybersecurity.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • This podcast is a round robin of panelists from the 2022 RSA Cybersecurity Conference, talking with three panelists from the panel called “All Hands on Deck: A Whole-of-Society Approach for Cybersecurity.”

  • One of the threats on the top of the panelists’ minds is supply chain security risks. A lot of reliance on third-party software is what is causing some of these risks, as is how pervasive some of these softwares are throughout the community, making a large range of software potentially vulnerable.

  • The only way to really tackle this is as a full cybersecurity community. There need to be partnerships between different industries working to keep our technology safe.

  • An example of these partnerships is seen in the Ukraine war. Russia is conducting a hybrid attack, and Microsoft partnered with Ukraine cybersecurity agencies to map out the threats.

  • The NOBELIUM attacks were an example of people sharing intel and insights through blogs and other means. The whole industry could come together and learn from it to see if they were getting attacked in the network.

  • As our technologies get more complex, the difficulty in repairing, managing, and protecting them gets more difficult. A car from the 80s was much easier to fix than one of today’s cars. This is especially true with remote work.

  • Interfacing with third parties to determine if a device is safe or if technology is working and secure isn’t enough anymore. The companies themselves need to be able to answer that question with confidence internally. For example, you need to be able to talk directly with Intel about the security of their products and know that they can answer that question.

  • Transparency is key to this collaboration and teamwork. Knowing what is inside your device empowers customers to make good decisions around their devices, the state of those devices, and if it is trustworthy. It puts some ownership and knowledge in the hands of the user.

  • What can product divisions be doing? First is investing in your own product division to focus on security research. Then it is about taking those learnings and improving your future products with that information. Constantly investing, learning, and improving.

  • The two potential goals of attackers are to either make money off of someone or to cause a disruption. They are using AI to do this. The models we use to detect and respond to attacks rely on the integrity of our data. So what happens when that data is altered by adversaries?

  • The NSA works to protect the US from cyber attacks. They are protecting the digital network and are watching threat factors. The guests discussed transparency between the NSA and the other sectors in the government to make sure that Americans are protected. They stressed the need to share information and partner together.

  • Who is responsible for cybersecurity? Everyone. The private sector, the government, you the user. Everyone. Because cyber is personal to all of us and affects all of us, we need to make sure that we are securing it as a community.

Some interesting quotes from today’s episode:

“Our dependence on this third-party software [for supply chain security] is growing and it is becoming very attractive for our threat actors to find the soft spots. They could easily convince an insider to get onto and modify some code in the supply chain, or they can inject this malicious payload into the supply chain.” - Aanchal Gupta

“The usage of this certain software is literally like salt in our pantry. And when I say salt in our pantry, when you look at different food items, and you start to look at the ingredient list, you will most likely find salt in there. And if someone were to tell you, ‘hey, salt is contaminated and you need to do something about it for the food items in your pantry,’ it would be immensely difficult… That’s what made Log4j such a big challenge for the entire community.” - Aanchal Gupta

“I think we have to continue to evolve this partnership globally, because that is the only way we can defend against these threats. Let’s also not penalize the people for sharing a breach of their system. We need to shift the culture from blame to community support. When we support organizations to be forthcoming about their experience, they get better insights. We are able to help identify the supply chain risks sooner.” - Aanchal Gupta

“The technology is so, so, so much more complicated. And the same is true for our platforms, whether it be a client platform, a server platform, and the like. Couple that with the fact that we have devices now being used in ways that have never been envisioned before. Workers that are outside the four walls of the company are subject to a whole different kind of attacks.” - Tom Garrison

“That first step is around transparency. So what we want to do is to peel back this sort of almost secrecy that’s existed around what components are used to build your device - whether it’s a PC or a server or an IOT device. And we think that with that transparency comes a level now of intelligence you can have.” - Tom Garrison

“Our adversaries have two intentions in mind. That is to make as much money as they can off of you, or cause as much disruption as they can. Or two of them together. And they’re using adversarial AI where they’ll come together and understand where the sweet spots are to affect us and to cause the most amount of damage or harm or financial damage. So from an adversarial AI perspective, how do we respond to that?” - Dr. Diane Janosek

“What do you have to do to kind of raise the bar? It’s giving the tools and the information, sharing what we know about vulnerabilities, sharing what we know about threat factors, sharing what we know about adversarial attacks and with the emerging threats that are coming down the pike. If we can share that with the other 80% in the healthcare sector, the financial sector, the energy sector, all 16 sectors… If we can share what we know, Americans as a whole can go to sleep knowing that their country is better protected.” - Dr. Diane Janosek

“It takes everybody. It takes people, patching their systems, doing the updates on their iPhone, making sure they have a password on their home network. You want to make sure that the government’s doing the right thing, that they’re really locking up the supply chain and that they’re really securing water supply plants. The planes are safe. The hospitals are safe. At the end of the day, cyber is personal… cyber affects all of us.” - Dr. Diane Janosek