Cyber Security Inside: Recent Episodes

Tom Garrison and Camille Morhardt

Cyber Security is no longer a topic that is addressed only by programmers and coders. CISOs and their executive peers need to think about “cyber security” differently. In this podcast, Tom Garrison, Vice President and GM of Client Security Strategy and Initiatives, and co-host Camille Morhardt, Director of Security Initiatives & Communications, will discuss relevant topics in clear, easy to understand language.

This podcast is intended for security experts and businesspeople alike. We will have industry leaders join in the conversation about today’s most important and timely security topics. Our goal is after listening, you walk away smarter about Cyber Security, and of course have fun along the way!

View Details

In this latest episode of InTechnology, Intel’s Rajan Panchanathan sits down with Doug Fisher, Chief Security and AI Officer at Lenovo, to explore how AI and cybersecurity converge to build digital trust. From ethical AI governance to resilient global supply chains, Doug shares Lenovo’s approach to secure innovation. He also discusses how ThinkShield Build Assure, a new solution offers a new level of security by ensuring device integrity from factory to deployment. Learn how this and other technologies from Lenovo and Intel can help your organization balance rapid AI advancement with a culture of responsibility, transparency, and data privacy—all while staying ahead of evolving threats.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this latest episode of InTechnology, Intel’s Rajan Panchanathan sits down with Nima Baiati, Executive Director and General Manager of Cybersecurity Solutions at Lenovo, to delve into the increasing risks of cybersecurity threats, and the complexities surrounding supply chain security in today's interconnected world. Nima describes Lenovo's proactive "secure by design" philosophy and how ThinkShield Build Assure, powered by Intel® Tiber™ Transparent Supply Chain, enhances component traceability and validation, both key to securing supply chains. The conversation highlights how this new level of transparency is a game-changer that will bring organizations unprecedented insight into their hardware supply chain.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into AI and automation in digital marketing with co-host John Gildea, Investment Director at Intel Capital, and guest Vivek Sharma, Co-Founder and CEO at Movable Ink. They talk about how AI has changed digital marketing over the decades, the mechanics of AI marketing, the industries and customers Movable Ink is working with, the possibilities beyond email marketing with AI and automation, Movable’s platforms Studio and Da Vinci, how their AI models build intelligence, the influence of AI on real-time offers and supply chain responses, customer concerns about AI in digital marketing, and more.

Learn more about Intel Capital: https://www.intelcapital.com/

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode, Camille Morhardt discusses cloud security, data sovereignty, and artificial intelligence with Jonas De Troy, Head of Public Cloud & Edge at Proximus and Gwenaelle Herve, Public & Sovereign Cloud Lead at Proximus NXT.They explore the interrelation of these themes, the challenges enterprises face in compliance with regulations, and the evolving landscape of cloud technology. The conversation highlights the importance of data qualification and the role of AI in enhancing security measures.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this InTechnology episode, Camille Morhardt discusses the application of artificial intelligence (AI) in the biopharmaceutical and life sciences sectors with Prashant Shah, Intel's CTO for federated artificial intelligence products, and Abhishek Pandey, a global lead and principal research scientist at AbbVie. The conversation centers on the potential of AI, particularly federated learning, to revolutionize drug discovery and development. They explore the challenges of data privacy and IP protection in this context, emphasizing the importance of collaboration and the role of initiatives like OpenFL and MLCommons in setting standards for AI in the industry.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into data security with co-host Sunil Kurkure, Managing Director at Intel Capital, and Anand Kashyap, Co-Founder and CEO of Fortanix. They talk about what inspired Anand to found Fortanix, the benefits of confidential computing, why Intel Capital is interested in Fortanix, AI security and attacks, how companies can stay prepared and manage their data security, AI at the edge, data sovereignty, the future of security with quantum compute and platformization, and more.

Learn more about Intel Capital: https://www.intelcapital.com/

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into AI game development with co-host Srini Ananth, Managing Director at Intel Capital, and guest Florin Radu, VP of Operations and Corporate Development at Inworld AI. They talk about how Inworld trains its NPCs and other AI gamedev solutions, examples of game studios using their tools, the impact of gaming on human socialization, Intel Capital’s investment in Inworld, the benefits of AI at the edge for gaming, improved game development cycles, and more.

Learn more about Intel Capital: https://www.intelcapital.com/

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into silicon photonics in personalized medicine with co-host Srini Ananth, Managing Director at Intel Capital, and guest Michael Dubrovsky, CPO and Co-Founder at SiPhox Health. They talk about the technological breakthroughs and benefits of silicon photonics, use cases for telecom and health diagnostics, Intel Capital’s interest in SiPhox, SiPhox’s unique approach to personalized diagnostics, protecting personal health data, applications of AI in medicine, and more.

Learn more about Intel Capital: https://www.intelcapital.com/

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into autonomous transportation with co-host Mark Rostick, Vice President and Senior Managing Director at Intel Capital, and guests from Beep—Joe Moye, CEO, and Kevin Reid, Chairman of the Board. They talk about Beep’s mission and why Intel Capital believes in it, the regulatory environment around autonomous transportation, how Beep differs from other autonomous vehicle companies, where Beep is currently operating, the importance of community engagement, the societal impacts of autonomous microtransit, their many safety measures, how Beep implements cybersecurity and AI, and more.

Learn more about Intel Capital: https://www.intelcapital.com/

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this InTechnology episode, Camille Morhardt explores the intricacies of water usage and conservation in semiconductor manufacturing with Vanessa Lanas Delbridge, Senior Environmental Engineer at Intel. Their conversation delves into Intel's ambitious goal of achieving net positive water status by 2030, a milestone already reached in four countries. They also discuss innovative strategies Intel employs to conserve water, such as collaborating with tool suppliers and implementing water reclamation facilities. Additionally, Vanessa shares how Intel uses digital twins for monitoring water usage and pinpointing areas for improvement.

Learn more:

Intel Water Restoration Progress Report: https://www.intel.com/content/www/us/en/environment/restore-water-goal-report.html

Intel’s Corporate Social Responsibility Report: https://www.intel.com/content/www/us/en/corporate-responsibility/corporate-responsibility.html

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into SambaNova’s full-stack AI solutions with co-host Stephanie Cope, Portfolio Development Manager at Intel Capital, and guest Rodrigo Liang, Co-Founder and CEO at SambaNova Systems. They talk about how SambaNova was founded, Intel Capital’s reasons for investment, the revolutionary LLM Samba-1, how SambaNova helps enterprises cost-effectively adopt and scale gen AI, the benefits of using an open source-based solution while still protecting private data, the power of language in LLMs, Stephanie’s approach to investing, and more.

Try out Samba-1: https://fast.snova.ai/

Learn more about Intel Capital: https://www.intelcapital.com/

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into the latest in AI policy with co-host Taylor Roberts, Director of Global Security Policy at Intel, and guests Jason Lazarski, Head of Sales at Opaque Systems, and Jonathan Ring, Deputy Assistant National Cyber Director for Technology Security at The White House Office of the National Cyber Director. They talk about the focuses and challenges of the recent AI Executive Order, similar AI policies like the AI EU Act and the EU Cyber Resilience Act, how to set industries up for success with AI policy, how countries are working together to develop AI policy, the role of confidential computing and trusted execution environments in securing encrypted data and AI models, how enterprises are adapting to new AI policy, the social challenges of AI adoption, and more.

Check out our previous episodes on AI policy:

Deep Dive: US Executive Order on Artificial Intelligence (Episode 181): https://cybersecurityinside.libsyn.com/181-deep-dive-us-executive-order-on-artificial-intelligence

Emerging U.S. Policies, Legislation, and Executive Orders on AI (Episode 178): https://cybersecurityinside.libsyn.com/178-emerging-us-policies-legislation-and-executive-orders-on-ai

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into generative AI with Lareina Yee, Senior Partner at McKinsey & Company. They talk about why gen AI has exploded in awareness and use, how it can be a great tool for knowledge workers, why humans are still needed, how gen AI is different from other forms of AI, different methods enterprises are taking when adopting generative AI, the importance of strategy and risk assessment, Lareina’s insights on the future of gen AI, and more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into Fly.io’s developer-focused public cloud with co-host Nick Washburn, Senior Managing Director at Intel Capital, and guest Kurt Mackey, Co-Founder and CEO of Fly.io. They talk about how Fly.io orients their cloud toward developers, the trade-offs of using their cloud, how they keep up with scaling needs, what the next big public cloud might look like, how Fly.io handles integrations, how increasing demands from machine learning and AI are shaping data center offerings, prioritizing security while still supplying a good user experience, why Intel Capital invested in Fly.io, and more.

Learn more about Intel Capital: https://www.intelcapital.com/

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into electrochemical additive manufacturing with episode co-host Jennifer Ard, Managing Director and Head of Investment Operations at Intel Capital, and guest Ian Winfield, Vice President of Product & Applications at Fabric8Labs. They talk about Fabric8Labs’ unique liquid-based approach to additive manufacturing, the scalability of their printers, the variety of industry applications for this technology, how AI and machine learning are driving the need for custom liquid cooling solutions, the sustainability benefits of their ECAM process, why Intel Capital chose to invest in Fabric8Labs, the company’s future goals, and more.

Learn more about Intel Capital: https://www.intelcapital.com/

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology recorded at RSA Conference 2024, Camille gets into quantum computing and post-quantum cryptography with Dr. Richard Searle, Chief AI Officer at Fortanix; Chris Hickman, Chief Security Officer at Keyfactor; and Andrew Driscoll, Quantum Security Engineer at Accenture. They talk about how quantum computing and post-quantum cryptography will work, the current threat of “steal now, decrypt later,” the countdown to Q-Day, how organizations can begin planning and migration for a post-quantum world, uses cases for quantum computing, cybersecurity concerns with post-quantum cryptography, evolving computing and cryptography standards, and much more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into parallel computing with Pradeep Dubey, Intel Senior Fellow at Intel Labs. They talk about how parallel computing works, why it’s becoming more necessary, how it uses AI and machine learning to process large amounts of data, the challenges of designing systems and architecture for parallel computing, how machines can help humans make better decisions, and much more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into generative AI (GenAI) and large language models (LLMs) with Aurora Quinn-Elmore, Founder and CEO of Metamorph AI. They talk about how LLMs models like ChatGPT and Google Gemini are trained, how to customize models for specific use cases, retrieval-augmented generation (RAG), the pros and cons of open-source versus non-open-source models for small to medium-sized businesses, the challenges of switching between models, improving AI literacy, researching GenAI data protection policies, and agentic AI.

Follow Aurora on LinkedIn: https://www.linkedin.com/in/auroraquinnelmore/

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into hardware attacks with Maggie Jauregui, a hardware security researcher at Intel. They talk about Maggie’s “secret superpower” of joy rooted in her Latin American upbringing, her first hardware hacking experiment with a hairdryer, the physics of hardware hacking, iSTARE’s proactive research, the possibility of remote hardware attacks, and Maggie’s positive outlook on hardware security.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into humanity and space exploration with Shehnaz Soni, Senior System Engineer at NASA and author of The Quantum Being. They talk about Shehnaz’s work on the Artemis program, why humanity is drawn to exploring beyond Earth, how she became interested in aerospace and aviation, bridging scientific and spiritual mindsets, how humanity will evolve alongside the next steps in space exploration, and more.

Read The Quantum Being: https://geni.us/QuantumBeing

Shehnaz Soni’s website: https://www.shehnazsoni.com/

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into endpoint vulnerability management beneath the OS with Intel® Device Heath with guest Novin Kaihani, Senior Director and GM of Client Software Products at Intel. They talk about why there’s a current lack of security for operating systems and below in the market today, how Intel’s partnership with Eclypisum is working to bridge that market gap, how the endpoint vulnerability management solution identifies vulnerabilities below the OS at the OS level, and the seamless integration of the system into Intel PCs.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille delves into side channels alongside episode co-host Anders Fogh; Fellow & Security Researcher at Intel, and guest Daniel Gruss; Associate Professor at Graz University of Technology. They talk about the exploitation of side channels, why side channels are not going away, common challenges and how to manage them, what evolving landscapes such as AI systems and space-based infrastructure mean for side channels, and more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into artificial general intelligence (AGI) and cognitive architecture with Peter Voss, CEO and Chief Scientist at Aigo.ai. They talk about how he helped coin the term artificial general intelligence, the definitions of AGI and intelligence, how current LLMs like ChatGPT are not really AGI, training and sensory input for AGI, metacognition, Aigo.ai’s “chatbot with a brain,” and how AGI might shape the future of humanity.

Read Peter Voss’ book, Artificial General Intelligence, here: https://link.springer.com/book/10.1007/978-3-540-68677-4

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into protecting product and data with episode co-host Mohsen Fazlian, Corporate Vice President and General Manager of Product Assurance and Security at Intel, and guest Doug Fisher, Senior Vice President and Chief Security Officer at Lenovo. They talk about taking a security-first philosophy to protect product across company divisions, the importance of security training employees at all levels of an organization, the benefits of red teaming and hackathon events, concerns and positive uses of AI in securing product and data, advancements in security practices including transparent supply chain and confidential computing, and much more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into emerging technologies and telecommunications with Mischa Dohler, VP of Emerging Technologies at Ericsson. They talk about his research with 5G for the arts and healthcare, use cases for AI in telecommunications, how Mischa keeps up with so many emerging technologies, neuromorphic computing, quantum computing, and more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into ethical hacking and security with Stephanie Domas, CISO at Canonical. They talk about Stephanie’s recent book on reverse engineering x86 software, the purpose and benefits of ethical hacking, how companies can change their security strategies from reactive to proactive, how to manage a team of ethical hackers, new technologies like AI and confidential computing from a security perspective, industry adoption of open source, and more.

Read Stephanie’s book, x86 Software Reverse-Engineering, Cracking, and Counter-Measures: https://www.amazon.com/x86-Software-Reverse-Engineering-Cracking-Counter-Measures/dp/1394199880/

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into Apple Vision Pro with Tony Mongkolsmai, Software Architect & Technical Evangelist at Intel and host of the Code Together podcast. They talk about Tony’s experience trying out the Apple Vision Pro in his everyday life, along with his take on its benefits and limitations.

Check out the Code Together podcast: https://codetogether.podbean.com/

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into finding sustainability solutions through AI with Peter Schelstraete, Co-Founder of Ubuntoo. They talk about Peter’s personal passion for sustainability inspiring him to found Ubuntoo, how Ubuntoo works as an environmental solutions platform, how Ubuntoo AI utilizes large language models, overcoming obstacles to integrating sustainability practices, the importance of looking across a company and around the world for inspiration on best practices, and how to make practical knowledge on sustainability more accessible.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into what CISOs should be focusing on this year with Jonathan Nguyen-Duy, Field CISO at Intel. They talk about the security insights from Verizon’s annual breach report, why cybersecurity is still struggling as an industry despite more spending and more jobs than ever before, new regulations on reporting cyberattacks, the ever-increasing importance of zero trust, improving user experiences while increasing data privacy, protecting critical national infrastructure, converging vendors to platforms and automating around that, the role of AI and generative AI in security, and more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into lessons in tech leadership with Board Member, former Intel CVP, and podcaster Rose Schooler. They talk about her “teach and learn” approach to leadership, consistency and clarity of communication, knowing your audience when presenting, leading with head and heart, how she grew an initiative into a billion-dollar business at Intel, the influence of her parents on her career, finding the courage to stand up for others, and more.

Check out The Maestro Mindset Podcast:

Apple Podcasts: https://podcasts.apple.com/us/podcast/the-maestro-mindset-formerly-lead-up-managing-and/id1680211940

Spotify: https://open.spotify.com/show/5w0pgBFL534ij6J8AdU3EE?si=c11561478c86457f

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into 5G cybersecurity and AI-powered RAN with Scott Poretsky, Director of Security for Ericsson. They talk about how radio access networks operate, what O-RAN is, the paradigm shifts with AI and machine learning, zero-trust architecture, the Ericsson Intelligent Automation Platform, cybersecurity evolutions from 4G to 6G, and much more.

Learn more about the Ericsson Intelligent Automation Platform (EIAP) Ecosystem here: https://www.ericsson.com/en/ran/intelligent-ran-automation/intelligent-automation-platform/ecosystem

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into zero trust and AI for 5G with Ken Urquhart, Global Vice President of 5G Strategy at Zscaler. They talk about the transition from 4G to 5G, the security and sustainability benefits of 5G networks, how and why companies can set up their own private 5G networks, uses of AI with 5G networks, the coming jump to 6G, and the role of zero trust in security for 5G networks and beyond, and much more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille takes a behind-the-scenes look at AI adoption with Navin Budhiraja, CTO of Vianai Systems. They talk about the lack of AI skill sets, the democratization of AI through open source, dangers of AI like deep fakes and bots, changes to the role of developers, how companies are deploying AI, data collection, and more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into open source with guest Jim Zemlin, Executive Director of The Linux Foundation, and co-host Melissa Evers, Vice President of the Software and Advanced Technology Group at Intel. They talk about the use of generative AI and LLMs with open-source software, the AI Alliance, the Open Source Security Foundation, the ever-changing threat landscape, AI tools for open-source security, security standards, and much more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into cybersecurity for AI and software optimization with Thomas Dullien, aka Halvar Flake. They talk about his work with Optimyze, cybersecurity and software optimization uses for large language models, the outlook for artificial general intelligence and other technology jumps, the data required to build large AI models, his research with Rowhammer, and more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille looks back on some of the most exciting conversations on AI in 2023. Things kick off with Andres Rodriguez, Intel Fellow, and his conversation on deep learning, a subset of machine learning. Then, Selvakumar Panneer and Omesh Tickoo, Principal Engineers at Intel Labs, discuss synthetic data. This is followed up by touching on large language models or LLMs with Sanjay Rajagopalan, Chief Design and Strategy Officer at Vianai Systems. Finally, the episode wraps up with independent AI policy and governance advisor Chloe Audio giving her insight on emerging AI regulations.

Listen to the full episodes:

What That Means with Camille: Deep Learning (142): https://cybersecurityinside.libsyn.com/142-what-that-means-with-camille-deep-learning

What That Means with Camille: Synthetic Data (139): https://cybersecurityinside.libsyn.com/139-what-that-means-with-camille-synthetic-data

Why and How Enterprises Are Adopting LLMs (174): https://cybersecurityinside.libsyn.com/174-why-and-how-enterprises-are-adopting-llms

Emerging U.S. Policies, Legislation, and Executive Orders on AI (178): https://cybersecurityinside.libsyn.com/178-emerging-us-policies-legislation-and-executive-orders-on-ai

Deep Dive: U.S. Executive Order on Artificial Intelligence (181): https://cybersecurityinside.libsyn.com/181-deep-dive-us-executive-order-on-artificial-intelligence

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into product security governance with Vernetta Dorsey Windsong, Director of Product Security Governance at Intel. They talk about how product security and governance practices work together, how to get started with product security governance, the challenges of implementing new practices, automation within a secure development lifecycle, the effects of AI on processes, preventing governance creep, and more.

Learn more about the secure development lifecycle in Vernetta and Camille’s previous conversation: https://cybersecurityinside.libsyn.com/49-what-than-means-with-camille-secure-development-lifecycle-sdl

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into runtime optimization with Asaf Ezra, CEO at Granulate. They talk about how exactly runtime optimization works, how projects like Photon and Gluten are changing the industry, Granulate’s runtime optimization solutions, future trends in hardware customization, how programming is changing with the dawn of generative AI, and more.

Read more about Intel Gaudi2’s performance as evaluated by NVIDIA and referenced by Asaf in the episode here: https://www.servethehome.com/nvidia-shows-intel-gaudi2-is-4x-better-performance-per-dollar-than-its-h100/

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille takes a look at our most popular episodes on cybersecurity in 2023. First up are conversation highlights on Root of Trust and firmware attacks with Jorge Myszne, Co-Founder of Kameleon. After that are highlights on confidential computing with Mark Russinovich, Technical Fellow and CTO of Microsoft Azure, and Anil Rao, a VP and GM at Intel. Finally are highlights on AI deep fakes with Ilke Demir, Senior Staff Research Scientist at Intel Labs and a creator of FakeCatcher.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille delves into a roundup of our most popular listener topics on sustainability in 2023. The first topic is green software with Asim Hussain, Director of Green Software and Ecosystems at Intel. The second covers electricity mapping featuring Olivier Corradi, Founder and CEO of Electricity Maps. Finally, on this roundup is energy efficiency in the cloud with Lily Looi, Intel Fellow as well as Chief Power Architect of Intel's Xeon product line.

Listen to the full episode (EP 137) - WTM: Green Software with Asim Hussain.

Listen to the full episode (EP 147) with Olivier Corradi – How Green Is Your Electricity?

Listen to the full episode (EP 148) - WTM: Energy Efficiency In The Cloud with Lily Looi.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille delves into the recent US Executive Order on artificial intelligence with Divyansh Kaushik, Miranda Bogen, and Chloe Autio. Divyansh Kaushik is an Associate Director for Emerging Technologies and National Security at the Federation of American Scientists. Miranda Bogen is the Director of the AI Governance Lab at the Center for Democracy and Technology. Chloe Autio is an independent AI policy and governance consultant. They talk about controversies of the Executive Order and its implications on key areas such as AI innovation, the private sector, data privacy, foreign governments & companies, and more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into data security and digital identity with Ashvin Kamaraju, Global Vice President of Engineering and Cloud Operations at Thales Cloud Protection & Licensing. They talk about the latest trends in data privacy and sovereignty, the primary components of data security, key management, how to protect against evolving cyber threats, the shifting needs of encryption with edge computing, the potential benefits and drawbacks of digital identities, and more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into cloud sovereignty with guest Mauro Capo, Managing Director and Cloud First/Sovereign Cloud Lead at Accenture, and co-host Paul O’Neill, Director of Strategic Business Development in Intel’s Confidential Computing Group. They talk about the political influences and benefits of data sovereignty, the definition of sovereign cloud, what adoption and implementation of cloud sovereignty looks like, data sovereignty solutions like confidential computing, and more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into emerging AI policy with Chloe Autio, independent AI policy and governance advisor. They talk about the current state of policies and legislation on artificial intelligence both in the U.S. and abroad, where policy discussions on AI are missing the mark, current hot topics in AI like data insights and open source, how tech companies are working with the government to create AI regulations, how business can evaluate their use of AI, and more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into AI literacy with Tara Chklovski, Founder and CEO of Technovation. They talk about the history of Technovation, how the program works, why it focuses on underprivileged girls, the real-world problems the girls are solving with their projects, how to bring AI and AI ethics into education, how large language models are changing tech education, and more.

To apply to be a participant or volunteer with Technovation, visit https://www.technovationchallenge.org/ .

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into confidential computing and securing Kubernetes containers with Felix Schuster, Co-Founder and CEO of Edgeless Systems. They talk about encrypted runtime, protecting workloads in the cloud, the benefits of open-source confidential computing, traceability and transparency of software, how Edgeless Systems is providing confidential computing to smaller cloud providers, and more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into encryption and encrypted computing with Ro Cammarota, Principal Engineer and Chief Scientist of Privacy-Enhanced Computing Research in the Emerging Security Lab at Intel Labs. They talk about Intel’s Encrypted Computing Software Development Kit, definitions of encrypted computing and homomorphic encryption, practical applications and standardization of homomorphic encryption, the potential security effects of quantum computing, hardware acceleration, and much more.

Learn more from Ro about Intel Labs’ work with the DARPA DPRIVE program to make fully homomorphic encryption viable here: https://community.intel.com/t5/Blogs/Tech-Innovation/Data-Center/Intel-Labs-Continues-Focused-Research-and-Standards-Efforts-to/post/1488532

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into large language models with Sanjay Rajagopalan, Chief Design and Strategy Officer at Vianai Systems. They talk about how LLMs work, what they’re best suited for, how and why they can be incorrect, alignment, enterprise applications, and pre- and post-processing review of inputs and outputs on language models.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille chats with leading tech industry guests at Intel Innovation 2023. They talk about what brings each guest to Intel Innovation, what their organizations are doing to innovate in their fields, and which trends they think people should be on alert for in the realm of cybersecurity, AI, and machine learning.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into Intel® Trust Authority with Nikhil Deshpande, its General Manager, and Raghu Yeluri, its Chief Architect. They talk about the uses of Intel® Trust Authority in confidential computing and attestation, how it’s currently being implemented, and what’s on the horizon for it.

View Details

In this episode of InTechnology, Camille gets into confidential computing and Intel® Trust Authority with Mark Russinovich, Technical Fellow and CTO of Microsoft Azure, and Anil Rao, VP and GM of Systems Architecture and Engineering in the Office of the CTO at Intel. They talk about the definitions of confidential computing and confidential AI, how Microsoft Azure is using Intel® Trust Authority, data sovereignty, and code transparency. They also discuss the democratization of AI and future concerns about AI as it continues to grow.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into the future of client computing with Rob Bruckner, Corporate VP and CTO of Client Platform Architecture and Definition (CPAD) at Intel. They talk about the current evolutions going on with client computing like AI and security, as well as what’s next for sustainability and the PC.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into AI distributed computing with Chris Kelly, Vice President of the Client Computing Group and General Manager of Platform Software Definition and Strategy at Intel. They talk about the evolution of AI into distributed computing models, Moore’s Law, developments in chip production and transistor size reduction, the future of client computing, and the rising AI PC era.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into edge computing and its influence on humanity with Joannie Fu, Vice President of the Network & Edge Group (NEX) Execution Office at Intel. They talk about the definition of the edge, how computing at the edge and AI are rapidly evolving, concerns about data privacy on devices at the edge, and how future generations will need to adapt their skill sets as technology changes.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this slightly different-from-usual episode of InTechnology, Camille gets into addiction recovery and how companies can better support employees with Kelsey Moreira, Founder and Chief Inspiration Officer of Doughp. They talk about Kelsey’s journey to sobriety through her time at Intel to today, her successful cookie dough business Doughp: Legit Cookie Dough, and how Doughp supports addiction recovery and mental health through their #Doughp4Hope initiative.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into the future of data centers with Matt Adiletta, Senior Fellow at Intel. They talk about the growing scale of data centers, how they’re being affected by large AI models, power efficiency, cooling, software infrastructure, and more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into Intel’s Transparent Supply Chain with Patrick Bohart, Director of Marketing at Intel. They talk about how Transparent Supply Chain is used to track product security from manufacturing through transit and delivery, its sustainability applications, and how blockchain is improving its security. They also get into the requirements and expectations of transparency, as well as the future of dynamic tracking with active component root of trust.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into the future of video meetings with Neil Fluester, Global Director of Technology Alliances at Crestron Electronics and host of CresTV. They talk about how AI is making video meetings more realistic, privacy concerns, vertical applications of video meetings, and more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into the future of virtual reality (VR) and augmented reality (AR) with Slava Podmurnyi, CEO of Visartech. They talk about the difference between VR and AR, the evolution of VR and AR devices, uses for these new technologies, their use of artificial intelligence, data collection and privacy, and predictions for the future with virtual and augmented reality.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into carbon footprinting with Elsa Olivetti, MIT professor and Edgerton Chair of the Material Science and Engineering Department. They talk about how carbon footprinting fits into broader lifecycle assessments, how PAIA is being used to determine carbon footprints, and how consumers also play a role in sustainability and carbon footprinting.

Learn more about PAIA: https://msl.mit.edu/projects/paia/main.html 

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into the future of work with Meghana Patwardhan, Vice President and General Manager of Dell Commercial Client Products. They talk about hybrid work environments, challenges to collaboration with remote work, the effects of AI on work and devices, the role of IT, and sustainability for the average consumer.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into corporate social responsibility (CSR) and environmental, social, and corporate governance (ESG) with Madison West, head of the Global Corporate Responsibility Office at Intel. They talk about how CSR and ESG initiatives have developed over time, methods for structuring CSR and ESG practices, and how Intel executes its own ESG strategy RISE.

Read Intel’s 2022-23 Corporate Responsibility Report: https://csrreportbuilder.intel.com/pdfbuilder/pdfs/CSR-2022-23-Full-Report.pdf

Customize your report view with the Report Builder: https://www.intel.com/content/www/us/en/corporate-responsibility/csr-report-builder.html 

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille gets into building technical teams, leadership, and coaching with Tom Garrison, Vice President and Chief Strategy Officer with the Intel PC Client Group. They talk about the qualities of a good leader, effective team-building strategies, and the importance of professional coaching.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into physical cybersecurity with the co-authors of Critical Convergence—Antoinette King, founder of Credo Cyber Consulting and author of The Digital Citizen's Guide to Cybersecurity, and Kasia Hanson, Global Director of Physical and Cybersecurity Ecosystem and Partnerships at Intel. They talk about how physical and cyber security are two sides of the same coin, how integrators are working to unify physical cybersecurity, and what everyone can do to better protect themselves and their businesses.

-Read Critical Convergence here: https://credocyber.com/credo-cyber-consulting-collaborates-with-intel-on-critical-convergence-ebook/

-Read The Digital Citizen's Guide to Cybersecurity here: https://www.amazon.com/Digital-Citizens-Guide-Cybersecurity-Empowered/dp/1956464220

-Listen to “What That Means with Camille: What Do Kids Know About Cybersecurity?” here: https://intechnology.intel.com/episodes/what-that-means-kids-cybersecurity/

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into machine identity with Kevin Bocek, Vice President of Security Strategy & Threat Intelligence at Venafi. They talk about the different types of machine identities, how to keep coding with generative AI secure, and how to better regulate machine identities as computing evolves.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into security in the healthcare and health insurance industries with two guests from Blue Shield of California—Bill Giard, Vice President of Enterprise Architecture & Health Innovation, and Eddie Borrero, Chief Information Security Officer. They talk about the current security threats facing healthcare, their effects, potential solutions, how AI and advanced analytics are being used to help, and much more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into nanotechnology, molecular manufacturing, and neurotechnology with Allison Duettmann, President and CEO of Foresight Institute. They talk about what these new technologies are being designed to do, some of the fears people have about them, and their intersection with AI and data privacy.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into repatriating data and data security with Chris Royles, Field CTO–EMEA at Cloudera. They talk about why some companies are moving from cloud computing back to onsite data centers, plus how these moves affect data security.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into genetics with Dr. Michael Snyder, Chairman of Stanford University’s Department of Genetics. They talk about the crossroads of genetics and big data like AI, personalized medicine, the possibilities of longevity and reverse aging, the leading ethical and social concerns about the field of genetics, and more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into sustainability for PCs with Gokul Subramaniam, Vice President and General Manager of Intel Client Platforms and Systems. They talk about reducing carbon footprints throughout the lifecycle of a PC, sustainability incentives for PC consumers and manufacturers, and new ways to give PCs a second life.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, we have an extended version of Camille’s conversation with Joscha Bach about machine consciousness. Bach is a research fellow and expert in AI and cognitive computing. They talk about the definition of consciousness, the possibilities of artificial intelligence, and the difficult ethical conversations about AI.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this repeat episode of InTechnology, Camille and Tom get into sustainable computing with Dr. Tamar Eilam, IBM Fellow and Chief Scientist for Sustainable Computing. They talk about the effects of hardware and software on energy efficiency, the current state of sustainable computing in the tech industry, and how AI is being used to create climate change solutions.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into generative AI with Nicolas Babin, President of Babin Business Consulting. They talk about how generative AI and ChatGPT work, some limitations of ChatGPT, and what generative AI and NFTs have to do with each other.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into energy efficiency in the Cloud with Lily Looi, Intel Fellow. They talk about the main ways data centers consume energy and ways to make data centers more energy efficient.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into electricity mapping with Olivier Corradi, Founder and CEO of Electricity Maps. 

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into data center demand with Allison Goodman, Senior Principal Engineer and Director of Optane Solutions Architecture at Intel. They talk about how data centers work and the ever-growing demands of compute, memory, storage, and networking in data centers.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into the future of cybersecurity with Moty Kanias, Vice President of Cyber Strategy and Alliances at NanoLock. They talk about vulnerabilities in legacy software and hardware, cyber attacks as both cybercrime and cyber war, and how zero trust policies can deter insider threats.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into digital health and personalized medicine with Ardy Arianpour, CEO and Co-Founder at SEQSTER. They talk about the fragmentation of digital health between health systems, the questions of privacy and security in personalized medicine, and the coming possibilities for leveraging health data.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into mobile security and SIM swaps with Haseeb Awan, CEO and Founder of Efani Secure Mobile. They talk about how SIM card attacks happen, what to do if you become a victim, and how you can best prevent these attacks from happening.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into deep learning with Andres Rodriguez. They talk about how deep learning works as opposed to traditional machine learning, the recent changes in deep learning models, and the future global impacts of deep learning.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into greenwashing with Caryn Herder Fritz, Intel Sustainability Initiative Lead at Cross-Intel Marketing Initiatives Group.

They talk about the importance of establishing trust with consumers when it comes to marketing sustainability, how companies can avoid greenwashing in their sustainability claims, and how we are only just now starting to see standards begin to develop for reporting on and communicating corporate sustainability.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into zero waste with zero waste expert Marina McCoy. They talk about foundational education on zero waste, steps individuals and businesses can take toward becoming zero waste, and the need for standards in sustainability.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into synthetic data with Selvakumar Panneer and Omesh Tickoo, Principal Engineers at Intel Labs. They talk about how synthetic data is being used today for things like AI and how it’s changing the world we experience.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into the cybersecurity of trains with Miki Shifman, Co-Founder and CTO of Cylus. They talk about how advanced train systems are today and what the rail industry is doing to stop cyber attacks.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into green software with Asim Hussain, Director of Green Software Engineering at Intel and co-founder of the Green Software Foundation. They talk about how green software offsets carbon emissions and how it can improve sustainability for the future.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into Root of Trust with Jorge Myszne. They talk about how Root of Trust works, why firmware attacks are such a big deal, and how companies can protect themselves with the recent rise in firmware attacks.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into deep fakes with Ilke Demir, Senior Staff Researcher at Intel Labs. They talk about deep fake detection, responsible deep fake generation, and media authentication.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into the security of “buy now, pay later” credit systems with guests Jim Ducharme, COO at Outseer, and Armen Najarian, an industry advisor in digital fraud and identity. They talk about the security risks of installment payment plans for online shopping, how artificial intelligence and machine learning are working to mitigate these risks, and the uptick in brand impersonation and phishing scams.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into ethical hacking with Ted Harrington, author of HACKABLE: How to Do Application Security Right and the Executive Partner at Independent Security Evaluators. They talk about what makes a good hacker, some surprising finds in hacking research, how ethical hacking teams can save developers time and money, and much more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom look back on their predictions for 2022 and make some predictions for the year ahead in technology, sustainability, and security. What did they correctly predict would be hot topics this year? What conversations do they think will be trending in the tech world next year? Find out in this reflection on AI, sustainability, machine consciousness, and more!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into batteries and AI with Jef Caers. They talk about why lithium-ion batteries are so important as we move to renewable energy, the mining of the metals these batteries require, how AI is being used to speed up the discovery of those metals, and more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into sustainable compute with Michelle Chuaprasert, Senior Director of Sustainable Compute and co-lead for the Carbon Neutral Global Challenge at Intel. They talk about what sustainable compute means, the lifecycle of the PC, the surprising innovations from software development and manufacturers alike towards sustainability, what carbon neutral computing looks like, and more.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom dive deep into corporate sustainability with Jen Huffstetler, Corporate Product Sustainability Lead at Intel. They talk about what sustainability means at a corporate level, how Intel is achieving its sustainability goals, eco-friendly insights for other companies, and what corporate sustainability looks like in the industry today.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into indigenous data sovereignty with Dawn Nafus (Anthropologist and Senior Research Scientist at Intel Labs), Bobby Maher (member of the Maiam Nayri Wingara Indigenous Data Sovereignty Collective), and Karaitiana Taiuru (Māori Indigenous Data Specialist). 

They talk about the definition of indigenous data sovereignty, cultural bias in data collection of indigenous peoples, indigenous peoples’ access to data collected about them, and why input from indigenous peoples in the data collection process is imperative.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this special episode of InTechnology, Camille and Tom get into the Thanksgiving spirit by sharing some of our listener’s favorite topics and episodes throughout the year so far as thanks for your continued support. They talk about cloud computing, IoT devices and AI security, sustainability, and machine consciousness. If you missed any of these episodes or want a refresher on their highlights, this episode is one you won’t want to miss.

Previous podcast episodes mentioned in this episode can be found here:

Ep102. Cloud Security: Resiliency and Shared Responsibility — https://cybersecurityinside.libsyn.com/102-cloud-security-resiliency-and-shared-responsibility

Ep96. The Cybersecurity of IoT: Protecting Our Systems – https://cybersecurityinside.libsyn.com/96-the-cybersecurity-of-iot-protecting-our-systems

Ep125. Sustainability with Tamar Eilam

https://cybersecurityinside.libsyn.com/125-sustainable-computing-taking-the-big-steps-to-a-smaller-footprint

Ep105. What That Means with Camille: Machine Consciousness – https://cybersecurityinside.libsyn.com/105-what-that-means-with-camille-machine-consciousness

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille explores high-performance computing (HPC) with James Reinders, HPC Engineer at Intel. They talk about how the architecture of supercomputers has changed over the years, HPC use cases, the challenges of high-performance computing, and the relationship between HPC, quantum computing, and artificial intelligence.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom explore sustainability in computing with Dr. Tamar Eilam, IBM Fellow and Chief Scientist for Sustainable Computing. They talk about the trends driving sustainability in computing, the current situation, sustainable software development, and how technology can help us combat climate change.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into renewable energy with Stephen Harper, Global Director of Environment and Energy Policy at Intel. They talk about legislation addressing renewable energy such as the CHIPS Act and the Inflation Reduction Act, the obstacles to innovation in renewable energy sources, and what the future of renewable energy looks like in the U.S.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of InTechnology, Camille and Tom get into convergence and sustainability in technology with Dr. Wayne Visser, Fellow at the Cambridge Institute for Sustainable Leadership. They talk about what convergence and sustainability look like in tech, how we can measure sustainability practices, and how changes to sustainability are made over time.

You can check out Dr. Visser’s book Thriving: The Breakthrough Movement to Regenerate Nature, Society, and the Economy at https://www.amazon.com/Thriving-Breakthrough-Movement-Regenerate-Society/dp/1639080074/, Dr. Visser’s own podcast Thriving: The Breakthrough Movement at https://thrivingpodcast.buzzsprout.com/, and all the latest endeavors from Dr. Visser at https://www.waynevisser.com/.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of What That Means, Camille gets into the latest trends in security with Ron Perez, Fellow and Chief Security Architect at Intel. They talk about how AI is being used for security, how security is being developed for AI, how to develop resiliency from cyber attacks, confidential computing, insider threats, quantum compute and post-quantum cryptography, supply chain security, and how companies can start implementing AI and machine learning.

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside, Camille and Tom dig into the relationship between software development and security with Harshil Parikh—Founder and CEO of Tromzo. They talk about how software development and security have evolved, structuring and automating the SDL, and the future outlook of software development in relation to security. 

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside What That Means, Camille gets into what oneAPI is with James R. Reinders, HPC Engineer at Intel. Have you ever heard the term oneAPI and wondered what it is? In this mini episode, Camille and James explain how it works, why it is being worked on, and what it might mean for the future of computing development. Listen in!

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside, Live from the Green Room, Camille sits down with Ria Cheruvu, AI Ethics Lead Architect at Intel Corporation. They get into the ethics of artificial intelligence, including bias, sustainability, the intentions of users and developers, and more. It is a fascinating conversation with Ria, an expert in the field. Be sure to listen in!

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside, Camille and Tom dive into quantum computing with Michele Mosca, Co-Founder and Professor at the University of Waterloo, and Co-founder, President, and CEO of EvolutionQ. They talk about how quantum computing works and why it is being developed, as well as the security concerns related to the development of quantum computers.

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside What That Means, Camille and Yulia Sandamirskaya, Applications Research Lead at Neuromorphic Computing Lab, talk about how robots learn. They discuss why robots are often very humanlike, how robots learn in new environments, and some things we need to consider as we develop them more such as security and how we are using them. Tune in!

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside What That Means, Camille and Yulia Sandamirskaya, Applications Research Lead at Neuromorphic Computing Lab, talk about how robots learn. They discuss why robots are often very humanlike, how robots learn in new environments, and some things we need to consider as we develop them more such as security and how we are using them. Tune in!

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside What That Means, Camille and Lee Phillips, Director of Ecosystem Strategy at Intel, talk all about 5G. The conversation covers everything from what 5G is, how it developed, the frequencies it travels on, to the potential health impacts it has on the human body. Lee is truly an expert on this and has a lot to share. Tune in to learn more!

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside What That Means, Camille and Lee Phillips, Director of Ecosystem Strategy at Intel, talk all about 5G. The conversation covers everything from what 5G is, how it developed, the frequencies it travels on, to the potential health impacts it has on the human body. Lee is truly an expert on this and has a lot to share. Tune in to learn more!

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside, Camille and Tom get into security and cyber crime with Brett Johnson, Original Internet Godfather and Chief Criminal Officer of Arkose Labs. Brett shares his story from when he was a cyber criminal, how he got the name AnglerPhish, and his perspectives on cyber security. Tune in to hear some fascinating stories!

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside, Camille and Tom get into security and cyber crime with Brett Johnson, Original Internet Godfather and Chief Criminal Officer of Arkose Labs. Brett shares his story from when he was a cyber criminal, how he got the name AnglerPhish, and his perspectives on cyber security. Tune in to hear some fascinating stories!

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside What That Means, Camille talks with three professors: Farinaz Koushanfar (Professor and Henry Booker Faculty Scholar at ECE University of California, San Diego, USA), N. Asokan (David R. Cheriton Chair and Executive Director of the Cybersecurity and Privacy Institute, University of Waterloo, Canada), and Ahmad Sadeghi (Professor at Technical University Darmstadt, Germany).

They talk all about AI security, why it is difficult to keep artificial intelligence secure, and how hardware plays a role in this. They have a wealth of knowledge between them and have many ideas and stories to share, so be sure to tune in!

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside What That Means, Camille talks with three professors: Farinaz Koushanfar (Professor and Henry Booker Faculty Scholar at ECE University of California, San Diego, USA), N. Asokan (David R. Cheriton Chair and Executive Director of the Cybersecurity and Privacy Institute, University of Waterloo, Canada), and Ahmad Sadeghi (Professor at Technical University Darmstadt, Germany).

They talk all about AI security, why it is difficult to keep artificial intelligence secure, and how hardware plays a role in this. They have a wealth of knowledge between them and have many ideas and stories to share, so be sure to tune in!

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside, Tom and Camille sit down with Mathieu Gorge, CEO & Founder of VigiTrust, Forbes Featured Author. They discuss the benefits and challenges of talking with higher ups and board members about cyber security needs, and how you can approach that conversation more effectively. Mathieu shares his 5 Stages of Cyber Security Grief and stories from his experiences on this episode. Check it out!

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside, Tom and Camille sit down with Mathieu Gorge, CEO & Founder of VigiTrust, Forbes Featured Author. They discuss the benefits and challenges of talking with higher ups and board members about cyber security needs, and how you can approach that conversation more effectively. Mathieu shares his 5 Stages of Cyber Security Grief and stories from his experiences on this episode. Check it out!

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside What That Means, Camille talks with Jerry Bryant, Senior Director Security Communications and Incident Response, and Crob, Director of Security Communication. They are also the hosts of Chips and Salsa! They discuss vulnerability disclosures, product security reports, and what factors into when to tell the public about a vulnerability.

Give it a listen!

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside, Camille and Tom sit down with Dr. Magda Chelly, Cybersecurity Leader, Author, and Entrepreneur to talk about who is responsible for cyber security. Curious about why the security defaults on the products you use aren’t what you expect? Wondering what responsibilities you have for your own protection and security? Tune in to hear Camille, Tom, and Magda break it down for you.

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside What That Means, Camille and Mykel Kochenderfer, Professor of Aeronautics and Astronautics, Human Centered AI Institute talk all things autonomous AI systems. They chat about everything from autonomous cars and aircraft to firefighting and mobility aids, as well as what some of the difficulties are in designing these systems. Tune in to learn more!

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside What That Means, Camille chats with Rita Wouhaybi, Senior AI Principal Engineer at Intel. After noting that artificial intelligence is just too big a topic to cover in one episode, they break down scaling AI at the edge in this episode. Rita shares her experience working to create AI with Audi and gives tips on how to scale artificial intelligence at the edge.

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside, Camille and Tom have a discussion with Kavitha Prasad, VP & GM Datacenter, AI and Cloud Execution and Strategy, about scaling artificial intelligence. Curious about what your AI strategy should be and how where the field is headed in the next few years might affect that? Tune in to hear more from an expert in working with a big company’s AI development and strategy.

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside What That Means, Camille gets to the bottom of the cloud with Monica Ene-Pietrosanu, Director of Software for Cloud and Enterprise Solutions at Intel. They chat about how the cloud really works in the background, what services are provided with new technology, and how security and privacy are being developed and focused on by cloud service providers. Curious about what the cloud really is? Be sure to give it a listen!

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside, Camille and Tom talk with Mike Nordquist, VP and GM of Commercial Client Planning and Architecture. They talk about Intel Threat Detection Technology, and how AI and the Internet of Things are parts of the future of this technology. Can we predict the future of cybersecurity well enough to stay protected? 

To find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, visit our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

Can machines attain consciousness, or is this just science fiction? Camille’s getting philosophical about this topic with Joscha Bach, Principal AI Engineer, Cognitive Computing at Intel! Their conversation covers machine consciousness, artificial intelligence, and the ethics of sentient machines. You won’t want to miss their intriguing insight!

Find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, on our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

Even small businesses need to be on top of cybersecurity! Tom and Camille are speaking today with Chris Apgar, CEO & President of Apgar & Associates, LLC about cybersecurity resources for small businesses. These resources include CISOs for hire, free government resources, and more! Be sure to tune in to hear about what security risks are out there and how your business size can change the impact they have on you.

Find more episodes of Cyber Security Inside, video interviews, and blogs on cybersecurity topics, on our website at https://cybersecurityinside.com.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside What That Means, Camille digs into artificial intelligence, natural language processing, and the balance of predictability and exploration with Ashwin Ram, Director of AI, Google Cloud, Office of the CTO. The conversation covers:

-  Why it is difficult for artificial intelligence to have a conversation with a human.

-  How artificial intelligence is developing with natural language processing to understand and interpret context.

-  Why there needs to be a balance in AI between exploration and exploitation.

-  How the data is being secured that is used to train artificial intelligence.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

View Details

In this episode of Cyber Security Inside, Camille and Tom take a dive into cloud security with Jo Peterson, Vice President Cloud & Security Services, Forbes Technology Council, CompTIA Advisory-Infrastructure. The conversation covers:

  • How the cloud has become a more integral part of businesses, and where we are headed with cloud.

  • What your responsibilities are for cloud security and the questions to ask when choosing a provider.

  • How artificial intelligence and the Internet of Things interact with cloud security.

  • What the biggest concerns are in cloud security and what experts are doing to make it more secure.

...and more. Don’t miss it!

We were honored to have Jo on the podcast, who has accomplished some amazing things this year! Check out her accolades:

  • Onalytica Who’s Who in Cybersecurity https://onalytica.com/wp-content/uploads/2022/02/Whos-Who-in-Cybersecurity.pdf

  • Engati LinkedIn 30 Top Voices in Tech https://www.engati.com/blog/linkedin-top-voices-in-tech

  • Thinkers360 Top 150 Women B2B Leaders to Follow in 2022 https://www.thinkers360.com/150-women-b2b-thought-leaders-you-should-follow-in-2022/

  • 2016-2022 CRN Women of the Channel Recipient https://www.crn.com/rankings-and-lists/wotc2022.htm

  • Onalytica Who’s Who in the Cloud https://onalytica.com/blog/posts/whos-who-in-cloud/

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • When you don’t own the hardware you are using, what can you do to keep yourself secure? We are all sharing a lot of the same underlying infrastructure, and sharing information and data on the public cloud. Keeping it secure is very important.

  • Customers are concerned with outages and resiliency of cloud systems. And there are some things that customers can do. Having things like High Availability, housing workloads across multiple availability zones, supporting region routing, backing up data, encrypting data, and more! These are the top concerns of customers right now.

  • Often cloud breaches happen with unsecured assets because someone internally made a mistake somewhere. The Shared Responsibility Model needs to be flexible and apply to each cloud provider. And knowing your responsibility within that model is important.

  • Splitting up an application between on-prem and in a CSP sometimes depends on financial means. It is more costly to run something in the cloud because of bandwidth and latency. So for one application, some of the storage might be on-prem and some of the computing might be done in the cloud, with you traversing back and forth.

  • Splitting up presences across geographic locations is also smart. If you have a west coast presence, but there is an earthquake that damages your systems, having an east coast presence as well is useful. And you can balance the application with application load balancers in those different availability zones.

  • There are a lot of suggestions and how-tos for best practices and using availability zones. But it also takes some technical knowledge and practice on how to build a secure cloud environment. At the end of the day, you are building your own infrastructure.

  • Cloud has grown and changed a lot over time, and it is still growing and changing. Especially with work from home, how we connect to the cloud and use it has changed. Maybe it’s time to do identity based, maybe the tech for VPNs still hold. We have to rethink who we are letting access data, and continually rethink as things change.

  • What advice does Jo Peterson have for people trying to select a cloud service provider partner? Know your inventory first, and know what you want to move to the cloud. Then look at what you have chosen and decide what specialization you might want to go with based on what you have.

  • When looking for a cloud service provider, it is important to know what you need and to find someone who specializes in that. If you are multinational, find someone who knows the regulations. If you are a beginner, find someone that can guide you and help you with what you need, specifically.

  • Artificial intelligence and the cloud are both increasing in use and they support each other. Businesses need both in the future, and they work together. With the Internet of Things, AI and the cloud will both be utilized.

Some interesting quotes from today’s episode:

“Recently, one of the major cloud hyperscalers had an outage. They actually had a couple in a row. And cloud systems are expected to always be on and news like that makes the headlines. What I’m hearing customers talk about is maybe the need to rethink a strategy about having all their eggs in one basket.” - Jo Peterson

“Have you secured your user end points? That translates into all end points. You might have the users squared away, but maybe you don’t have your VM squared away. Maybe you don’t have your server squared away.” - Jo Peterson

“Wherever the disaster happens, it’s still a disaster. So if you’re running in a different availability zone, you’re theoretically dealing with a whole other stack of infrastructure.” - Jo Peterson on how availability zones are useful protections from natural disasters to hackers

“All of the hyperscalers do a really great job of helping to inform and educate potential clients. So every one of them has how-to guides. But at the end of the day, it’s you building your infrastructure. So what I see happen in shops that don’t have a lot of help, is they’ll go to a managed service provider, a CSP, first to get that sort of architectural best practice from that company. And they’ll learn as they go.” - Jo Peterson

“Well, cloud is a teenager, and it’s growing up. There’s things that are happening as it grows up and matures. The world around it is changing and its world is changing. So there’s this sort of dual effect.” - Jo Peterson

“Current estimates expect today’s $2.5 billion ML market (cloud ML market) to reach $13 billion by 2025. It’s a pretty big increase, right? And Deloitte put out a 2020 study of AI that revealed that 83% of organizations expect AI to be critical to their business success in the next two years. So cloud drives measurable benefits for AI programs.” - Jo Peterson

“I think we’re just going to be seeing more AI and cloud together, like peanut butter and jelly.” - Jo Peterson

“I think we’re going to see, particularly in certain verticals, like retail, healthcare… We’ll see edge cloud deployments. And he who has the data and he who uses the data is going to be first. You’re going to see market disruption. You’re going to see first to market advantage by companies that are using that edge, that customer data most creatively.” - Jo Peterson

View Details

In this episode of Cyber Security Inside, panelists from the 2022 RSA Conference share their thoughts about collaboration against some of the biggest cybersecurity threats. Camille Morhardt talks with Tom Garrison (VP & GM Client Security Strategy & Initiatives at Intel Corporation), Abhilasha Bhargav-Spantzel (Partner Security Architect, Microsoft Corporation), Aanchal Gupta (VP Microsoft Security Response Center, Microsoft), and Dr. Diane Janosek (Director, Commandant , National Cryptologic School, NSA).

The conversation covers:

  • Why our panelists think collaboration across the private and public sectors is the only way forward in cybersecurity.

  • What the panelists think about threats to the supply chain.

  • Why it’s true that as we develop more complex technology, protecting gets more difficult.

  • What our panelists think are the most urgent things to be thinking about in the world of cybersecurity.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • This podcast is a round robin of panelists from the 2022 RSA Cybersecurity Conference, talking with three panelists from the panel called “All Hands on Deck: A Whole-of-Society Approach for Cybersecurity.”

  • One of the threats on the top of the panelists’ minds is supply chain security risks. A lot of reliance on third-party software is what is causing some of these risks, as is how pervasive some of these softwares are throughout the community, making a large range of software potentially vulnerable.

  • The only way to really tackle this is as a full cybersecurity community. There need to be partnerships between different industries working to keep our technology safe.

  • An example of these partnerships is seen in the Ukraine war. Russia is conducting a hybrid attack, and Microsoft partnered with Ukraine cybersecurity agencies to map out the threats.

  • The NOBELIUM attacks were an example of people sharing intel and insights through blogs and other means. The whole industry could come together and learn from it to see if they were getting attacked in the network.

  • As our technologies get more complex, the difficulty in repairing, managing, and protecting them gets more difficult. A car from the 80s was much easier to fix than one of today’s cars. This is especially true with remote work.

  • Interfacing with third parties to determine if a device is safe or if technology is working and secure isn’t enough anymore. The companies themselves need to be able to answer that question with confidence internally. For example, you need to be able to talk directly with Intel about the security of their products and know that they can answer that question.

  • Transparency is key to this collaboration and teamwork. Knowing what is inside your device empowers customers to make good decisions around their devices, the state of those devices, and if it is trustworthy. It puts some ownership and knowledge in the hands of the user.

  • What can product divisions be doing? First is investing in your own product division to focus on security research. Then it is about taking those learnings and improving your future products with that information. Constantly investing, learning, and improving.

  • The two potential goals of attackers are to either make money off of someone or to cause a disruption. They are using AI to do this. The models we use to detect and respond to attacks rely on the integrity of our data. So what happens when that data is altered by adversaries?

  • The NSA works to protect the US from cyber attacks. They are protecting the digital network and are watching threat factors. The guests discussed transparency between the NSA and the other sectors in the government to make sure that Americans are protected. They stressed the need to share information and partner together.

  • Who is responsible for cybersecurity? Everyone. The private sector, the government, you the user. Everyone. Because cyber is personal to all of us and affects all of us, we need to make sure that we are securing it as a community.

Some interesting quotes from today’s episode:

“Our dependence on this third-party software [for supply chain security] is growing and it is becoming very attractive for our threat actors to find the soft spots. They could easily convince an insider to get onto and modify some code in the supply chain, or they can inject this malicious payload into the supply chain.” - Aanchal Gupta

“The usage of this certain software is literally like salt in our pantry. And when I say salt in our pantry, when you look at different food items, and you start to look at the ingredient list, you will most likely find salt in there. And if someone were to tell you, ‘hey, salt is contaminated and you need to do something about it for the food items in your pantry,’ it would be immensely difficult… That’s what made Log4j such a big challenge for the entire community.” - Aanchal Gupta

“I think we have to continue to evolve this partnership globally, because that is the only way we can defend against these threats. Let’s also not penalize the people for sharing a breach of their system. We need to shift the culture from blame to community support. When we support organizations to be forthcoming about their experience, they get better insights. We are able to help identify the supply chain risks sooner.” - Aanchal Gupta

“The technology is so, so, so much more complicated. And the same is true for our platforms, whether it be a client platform, a server platform, and the like. Couple that with the fact that we have devices now being used in ways that have never been envisioned before. Workers that are outside the four walls of the company are subject to a whole different kind of attacks.” - Tom Garrison

“That first step is around transparency. So what we want to do is to peel back this sort of almost secrecy that’s existed around what components are used to build your device - whether it’s a PC or a server or an IOT device. And we think that with that transparency comes a level now of intelligence you can have.” - Tom Garrison

“Our adversaries have two intentions in mind. That is to make as much money as they can off of you, or cause as much disruption as they can. Or two of them together. And they’re using adversarial AI where they’ll come together and understand where the sweet spots are to affect us and to cause the most amount of damage or harm or financial damage. So from an adversarial AI perspective, how do we respond to that?” - Dr. Diane Janosek

“What do you have to do to kind of raise the bar? It’s giving the tools and the information, sharing what we know about vulnerabilities, sharing what we know about threat factors, sharing what we know about adversarial attacks and with the emerging threats that are coming down the pike. If we can share that with the other 80% in the healthcare sector, the financial sector, the energy sector, all 16 sectors… If we can share what we know, Americans as a whole can go to sleep knowing that their country is better protected.” - Dr. Diane Janosek

“It takes everybody. It takes people, patching their systems, doing the updates on their iPhone, making sure they have a password on their home network. You want to make sure that the government’s doing the right thing, that they’re really locking up the supply chain and that they’re really securing water supply plants. The planes are safe. The hospitals are safe. At the end of the day, cyber is personal… cyber affects all of us.” - Dr. Diane Janosek

View Details

In this episode of Cyber Security Inside, Camille and Tom celebrate 100 episodes by reviewing their top ten fun facts their guests and them have shared throughout those episodes. Join them in celebrating!

Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • Camille and Tom review 100 episodes of fun facts. At the end of CSI episodes, they always bring fun facts at the end and ask their guests to do the same. These are some of their favorites that have been shared throughout the history of CSI podcasts.

  • Number 10 was shared by Alex Ionescu, and is about Legos. It is possible that boxes can be packaged with an incorrect piece, because the system looks for colors, size, and weight. So there is a very small chance that a piece could fool the system and sneak into a box.

  • Fun fact nine was that the stickers on fruit are actually edible! So if you accidentally miss one and eat it, you are safe.

  • Tom shared fun fact number eight all those episodes ago. It was that Venus is actually the hottest planet in the solar system, not Mercury. This is strange, because Mercury is actually closer to the sun!

  • Tom also brought number seven to the table, and it is all about falcons. Usually falcons use their talons to attack prey. But peregrine falcons, because they are smaller, punch their prey with their talons at high speeds, attempting to stun.

  • Camille shared fun fact number six in a previous episode. She shared that camels are picky creatures, smelling their food with one nostril at a time before eating. It also turns out that they can exhale air out of their nose that is much cooler than their body temperature. This helps them reduce water loss.

  • Number five is about the number of people on the planet. If you took every person on the planet and stood them shoulder to shoulder, it turns out they could all fit in the city of Los Angeles!

  • Fun fact number four is another animal fact! There is a moth in Madagascar that exclusively eats the tears of sleeping birds. They use their beaks to slip under the eyelid to feed.

  • Tom shared fun fact number three as well. You might think that lightning flashes are fast. However, there is a record lightning strike that clocked in at 17.1 second in Uruguay.

  • Fun fact number two is also about animals! It turns out that squirrels are a problem for the energy grid. Another animal that causes problems on the electrical grid is cockatoos, who sharpen their beaks on fiber optic cables.

  • The number one fun fact features goldfish. They are smarter than we think they are! There is a study in Israel in which a goldfish was taught to drive in its tank. It hit a target to receive treats.

  • Camille and Tom also shared some new fun facts in honor of the 100th episode. Camille shared about the trees that make telephone poles and why. This is the Douglas Fir! Tom and Camille share a few facts about the particular tree as well!

  • Tom’s fun facts were cybersecurity focused. Passwords are one of the most breached parts of security. They are also one of the main reasons people stop a purchase (forgetting a password) and one of the main help desk calls.

Some interesting quotes from today’s episode:

“So for all of our listeners, today is a very special day. This is our hundredth episode! Who would’ve thought? Hundred episodes, and so we're going to have a lot of fun today.” - Tom Garrison

“I like some of the expansion we’re doing into topics that are cyber security related, but also pull in other relevant topics that are intersecting more and more. Like topics around sustainability and safety and privacy.” - Camille Morhardt

“We both want to thank everybody for listening to this episode and thanks for listening to all our previous episodes as well. We’ve had a tremendous amount of success and we ant to make sure we’re giving you guys interesting information and also entertaining you at the same time. So thank you.” - Tom Garrison

View Details

In this episode of Cyber Security Inside What That Means, Camille chats with the three leaders of the teams that won the Hack@ event in December, Animesh Basak Chowdhury and Baleegh Ahmad from NYU, and Orlando R. Arias from University of Florida to learn more about the event and the strategy behind it.

The conversation covers:

  • What the Hack@DAC event is, and how people choose their teams.

  • Some of the strategies used by the winning teams.

  • What the event is like while it is running, and why people should try and participate.

  • The realistic nature of the event and how it relates to the cybersecurity field itself.

... and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • The guests from this podcast were all leaders of the teams that won the Hack@ event, a hardware security competition. The competition is a fun, intense two day event. Some teams went in to test some of their own tools.

  • Some teams used some hardware features they brought with them, and also had to write code on site on the fly. There are different beliefs on how big your team should be and how working together is very important.

  • One team focused on peripherals, assigning different ones to different people. They then realized that since everything was connected, they needed to shift strategy.

  • It is clear that in a team like this, it is important to identify each team member’s strength. One might be better at user exploits while another is more experienced in automated exploits. Strategizing like this is important in these competitions, but also in practice.

  • Often you get the chance to evaluate the SOC before the competition and make a plan. Some teams took this opportunity to identify the areas that were most vulnerable, and therefore would likely have the most bugs during the competition.

  • These competitions often involve working with very little sleep and division of tasks. This requires good teamwork and planning skills.

  • The realism of this competition varied between the competitors. Some acknowledged the 24/7 nature of cybersecurity and that the work is never done. You are always finding new bugs and breaches. Others talked about some of the bugs that were present never should have made it through to hardware generation.

  • Organizers want to see how participants go to find the bugs and the vulnerabilities. So they try to make it realistic. However, they also introduce more bugs than might actually exist for the participants. This might change over time to increase the difficulty and because of the developing nature of the field, to continue making it useful.

  • What do these coders say to look out for? Double and triple check assignments and access controls. Use formal verification tools to ensure quality of code. Use more than those tools as well, including other types of analysis.

Some interesting quotes from today’s episode:

“So here’s the bug, here are the consequences of the bug once you run this piece of code. Meaning we will access cryptographic keys that we will otherwise have no access to. We will change security settings on the SOC that we will normally have no access to.” - Orlando Arias

“The more people you have, the better. That’s for sure. Because quantity matters. It’s the amount of bugs you can identify and there were plenty out there. So I think within that time frame, especially because of that time crunch, it’s definitely a team sport. You have advantage in numbers.” - Baleegh Ahmad

“When we were competing, we were adopting different strategies and those strategies were orthogonal. So after the competition, we were thinking that if both teams combined together, we would have scored more points than individual teams.” - Animesh Chowdury

“From the organizer perspective, what they actually want is to evaluate how people actually approach this problem of finding vulnerabilities in the hardware. So they try to actually insert bugs in this hardware which actually resemble similar sorts of actual vulnerabilities which exist in the hardware.” - Animesh Chowdury

“In previous editions of Hack@DAC as well, participants were able to find bugs that weren’t deliberately introduced… A bit gone, an incomplete assignment, a wrong password check, stuff like that. So for the purpose of competition, there are a few easy ones introduced, but they also to a certain extent do represent the kind of mistakes that can be made.” - Baleegh Ahmad

“I believe we have to go beyond just formal verification tools. Other types of analysis as well. Static checks… anything you can think of, go ahead and throw at it. Even then things will go ahead and slip by.” - Orlando Arias

“One of our objectives was to beta tools, the tools we had previously developed, to see how well they do against a scenario that we didn’t concoct ourselves. So even just for that, it was just a learning experience. We got to use other tools that we hadn’t used before either.” - Orlando Arias

View Details

In this episode of Cyber Security Inside What That Means, Camille continues to dive into the idea of confidential computing and trust execution environments with Ron Perez, Intel Fellow, Chief Security Architect, CTO Office. The conversation covers:

  • What confidential computing and trust execution environments are.

  • Why we need them, and what data needs to be inside them.

  • How confidential computing works in something like the cloud.

  • Balancing security with usage and effectiveness using confidential computing.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • Security is a very broad term. It can be making sure there are no vulnerabilities in products and also tapping into new capabilities and features for customers. The latter is where Ron focuses, because he wants to make sure technology is not limiting people, but is allowing them to do things they wouldn’t or couldn’t do before.

  • An example of this is cloud computing. It makes things more efficient and easier to be shared, but it also comes with security vulnerabilities. So new security needs to be developed to assure the safety of the work in these environments.

  • A perfect security situation is essentially encasing your computer in cement and not using it. But that’s not very useful. People are wanting to do more, share more, and connect more in industry today, which creates a huge challenge. This is why security architects and technologists exist, and why they have so much job security.

  • Although ransomware is incredibly important to address and focus on right now, it is also the case that we are constantly connecting our networks and striving for computing on a global scale. This might magnify any threat or vulnerability because of the connections.

  • The idea of “break once, run everywhere” is going to become a real problem with how interconnected our systems are becoming. This is why security assurance is so important, and why we need to move back to focusing on this as an industry.

  • We have moved past the point of being able to use paper (except maybe for something like voting) because of the speed and connectivity of everything. That’s why we have things like zero trust, down to the smallest pieces of software and hardware.

  • Zero trust and confidential computing are complimentary. Confidential computing is about protecting data in use, by doing the computing in a trusted execution environment that is hardware based.

  • Why is it difficult to protect data while it’s in use? It’s being accessed by several different things: memory, processors, another compute engine, the software you’re using to do something to the data… There may be copies of it as the software is optimizing, and there is a lot happening to it at once.

  • A trusted execution environment is focused on confidentiality. It is also about protecting the data and seeing if the data and code have been modified in any way. At a minimum, it must do these two things.

  • A software like Intel Software Guard Extensions (SGX) can separate what code and data is inside the trusted environment and what is outside, and creates a strong separation between the two.

  • SGX also protects the memory that the code and data are in during the processing and use, and encrypts it. There are softwares that are also trying to support multiple environments at different levels of capability.

  • In the past, computer security has been based on a hierarchy, needing to trust your data, the software, the OS, the hardware, and more. You have to secure everything under your data as well. With confidential computing, you only need to trust your data and the environment.

  • Being about to only need to trust those two things is really powerful when you think on a global, interconnected scale. When your code is running across the globe, confidential computing helps you assure that it is protected.

  • Because the cloud has grown so much in how much it’s being used, there is some worry about who has access to data in it, and the possibility that someone could access it. We’re relying a lot on the ethics of the people running the security. It is about the capability to access it more than anything.

  • Confidential computing now allows those providers to say that they absolutely cannot see their data. You are just paying for their resources and their bandwidth. It is not based on their own ethical code, they physically cannot see it.

Some interesting quotes from today’s episode:

“Security is very broad. It applies to so many things. And in fact, just saying security is not enough, because everybody will have a different image in their head of what that means.” - Ron Perez

“But as a security technologist, you realize that yeah, sharing is not necessarily a good thing. That’s where bad things happen. So we need new technologies to provide assurances, security assurances - confidence, basically - that you still have the same safety in terms of the security of your workloads in that environment that you can’t control.” - Ron Perez

“We’re really trying to do computing on a global scale. We have a number of cloud service providers and telco providers, etc. All these networks and all these systems are going to be linked together… That massive scale is the part I’m worried about, because now any little vulnerability can be magnified because, most likely, we’re using these same technologies everywhere else. So the break once, run everywhere problem is going to be huge.” - Ron Perez

“Voting, for example, is probably an area where we should look at still having paper. Other than that, the speed of everything we’re doing today really won’t allow us to go back to those days. Even those systems that had back then. So what is a server, and can you put it in a silo?” - Ron Perez

“The past 40, 50, 60 years now, we’ve been figuring out how to secure data when it’s being stored, at rest, and when it’s in transit, over network. That’s been the whole purpose of computing security and the research and all the developments we’ve had. But we’ve missed this whole in-use part.” - Ron Perez

“We’re talking about when the homomorphic encryption first reemerged as a real possibility on the scene in 2009, they were thousands of orders of magnitude to worse performance. We’ve got that down now to just a few orders of magnitude, but even that obviously is not practical for most workloads. So we still have this need for what we can do short of that until we get to that nirvana.” - Ron Perez

“Confidential computing now allows us to say, okay, you can take the thing that you care about that you want to protect, and the hardware which implements these trusted execution environments, and that’s all you have to trust. You don’t have to trust any of the operating system, the hypervisor, the other applications, the other middleware on the platform, the other firmware on the platform. All you have to do is trust those two things.” - Ron Perez

View Details

In this episode of Cyber Security Inside What That Means, Camille breaks down and defines confidential computing with Amy Santoni, Intel Fellow, Design Engineering Group, and Chief Xeon Security Architect, Datacenter Processor Architecture. The conversation covers:

  • What confidential computing is and why it is important.

  • Why confidential computing is a focus of cybersecurity development right now.

  • What a trusted execution environment is.

  • What to put in a trusted execution environment and what data is safe to stay out.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • Xeon is a line of processors in the server space that Intel produces. This is what Amy works in.

  • Confidential computing is about protecting data as it is being processed. It is protecting it while it is processing in the CPU. Experts have really figured out how to protect data where it is stored and while it is being transmitted, so now it is about while it is in use.

  • The reason we are getting to this now, is that it follows how the attacks have happened. The attacks started at what is on your disks, then intercepting in transit, and now this is where attacks are happening.

  • An example of this happening that is current is COVID x-rays. There are many x-rays, and AI models have been trained to look at those x-rays and automate and improve the accuracy of diagnosis. The data for training these AI models is coming from hospitals, while preserving the privacy of the patients. But securing that data and information while training and using the AI is part of confidential computing.

  • There are many layers to this protection, including protecting the environment from being tricked by someone. For example, we don’t want an environment to think it’s running on a secure Intel server when it is not. And we need protections to keep that from happening.

  • So why not put everything in a trusted execution environment? There are a few reasons. The first is that it is not free. Another is that there is a lot of software enabling to make this work, and it isn’t the simplest process. There is a balance of resources and how much the data needs to be protected.

  • There are different types of trusted execution environments that work at different levels of your software and hardware. It could be at the app level, or the OS level. You can choose what parts of your data and even parts of your software go into these environments.

  • There is a lot of hesitancy for people using the cloud for storing their data, because it is in a place with many other people’s data. Confidential computing is important for this, because it makes each person’s lock, or walls around their data, unique. So even if my data and your data are next to each other, I can’t access yours and you can’t access mine.

  • COVID helped us realize that we needed agility in computing, but there was a push to do this before COVID as well. The desire to protect data at every part of the process, including when it is being processed, has been being looked at for a while. Even during the Snowden times.

  • It is difficult to predict how much of our hardware and software will be in these environments, and the projections for growth vary widely. However, it is all growth projections, and all of them are large increases.

  • Another industry trend is standardizing communication from how diverse it is across servers so that all the components work together. Another is working on the safety of computer memory, and how the software and hardware work together on that.

  • Physical protection has also become increasingly important as technology increases in our world. From Facebook and phones to the mall and the football stadium to a console, this has become very important. As data travels, it needs to be protected as well from someone physically trying to access the data.

Some interesting quotes from today’s episode:

“Confidential computing is really focused on while [data] is being used. So the other ones we’ve solved, and then confidential computing, the new part, is: ‘hey, while I’m computing this data, let’s make sure it’s confidential and it’s protected.’” - Amy Santoni

“It followed the attack vectors. If you think about how malware started, it started corrupting things on your disk. And then people started putting sniffers or using things at the network site to intercept things between point A and point B. So this is where the attacks are going and where we need to start protecting.” - Amy Santoni

“That’s the trusted execution environment. It’s a new environment and new hardware protections to protect the code and data within that trusted execution environment. Secure enclaves is a particular trusted execution environment.” - Amy Santoni

“You can split your app into these trusted and untrusted parts, but again, the level of detail and the level of software enabling is greater in that second case. It reduces the attack surface to the smallest possible one, because you’re just cutting out part of your app and saying, ‘this is the most critical part that I want to protect.’ And all the rest of the app is untrusted. It can’t get to that data.” - Amy Santoni

“What confidential computing is bringing is extra confidence that I can take these things that maybe I wasn’t comfortable taking to cloud before, and move them to cloud. And I have this extra hardware layer of protection to keep my data private from other people running on the same machine, but also from the cloud service provider, from that virtual machine monitor that happens to be running.” - Amy Santoni

“I think that there was a push for this even before COVID, the move to protect the data while it’s being computed. I think people have recognized that for a while. I don’t know that I have a good example of a catalyst other than the one I’m familiar with, which is, like I said, we’ve called it the Snowden effect. When people realized that the government could get to some data that they didn’t think they could get to.” - Amy Santoni

“We’ve heard Microsoft say they think that the majority of their cloud, let’s call it infrastructure, as a service will be running in some trusted execution environment this decade. So that’s the projections - like the growth projections for the growth of confidential compute vary from 5x to 20x.” - Amy Santoni

“What we’re trying to do is make sure that all of those processing places along the path have, again, from a security centric point of view, have a trusted execution environment. They don’t all have to be the same necessarily, but have some protection. So whether I’m processing here or processing there, I have some protection for my data.” - Amy Santoni

View Details

In this episode of Cyber Security Inside, Camille and Tom get to chat with Malcolm Harkins, Chief Security & Trust Officer at Epiphany Systems, and Rob Bathurst, Co-Founder & Chief Technology Officer at Epiphany Systems about the Internet of Things and thinking like attackers to protect systems. The conversation covers:

  • How the systems in a building physically can be a vulnerability in an organization’s systems.

  • How thinking like an adversary and what their goals might be is the key to protecting your systems the best you can.

  • How complex Internet of Things systems are, and ideas on how to protect them.

  • The difference between vulnerability and exploitability, and how to look at both.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • The Internet of Things, or IoT, enables a lot of capabilities, but also creates a lot of security issues. To adjust for this, we have to change the way industry views security.

  • Everything is connected to technology and networks now, from air conditioning regulation to elevators, it is all connected and inside of a network. Securing that system is incredibly important, because it is now about peoples’ safety inside the building.

  • It might be easier for an attacker to go after these systems than the computers and servers inside the buildings. For example, at a large sporting event, if you own the stadium, you own the event.

  • To learn how to protect a building or an organization, you have to work backwards by thinking about how somebody might disrupt that building. You can then work on protecting it with that information. This is tricky when you have many different parties in a space with different goals and access levels.

  • At a stadium, for example, you have food vendors, the entertainment, and more. They all need access to process credit cards, access for fans to tweet, etc. So do you put them on your internal network or on an outside network? Assessing the threat is an important part of this decision.

  • This is similar to threat modeling, but with an extra complexity with the IoT systems and the interacting networks. If one vulnerability in one area could take down an entire operation, it is a big deal that requires a lot of consideration. Even removing one system, like the elevator system, can create panic and shut down an entire operation.

  • To really start to secure these systems, you need to think like the people trying to take them down. Take a good look at your organization, your business, and ask yourself: if I were an adversary, where would I go for maximum disruption?

  • There are differences between enterprise and IoT, including IoT having less visibility and more complexity because it is nested. The connectivity of everything is deep, and protecting a perimeter isn’t as realistic in IoT as it is in enterprise.

  • Coming together as a team to talk about security and what could potentially happen is one of the best ways to create a defensive understanding. We can’t stay in our small silos with this connectivity - we have to talk to each other and expand the reach of each of our scopes.

  • It is impossible to prevent every attack. That’s why it is important to identify the goal of the attacker and evaluate your system based on that information. It is more about managing the cumulative impact and reducing it.

  • When looking at something like Log4j, you need to look at where the maximum impact to your business is and address the vulnerability there. Otherwise, you might cripple the enterprise because of the effort and time put into testing, checking, and remediating areas that aren’t as critical.

  • Exploits apply to more than just vulnerabilities, and vulnerabilities are not just flaws in software or hardware. It is all about the adversary’s ability to take advantage of either. And they don’t just apply to single technical conditions, but the relationship between them.

  • A way to think about this is to relate it to fire prevention. You can’t prevent every fire ever from occurring in your building. But you can have smoke detectors, sprinklers, fire doors, and ways to call the fire department. And the more protections you have in place, the faster you can isolate the problem and resume operations, rather than the whole building going down. Proactivity is important!

Some interesting quotes from today’s episode:

“If you look at a building, most people just think of it as a shell with glass and doors and floors. And when you really look at it, it really is a connection of different systems. In most modern buildings because of energy regulation and things they get for LEED certification (basically how efficient their building is) they put in automated control systems for their furnaces, their boilers, their air conditioning units, elevators, power systems, access control.” - Rob Bathurst

“Think of the recent ransomware trend where organizations have been impacted and they’ve been held hostage. In some cases, it might be easier for an attacker to, in essence, attack and exploit the building and create that ransomware event rather than just all the PCs and servers.” - Malcolm Harkins

“You have to understand the way an adversary or somebody might disrupt that building, that organization, the people within it. And based on those objectives, based on those goals, you can kind of work backwards and say, how do I protect those systems?” - Rob Bathurst

“What might seem like an obscure vulnerability that could be exploited in one area could actually take down the entirety of an operation. Shut down the elevator system, turn off the fire life safety system, shut down the heating and air conditioning… Think of the chaos that would create.” - Malcolm Harkins

“People naturally want to think good thoughts. They want to be positive. They want to do the best for the places they work. And that sometimes keeps them from thinking: oh, if X, Y, Z went down, the whole place would fall apart. Because that’s the place they work. But what we try and tell people is that's the mentality you need to be able to start to understand how to more properly architect and defend yourself.” - Rob Bathurst

“That’s how the bad folks go from an initial foothold, that toehold, by popping one thing. And then all of a sudden navigating their way through the daisy chain of connections, to the moment of material impact.” - Malcolm Harkins

“When you look at things at a: what are we trying to do? We’re not trying to stop all things all the time forever, because it’s just an impossible task. The environment is too dynamic, everything else is going on. What we’re trying to do is we’re trying to limit the attacker’s opportunity at the moments of greatest weakness.” - Rob Bathurst

“You can build a strategy, as Malcolm pointed out, to reduce the exploitable paths. And for the ones you can’t reduce, create resilience, create friction as we typically call it, so that you are aware the adversary is trying something or that you’re able to block it.” - Rob Bathurst

“You can be vulnerable, but not be exploitable. You could have an exploit happen again at a laptop or a pinpoint device, but that doesn’t mean your organization is exploitable to a material event.” - Malcolm Harkins

“When you build the building, you have a building inspector, you have a fire marshal, you have people come around and check it and evaluate it, and make sure it’s up to code. And we don’t have that kind of same rigidity in the security space.” - Rob Bathurst

View Details

In this episode of Cyber Security Inside Live from The Green Room, Camille talks with Raghu Yeluri, Intel Senior Principal Engineer and Lead Security Architect from Intel’s Vision Conference in Texas. The conversation covers:

  • A high-level definition of Project Amber and overview of what confidential computing is.

  • At the core, confidential compute is where data and IP get processed and the need to be protected and isolated from the platform and the infrastructure administrators.

  • Why customers are worried about security as they move their workloads to the Cloud and how confidential computing can help address these concerns.

  • The three stages of data protection: at rest, in transit, and data protection in use. Most customers want an independent entity to verify the trusted execution environment to ensure it is trustworthy. That trust authority is what we call Project Amber.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • Project Amber is a trust authority that verifies the trusted execution environment (TTE) for data projection in use.

  • Confidential Computing is a new technology that helps provide data projection, especially as more people move to the cloud.

  • The industry is starting to converge on building confidential compute in the following approaches: Use of trusted execution environments and homomorphic encryption.

  • Trusted execution environments are a way to enable confidential computing.

Some interesting quotes from today’s episode:

“But the workflow required to verify this in a trustworthy way, is a complex operation. So, the question people ask us is, how do you assure to me that a service like Amber is doing what it is supposed to do? The verification of other trusted execution environments, in an integrity protected in a trustworthy way. How do I trust that you are doing your job correctly? We call that faithful verification.” says Raghu Yeluri

“Most enterprise customers don't like to run in one cloud provider, they want to run their workloads in multiple clouds, some would like to work in Azure, IBM, and Google Cloud, for example. You don't want to have a separate Attestation service.” Raghu Yeluri.

“If I have a client device that is trying to access a service in the cloud, I need to verify my trustworthiness to the cloud service. Before I get access to that service, I could be a bad actor, trying to access a good service that's running in a trusted execution environment. And I can exfiltrate or infiltrate data from there.”

“Confidential compute, it's the new technology focus for the industry right now, especially as more and more people are moving to cloud computing. Some people say it's the biggest transition in computer security since the 1970s.”

View Details

In this episode of Cyber Security Inside What That Means, Camille dives into next generation cryptography and quantum computing with Eddy Zervigon, CEO of Quantum Xchange and Independent Board Member. The conversation covers:

  • The new era of cryptography due to the advancement of quantum computing.

  • How two-factor authentication and the idea behind it is one solution to making things more secure.

  • How satellites pose particular challenges but are also incredibly important to secure.

  • What thought leaders are doing now and where we are headed in this field.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • We are about to have a huge cryptographic migration due to quantum computing and advanced computing. This is because for a long time we’ve used basic math to encrypt data, and computers are now starting to be able to do the math to break the encryption.

  • We are entering the post-quantum era, and we will need to develop new security protocols and security measures. If we don’t adapt, there could be catastrophic losses.

  • There are two main approaches to solving this problem. The first is factoring a very large number into its two prime numbers using algorithms. Computers aren’t very good at that.

  • The second is called quantum key distribution, which uses physics and photonic delivery. This is expensive and hard to scale, but work is being done to incorporate both of these tools into security moving forward.

  • There are now multiple points of communication between devices. Previously, there was only one communication line, so both the data and the encryption key had to travel together. Now, with wifi, cell access, and access through many apps, there are multiple paths to send data through to make it more secure.

  • To protect a series of data transmissions, they are now essentially trying to use a two-factor authentication type of technology, where it is an out-of-band key.

  • One of the problems with satellites is that once it leaves Earth you can’t send a repairman to go fix it. Because of this, needing to future-proof satellites has become important. Especially with the increasing number of satellites being launched each year and the decreased cost to do so.

  • It’s important to not only protect the information coming to and from the satellites, but also to protect control of the satellites themselves. Not only to protect imaging and communication, but also to make sure the satellite stays in its orbit and in its path.

  • This quantum computing is also prevalent in government and financial institutions, which is why so much research is being done. There are also some real safety concerns with how much technology has been integrated into our infrastructure.

  • Killware is the new ransomware that is focused not on extracting money or compensation, but is focused on actually destroying the resources that are being attacked.

  • The new Executive Order that came out about next generation cryptography is going to strongly encourage government agencies to invest in and find out how to use this to protect data. There are not currently any penalties for not doing so, but those will come.

  • This is because many of what we now consider normal technology, such as two-factor authentication, were first introduced as government protections.

  • Bad hackers are collecting information right now, even though they can’t decrypt it, to learn from it and to potentially decrypt it in the future when they have the capability to do so. The problem is happening now, even if it hasn’t fully come to fruition yet.

  • Quantum threat assessment is something that is happening now, to develop a threat matrix and identify your largest vulnerabilities. Tracing where your data is and where you lose control of it is important right now. In this moment, finding people who are willing to be a leader in this area is also important, since in two to three years this will be a necessity, not a differentiator.

  • Of course, performance degradation is an issue as well, and plays a key role in this research and development. The cost of transmitting the key can’t be too high.

Some interesting quotes from today’s episode:

“It’s basically, let’s encrypt the data with math that’s very hard to break. And the good news is that for 45 years we’ve done a better job of encrypting than the bad guys have done with their ability to decrypt that information. So it’s been an extraordinary run, but now we’re coming to a point where computers are able to do exactly that very calculation, easily and efficiently.” - Eddy Zervigon

“Now, if you look at even your cell phone, you’ve got wifi, and you’ve got your cell access, and multiple points of carriage - through your WhatsApp account, or your signal, or your Netflix account. So there are multiple paths, so why are we not incorporating the fact that we can now deliver multiple paths to separate the key from the data and make it that much harder for an attacker to be able to successfully decrypt information?” - Eddy Zervigon

“It’s basically two-factor authentication for encryption keys. I remember five years ago two-factor authentication was really cool stuff that you would do when you were trying to send a wire for $50,000. Now you can’t even buy concert tickets without two-factor authentication.” - Eddy Zervigon

“It’s important to protect it, not only as it relates to the telemetry tracking and control… but also the data coming onto the satellite and coming off of the satellite. That’s important because you’re talking about 4,200 commercial satellites up there, and that’s growing at about 20% a year.” - Eddy Zervigon

“If you think about it, the ability to deliver an out-of-band key anywhere in the world, especially as you’re talking about military and intelligence applications, is incredibly important. Especially in light of these oncoming advancements in computing.” - Eddy Zervigon

“Energy is one that’s extremely important, because that’s where you’ll see real, what we call killware, which is the next generation of ransomware. We’ve seen with the Colonial Pipeline what we could basically call a rudimentary attack can do and the ill effects that come from it.” - Eddy Zervigon

“One thing that we’ve seen as a result of the pandemic, is that we are extending the range of what is reasonably acceptable in terms of the edge of computing, and being able to access network controls - significant, important network access controls. That’s all great, but that comes at a cost.” - Eddy Zervigon

“‘Out of band’ means over a separate channel… If I’m in my bank account on the internet and I’m trying to wire my brother $15,000, and all of the sudden I’m going to get a token on my cell phone, a completely different communication - it’s a cell communication of the token that I now have to input into that. It’s the same concept.” - Eddy Zervigon

View Details

In this episode of Cyber Security Inside, Camille and Tom chat with ​​Abhilasha Bhargav-Spantzel, Partner Security Architect, about introducing cybersecurity to kids as well as making it more accessible to all. The conversation covers:

  • Different ways to get kids interested in cybersecurity from an early age, including competitions and education opportunities.

  • How cybersecurity is a very holistic field that takes knowledge and skills from many disciplines.

  • How perspectives on technology and cybersecurity have changed throughout the generations.

  • How organizations are working to increase diversity across gender, race, socioeconomics, and disabilities.

...and more. Don’t miss it!

Here are the links for cybersecurity opportunities that were talked about in the episode:

National Cyber League: https://nationalcyberleague.org/

Norcal Cyber: Mayors Cup (norcalcyber.org)

Cyber Patriot: AFA CyberPatriot Website (uscyberpatriot.org)

National Initiative for Cybersecurity Education (NICE) | NIST

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • With how important cyber security work is, and how much it is growing, how do we get the people to do the jobs? And how does someone get into the industry? How do we introduce younger kids to the topic?

  • Abhilasha loved math as a kid, and had some great opportunities to connect those to technology and security early on.

  • Cybersecurity combines many areas and topics. It is math and technology and computing, but it is also psychology and knowing how people might be manipulated. It’s a combination of many fields, all in one.

  • Thinking holistically is an important part of bringing in kids and helping them learn cybersecurity. They already have curiosity and ingenuity and energy. It is about sparking their interest to learn some of the technical pieces.

  • One way to get kids interested is to gamify the learning. Hold competitions, provide courses, and make it fun. There are many platforms doing this already. Another thing that works very well is older kids teaching younger kids.

  • Abhilasha can see differences between generations of people because of how fast technology grows. There is so much knowledge of systems and structures in some generations, but that can also come with less of an ability to try something new or look at something in a new way.

  • Younger generations might lack the technical knowledge and perspective of how technology has changed, but they will also go at something fearlessly and tirelessly until they really understand it. Working together across generations can be the best way to tackle these problems!

  • Because the younger generation grew up with technology as a part of life, and didn’t have to integrate it into their lives, there is sometimes a lack of understanding of how things work. That is why exposing young people early is important.

  • Because of how the internet has connected people, kids are collaborating with and communicating with people all over the world. They feel a bit differently about something like nation state attacks, because they have friends in those countries.

  • Kids now are very worried about privacy. They often think they are being recorded, or like their information is being documented quite frequently. This is something that needs to be addressed, not only because it is important, but also because they have trouble moving on from that idea to the next.

  • Focusing on diversity, in gender, race, and more, is very important and a big focus on many organizations right now. This could be focusing on kids, but also on people who are in other industries and offering training to these women.

  • There is a digital divide, and access is incredibly important. Making courses and resources available to many different communities is part of this. During COVID, this was seen in a more urgent, obvious way. Trying to get diversity in these cyber jobs also means starting early in underserved communities to provide resources and education.

  • Accessibility means not only technological accessibility but also for people with disabilities, who are blind, who might need to access it in a different way. Access is a big focus for many organizations rights now.

Some interesting quotes from today’s episode:

“Someone asked me just a few days back on what gives me hope. Because we deal with unrelenting headlines, we deal with serious cyber security attacks across the globe. You’ve seen the rise in nation, state attacks, organized crime, ransomware, you name it. It can be exhausting… And what gives me tremendous hope is when I work with the kids, and I see the light at the end of the tunnel.” - Abhilasha Bhargav-Spantzel

“And the kids don’t know these boundaries, you know? They are just working together to see how they can protect themselves.” - Abhilasha Bhargav-Spantzel

“The future is both, right? Not just red and blue, the ability to know both sides of it, some adversarial thinking. I think the kids love this model of ‘think bad, do good.’ So think what can go wrong, and then do what you can to protect against the wrong.” - Abhilasha Bhargav-Spantzel

“It’s not a type of kids or type of people who are working on computing. As we talked about earlier, it’s so multidisciplinary. Anybody from any field has something to offer. And your diverse mindset is so, so important.” - Abhilasha Bhargav-Spantzel

“For girls, even for certain underserved communities, making compute options available in different manners is a part of ongoing work. So it’s not just say Minecraft, or certain types of cyber competitions. Now you’ll see that these competitions are getting more inclusive and making sure they choose those majors.” - Abhilasha Bhargav-Spantzel

“Give them a fighting chance to get that cyber security job, which will help role model for other girls or their kids to take up that. So we need to do it in both angles as part of the education pipelines, but also for the gap that we have today - get more women, get more diversity in those.” - Abhilasha Bhargav-Spantzel

“One thing that we also want to work on is the kids who may be needing more of the accessibility; the kids who may be blind or have other aspects. Accessible cybersecurity education is something that we’re also working on to make it available for even broader communities. And they do brilliantly, by the way.” - Abhilasha Bhargav-Spantzel

View Details

In this episode of Cyber Security Inside What That Means, Camille has a conversation with some of the most important people in the cybersecurity conversation: kids. From the 4th grade to recently graduating college, Arnold, Mahika, Heidi, Yousef, Harrison, and Priyam shared their stories and inspiration for learning cybersecurity. The conversation covers:

  • Who the kids in the conversation are, and why they are important to the cybersecurity conversation.

  • How they got involved in cybersecurity, and the learning opportunities they have sought out.

  • Their perspectives on what is really important in cybersecurity, and how their thoughts are both similar to and different from those of adults.

  • Why cybersecurity is important for everyone to learn about, and ways people can do just that.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • In this episode, we hear from all sorts of young people, from 4th grade to recent college graduates, with cybersecurity experience ranging from 2 months to many years. They talk about what cybersecurity means to them, what they are learning, and how they are all learning from one another.

  • When asking the kids, they think that there are a lot of similarities in how adults and kids think about cybersecurity. They do think that a primary difference is that kids think more about privacy, and adults think more about infrastructure.

  • Something that brought together many of the individuals in this conversation was competitions and a team of friends coming together over a shared passion for cybersecurity.

  • In particular, they talk about Fuse Breakers, a group of kids trying to teach other kids about cybersecurity.

  • Kids talked about learning from people closer to their age being beneficial because of being able to speak a similar language and to share a similar perspective. They can teach each other in ways they understand.

  • Some of the kids gained interest in cybersecurity from gaming, others from friends, and others from family members. Some had opportunities to take classes in school, and others sought out opportunities to learn from their peers. They enjoyed learning from people similar to their age.

  • Many of these kids have been in a competition for cybersecurity. They will give you a computer with problems and ask you to fix them. There is also password cracking and more, and you can compete individually or on a team. A lot of experience is gained for these kids.

  • The kids made it very clear that no matter what they study or what career they go into, it has been clear to them that cybersecurity will be a part of their future. Each one found an interest in the field in a different way. Many of them talked about the overlap between jobs like being a doctor, a biologist, and others, and cybersecurity.

  • The young people interviewed talked about the progression of technology and how it has integrated its way into every profession and so many other places in life.

  • They talked about how cybersecurity affects us in our everyday lives. Harrison shared a story about his Instagram account getting hacked, and how dual factor authentication saved his account access. Cybersecurity is relatable and important for everyone.

Some interesting quotes from today’s episode:

“There was a shortage on gasoline in some areas because their system was hacked… If there wasn’t cybersecurity at all, then it would have more serious things that just gasoline, like hospitals could get hacked.” - Heidi

“One thing that I noticed is that, like, in most schools - or everywhere, really - one generation teaches the next. But why not the same generation teaching each other?” - Heidi

“So, cybersecurity to me isn’t just, like, competitions and fun. It’s also what comes to mind first: it’s exploiting areas and then improving it, which improves all platforms.” - Heidi

“I think a lot of it’s definitely collaboration, because in most competitions I’ve been in, it’s been very team oriented… It’s a lot of true collaboration, because you’re, like, in the same room, you’re talking, and bouncing ideas off of each other. It’s a whole team effort, even though there’s only one or two people on a system at one time.” - Harrison

“We learned about [cybersecurity] in school, and it was not really a big thing, but then cyber bullying came up, and I guess the way those two connected, that was really interesting to me.” - Mahika

“We’ve talked about all these competitions and really advanced topics, like encryption, password cracking, and that type of thing. And I just kind of want to point out how, like, relatable all this is. Even though it sounds loftey and over complicated, it affects us in our everyday life.” - Harrison

“Like, just a couple of weeks ago, someone tried to hack my Instagram. They got through a really complex password… And the only reason why I still have access to my Instagram account is because I had dual factor authentication turned on.” - Harrison

“When we were kids, we were told to be aware of strangers. But these days, it’s more like, be aware of cyber strangers. Because we are exposed to so many now on many platforms. So it’s important to know a bit about how to protect your privacy on your devices.” - Priyam

View Details

In this episode of Cyber Security Inside, Camille and Tom dive into the background and career development of Keren Elazari, The Friendly Hacker. The conversation covers:

  • How Keren got into hacking, and how her interests changed to friendly hacking over time.

  • The different varieties of hacking and how someone might get involved or choose a path in the profession.

  • Who has inspired Keren throughout her career, and how the diversity in the field of cybersecurity has increased significantly.

  • Advice for someone wanting to get started in hacking and cybersecurity.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • Keren Elazari became interested in computers at a very young age, using the school computers and robotics lab to learn more. This is how she became inspired.

  • She truly wanted to learn and find out more about the world. But sometimes, information was hidden behind passwords, so she taught herself how to access that information.

  • Her first inspiration to become a hacker was Angelina Jolie in a movie where she portrayed a high school hacker. The cast was a group of people that was diverse and that became heroes in their own story, and she could see herself in the characters.

  • From there, Keren was to be drafted into the military (there is a mandatory draft in Israel). When asked what she would be good at, she said she wanted to be a hacker for the army. She was sent to the Communication Security Department in the military.

  • This is the first time she saw the opportunity as a hacker to protect things, not just break them. She learned how to use her skills in a structured environment, and to embrace both the protecting and the breaking.

  • Keren has found herself in several situations where she was one of very few women in the room. A hacking conference, a role in the military. However, she was always able to find a role model or a connection with someone and show her talent.

  • Hacking requires a curious mindset. A mind that asks questions, that takes things apart, that pokes holes. And there are ways to cultivate that mindset with puzzles, challenges, and exploration. It also requires technical knowledge, of course.

  • Just like in the medical field, there are many specialities and types of hacking. You can generalize, and you can specialize, but you are exposed to various things along the way. The key is: what grabs your attention?

  • The makeup of people in cybersecurity has changed significantly over time. There are more women and more diversity in general in the cybersecurity field.

  • Recently, Keren has been working in bug bounty research. This is when any company of any size can work with hackers all over the world to raise security across the board. She is also working on a course for students going into management professions to have a security mindset.

  • What has surprised Keren about hackers recently? That they went after systems like healthcare during the pandemic. Although they go where the money is, the lack of ethics was surprising during a time when we needed healthcare so desperately.

  • Security is not about the destination. We will never get to a place where we are done, or that we win. There will always be a new vulnerability and a new criminal business model. However, Keren is optimistic because for the number of criminal hackers out there, there is a large number of friendly hackers helping fight.

  • The Leading Cyber Ladies network is working hard to introduce women to cybersecurity and friendly hacking. Keren recommends that no matter who you are, if you are interested in hacking you should reach out to your local events and meetups.

Some interesting quotes from today’s episode:

“As a girl, instead of a bedtime story, I would read the encyclopedia. True story! That’s how much of a nerd I am. And I had so many burning questions that when we received access to the internet in Israel - which happened around 1993 - it was amazing! It was like the world’s largest encyclopedia.” - Keren Elazari

“I had to teach myself how to access all of that information. And to me, it wasn’t a criminal act, it was a really passionate curiosity. I never for once realized that what I was doing could be illegal or wrong.” - Keren Elazari

“It was a group of people that represented hackers, but they looked like all kinds of people. And it really captured my imagination that high school kids could become the heroes of their own story through hacking. So that’s when I realized this is what I am. This is what I want to become. This is the world I belong in. It’s the world of hackers.” - Keren Elazari

“I had to learn how to use it to protect systems and not just break things. I was much better at breaking things and poking holes in systems than I was at building secure systems. And through the military service I had to practice both of those mindsets.” - Keren Elazari

“It was quite equalizing, because as a woman, I was serving with other young men and women. And it wasn’t about my gender in that particular role. It was just about the talent and the passion that everybody could bring to the job. And oftentimes I would be the only woman in the room or the youngest person in the room, or both. And I believe that through my passion for technology, I was able to overcome those odds and present a point of view that hacking is valuable and the hacker mindset is valuable.” - Keren Elazari

“I have more than 25 yeras of perspective in the cybersecurity world. The days of when I was the only girl there, those days have absolutely changed. Nowadays I see women all across different positions in cybersecurity; whether it’s entry-level positions, students at Tel Aviv University where I’m a researcher, or at different parts of our community… I see women all across the cybersecurity realm.” - Keren Elazari

“I do believe that we need all the help we can get. That security is a team sport. It’s not just up to one government agency or a technology company to solve on their own. My vision for the security world is one of a digital immune system where hackers play their part by helping identify vulnerabilities.” - Keren Elazari

“That’s the challenge, I think, with cybersecurity. We have to really keep our optimism… Cybersecurity and achieving security, it’s not a destination. It’s not a train that you get on, and then at the end, you say ‘I’m secure. I’m done.’ It’s a journey that’s continuous.” - Keren Elazari

View Details

In this episode of Cyber Security Inside What That Means, Camille takes a deep dive into ambient compute (also known as ubiquitous compute) with Mohammed R. Haghighat, Fellow at Intel.

The conversation covers:

  • How we are moving into an era of ambient computing, and technologies are emerging to transition us into that era.

  • What ambient computing might look like in everyday life, such as in a mall, at a traffic light, or an evening at home.

  • How privacy plays a role in ambient computing, and what needs to happen to make sure people are protected.

  • What the long term goals are of ambient computing and how it will adjust our daily lives.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • There are three main eras of computing: the first is the mainframe era. That was where you interacted with a computer using punch cards or an unintelligent terminal.

  • The next era was the PC, or personal computing era. In that era came smartphones, the cloud, and your own personal computers.

  • We are now in the early stages of the ambient era, where computing interacts with the ambient. Instead of interacting with a PC or your phone, you are interacting with the ambient.

  • Transitions between these eras are helped along by technologies rooted in the current era with elements of what is to come. For example, the internet started to hint about the cloud, in that you don’t have to store everything on your PC itself.

  • The transitional technologies transitioning us into the ambient era are things like the cloud, Internet of Things, and more. The direction we are headed is that you will no longer need to instruct a piece of technology to get something to happen.

  • For example, if you wanted to go speak at a conference, and you needed to go to the store, an intelligent store would know your intention and what you would need. Specific things would then be advertised to you. Perhaps you like to minimize cost, or wear specific clothes - it would know.

  • Privacy is, of course, a major concern with ambient computing. The ambient should be able to support the level of privacy you want to uphold. There would be a mechanism to express your privacy needs, and things will happen for you.

  • For a comparison today, think about searching on Google. Right now, you don’t even have to finish searching - Google will often predict what your query will be. Imagine that with ambient computing. If you want something, the search will be there, but it will also predict what you want in advance.

  • Something that is very important is interoperability (devices working collaboratively together). The AI will need to work together across different devices. Discoverability is also important, while remembering privacy, so that ambient technology can work in public spaces as well.

  • For ease, devices would need to interact with each other without having a pre-prescribed program to do so. Because you move your computing with you, it will be important for devices to provide information about themselves and to take in information about other devices so they can interact.

  • Part of how this could work initially is carrying around some sort of beacon that constantly broadcasts a URL. You can decide what is on that webpage that is visible to others. Of course, how you access the rest of your information is part of the privacy that surrounds all of this.

  • Once you have your device near a beacon, it can communicate with it. Say a dress in a store has one of these beacons, and it has the price and other information about it. Your device can communicate with it without you ever being involved.

  • From there, the entire mall is broadcasting via these beacons, so can my artificial intelligence then optimize what I actually see based on what it knows about me?

  • We have a long way to go to get there, but the transitional technologies have begun and ambient technology is becoming the main type of computation. It is the direction we are headed. The protocols and privacy concerns are being actively discussed and communicated about as the technology is developing.

Some interesting quotes from today’s episode:

“Technologies from eras could co-exist; in the PC era, we still had mainframes and we still actually have it now. And now in the ambient computing era, we would be having PCs, and we still might have main computers. But the dominant form of computing is changing.” - Mohammed R. Haghighat

“In the ambient computing era, user interface is going to be primarily AI - artificial intelligence. Ambient would be intelligent; it would know about you and there will be a lot of preparatory things that ambient could do on your behalf.” - Mohammed R. Haghighat

“The ambient knows about you, about your profile, about what you desire; when to turn the light on, when to play music for you, et cetera. And you will have the option of configuring and setting things the way you want, but in a natural way.” - Mohammed R. Haghighat

“The form of a UI is basically advancing, whether it would be through something you would get on your phone, or on your screen, or on your wall, or on your smart glass. They are all possible, but technologies have to be developed, and the best solution will be the one that survives and thrives.” - Mohammed R. Haghighat

“It is inconceivable that one particular vendor can own all the devices in the world. So the devices have to be able to work with each other, they have to be interoperable, their properties and capabilities have to be discoverable. The same way that basically a search engine could go and look at a page and figure out what is in it, your devices should be able to look around and find the information and services that are in the ambient.” - Mohammed R. Haghighat

“In the ambient era, you are moving your computing with you, and the way you will be interacting with an intelligent ambient depends on what is surrounding you, what is available to you. You may have your phone with you or not, or a display might be available to you or not. So dynamic customizable for user intelligent information would be flowing around in that era.” - Mohammed R. Haghighat

“Devices and gadgets are all consumers of this information and producers of the information. And of course for that, one needs to establish a secure and private mechanism.” - Mohammed R. Haghighat

“The main notion there is having the ability of controlling the ownership and revenue out of the data, which is valuable - that is by itself a whole discussion.” - Mohammed R. Haghighat

“The big deal, I think, is that it is ambient that is becoming smart, that it’s becoming intelligent. It is actually a learning thing. And it records things about me, it knows things about me, it anticipates on my behalf. And eventually we’ll get there.” - Mohammed R. Haghighat

View Details

In this episode of Cyber Security Inside, Camille and Tom chat with Greg Lavender, Chief Technical Officer at Intel, about his career path, his experiences in banking and security, and his intriguing stories that illustrate cybersecurity ideas. The conversation covers:

  • Greg’s career path from his interest in computers as a kid, to his coding career, to his experience in banking security, to his current position at Intel.

  • How you always need to assume you are going to be targeted, especially as a business or corporation, for cyber attacks.

  • Some of the procedures and security measures you follow to stop a cyber attack as soon as possible.

  • How cyber security is changing because of the increased amount of data and product, and the increased usage of both of those.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • When we think about security and security careers, we aren’t talking about a theoretical idea; it is something that affects people daily and can have huge impacts on lives.

  • This interview is with Greg Lavender, Intel’s Chief Technical Officer. He was introduced to computers early, and many years of coding professionally has led to his current role with the company.

  • Greg realized early on that what makes a computer fun is what you can connect it with and who you can engage with. It opens up new possibilities and opportunities for development.

  • When he worked at banks, he really began to understand what goes into cybersecurity, and what you need to prepare for. Whether it’s cyber attacks, phishing schemes, or malicious actors, a lot can come up when you are dealing with money. This is especially true in an age where we have mobile banking and employees working from home.

  • Resiliency in security has been a topic that has come up more and more. Rather than constantly being in a cycle of detecting and protecting, we need to be working towards a mindset of learning from breaches and incorporating what we learned.

  • One of the keys to responding to and preventing wide scale cyber attacks is a network that is agile and flexible. If you have a network that you can quarantine part of without taking down everything, you are in a much better position. And it has to be seeded into every part of your critical infrastructure.

  • An added difficulty is that the surface area of possible attacks is constantly growing. Whether it be the cloud, data in RAM, encrypted data… We are creating new data at a high rate. You have to assume you will be attacked, and learn how to mitigate it.

  • Greg tells several stories about what he has experienced in his position and what he has learned from it. There are methods to detecting and eradicating malware and other attacks that he has witnessed and used.

  • One story that he told was about a CFO approving a request for a wire transfer that was fraudulent. He walked us through the process that was needed to address the situation, which included notifying the FBI, following jurisdiction, and working with the Financial Crimes Enforcement Network, or FinCEN.

  • Business and large corporations are not the only ones at risk for cyber attacks and phishing. Individual consumers are also at risk. Attackers target everyone.

  • Something that is overlooked is that oftentimes the worst and least secure usernames and passwords actually belong to security people. “Admin” for username and password is not secure, but it is very common. Part of what needs to happen is education and checking each other to ensure these gaps are not left.

  • Trust is a very important part of security and needs to be included in each part of the security design process. It can’t just be about making your own individual product secure, but about bettering security entirely.

  • Greg shares an interesting story about his experience with device theft at an airport. He talks about how physical security and cyber security intersected to find his device. It was a great example of executing a kill chain.

Some interesting quotes from today’s episode:

“My father, he put me in a special school in Washington, DC, where I learned binary hexadecimal octal arithmetic in the third grade… I didn’t know what it was or what it was used for. I just knew that it was sort of this kind of funny math that you could do and come up with crazy numbers.” - Greg Lavender

“I still remember the day, you know, when you would do all your downloads at night so it’s not to congest the internet during the day.” - Greg Lavender

“When you work in networking, you work in security from the get go. My whole career, it’s like security and networking have gone hand in hand.” - Greg Lavender

“I got a real live awakening to the real world of state-sponsored cyber attacks, malicious actors - both insider and outsider - money laundering, and of course anti-money laundering mechanisms, phishing attacks, you know, bank fraud. I mean, it’s pretty scary actually. Just the sheer scale and size of what’s required in a large global organization with employees running around with mobile phones and laptops - how to secure the edge and then how to protect the core.” - Greg Lavender

“A bank certainly understands how to make computing resilient, networks resilient, software resilient, but it’s very expensive. And most organizations can’t afford it. And this is why the attack surface is so porous.” - Greg Lavender

“You have to assume that the advanced persistent threat is always there. You never feel secure. I remember briefing the board once and they said, ‘Greg, can you give us the guarantee that we’re not gonna be hacked?’ I said, ‘No, I can’t.’ …You’re only as good as the last attack.” - Greg Lavender

“Every consumer - not to scare everybody - but every consumer is at risk of these fake wire transfers… So if you get phished, you know, for making some payment that you think is legit, but it’s not legit, your recourse for getting that money back is near nil.” - Greg Lavender

“There’s an old saying about home security. You just make your house more secure than your neighbor’s. Right? But if we just do that, you know, we didn’t really solve the problem for the neighborhood. You solved the problem for your house, but you didn’t solve the problem for the neighborhood.” - Greg Lavender

View Details

In this episode of Cyber Security Inside What That Means, Camille takes a deep dive into the topics of developers with Bill Pearson, Vice President in the Internet of Things Group at Intel, and GM of Developer Enabling. The conversation covers:

  • What the role of a developer is, and how it has changed over time.

  • How security plays a role in a developer’s mindset and job.

  • The balance and tradeoffs between security and user experience in software development.

  • How artificial intelligence has become a part of every software developer’s job.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • The definition of Developer is, quite simply, someone who develops something. This is often a software developer, but it can also mean hardware developers. Hardware developers work both on the small scale like phones, and can work on large scales like industrial manufacturing.

  • A developer has a lot of choices and a lot of different roles and responsibilities depending on those choices. Perhaps they are more interested in consumer tech and applications. Or maybe they prefer larger devices like robot arms.

  • This will determine where they work and how they are hired as well. Developers might work for hire by contract, at a startup, or at a larger company.

  • Learning to break things is also part of a developer’s job, so they can think more about security and do testing before what they have developed is released.

  • There are tradeoffs between security and experience in any software development. How easy is it to access things? What needs to be protected, and what is the best way to protect it?

  • One example is where to put a login on a site. One method is to put it at the beginning, so that nothing is accessible until you log in. Another is to put it somewhere in the middle, where you can access a catalog but can’t download anything unless you log in.

  • Thinking about security from the very beginning of development is incredibly important. A willingness to share and work together can also impact the quality and security of what you have developed. Consultants can come to test and try to break your product.

  • Trust has become an important part of security, as is changing up types of security and encryption. Because the things that developers are working on are so varied and the problems they are trying to solve are so different, helping the developer get their job done is the most important thing. From there, you go a million different directions for security.

  • There are reference implementations for security and development that are most often in a vertical-specific use case. The more that developers can be provided with a specific solution to their specific problem, the more it resonates with them. It gives them a “why” to the solution they are exploring and the model they are using.

  • Developers are much more interested in AI these days. It helps protect algorithms, increase security, and collect and analyze data in a secure way. Another thing that has changed is that there is more integration in teams working on applications handling data and security.

  • This is because AI is found in every piece of software engineering now, from self-driving cars, to phone applications, to intelligent machines, we see it everywhere.

  • What does it mean to be ethical in AI? There are new sets of standards and practices that have had to be developed and are being developed that are being built into education and agreements to address this.

Some interesting quotes from today’s episode:

“Back in the day, I had people looking at C++ development, and that was the thing so they became experts. The very best developers keep learning every day. Now those same developers might be doing Python and building AI applications.” - Bill Pearson

“So it’s this idea of shared security as well, where not only do I need to expect that the providers have the tools and resources that I’m using think about security, but that I’m thinking about security in my day-to-day activities including trying to break things and penetrate my own systems.” - Bill Pearson

“I do think that developers every day are trading off where and how to approach security versus how to make an experience that their customers are going to want to use.” - Bill Pearson

“One thing though, that I know is really important, is to make sure that whatever stance you take on security as a developer, that it’s thought about from the beginning.” - Bill Pearson

“You see people paying more attention to hardware or software root of trust - that really powerful root of trust. And then use that as a basis for building out the rest of their security infrastructure.” - Bill Pearson

“The notion is that by showing them how to build that solution, we just help get their mind around what types of hardware I needed, what types of software, how I implement security, how I implement AI, how those two work together - and with that orientation, they can then get a solid example of how to implement it.” - Bill Pearson

“In the past, what I’d seen is there’s a lot of developers who are kind of in their niche technology area… Today, what I’ve noticed is that, regardless of the use case, regardless of the industry, regardless of the technology, AI seems to be showing up for developers.” - Bill Pearson

“To me, that’s sort of the nature of developers. It’s their creativity, their innovation, and their willingness to try new things and see what sticks. So you always end up, then, with some technology that you’ve built, and then the developers are applying it to new and creative ways to their own applications. And to me, it’s one of the most fascinating and satisfying things about being in this world with developers.” - Bill Pearson

View Details

In this episode of Cyber Security Inside, Camille and Tom get into Modern Privacy Controls with Pierre Racz, President at Genetec. The conversation covers:

  • Modern privacy requirements and surveillance best practice.

  • How to protect your company, by protecting your customers’ personal information and privacy.

  • Privacy considerations for consumer data processing and the companies collecting personal information.

  • Applying identity management and basic cyber security governance as best practice

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • Data management and protection is something that is really on the forefront for most industries, and particularly the IOT business

  • Genetec is number one worldwide for physical security networked video solutions, and number two worldwide for physical security access control solutions.

  • Genetec is currently in over 200 international airports, in addition to many schools, hospitals, public infrastructure – particularly in G-18 countries.

  • Almost everything we have today has a computer in it and cameras are no different. Some of the stuff that is produced for consumers is inexpensive, but doesn't have computing power to manage security, sometimes the software is a bit on the sloppy side. The best manufacturers have hardened their cameras against cyber security breaches.

  • Putting junk IOT devices on the internet, not only can put your system at risk, and can damage the ecosystem for all of us

  • Bono Pastore Principle: if you're going to be a good shepherd of your IOT devices, put quality stuff from trustworthy manufacturers on the internet.

  • To monetize the internet, advertising emerged. Personal information and data can target customers, then data becomes a commodity. But who owns the data? When does “free” become too expensive?

  • With regards to personal data and privacy, we have to rethink whose information, is it? and who has the right to help themselves to it?

  • Genetec invented “privacy protector” and are the only company that has 12 years accreditation by the European Union privacy guards. This protects citizen privacy.

  • The Genetec system requires two trusted people with security keys to access HD video footage, otherwise encrypted footage is unrecognizable. Both of these people have to agree that the incident is severe enough the right to privacy is overridden by the right to be safe.

  • Soon companies will be held liable for misuse of customer data. Now is the time to make sure software is secure and protected.

  • We need laws where the executives are personally liable for the stewardship of this information, because this information creates value in our society. And if they don't put in the proper governance of this, they should be held liable.

  • Strong multi-factor authentication and hardened crypto devices are ideal, to avoid password breaches.

  • Identity management and basic cyber security governance are good basic practices that people should be implementing anywhere in any company.

  • What do drinks with Sting, punching falcons and magnetic screwdrivers have in common? They are all fun facts from this episode of “Cyber Security Inside”

View Details

In this episode of What That Means, Camille discusses Silicon Threat Detection & Intel® Threat Detection Technology with Ram Chary, Senior Director of Engineering, Intel Software & Advanced Technology Group at Intel. The conversation covers:

  • Cyber threat detection at the silicon level

  • Mitigating risks from malware and ransomware attacks

  • Applying PMU (Performance Monitoring Unit) to CPU across all Intel architecture

  • Advantages of using Intel Threat Detection Technology

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • Ram Chary and his team at Intel invented threat detection technology

  • Ransomware used to be on the fringe of security threats, now it touches everyone from small business to enterprises and everything in between – including supply chain.

  • Intel has utilized CPU programming to detect malware and ransomware threats

  • Machine learning algorithms are also trained to detect false positives

  • Ransomware most often will lay dormant until it can connect to a backend server somewhere to get encryption keys. Intel Threat Detection is trained to find those dormant programs and attack them before they infect entire enterprise systems

  • Intel CPUs have a “performance monitoring unit” (PMU), which is on the CPU and it's tracking micro architectural details happening in real time.

  • Machine learning models are only as good as the data they are trained on.

  • 2 Major Advantages: 1) Using PMU within the CPU provides the ability to track and detain malware before it encrypts the system, or gets a hold of any information; 2) Working with our partners enables us to update for new threats as they occur

  • The PMU (Performance Monitoring Unit) is across all Intel CPU’s from PC to server architecture

Some interesting quotes from today’s episode:

“The whole idea of detection is we can give this immediate notification to our partners to do remediation.” – Ram Chary

“Every day you have to be focused: You have to be deliberate in what you do and use the tools that are available. Use the biometrics; if it's second factor authentication, use it.” – Ram Chary

View Details

In this episode of Cyber Security Inside, Camille and Tom chat about digital transformation and security with Darren Pulsipher, Chief Solutions Architect, Public Sector at Intel. The conversation covers:

  • How the move to remote work has sped up not only the process of using the cloud and digital transformation, but also the willingness to dive into the idea of digital transformation.

  • Companies have a lot of decisions to make when it comes to security breaches, and need to consider many factors.

  • Who is responsible for data security and access in the cloud, and why.

  • How automating security might play a positive role in the future.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • With digital transformation, people often talk about the cloud. But there is more than one cloud, and they have to communicate with each other. Keeping that secure is a large part of this conversation.

  • Before COVID, there was a lot of confusion about whether to go to the cloud or not. But COVID accelerated the timeline of the cloud and digital transformation. The remote workforce became a necessity and an asset.

  • Now, it’s all about security given the number of breaches there have been over the past 18 months. And it has been new security breaches in places we weren’t expecting, such as meat plants.

  • Sometimes security breaches are not just about if they pay ransom or not. Sometimes it’s about who they tell and if they make it public.

  • When Target was breached, they made the information public quickly. Others have sat on the data for a while until after they were able to fix the breach. Those are big decisions to make, and it is about more than security - it’s also about PR.

  • Darren’s prediction for the future of CIOs is that they move away from being Chief Infrastructure Officers and move into being Chief Information Officers. They will be more focused on driving competition and innovation inside companies.

  • There is a line that companies walk concerning privacy. If they are too transparent, they would be giving information about where data is locally housed or where it is in the cloud, which could be dangerous. On the other hand, there is a desire for transparency and explainability in the public. Legal heps CIOs walk that line, and reframe the discussion to focus on the fact that the data is secure, not where it is secured.

  • There is misinformation about the services that cloud service providers give. They are not responsible for data security. If you are storing something in the cloud, you need to be encrypting it and managing access to it.

  • The type of security and cloud use completely depends on the product you are offering and the industry you are in. A bank will handle cloud access very differently than a startup trying to get people engaged.

  • A mentality change needs to happen to really have security embedded in development and structure. Part of this is that security needs to make it easier to secure things for developers to help them get on board, and to not slow them down as much and create as much frustration. We have to make it easy.

  • Hackers are getting smarter and doing more clever things to get the information they need. And our response is automation so that security can happen automatically without human interaction. We are moving away from click ops and moving more towards a fully automated security center.

Some interesting quotes from today’s episode:

“Do I go to the cloud? Do I stay on-prem? COVID hits - it’s amazing what a pandemic will do to focus. Plans they had to move everyone to Office 365 in the next three years happened in three weeks. People were now looking at the remote work force as an asset, not as a detriment.” - Darren Pulsipher

“Because of the move to cloud so much in the last 18 months, they’re okay now if something gets infected. They’ll just shut it off, and move it somewhere else. They’re concerned more about their data. Is their data going to be held ransom? Is someone going to take copies of their data and release it out into the public?” - Darren Pulsipher

“I think the big emphasis is on information management, information structure - and that doesn’t mean throwing everything into one data center. There’s just too much data everywhere. So now it’s the job of information officers to find where the data is.” - Darren Pulsipher

“It’s funny, when I talk to individuals about privacy, they get very concerned. And then I see them on Instagram sharing pictures, and I’m like, “Okay.” So there’s a perception of privacy.” - Darren Pulsipher

“I think we’re at the point now where I don’t think it really matters where, as long as it is following good security best practices.” - Darren Pulsipher

“If you have data in the cloud, you’re responsible for the security of that data. It’s not the cloud service provider. Which means you should be encrypting that data in the cloud.” - Darren Pulsipher

“If you’re not building security into the products you’re developing, and they’re bolted on afterwards, you’re still going to get these Frankenstein applications out there and security will be a constant battle.” - Darren Pulsipher

“Security postures can happen automatically without human interaction. And the companies I start seeing doing that are having quite a bit of success in deploying new applications faster and with more security.” - Darren Pulsipher

View Details

In this episode of Cyber Security Inside What That Means, Camille jumps into the conversation on cybernetics with Genevieve Bell. For International Women’s Day, the podcast is honored to have Genevieve as a guest, who is accomplished, thoughtful, and influential. Genevieve Bell is Director of 3A Institute, Sr. Fellow at Intel, Director of School of Cybernetics, and Distinguished Professor at Australian National University.

The conversation covers:

  • What cybernetic technology is, the history of it, and what is happening with it and artificial intelligence today.

  • How computer science is meeting climate change, privacy, and social sciences in the field of cybernetics.

  • How cybernetic technology is intricately connected with history and changing perceptions of privacy and control.

  • What sustainability looks like in cybernetics and cyber security.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • Cybernetics has been around for decades - over 80 years. It may sound familiar because of science fiction. However, it began as science fact around World War II. It was created to help manage the problem of control and communication in machines and humans.

  • The group of people who make decisions and study humanity were worried about what technology could do in a destructive way. Cybernetics was supposed to be a framework for how we would manage technology and would create a critical infrastructure.

  • As we have moved into the 21st century, the way we think about control has changed. Cybernetics is about understanding how things flow and ensuring an ability to stop it from unfolding if it looks like we need to.

  • Technology is already in our bodies - vaccines are a good example of this. Again, the key thing in cybernetics is control and the ability to have control over your own body and decisions. Because of how history has unfolded and prejudice has played a role, there are people who have less control - we need to ensure that consent is a part of the process, but also asking questions about who is benefitting from the technology.

  • Each time we develop technology and computer systems to make things more efficient or convenient or to better do specific tasks, we have to look at every angle. How do self-driving cars impact pedestrian safety? And how does that impact people with physical disabilities trying to cross the street more slowly?

  • Surveillance and data collection are a huge part of both AI and cybernetics. Often, surveillance can be good, such as when we surveil wildlife populations to ensure they are healthy, or our water systems to ensure everything is working properly. A different approach needs to be taken with humans. Many large companies have made decisions about what technology they should or shouldn’t be using because they are waiting on policy or legislation or settings.

  • Because how people think about and manage privacy has changed over time and will continue to change, designing technology and AI systems for privacy is very difficult. People don’t just worry about their personal data and cyber threats, they also worry about what judgements will be made about them with that data.

  • Data is always based on what you have done in the past, which worries some researchers. This means that it is less likely for you to see something outside of the frame of reference you already have, which might limit your ability to grow and change and connect with others.

  • Sustainability plays a large role in cybernetics in a few ways. The first is knowledge, and making sure that many people have that knowledge and a role in the development of the technology in the community it is being used in. Then it is sustainable over time in a healthy way.

  • But it is also about climate change and environmental impacts. We have to ensure that technology is not contributing to the environmental problem.

Some interesting quotes from today’s episode:

“It’s a term that kind of noodled around in science fiction for a long time. The reason we got it in science fiction, however, is it started in science fact.” - Genevieve Bell

“And coming out of World War II, it was really clear that computers weren’t just going to be big machines that crunch numbers to aim guns. They were going to be objects that could sit inside of decision-making frameworks and industry and scientific discovery, and potentially even inside people’s homes.” - Genevieve Bell

“It lets you think about systems. It’s a systems level approach that argues pretty persuasively that you can’t think about technology without thinking about humans and the environment.” - Genevieve Bell

“Think about the ways in which certain bodies have had work done to them without their consent. And you start to realize that the notion about the most recent nanotechnologies over various forms of computational technologies in our bodies are actually part of a much longer legacy where those questions are already highly charged.” - Genevieve Bell

“What information is being collected? Who has access to it? What sense is being made of it? How is that sense-making being used for further determinations?” - Genevieve Bell

“Whether that’s the lightweight things that sit inside Netflix, or inside dating apps, or inside Amazon, which is really about determining who you are and what you’d like in order to work out what you might like next. So think about that, and use the word ‘desire…’ How do we help satisfy your desires for things or people or stuff.” - Genevieve Bell

“Privacy is a relatively new term, and our notions about what is private and what isn’t are incredibly fungible and have changed remarkably, even over the arc of our lifetimes. And I imagine it will continue to do so.” - Genevieve Bell

“One of the problems with the way data is often mobilized is that what it does is that the choices you are given at any kind of moment in a recommendation engine, for example, are based on what you’ve already done. So it’s always based on the past. And one of the things that happens there is that you can then get locked into who you’ve been and limit your possibility of growing, changing, being something different.” - Genevieve Bell

View Details

In this episode of Cyber Security Inside, Camille and Tom conclude their interviews from Intel’s AI Everywhere conference by talking with Nufar Gaspar, Director of AI Everywhere at Intel and Product & Strategy at AI Group. She is also the head of the conference itself.

This conversation is part 3 of a 3-part series from AI Everywhere, ​​an internal Intel initiative and conference which includes keynotes, tech talks, tutorials, and an AI expo. The objective of this internal meeting is to encourage Intel employees to apply AI thinking and approaches to their jobs.

The conversation covers:

  • Tips for creating and leading AI training and conferences from the head of this conference.

  • Discussion about the methodologies that already exist for implementing AI.

  • The importance of AI experts and business experts collaborating and leveraging each other’s skills when implementing AI.

  • Advice on not reinventing the wheel, since AI and its methodologies have been around for longer than one might think.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • Although the hype about AI is relatively new, it’s actually been around for many years.

  • One of the big reasons that a company might fail in their implementation of AI is that they don’t properly select what to work on. They either don’t have the experience, it isn’t feasible, or not everyone agrees that what they are working on is critical. You need to do your due diligence to make sure that you are working on something that will be both feasible and successful.

  • There are well-established methodologies for implementing AI that have been around for a couple of decades. Having your team be educated in these is important so they use the right tools and approach it appropriately.

  • It is also important to make sure the business experts and the AI experts are collaborating and doing what they are experts in, meeting each other halfway.

  • If you are thinking about having your own conference, training, or events around AI, the people who put on this conference recommend catering to a vast range of skills and experience levels. They also recommend diverse content and training.

  • You don’t necessarily need to build in all sorts of new infrastructure and backend to introduce AI. Usually there is already data being collected for other things, and IT can support that workload.

  • Introducing AI requires faith from business partners and requires you having a strong partnership and collaboration with them so it is less intimidating and more transformational.

  • Something else to think about is how to do AI and machine learning at a lower scale and lower cost so that it is more sustainable for organizations.

Some interesting quotes from today’s episode:

“So, first of all, I think a lot of it goes back to training and making sure that people not just learn only the Intro to AI course, but rather learn the BKMs and the methodology and how to properly go after exploring a new idea with AI.” - Nufar Gaspar

“Having good data is not just for AI. It’s also for analytics and automation. And actually, a lot of the work that is usually being done by IT is to redesign the business process - really structure the data. So once that is done for it, even if it’s done for other purposes, usually it will be easier to introduce AI.” - Nufar Gaspar

“It’s a very high-end technology that sometimes requires even more high-end than ideal kind of workloads or IT systems. It requires a lot of faith from the business partners.” - Nufar Gaspar

View Details

In this episode of Cyber Security Inside, Tom and Camille dive deeper into artificial intelligence with Dr. Amitai Armon, Chief Data Scientist in the IT Artificial Intelligence Group at Intel. This conversation is part 2 of a 3-part series from AI Everywhere, ​​an internal Intel initiative and conference which includes keynotes, tech talks, tutorials, and an AI expo. The objective of this internal meeting is to encourage Intel employees to apply AI thinking and approaches to their jobs.

The conversation covers:

  • How artificial intelligence is being used in the industrial setting and what the goals of AI are there.

  • Who these data scientists are who are developing AI models, and the skills and mindset they need to have to do it successfully.

  • How AI is not being developed to replace humans, but to help them be more efficient and focus on what humans are better at.

  • What is holding up AI development and where it might go in the future.

...and more. Don’t miss it!

If you are interested in reading the article referenced and written by Amitai, you can find it at this link: https://www.calcalistech.com/ctech/articles/0,7340,L-3929057,00.html

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • AI is most often used in consumer software right now, such as in Google and Facebook. This team is focusing on using AI in an industrial setting by trying to make the machines smarter and the factories smarter. The goal is to make the manufacturing process more efficient and more useful.

  • The development of this AI takes people who are actually building the AI models, but also people who are building the product around the models, storing and collecting data, and engaging with customers to learn what needs need to be met.

  • A data scientist who builds the models needs to be passionate about data science and modeling and building products.

  • When talking about AI in different situations, say like a hospital, an AI is not replacing a doctor. It is just making the processing large amounts of data part easier. Humans are better at inferring from data, so they don’t need as much. But AI can process much more data. They work together.

  • AI does great with lots and lots of information. You can give it lots of x-rays, each with some kind of indication of whether the x-ray meant something bad or not, and the AI can learn from it. But humans can learn from 5 examples about what an x-ray should look like and understand it. AI complements people. Humans extrapolate from little information, and AI processes and interprets from a lot more information. Both are valuable.

  • None of the researchers and scientists on this team believe that AI will replace humans - not anytime soon. Humans still learn better and can infer. But AI can still be helpful in many ways.

  • There are some things an AI will never really be able to do or understand, like loving a child or feeling hungry. So it will continue to evolve to get really good at specific tasks, but it is a very long time until we have a general intelligence that can really rival that of humans.

  • It is important for people to know about AI and how it works, because it is already used so much in our day-to-day lives. In money, medicine, the internet, and more, AI is already used. So we should make sure it is used for good.

  • And who decides what is “good?” Currently, humans. Robots won’t be making those decisions.

  • What is preventing the development of AI from going much faster? It’s really 3 things: not having enough AI professionals (it isn’t a required course in CS degrees), computer development needing to happen, and also understanding the “secrets of nature” (Amitai). Do we know how learning and reasoning really works, or how it should work? That’s a hard question to answer.

Some interesting quotes from today’s episode:

“Not only are the machines and factories becoming smarter, the processors are also smarter. Instead of behaving the same way in every computer, they adapt themselves to the usage of the computer.” - Amitai Armon

“We need talented researchers who can do the technological breakthroughs, but can adapt them to reality - to not try to just publish a paper. I would say there are dozens of thousands of papers published in AI every year.” - Amitai Armon

“AI works differently than humans. The way that AI learns is different.. The human brain still works, learns, in a more sophisticated way than AI systems learn.” - Amitai Armon

“AI, in a sense, complements people in what it is able to do. In Intel, we believe that AI empowers people. People who use AI are able to do more and focus on what they are good at and what they like to do. Not on the tedious things that AI does better, but on the things we have advantage in.” - Amitai Armon

“The bottom line is that humans still have a learning mechanism which is far better than the learning mechanism of neural networks or other AI models. The human learning mechanism evolved over a billion years of evolution… Still, we don’t understand how humans learn, and AI learns in a much less efficient way. But it still has advantages.” - Amitai Armon

“I think it’s important for people to be educated about AI, right? It’s all around us. It’s approving our credit transactions, it decides what we see on the net, on the web. So it’s important for people to know more about it.” - Amitai Armon

“The smartest machines will probably also have no desire to conquer the world. They will just play chess or play Go… We shouldn’t be afraid of those apocalyptic scenarios of robots waking up and conquering us.” - Amitai Armon after saying that the smartest humans don’t want to rule the world, so the smartest robots shouldn’t either

View Details

In this episode of Cyber Security Inside, Camille and Tom chat with Itay Yogev, GM of Artificial Intelligence at Intel IT. This conversation is part 1 of a 3 part series from AI Everywhere, ​​an internal Intel initiative and conference which includes keynotes, tech talks, tutorials, and an AI expo. The conversation covers:

  • What is happening in artificial intelligence right now, and that it might be more developed than most people think.

  • Areas that AI is being used in, including quality improvement, sales assistants, and finding bugs.

  • Where AI is heading in the future in the workplace.

  • The ethics and privacy concerns on the minds of the people building the AI.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • AI is not something that is coming in the future in some science fiction setting. It is here now, helping solve problems, improve companies, and create algorithms.

  • Part of what AI is being used for at Intel is quality improvement, since being able to find bugs is so difficult and AI can help with that.

  • There are also AIs that are being developed to be sales assistants to help salespeople understand customer needs and be more accurate and efficient in doing that.

  • Future AI development could involve the judgment that machines can apply. Today that is pretty narrow in comparison to humans, when talking about problems we haven’t seen before.

  • A lot of goals for AI in the next few years involve measurable targets like finding a higher percentage of bugs, helping humans do their jobs better by improving efficiency, and things like that. And then some goals involve creativity and judgment.

  • For people who work in AI, privacy should be a huge part of their work. This group is ensuring they are not collecting any personal information and are careful about the information they collect and use.

  • Many people might think that AI is not really happening at the level that it is. But really, we are already using it in our homes and relying on it. By focusing it on specific tasks for the workplace, these groups are just expanding that idea. There is also some resistance to AI development, but a lot of that is dwindling. It is now about making sure that humans retain control in terms of both ethics and algorithms. They want to make it the right way.

  • One big reason resistance to AI has lessened? It works. It yields results. It can take away the mundane tasks that people don’t like to do, and can point people towards areas that are value-add. It allows people to focus on what really feels valuable. This is building trust so that development teams can work more closely together with the teams they are building the AIs for.

Some interesting quotes from today’s episode:

“I think for many people, AI is like a crystal ball. People think it’s either a hype or it can solve everything. But, like in many other cases of technology, we are somewhere in the middle.” - Itay Yogev

“What we know for sure is that in the next 3 to 5 years, we could make like a 10x bigger impact inside of Intel with AI in terms of relieving what we call the human bottleneck. By building smarter and smarter AI tools that are partnering with our engineers.” - Itay Yogev

“Privacy matters a lot. People that are in the AI field are aware of its power and what the future looks like. They really should care a lot about it. We are lucky to work in a company that has established a program that is ensuring an ethical AI.” - Itay Yogev

“I think 2 to 3 years back, there were a lot of concerns or even people resented or were struggling to accept the fact that AI is becoming a thing in the day-to-day life at the workplace. At home, it’s already happened to us - we are relying on that. But in the workplace, there was a lot of resistance to this change a few years back.” - Itay Yogev

“Now the challenge is becoming more on how much can I rely on these systems and solutions that are becoming more and more intrusive, and make sure that humans still retain a high degree of control on things that we want to control.” - Itay Yogev

“When it works over time and yields value, it creates an appetite for more.” - Itay Yogev on why resistance to AI has lessened

View Details

In this episode of Cyber Security Inside What That Means, Camille talks with three experts in very different fields all coming together to look at intelligent systems and emotion recognition research. Her guests are Saurav Sahay (Staff Researcher and Manager of Multimodal Dialogue and Interactions Team at Intel Labs), Sinem Aslan (Research Scientists), and Dawn Nafus (Anthropologist). The conversation covers:

  • What emotional recognition research is and why it is such a collaborative area of research across disciplines.

  • Areas this research is being tested and used in, including driving, classrooms, predictive text, and in medicine.

  • What types of sensors are used to collect data for emotional recognition.

  • The ethics and questions behind this research and what the researchers are doing to address them in advance.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • Emotional recognition research gets into a place with ethics and insight from a multitude of fields is incredibly important, so it is often a collaborative research between ethicists, anthropologists, and computer scientists.

  • Emotional recognition is when an AI can recognize different emotional states through facial expressions, body language, and tone.

  • This research is being used to assess if a driver is drowsy, if a student is engaged or distracted, and more. They are looking at facial expressions, but also other sensors because facial expressions can be so subtle. They are using cameras, performance data, and more to get a combined data set and a better picture of what is happening.

  • The “yikes” factor is that people can be monitored and they may not be able to conceal things with so many sensors happening. That is why ethicists and anthropologists need to be involved in this type of research. Especially when you start to make claims about someone, how they feel, and how they are engaging.

  • In thinking about using this technology with students, the researchers discuss how this can benefit a blended learning or online classroom. In a teacher’s day-to-day job, they are essentially responding to the students’ emotional states, and they can read that when they are in person. But when a student is on a computer, or when the classroom is very full of students, that emotional data is gone or hard to obtain. This research is trying to obtain that data to help with efficiency and effectiveness.

  • Where this research could go can sound scary. This is why these particular researchers are focusing their research on things like giving teachers information to start a conversation with a student, not evaluating a student or doing a summative evaluation of a whole class. They are not saying the teacher should entirely rely on the evaluation, but should use it as information as a starting point. Although this could be used for negative purposes, it is not the researchers’ intent.

  • Postpartum depression is another area where this research is being used, to try and detect whether someone is going through it or not.

  • The researchers discussed that even though their intent is important, they have to put on the hat of what could happen with their technology when someone else purchases it. Although intent is a great place to start, it is not the whole story. And this is part of their research as well. They also encourage people to be tough customers and ask good questions of companies and organizations that are using technology like this.

  • There is not legally a universal standard for privacy, which also plays a role in this. Also, there are significantly different opinions across cultures with how communication works and what it means to be watched or to be private.

  • There are many types of sensors for this type of work, including cameras, gesture recognition, wifi signal detection, and language processing. There are audio, vision, and text inputs, as well as things like heart rate. If you suddenly start hitting the keyboard really hard, or slowing down, that is one signal that an emotional state has changed.

  • Language sensors and human-brain interfaces are developing enough to be able to detect words from characters you’re thinking about. You can see this in predictive text on your phone, on autocomplete, etc. There is also work being done with connecting EEG signals with this word prediction technology. This might be useful for patients who are not able to speak well. The tech is limited right now, but it is getting better.

Some interesting quotes from today’s episode:

“Facial expressions and physiological sensing to audio sensing, using acoustic context… Using say, for example, how you type on the keyboard, your typing speed, and things like that, and takes into account all of these sensors to compute emotional states.” Saurav Sahay

“In my vehicle I have this amazing attention-assist feature that tells me when I’m drowsy. So this system is also using some flavors of sensing to detect if I’m alert or not.” - Saurav Sahay

“We know that learning is emotional as much as intellectual. So we are trying to understand whether a student is on task or off task during learning, but at the same time, the other level of engagement is emotional engagement, whether they are confused, bored, or satisfied at any time of learning.” - Sinem Aslan

“If we ask who’s in charge, who benefits, who doesn’t, and who gets to make these technologies at all, then we can start to unpack where’s the benefits and where’s the real risk?” Dawn Nafus

“Even myself would not be okay with sharing my emotional states with my manager, because that’s not what she does on a day-to-day basis. That’s extra information for her. But in a classroom scenario, it’s already part of that context. And what we are doing is really making it more efficient.” - Sinem Aslan

“As a society, we need to be much tougher customers. When schools are starting to purchase this stuff, we need to, as the responsible AI community, be supporting them and asking the really hard questions… And with that kind of more skeptical customer base, then we can start to make sure that things land where they want to land.” - Dawn Nafus

“I remember a demo that happened more than 10 years ago, when I was at Georgia Tech. There was a person sitting on a machine, and he was thinking about getting a mug of coffee. And there was this robot that just by magic gave coffee to the person. So just like that, neural interfaces are getting mature enough with a lot of sensing that happens.” - Saurav Sahay

“We can potentially control the bias in machine learning models by controlling the data set that we are kind of training them with. But on the other hand, there is also the bias that humans do on a day-to-day basis. So, how do we balance these two?” - Sinem Aslan

View Details

In this episode of Cyber Security Inside, Tom and Camille dive into managing and securing patch updates with Gabe Frost, Group Project Manager at Microsoft. The conversation covers:

  • How conversations about patches and updates have changed over the past few years as we have become increasingly digital and hybrid.

  • How the wide variety of hardware and software combinations makes it difficult to predict how a patch will run.

  • New technology that is being developed to collect information to make patches and updates work in such a diverse landscape.

  • How to manage risk and security when sending an update to large numbers of people.

... and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • With how the world has changed to become so much more digital and so much more hybrid over the past few years, thinking about patches and updates has changed significantly.

  • There are now so many different combinations of hardware and software that it is nearly impossible to know everything that could happen and everything that might need to be built into updates. This is why many people in the industry, including Microsoft, are focusing so much on analytics.

  • Because there are so many softwares interacting with each other, there is no way to predict all the possible scenarios. Sometimes, a device might not update like expected, and people want to know why. IT then has to use logs and tools and try to debug what happened and why the intent of the programmer is not being carried out. This is very challenging, especially remotely.

  • In terms of waiting to run a patch, the answer is not always clear cut. Sometimes there are patches that apply to every user that have to do with broad organization risk and security. But sometimes there are security issues that only affect a certain combination of factors. There is no one-size-fits-all-answer.

  • There is a risk with every part of this. From waiting to run an update to having everything on auto updates, there will always be the possibility of creating a vulnerability. This is partially why not all users will always get an update at the same time. Some updates are pushed in “rings,” or groups of people that get updates in a roll-out way.

  • When they roll out updates, there is more that goes into that than one might think. How do you decide which devices to put in the first ring for updates? Perhaps it’s the people that will be more accommodating to risk. So it is often the tech folks, who will understand if something happens.

  • Because the hardware and software can vary so drastically from device to device, when rolling out an update teams have to look really carefully at signals coming back from those devices and error reports and crashes. And that requires building machine learning and AI models to do.

  • Because updates and patches can really affect productivity and sometimes the economy, there is a lot of impact on the world that can happen with these updates. Deployment has to be carefully planned and consideration has to go to spreading out the risk and leveraging the capabilities to manage the risk.

  • There are tools, even ones that Microsoft provides and is testing, to help manage risk. They can select the smallest number of devices in your company as possible that have the highest concentration of hardware and software combinations so that you can pull as much data as possible while putting the fewest devices possible at risk.

  • Governments are starting to encourage populations to update. It could be that they get more involved in this in the future.

Some interesting quotes from today’s episode:

“Figuring out how to do this together in a way, and deliver solutions and tech that address the broad set of problems, because they’re all intertwined, you know?” - Gabe Frost on people collaborating to address new developments in updates and patches

“We’ve spent a long time making sure that the human sitting behind the PC attached to a device is really the human we think they are. But we haven’t spent as much time saying, ‘Is that device really the device we expect it to be?’” - Tom Garrison on shifting focus

“IT has been given this monumental task of just somehow knowing everything, right? And figuring out how to overcome all the obstacles that are presented to them, oftentimes blindly.” - Gabe Frost

“You need to have some sense of what compliance means to you and what software revisions are on that machine, when there’s umpteen amount of updaters that are floating around.” - Gabe Frost

“The biggest challenge is the balance between user experience and security.” - Gabe Frost on waiting to patch or patches that don’t apply to every user

“Is there risk? Yes. The question is what are the tools that you have to manage that risk so that you’re transferring unknowns to knowns.” - Gabe Frost on if there is a risk on having everything auto update

“What we’ve had to learn when we roll out updates to the billions of devices on Windows is: how do we determine the probability on a per device basis that this update is going to be successful on this device?” - Gabe Frost on the unknowns of updates on different devices with different hardware and software

“It’s an economy, and they’re changing all the time. How you reason through that risk is super challenging” - Gabe Frost on rolling out to devices

“If you turn on device telemetry and you authorize Microsoft service - our deployment service - to process that information in a compliant data boundary for you, then it will actually determine: of this big group of devices you handed me, what is the smallest number of devices that have the highest concentration of hardware and software combinations? And it will only pick those. So I can get you the broadest coverage with the least amount of devices.” - Gabe Frost on using tools to determine rings

“There’s just more and more on-ramps for malicious activity and it just presents that much more of a challenge for our partners - in IT, customers. It’s never been more important to be thinking about patch compliance and what it means.” - Gabe Frost

“It’s not only the tools and the flexibility in terms of how to update these things, but also how to reason over it, how to reason over your success, and how to reason over opportunities to actually improve and get better.” - Gabe Frost on what success looks like in patch compliance

View Details

In this episode of Cyber Security Inside What That Means, Camille explores intelligent systems and artificial intelligence with Lama Nachman, Intel Fellow and Director of Human & AI Systems Research Lab. The conversation covers:

  • Intelligent systems using a combination of observation, social science, artificial intelligence and more to improve human experience.

  • The difference between a full virtual setting and one that is a balance of virtual and analog.

  • What type of devices are used to observe and improve day-to-day activities, and how they work.

  • How privacy and ethics play a role in these systems as the digital and physical worlds become more blended.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • Intelligent systems research is focused on using social science, design, AI, hardware engineering, and software engineering to augment and amplify human capabilities and experiences with AI.

  • This is more than just improving your experience when using your PC or device. It is about improving your day-to-day tasks using technology in the physical environment.

  • The idea is that humans are really good at some things, and AI is really good at others. And oftentimes these aren’t the same things. For example, AI is really good at processing huge amounts of data, which humans can’t do efficiently. If we can put these things together - what a human is good at and what an AI is good at - it can lead to better problem-solving and development.

  • Some environments are harder to observe than others, but still could have huge benefits. If we look at early childhood learning, there isn’t a lot of screen usage, but a lot of learning is taking place. If we can get AI to observe that and learn from it, we can then bring a conversation to the physical world that helps that learning. Something that is being developed is a projection in that classroom on the wall that kids have to create a course for the projection to land on or interact with. It increases engagement. It also requires turning the space into a smart space with cameras, servers, etc.

  • The key thing here is the balance between virtual and analog. If it was full virtual, analyzing the data would be easy. But because we want it to be a balance of both, it is a hard problem to work with, because observing and learning is much harder for the AI. This information comes from cameras, microphones, text, and other things like heart rate and skin temperature. There are also sensors that capture muscle movement and brain waves for people with disabilities.

  • Wireless sensing, as opposed to cameras, is one way information can be collected about where people are moving, when they are, etc. This removes some hesitation for people not wanting cameras watching them, but still collects data. Movement is an important data point for AI. If someone is walking towards their computer to turn it on, the AI might start turning things on in the background to make boot-up faster. If someone is walking around in the kitchen, the AI can infer they are making dinner and make that process easier.

  • EEG sensors are also being used for people who can’t communicate traditionally to help learn and interpret what different brain signals mean so that communication can happen.

  • Privacy and ethics are being taken into consideration when the developers look at how the data is collected, where it is getting sent, and where it is getting analyzed. They are also looking at equity and bias in terms of who is building and looking at the algorithms.

Some interesting quotes from today’s episode:

“In terms of learning in a physical environment or working in a fab or just helping people with disabilities, as an example, what can we utilize as signals in the physical world? Then, with a lot of algorithmic innovation, turn that into understanding so we can better facilitate experiences for people as they traverse their normal life.” - Lama Nachman

“You’re looking at augmenting human experience, so we’re focused on humans here and using technology and using sensors to understand better what is the human experience, and then improve that experience.” - Camille Morhardt summing up intelligent systems

“So if you understood what somebody is doing, and if you understood what is supposed to happen, and the AI system can actually converse well with the human, then you could see how you can start to think of these things as human-AI systems where we’re bringing the best of the human and the best of your AI system.” - Lama Nachman

“It’s amazing, because we’ve done tons of automation in general, especially in chip manufacturing. But you walk into a fab and you still see tons of people. It’s not that the people disappear, they just do different tasks in the fab.” - Lama Nachman

“Technology needs to come into the physical world, observe, and then have a conversation that is actually situated in that physical world.” - Lama Nachman

“Ultimately there are all sorts of experiences within that spectrum - from total virtual reality where everything is virtual to everything analog and everything in between within that spectrum, right? What’s really interesting about this is what is the problem that you’re trying to solve, and what are the concerns that you’re trying to mitigate?” - Lama Nachman

“Actually, to solve some of the privacy issues, one of the things that you could do is reduce the gap between what is being sensed and what is being inferred.” - Lama Nachman

“How do you enable responsible development of AI? That means at the very early stages, you’re asking questions about risk.You’re looking at the project as a whole before you start developing.” - Lama Nachman

View Details

In this episode of Cyber Security Inside, Camille and Tom review the article they wrote about cybersecurity trends, discussing what’s important right now and topics on the horizon. The conversation covers:

  • How networks, connectivity, and cloudification are now considered critical infrastructure and how privacy and security are tied to this.

  • Artificial intelligence being both incredibly helpful and incredibly dangerous.

  • How we think about trust in the digital world, both related to the computers in our systems and the people behind those computers.

  • Quantum computing and other things coming in the near future that we should be preparing for now.

...and more. Don’t miss it!

To read the article, go to this link: https://www.helpnetsecurity.com/2021/12/21/top-cybersecurity-trends-2022/

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • This episode focuses on an article that Tom and Camille wrote about future trends. They talk through the article itself, as well as expand on some of the ideas from the article.

  • One of the trends they talked about was critical infrastructure. Critical infrastructure is now more than just roads, water, and electrical grids. It’s now things like communication and connection and digitivity. Digital security and privacy are now a part of this as well.

  • We have so many devices and big infrastructure, including things floating around in space and medical devices in your body. How do you protect those things from being hacked? How do you update those things without having something that can be accessed by others?

  • Artificial intelligence is another topic they focused on. A lot depends on what it is being used for. There is AI in the medical field helping detect anomalies far earlier than human eyes could so that issues can be addressed earlier than they would otherwise. But AI is also being used to find vulnerabilities and attack.

  • AI is also in its infancy. Soon we will know so much more about how it is used to attack systems and also be beneficial. It is both systemic and personal.

  • Privacy and information security is something that is deeply related to AI and also other facets of security. Although it might seem like paranoia, these are real things that have happened and could happen. Although it might sound outlandish, these things are likely.

  • Insider threats is another topic that has been explored, which is deeply tied to trust. As companies are monitoring your computer, how do they know if new and strange behavior is you about to steal or share information you shouldn’t, or an application that has taken over your computer? We need to know both the person sitting behind the device as well as the device itself (both hardware and software), and be able to trust both. We’re starting to learn how to do this.

  • There was a giant shift to working from home and the cloudification of data and systems. The workforce has distributed in space, and it is a different level of needing to know how to protect devices, systems, and people.

  • Quantum computing is something that is coming and coming quickly. There are people all over the world working hard to evolve cryptography so that devices and products like cars, planes, and more are protected when quantum computers arrive.

Some interesting quotes from today’s episode:

“Threats are not necessarily big explosions anymore; they can be destabilizing things that make people feel uncomfortable… Like people now are putting some of their genetic information online as they’re doing ancestry tracking. It’s not a problem now, but what happens in 20 years? What could somebody use that for?” - Camille

“When you test for security, you’re oftentimes purposefully testing the device in a way it’s not supposed to be used. That’s the way the human brain is working. And now enter artificial intelligence, there could be classes of attacks that the human brain hasn’t thought of yet.” - Tom

“If you have a neuroprosthetic, for example, that helps you move a prosthetic arm - if humanity gets to the point where they can write that signal - if something like that is hacked, you can move somebody’s arm without their permission… it’s at the very personal level.” - Camille

“But now, what is the information that matters, and how can that information be used in a way that maybe nobody’s considered up until now? But somebody will, and then obviously now that becomes privacy related.” - Tom

“People listening to this may not live in the cybersecurity world and may start saying, “Are we just being paranoid?” And to the folks that maybe haven’t been as deep in some of these topics, these are not outlandish schemes or threats that could theoretically happen but will never happen. These are very real and they’re already happening or they’re right on the cusp of happening.” - Tom

“What about the hardware itself? What are we doing to determine whether or not we have trust of the machine, and is that only happening at the very first rollout of the machine? Or are there protections we can put in place over the course of its lifecycle?” - Camille

“I think the silver lining through a pretty dark cloud in 2020 and 2021 is that people are much more attuned to supply chain in general, and the dependencies they have on a healthy supply chain.” - Tom

“It’s not hyperbole to say that all security that exists today can be easily defeated by a quantum computer. And so, the logical question if that’s true is what are we going to do about it?” - Tom

View Details

In this episode of Cyber Security Inside What That Means, Camille continues her conversation on non-fungible tokens (NFTs) with Mic Bowman, Senior Principal Engineer at Intel. This second part of the conversation covers:

  • Why NFTs exist and some thoughts on why we are creating scarcity in the digital world.

  • Where NFTs might be headed, such as in the direction of patents and software.

  • How NFTs could allow people who collect data to get that information to people who need the data.

  • How privacy and ethics play a role in NFTs and the passing of digital data.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • One way an NFT could work is that you build a model that you can use as a plug in or something in your own software. And someone else can use it in their software, but they don’t own the NFT so they can’t see how the software is built. It gives us new ways to define what ownership is.

  • It could be possible to code an NFT such that you don’t only own the art, but also the copyright. It becomes a licensed art piece. Some have discussed using NFTs in patents.

  • Right now there are copyright laws in simple media. But as we extend the idea of NFTs into patents and other industries, we don’t know what ownership of the NFTs actually conveys. There will need to be some serious legal discussions, and it isn’t well-defined yet.

  • We currently have sensors collecting all kinds of data that would be useful to people. But getting that data to an open market of people who might find it valuable is really difficult and not cost effective right now. If we can connect the data makers with those who want the data in an open market, we can collect and publish things we couldn’t have before. An example of this is an existing vineyard who already collects soil data and climate data for optimizing growing now has a way to get that information to someone wanting to start a new field.

  • YouTube is a good analogy for NFTs. YouTube gives someone who knows something or can do something well an opportunity to monetize that skill through advertisements or subscriptions. Right now, when data is collected, there is no way to monetize that or get value on that information. If there were, like NFTs, we might see people collecting and sharing more information. Of course, one danger of this is ensuring that the data is being used appropriately, which is still very much an open question.

  • How do you protect the asset that goes along with NFTs? Let’s say I have a model that I have trained using machine learning and confidential information. When I give you the right to use the model, I don’t give you the right to see the data that went into training it. But how do I stop you from copying this asset and selling it independently?

  • We know how to trade NFTs, but what we aren’t great at yet is updating the NFT as we trade physical things. Syncing those two things is difficult unless you build it that way from the beginning.

  • Partial ownership of NFTs is interesting. You can’t own part of an image, like a slice of pixels, but if you are purchasing it for investment and resale, partial ownership makes a lot of sense.

  • Why create digital scarcity when anything digital can be reproduced? Why is scarcity valuable? It makes things collectible. The whole point is that we can own something that nobody else does, and defining the value of owning that thing. You can own a digital print of a Monet, but it isn’t the original Monet. And for somebody, it is worth the money to own that collectible.

Some interesting quotes from today’s episode:

“There was one company that was talking about taking all of their patents, creating NFTs for the patents, and ownership of the NFT would convey certain rights to use the intellectual property that was part of the patent.” - Mic Bowman on where NFTs might be headed

“The asset is a separate thing out there, the picture. I may try to resell the picture, even though the NFT doesn’t necessarily give me the rights to do that. And honestly that distinction between the two and sort of these open market may be the biggest barrier in extending NFTs out into new assets.” - Mic Bowman

“In some sense this is the most exciting and most speculative kind of aspect and usage for NFTs is can we really start to monetize data?” - Mic Bowman

“It’s terrifying, actually. The biggest barrier for me on the technical side is how do we make it possible to do this monetization of data and preserve the appropriate use of that data?” - Mic Bowman on needing also pay attention to ethics and privacy when talking about NFTs

“Are there ways that we can protect the intellectual property and those assets to create digital scarcity and to protect the assets more rigidly than we currently have?” - Mic Bowman

“The digital print may look just as good on my wall, but it’s not a Monet. It’s not the original Monet. The print on my wall is worth $25 bucks. The Monet, the painting Waterfront just sold at Christie’s for what, $60 million or some ridiculously high number. It’s worth that much to somebody. Is it worth it because they are a collector? Is it worth it because they value seeing the paintbrush strokes on the Monet? I don’t know.” - Mic Bowman

View Details

In this episode of Cyber Security Inside What That Means, Camille Morhardt jumps into the non-fungible token (NFT) conversation with Mic Bowman, Senior Principal Engineer at Intel. The conversation covers:

  • What an NFT is, with several examples

  • How an NFT is purchased and traded

  • How owning an NFT is different from owning the asset the NFT is connected to, and potential issues and opportunities that arise from that idea

  • What an NFT could become in the future, and where we might be headed

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • NFTs, or non-fungible tokens, are a tradable representation for digital assets. It’s like the title for your car - it conveys a sense of the vehicle and ownership, but the vehicle itself is separate from the title.

  • NFTs are pretty much only bought with cryptocurrency. And the NFT itself, the asset, cannot be subdividable (even if we can have partial ownership). For example, multiple people can own a piece of art together, but you can’t cut up the work of art.

  • Although digital art can be copied and downloaded, what NFTs really focus on is that we create value in ownership and where it came from. What makes it valuable is our belief that it has value because of who created it, where it came from, or what it is.

  • Digital marketplaces have existed in video games for quite a while. In World of Warcraft, you can buy certain characters or levels or things that will add value to your game. What the NFT does is allow the marketplace to be open. It becomes more about investment and market dynamics, and could create more opportunities for making these things happen. It moves the marketplace outside the game.

  • The music industry is using NFTs in creative ways as well. Beyond just purchasing a song or an album, an NFT can allow for different ways to get revenue from the artists’ clientele. Perhaps you can get credits for purchasing better tickets, or being a part of a fan club. It’s about the ownership more than the thing itself.

  • In terms of who makes the money, in some ways it is the companies and the businesses who are taking taxes or transaction fees or licensing fees. In others it is the creators. In others, it’s investors and external people. It’s an economy with every complexity that goes into any economy.

  • The majority of things being traded as NFTs right now are digital (images, videos, events, items, etc.). But once we have the NFTs and that abstract representation of a tradable interface, it can be bound to anything, even the non-digital.

  • For some NFTs, you can only see the asset if you are on that platform. The platform will manage who has access. However in an open market, there isn’t a guarantee that you will be able to always access it from the platform that sold it to you. Some people are told to make a copy of the asset quickly, before it goes away.

  • In some cases, when you buy an NFT, it comes with a licensing agreement that tells you what you can and can’t do with the asset. Are you able to collect fees or royalties on someone else using it? Can you trade it or resell it? It is very case-by-case, and is often not defined. You own the NFT, you don’t necessarily own the asset. This could become future legal battles in the future.

Some interesting quotes from today’s episode:

“Really what you’re purchasing with an NFT is provenance. It’s kind of like when you purchase an antique, you can buy an old dresser and it’s kind of an old dresser. But if that old dresser once sat in George Washington’s mansion, then it’s a very different thing, right? You can come up with other dressers that might be the same, but the fact that it came from George Washington’s mansion is what really adds value and creates value.” - Mic Bowman

“It’s not that the tweet itself is that interesting. It’s that Jack Dorsey created the NFT for it. So anybody can go out and make a copy of the tweet. Who cares, right? We can all go back and look at it. But only one person can own Jack Dorsey’s NFT that he created for it.” - Mic Bowman

“It goes back in some sense to that notion of collectibles. It’s what makes the Honus Wagner baseball card worth $2 million. It’s a piece of cardboard, right? What makes it valuable is that people believe it has value.” - Mic Bowman

“What makes an original Monet worth $50 million? Is it because the painting itself is worth $50 million? Maybe for some people. But it’s the ownership of the Monet. That’s really what it’s about.” - Mic Bowman

“It’s a marketplace for connecting value and value chains. And once you have this NFT, what you can trade is almost universal.” - Mic Bowman

“An NFT is nothing more than a unique identifier. Think of it as a serial number.” - Mic Bowman

“In some cases, the artist can retain the copyright. An artist could potentially make revenue every time you trade, or show, or make available the asset. So, the asset is existing independent of your ownership of it.”- Camille Morhardt

View Details

In this episode of Cyber Security Inside, Camille and Tom get into the biggest cybersecurity topics of the past year with Maribel Lopez, Founder and Principal Analyst at Lopez Research. The conversation covers

  • The large scale attacks on infrastructure this year on a wide range of companies.

  • Where the attacks were occurring to have the biggest impact on systems.

  • The development of artificial intelligence and how far along we are in that area.

  • Ways to convince companies and decision makers to focus on cybersecurity.

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • One of the more surprising things that became big this year was large scale attacks on a wide range of companies (gas lines, hospitals, schools, etc.). Things now feel more targeted and directed than just opportunistic.

  • Right now, companies trying to fix vulnerabilities are highly dependent on consumers updating their systems. So, attackers can just wait until a vulnerability is pointed out by ethical researchers, and then count on not everyone updating.

  • Attacks expanded into areas like the supply chain, because it isn’t just about the core systems of the company anymore, it’s about every part of the process that relies on technology.

  • Having old infrastructure can really hurt a company or a business. And at this point, people can’t say they didn’t know, since there have been so many examples to learn from. The responsible thing to do as a company is to have modern infrastructure. It is very expensive, too, of course.

  • With AI, there are big questions about how the models they are developing based on information might impact privacy.

  • Data loss has been a huge topic as well. When a company loses a bunch of data, we have to think about how they were collecting the data, how it was encrypted, how AIs were accessing it and analyzing the data. How do we collect data in a safe, privacy centered way, while still getting useful information that will help create new business models?

  • The more connected things are, the more risk there is if an attack happens. Although connection in infrastructure might make the infrastructure run better, if it were to be attacked it could affect huge systems instead of an individual instance. For example, consider if all traffic lights were linked. Now, hacking the traffic lights can cause a huge grid-lock.

  • AI has been great to help run and develop security software. However, the other side, the hackers, are also using AI to find vulnerabilities. It is a constant battle. But, we are still early in the AI process and a long way to go in research and development.

  • One way to help convince companies to focus on cybersecurity is to show them the monetary impact of what they will lose by being shut down, or what they might have to pay by losing customer data. Another way to convince them is to look at brand reputation for getting attacked and losing data.

  • When looking at security, we need to look at the problem first. Often, we have the technology and look for places to apply the technology. That is backwards.

Some interesting quotes from today’s episode:

“These were things where it’s like, if you can figure out what the potential vulnerabilities are there, look for them, make that type of attack, you know that you’re a success in getting paid as a malicious actor is pretty high because it is a critical infrastructure.” - Maribel Lopez

“I think that the first stage, you know, before we even talk about regulation, is just for every organization to try to figure out: is your IT infrastructure holding you back? And I’m not talking about an agile, digital transformation way. I’m talking about an it-will-shut-your-business-down way.” - Maribel Lopez

“It’s not just security, it’s also privacy. It’s also functional safety or personal safety. And then you’re very quickly kind of moving into the ethics space.” - Camille Morhardt on how tech has become part of medicine, space exploration, and more

“The greatness and the sorrow of AI is Ai can take a lot of data, and it can find a lot of patterns and insights very quickly.” - Maribel Lopez on how AI can be very helpful, but can also open the door for attackers

“If you ask me where we are and we put it into, say, like a baseball analogy, we’re probably in the fourth inning of what’s going on with AI.” - Maribel Lopez on the development of AI

“One of the things we talked about a lot is using AI just to figure out if you have been breached - if there’s some activity that’s going on within. You know, somebody who’s just lying in wait for the perfect data or to set up the perfect attack. You know, there were statistics that it took 9 months to a year for a lot of organizations to figure that out on their own.” - Maribel Lopez

“When somebody comes to you and says, ‘Hey, are we secure?’ That’s a question that nobody can really answer truthfully. But it is a question that is legitimately asked to every senior business executive at some point in their career.” - Maribel Lopez

View Details

In this episode of Cyber Security Inside What That Means, Camille talks with Roman Zhukov, Product Security Manager at Intel about Security Champions and their roles in product development.

The conversation covers:

  • What a Security Champion is, and what they do in a product team.

  • How the role of a Security Champion has changed over time with new security needs.

  • How to encourage Security Champion and cybersecurity training effectively by using the carrot over the stick.

  • Who is responsible for what parts of security in product development.

... and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • The definition of what a “security champion” is evolves over time. The purpose is to put security first and incorporate it into every part of a company. They educate, they adopt policy, they communicate, and they help enable positive security change.

  • A security champion can be a liaison between a product division and a security group.

  • Their job is to ensure their team is ready to meet security needs.

  • You can be trained to become a security champion, even if it isn’t your formal role. They can spread knowledge to teammates.

  • This is so important because users often will trust big companies or services to provide security - so much so that they won’t do anything in securing themselves. So, we need someone on the product team reminding people of that and making sure security is a first priority.

  • Companies that have been doing this a while and have made good strides in security have KPIs for both the business parts and the security parts.

  • Originally, security champions were the bridge between the two departments (security and another like development or IT). The two sides used to battle one another, and a security champion helped them through that. Now, though, they serve more as a person who is encouraging employees to learn and to stay committed to security policy. They don’t know as much as someone in the security team, but they can answer questions and relay info.

  • In terms of thinking about the carrot vs. the stick tactic of getting people to think about security and be compliant with requirements, historically security has always used the stick. But what they’ve found is that the stick (do it because you must) only gets minimal compliance, which isn’t enough in today’s world. The carrot comes into play with making training fun and desirable to do. Make it a competition, and change your approach to training your personnel in security.

  • Having security champions is worth finding resources for. They guide the product team, and help the team to start thinking like a hacker. Try to break the product, and then develop something to prevent that from happening.

  • We need more daily security tasks (about 90%) to be completed by the native team with help from a security champion, instead of going to the central security team.

Some interesting quotes from today’s episode:

“Often the case is that the term security champion is perceived as the specific job, or just even yet another buzzword. But there is not actually one specific definition, it evolves over time.” - Roman Zhukov

“Influencers from these divisions who have to really understand that security is not a feature, but a part of daily life.” - Roman Zhukov

“I think this is the era when security first mindsets start to play.” - Roman Zhukov

“The thing is, security is no longer a product feature or a company’s feature. It’s part of normal functionality of our organization.” - Roman Zhukov

“I know that the integration of product development life cycles and security development life cycles has been a trend, right? So I think things like that probably help. We kind of back it up so that you’re not doing a security review at the very end, pre-ship, and discovering a whole bunch of problems you have to address; you’re finding them along the way.” - Camille Morhardt

“Just to realign policy and establish requirements or running your scanning tool is not enough. Why? Because implementing [those] alone, they cannot help to grow security mindsets and to make these cultural shifts.” - Roman Zhukov

“Cybersecurity is widely unfair, right? A hacker needs to succeed only once to get what they want, while a business needs to succeed every day to prevent that from happening.” - Roman Zhukov

View Details

In this episode of Cyber Security Inside, Camille and Tom revisit the best pieces of cybersecurity advice from experts they have interviewed throughout the year 2021. This advice is for users, companies, and manufacturers.

They talk about:

  • Always being prepared for the worst-case security scenario, such as the SolarWinds attack.

  • Accountability in cybersecurity and putting the training focus on IT and security professionals, rather than just users.

  • How remote work has impacted cybersecurity in how we access our work digitally and what physical systems we are able to have set up in our home.

  • How security should be a part of every aspect of a device, not just a feature.

... and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • This is a special edition of the podcast where Tom and Camille look back at tips and advice guests have given about cybersecurity over the year 2021.

  • One piece of advice, from Eric Cole, was to always operate as if we are going to be hit by something like the SolarWinds attack at the beginning of this year. He talks about having firewalls and filtering devices to limit access to your private network, and to use software sniffers to make sure there is no extra activity or connections.

  • Accountability in the security industry is very important, according to Malcolm Harkins. When there is a large-scale attack, there needs to be a review to identify what controls failed, label what failed and the company that sold you, and put it out publicly.

  • Right now, the way we put blame on people for cyber attacks is by putting that blame on the users, says Malcolm Harkins. We tell them to be more careful, to be more informed, etc. Being cautious is good, but we also need to understand how to make systems in general more secure and more accountable. This is because we limit what computing can do by scaring people and putting blame on them. The way we engage with computing is the same way we become vulnerable to attacks. We have to train users, but we also have to have accountability on the company’s side.

  • Right now a lot of training that is occurring in cybersecurity is on the user side. But maybe it should be more on the IT/developers/technical population side. It would probably have a bigger payoff in the end.

  • Doing the basics is super important. Keep your machines updated, use vulnerability fixes, etc. But do it across your entire infrastructure.

  • The Work-from-Home necessity has also created different technology and security needs and risks. Devices are now hooked up to at-home devices (consumer routers, printers, etc.) that open up more opportunities for attacks. Also, because of the speed at which devices had to be available, things were missed and infrastructure was not correctly set up with cybersecurity in mind.

  • According to Carolina Milanese, there are essentially two options for companies with employees working remotely. The first is for the IT department to dictate everything about how you connect, what you use, etc. The second is for IT to just provide the equipment with cellular connections. When working remotely becomes an option more than a mandate, corporations will likely have really specific requirements not only for your tech, but also for your space and furniture for liability purposes.

  • Security is not just a built in feature, but should be a part of every aspect of a device. Having a learning mindset is important; it allows us to take what we learned from previous issues and build that into future products to make them better. This is seen in threat modeling.

  • Security impacts everything, whether you have thought about it or not!

Some interesting quotes from today’s episode:

“Make sure you’re very careful and deliberate about updates. A lot of vendor software updates are functionality that you don’t need and add complexity. So have a strict rule that you’re only going to update after verification and validation.” - Eric Cole

“The people that I know that are in the security industry have been saying for so long that it’s just a matter of time. This wasn’t actually a groundbreak attack at all, other than it was a large enough scale attack to where it was newsworthy and people that really hadn’t been paying attention that were kind of sleeping, finally got shaken by the shoulders.” - Tom Garrison on the SolarWinds attack

“Yeah, not really a wake-up call when it’s the fifth time you’ve hit the snooze button on your alarm.” - Camille Morhardt on the SolarWinds attack

“I think we are doing band-aids, bubble gum, and baling wire making up for dated security technologies and other technologies that won’t work; they’re insufficient and flawed controls.” - Malcolm Harkins

“But how do I use my computer? I click on things. I open things, right? If I’m afraid to go do that, I’ve just reduced what computing is about and how I use it and how I engage it.” - Malcolm Harkins on where we put the blame for cyber attacks

“Just think of your phone, you know, which is… a consumer device. But how much data exists on that device?” - Tom Garrison on the work-from-home situation and where vulnerabilities have opened up in the last year

“To be honest, teaching people how valuable that data, that information is so that there’s more of an understanding of how I use it, where I use it, what kind of device I use to access it and so forth.” - Carolina Milanese on what can help secure remote and cloud-based work.

“Every system is different and used for different purposes. Thus, every threat model is unique and deserves its own diligence and attention.” - Johnny Valamehr

“Security should be a part of everybody’s job and everything that you do you need to think, is there a security impact to what you’re doing, even if it doesn’t seem like that in the beginning?” - Dina Treves

View Details

In this episode of Cyber Security Inside, Camille talks with undergraduate students Ifesi Dimma Onubogu, Isabella Siu, and Sarah Schaber, Princeton-Intel 2021 Alumni and participants in the Research Experience for Undergraduates Program.

The conversation covers:

  • How undergraduate students got interested in the field of cybersecurity and privacy, and what brought them to their current studies.

  • The Princeton-Intel summer program and what the students learned and gained from that experience.

  • What these thoughtful and talented students think about the importance of cybersecurity in different areas of study.

  • Advice these students have for high school students about their future paths and opportunities.

... and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • These three students are from Intel and Princeton’s summer research experience for undergraduates. None of them go to Princeton, but all do very interesting research and participated in the program.

  • One student worked in network security and privacy, and was surprised by the complexity and inconsistency of the internet.

  • Other students worked on software that ensures image files haven’t been corrupted. They got to work on the interface between hardware and software, rather than working on one exclusively. They learned how things are interconnected and work together.

  • We got to hear about how the students got into this field and what sparked their interest. For one, it was the professors who were teaching the classes in the program and the research they were doing sounding interesting and fun.

  • Another was introduced by a friend’s mom teaching a computer science class in high school.

  • Another was introduced by her dad who owns an engineering firm she used to tag along to.

  • They are studying a variety of computer and security related fields now, and want to continue to find connections to the experiences they had this summer in cybersecurity. One is looking at biomedical imaging, another is exploring electrical engineering.

  • Networks and security are important everywhere, even in research on bees! When trying to find out why bees might run away from a hive, monitoring devices can start to figure out why without disturbing the bees.

  • The students gave several pieces of advice to students who might be interested in this field and ones like it. One piece of advice was to take every opportunity and to seek out new ones that will give you experience in a new area. You might be surprised at what sparks your interest. At the very least, you make new connections and friends in the experiences and learned something.

  • They gave some insightful thoughts on what a career is and how it is about sharing, networking, and becoming a part of the lifestyle. The ballerina metaphor helped highlight the difference between a hobby and a career.

  • They all spoke highly of taking opportunities and reaching out to people in fields you are interested in. Collaborating and learning, and not being afraid to take risks and ask questions is very important.

Some interesting quotes from today’s episode:

“I just found it very interesting how the internet is its own world, kind of just thriving that I did not completely look at before.” - Ifesi Onubogu

“Especially by the end, I hadn’t realized how much I had learned. I kind of came as a shock. When it actually hit me, like, wow! We actually learned so much and it was just eight weeks!” - Sarach Schaber

“I think my interest is in networks and the information they hold and how vital it is that we have tools that developers can leverage to secure applications under networks.” - Ifesi Onubogu

“Cybersecurity for me is more than just a hobby or a subject in school. It’s evolved from being the thing I heard about with my dad to most definitely a career at this point.” - Ifesi Onubogu

“Any opportunity you see, go for it, even if you’re like ‘Oh, that’s so out of my comfort zone.’ I think doing really different things leads you to raise the opportunity.” - Isabella Siu

“So I think the more things that you’re willing to open yourself up to, the more things that are willing to open up to you, the more things you try, just the better off you’ll be.” - Sarah Schaber

“Their best ideas are normally born in weird hours of the night, alone in your apartment, staring at whatever you're staring at. But there has to be some level of interaction with the industry you claim to be a part of. Right? So you can't call yourself a computer engineer if you don't throw yourself into the industry to learn from other people and talk to other people.” - Ifesi Onubogu

“As much as you need to grow on your own, remember that you are a part of the teaming industry, right? People and learning is a collaborative thing. It’s iterative and it’s collaborative and it looks different for different people. And it’s important to embrace it.” - Ifesi Onubogu

View Details

Have you been hearing about the new Infrastructure Bill that passed Congress? Are you curious about what moves the government is making to address the semiconductor shortage? In this episode of Cyber Security Inside, Camille and Tom get into the Infrastructure Bill recently signed into law with Jason Oxman, President and CEO, Information Technology Industry Council (ITI).

The conversation covers:

  • The Infrastructure Bill recently passed by the U.S. Congress and what implications it holds for cybersecurity

  • Who the Infrastructure Bill is serving and why

  • How the government is making sure that the networks deployed in this bill are secure

  • What the CHIPS Act is and how it is designed to help with situations like the semiconductor shortage

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • The Infrastructure Bill has now been signed into law. It is mostly focused on broadband infrastructure, and is investing over $40 billion in improving broadband and equity across the country.

  • Broadband enables everything else that the tech industry does, so making sure everyone has access and it is equitable access is very important. Providing access to underserved communities is key right now.

  • Some of the cyber attacks and ransomware attacks that this infrastructure package is trying to prevent include attacks on US businesses, and some include cyber attacks on national security from foreign actors.

  • In this package, there is funding for an Office of the National Cyber Director, which is new for our federal government. Previously everything had been handled by individual agencies.

  • This bill provides a lot of money to address cyber security risks and to help fund cyber security measures on a local, state, and national level.

  • Just like roads and bridges need repair and might collapse, digital infrastructure is at risk of cyber attacks and needs to be maintained. That is why these investments are so important.

  • We don’t have a federal privacy law, although other countries do. Some states in the U.S. have decided to do so on their own. This bill does not address that, but it certainly needs to be a topic of discussion.

  • The CHIPS Act is designed to do two things: one is to provide incentive to semiconductor manufacturers to build more plants in the U.S. The second is to provide money for R&D and more to support the semiconductor needs of the Department of Defense.

  • The U.S. is responsible for fewer and fewer amounts of semiconductor production over the past several years, and the government has a goal of getting back to at least ⅓ of the world’s semiconductors.

  • Most of the money is allocated for “next generation investment” (Jason) and is earmarked for advanced technology.

  • Quantum computing and AI are both areas of investment in the U.S., and other places in the world. The EU is working on really similar legislation with similar goals.

  • Implementation will be messy and slow, but it’s a good step in the right direction!

Some interesting quotes from today’s episode:

“There's a joke in Washington that every week is Infrastructure Week.” - Jason

“So it's investment in broadband in underserved and in unserved areas, investment to schools and libraries, health centers, public safety facilities, community housing projects.” - Jason

“But there are also elements of the, uh, infrastructure law, like the Digital Equity Act program. That's about a $3 billion program that's focused on promoting adoption and digital inclusion in underserved areas. There's an investment focus on connectivity, making sure that people who can't afford broadband, uh, can get help from the government because broadband is not a luxury anymore. It's a necessity.” - Jason

“We're very focused in helping state and local governments and municipalities secure their infrastructure because those are logical attacks for cyber criminals.” - Jason

“The federal government taking this on as part of the Infrastructure Bill is a good reminder that infrastructure is roads and bridges and waterways and utilities, but it's also broadband and digital networks and systems. And in the same way that we need to invest in and are now investing to make sure that roads and bridges and tunnels don't fall down or collapse, the digital equivalent of that infrastructure falling down and collapsing is a cyber attack.” - Jason

“You can not open a newspaper and not hear about the semiconductor shortage that's impacting every aspect of every manufacturer of every product in the country.”- Jason

“AI is enormously important. It is the future of a lot of technology. And obviously the semiconductor manufacturing is crucial to the computing power that will drive AI.” - Jason

“Our member companies at ITI are very focused on helping address the digital divide by deploying broadband, to unserved and underserved Americans of which there are tens of millions. So a lot of people to reach with a combination of wireless and wireline services.” - Jason

View Details

In this episode of Cyber Security Inside, Camille and Tom discuss the intent behind and the possible implications of the CHIPS Act and how it could impact the shortage of semiconductors. Their guest is Ollie Whitehouse, Group CTO for NCC Group.

Among the topics they discuss:

  • What is the CHIPS Act?

  • If the CHIPS Act is passed, how will it impact supply and demand for CPUs?

  • What are the economic incentives proposed by the CHIPS Act?

  • What could the CHIPS Act mean geopolitically?

... and more. Don't miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • The CHIPS Act will create tax breaks to allow the US to wean off foreign supply of materials to manufacture central processing units

  • The US and Europe will need friendly partners to access raw materials

  • The Act means once there is a secure supply of raw materials the US can produce the volume and quality to supply the domestic market

  • The demand for semiconductors already exists, but the Act will help a national infrastructure meet the demand.

Some interesting quotes from today’s episode:

“I think that the demand is already there. You know, I think we are seeing why the activities, which are precluding certain technologies manufactured from certain regions from being able to use indigenous core critical national infrastructure. And we will only expect that. And so that will ultimately continue to drive demand from trusted partners.”

“There's obviously the ability to do a degree of domestic production in the US today. But it can not meet all of the demand. And so the reality is, there are some components, some CPU, some chips, which are manufactured overseas and the likes of China and other states.”

“We're seeing more broadly as balkanization of technology. You know, we are starting to see fractures. We are starting to see countries increasingly distrust each other, and a desire for sovereignty, in terms of technology production. I think the rationale for this act and this aspiration actually makes quite a lot of sense. So one is, it is such a critical component, you know, in that it sits at the root of trust to pretty much all software layers, just top of it. And so you want to ensure the integrity of that.”

View Details

In this episode of What That Means, Camille discusses data anonymization with Kristin Ulrich, Senior Solutions Specialist at SAP for HANA architecture. Find out why data privacy should matter to you.

The conversation covers:

  • What data anonymization means

  • The difference between pseudonymization and anonymization

  • What questions you need to ask before sharing data with another company

  • How different legislations impact data anonymization and data sharing

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • Data anonymization means information is irreversibly altered and can no longer be identified directly, or indirectly

  • The type of parameters or methodology applied to a data set will depend on on each individual data set

  • There is always a level of risk involved with anonymization, you cannot guarantee complete anonymity

  • If you are working with companies in different countries make sure you understand any data regulations laws, in some cases they are continually evolving.

Some interesting quotes from today’s episode:

“And every time we speak about data anonymization, it's really important for us to really get into the depths of the use case and then decide which of the two methodologies should be applied and how we can actually bring the use case to life.”

“So I think it's always super important to get down to the use case to really understand what it is the other person wants to get out of the data and then see if we have the right technology in place and the right people in place to actually do it, to actually put it to life.”

“I think the most important topic to solve is the unstructured data part, because then we would probably be able to think about use cases that are currently unthinkable—at least that's my current understanding and my current assumption. But maybe it's something completely different and something you and I are not even thinking about today.”

View Details

In the spirit of Thanksgiving Tom and Camille highlight the work their guests are doing that they are thankful for — including ethical considerations of AI, why the race for AI is one of most important for humankind, and how academia and the cyber security industry can work together.

The conversation covers:

  • Leading thoughts on AI

  • Ethical considerations of AI

  • Cyber security and digital manufacturing technologies

  • Why the relationship between academics and the cyber security industry matters

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • AI is one of the most important races in humankind right now, coming second will not be an option.

  • Human ethics needs to be taken into consideration when developing AI. AI is built on systems and structures in society. These systems have racist structures which means we need to be careful AI doesn’t perpetuate inequality.

  • Digital manufacturers are working on the ability to detect data hacks as they transmit data all over the world.

  • Academics and the data security industry need to make sure they are engaging with each other to understand future trends.

Some interesting quotes from today’s episode:

“When it comes to certain technologies like Artificial Intelligence, coming in second place can't happen. You know, there's such a first mover’s advantage. This is one of the reasons why Vladmir Putin said “whoever masters AI’s gonna master the world.” So that race, yes, brings out the best in us, but in some cases, if we don't win, it's going to have an impact on our economy.” Will Hurd, former Congressman and undercover CIA officer

“When we ask or think about, you know, who is this responsible to? I think the first question is really where is the greatest impact going to be felt? And to figure that out, I always start by asking or thinking about, you know, in which context will this technology we use be deployed? And who are the communities and users who might be impacted?.” Chloe Autio, Intel alumni and Advisor and Senior Manager, the Cantellus Group

“The data security issues, the ability to sort of get in there and, and hack any of that and modify any of that is just sort of stop and stop and step back and think about that and you're like, “Holy cow! There's so many places this could go wrong now. Right. And how do I secure all of this?” Tim Simpson, Paul Morrow Professor of Engineering Design and Manufacturing at Penn State

Links to full episodes with each guest:

Will Hurd: A Former CIA Officer and Congressman's Thoughts on Cybersecurity, AI and More (Part 1)

Chloe Autio: What That Means with Camille: Responsible AI

Tim Simpson: Ensuring Security in 3D Printing and Additive Manufacturing

Jason Fung: What That Means with Camille: Offensive Research, aka Hacking

View Details

The kinds of personal information we put out there may seem safe today, but what about five, ten, twenty or thirty years down the line? On this episode of #CyberSecurityInside, Tom and Camille are joined by guest Alex Ionescu, a founder of Windsider Seminars & Solutions Inc. and the previous VP of Endpoint Engineering at CrowdStrike, to talk about how privacy concerns change and evolve over time, and how what we deem acceptable now could quickly become outdated.

They cover:

  • Examples of how the cybersecurity landscape has changed and evolved over the years

  • The major vulnerabilities that still exist in the endpoint, and where some advancements may happen

  • Why the shift to virtualization in cloud environments is helping to harden security

  • How even the word “security” itself has evolved over the years, and now includes things like privacy and ethics under its umbrella

  • Why the kinds of data and information we share online today might be cause for concern in the future

  • The current reasonable applications of artificial intelligence in cybersecurity

  • Buzzwords that should raise red flags

... and more. Tune in now!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • Even a decade ago, you couldn’t necessarily do much with someone’s information, whereas now, the information we share can be much more easily exploited.

  • Security has become a major part of the marketing lingo, because people care just as much about that as they do speed; this was not true ten years ago, and is an example of how cybersecurity has entered the public consciousness in a big way.

  • As we increasingly conduct our personal and professional lives online, the concept of security has come to include things like honesty and integrity.

  • People should start thinking more critically about the information they share, because while a lot of it might not be exploitable today, it very well could be in the future.

  • An example of something that we might really frown upon in the future is sharing our genetic information via services like 23andMe.

  • For now, we absolutely still need a human element when it comes to security; we might not one day, but at this point there are no systems sophisticated enough that no double-checking or audits are required.

Some interesting quotes from today’s episode:

“10 years ago it was science fiction for most folks. So a lot of little things have changed, but I think that societal changes is the one that marks me the most.”

“I think in some ways behavior is changing, but a related question would be: is the change in behavior mounting to anything?”

“I’m not saying we’re fighting a losing battle, but I do think we’re swimming against the current, so to speak. And there’s a lot more swimming that needs to be done.”

“The cloud is not a panacea; it’s obviously got its own issues as well, but it’s a more modern set of systems that can be secured a little bit better than the average endpoint.”

“Artificial Intelligence. If you hear those two words, it’s time to run away.”

View Details

Supply chain security has taken on new importance, especially in a post-COVID world; from healthcare to finance, the cybersecurity threats posed to people’s lives are very real.

On this episode of Cyber Security Inside, Tom and Camille are joined by Rick Martinez, Sr. Distinguished Engineer, Office of CTO at Dell Technologies, and John Boyle, Cybersecurity Solutions & Supply Chain Security Product Management at Dell Technologies, to break down what companies are doing to mitigate these risks, what best practices entail, how Dell and Intel have partnered up on the road to boosted supply chain security and more.

They cover:

  • The significance of a transparent supply chain

  • The details of the partnership between Intel and Dell, and why it’s important

  • The timelines involved in figuring out adversaries’ next moves and applying mitigations

  • How supply chain security is optimized

  • What Secure Verification Component is

  • Best practices for companies to follow

... and more. Join the conversation now!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • Security has become a top tier concern for customers, and being proactive is key to mitigating any threats coming customers’ way.

  • In addition to security, sustainability has also become a primary concern for customers.

  • Secure Component Verification ensures that customers receive exactly what has been shipped to them.

  • Nowadays, the stakes are much higher considering attackers can target institutions from healthcare to finance that impact real lives.

  • It’s important to be involved with the security community, security researchers and hackers, in order to best mitigate threats.

  • It’s also best to have the latest and greatest updates to your system in order to prevent attacks.

Some interesting quotes from today’s episode:

“It's kinda cool that we get to hang out with hackers and hang out with other security community and practitioners so that we can really have that three to five-year crystal ball of what the adversaries are going to be doing in that timeframe.”

“Our context isn't just getting the system from our shipping facility to the customer's loading dock. It's the entire end-to-end--from when we design a system to the end of life of the system in the customer's environment, and making sure that the system is secure throughout that entire life cycle.”

“We are constantly evolving, just the hardening of the platform, our supply chain security, pretty much everything that we do around manufacturing and developing and shipping systems to users.”

“We're checking the security posture of the devices in the supply chain before we send it to customers with the tools that customers can use on their end to do this exact same thing.”

“When you have these attackers bringing down environments for healthcare, financial services, energy...it is impacting real lives.”

“We are impacting businesses that impact real lives; and when those are compromised, it's not good for people around in the global community.”

View Details

There are infinite vulnerabilities out there that make us susceptible to instances of cyberattack, and as of this year, we’re on track to have identified 20,000 of them. While there’s a whole risk mitigation ecosystem in place, CVE (formerly known as the Common Vulnerabilities and Exposures Program) has played a huge role in establishing a dictionary-esque database with IDs and definitions for each known vulnerability.

On this episode of What That Means, Camille is joined by returning guest Katie Trimble-Noble (Intel - Director, PSIRT & Bug Bounty) to describe the critical nature of CVE in greater detail.

They cover:

  • The origins and evolution of CVE (formerly known as the Common Vulnerabilities and Exposures Program)

  • Why CVE matters, and what it does and doesn’t do

  • How NVD (the National Vulnerability Database) and CVSS (the Common Vulnerability Scoring System) differ from and apply to CVE

  • How risk severity is actually scored

  • Who and what CVE Naming Authorities (CNA) are, why they’re important, and the process of becoming one

... and more. Really interesting stuff, so tune in!

*And if you like what you hear, catch an earlier conversation Camille had with Katie in WTM Episode 26: Bug Bounty and Crowdsourced Security; Alexander (RoRo) Romero joins them for a great discussion, and you don’t want to miss it: https://bit.ly/3mv9yVr

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • CVE makes up an important part of the mitigation ecosystem, and its main mission is to catalog and identify known vulnerabilities; we can think of it as a sort of dictionary in that it tells you the definitions of vulnerabilities.

  • Although CVE does not expand on the severity of vulnerabilities, it does list which ones are in your network; NVD and CVSS help to paint a clearer picture of risk level.

  • While ideally everything would be patched, there has to be a hierarchy of priority; that’s what makes CVE so crucial, because it enables system admins to differentiate and decide what to patch first based on risk analysis.

  • CVE also helps to identify vulnerabilities in a universally recognizable way.

  • Some vulnerabilities can intersect to form an attack chain, which is a common phenomenon that’s often referred to as a “daisy chain.”

  • CNAs are vendors, government agencies and research organizations that have a deep knowledge of vulnerabilities because they own a product or have done extensive research on it; these CNAs can publish directly to the CVE Master List.

  • There are currently 161 CNAs around the world, one of which is Intel.

  • In 2021, 20,000 vulnerabilities are on track to be identified to date.

  • There is no cookie cutter response to risk, because the things that get fixed and in what order are dependent upon implementation.

  • It’s important for consumers to put pressure on manufacturers to be transparent about vulnerabilities, because in the end, it strengthens the entire ecosystem.

Some interesting quotes from today’s episode:

“Everyone uses CVE. And the reason that you use CVE is when you’re doing your risk analysis to patch management, your system admins need to know what are we vulnerable to so that they can make that risk-based decision of what gets patched first.”

“Really risk is in the eye of the beholder. I can’t say what’s more important for you to patch because you have certain mitigating compensating controls on your end, the implementation end of the user. The implementation really dictates how things get fixed in what order they get fixed.”

“It’s not the mission of the CVE program to really get into some of those kind of theoretical details. It’s more sticking to the mission of the CVE program to identify and catalog those vulnerabilities so that you can enable the user end with the best risk-based program that can be available. It’s all about transparency and truth.”

“There was a lot of back and forth about what exactly is an exposure. So ultimately it was decided that in the best interest of the community, it was better to focus on CVEs in the form of vulnerability identification.”

“The CVE Master List is really just a reflection of the known vulnerabilities; there are an infinite number of vulnerabilities out there.”

“I mean, my Fitbit could have vulnerabilities and that’s not something you saw 10 years ago.”

“I think that we’re going to continue to see a rapid increase in the quantity of vulnerabilities that have been identified. And that’s why it’s so important to have that community based approach, those CNAs, those people who are sitting there cataloging vulnerabilities in their systems.”

“As the consumer, you want to put pressure on your product manufacturer to build a secure product.”

“If you can attack that insulin pump and you can cause an insulin pump to dump all the insulin in one minute, you can kill a person. That is a frightening vulnerability and those kinds of real-world sort of impacts they’re not theoretical anymore. They’re very real today.”

“When you disclose vulnerabilities, you make the overall ecosystem stronger and better and smarter.”

View Details

Why would a tech employee turn to e-crime? Well, often it has to do with feelings of discontentment within their jobs or their lives. How, then, can companies best mitigate insider threats? On this episode of #CyberSecurityInside, Tom and Camille are joined by guest Rick Jordan, CEO and Founder of ReachOut Technology, to take a deep dive; if you’re looking for a fascinating conversation about things like ethical hacking and the human element of cybersecurity, this is it!

They cover:

  • Who gets involved with e-crime groups and why

  • How those e-crime groups can take advantage of disgruntled tech employees to find hacking backdoors

  • Why this year in particular has been especially stressful for security and engineers

  • What companies can do to mitigate insider threats

  • How automation and AI factor into risk management

... and more. Tune in now!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • E-crime groups are often able to tap into tech employees’ insider knowledge through financial coersement to find hacking backdoors.

  • Even though the e-crime groups are paying these tech employees, the sum they part with often ends up being far cheaper than running their own research and development schemes.

  • The tech employees they target are often discontent with their own circumstances, whether at work or just generally in life.

  • In order to mitigate against cyberattacks, then, you have to have things in place within an organization to boost human morale, as well as a tech element to help combat outside hackers.

  • There also needs to be holistic, big-picture thinking in order to prevent cyberattacks, which requires a more zoomed out approach and (in some cases) more work to ensure employees only have the level of permissions they need to get their specific job done.

  • Monitoring tools can be used for good to examine anomalies within functional groups to find out where workers are getting stuck, thus allowing companies to prevent the frustrations that can lead to employees turning into insider threats.

  • And while AI and automation can be useful tools in tracking and assessing risk, there does still need to be a human element involved in the process.

Some interesting quotes from today’s episode:

“I always equate hackers to like Pablo Escobar, because of all these, like cloaked people in hoods that you see, when you type in dark web and look at the images on Google search. That's not what the frickin’ hackers look like, you know, they look like you and me.”

“For cybersecurity, the human element really is the front door.”

“There's a blending that has to take place for the mitigation within the organization.”

“That's the human element because if they're not as frustrated in their jobs, they're not going to become that discontent threat actor or an insider threat if they're paid well, if they're taken care of, and they feel like they're contributing to something bigger than themselves.”

“If you take a look at the functional groups and look at the anomalies within those functional groups, the data is a lot more accurate and predictable in those ways.”

“It's almost like it's not their fault, because people are humans, and they have struggles. And maybe they made bad choices to get to this point. But now they make even worse choices to try to compensate for the bad choices they made or maybe something wasn't even their fault whatsoever. And they're just having hard times, especially after like, again, this last year, a lot of people were hit hard with the pandemic.”

View Details

As the technological landscape moves ever onward and upward, it can be difficult for legislation to keep up. How is security policy trying to keep in stride, especially when certain aspects are viewed differently around the globe? On this episode of What That Means, Camille is joined by Dr. Amit Elazari Bar On, Director, Global Cybersecurity Policy at Intel, as well as Dr. Anahit Tarkhanyan, IOT Security Architect and Principal Engineer at Intel, to discuss all of this and more.

They cover:

  • Whether or not the concept of security is constant, considering privacy is defined differently around the world, and how that affects policy-making

  • What the National Institute of Standards and Technology (NIST) is and what its primary roles are

  • Why it’s important to have standards to adhere to as security policies are developed

  • The important things to define as things like measurability are considered in security policy

  • The six key pillars that NIST says your IOT (Internet of Things) device must support

  • Where people should look for regulations and guidance, as well as how to tell the differentiating factors between recommendations and steadfast rules

... and more. Important discussion, be sure to tune in!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • Policy is shaped around technological innovations, and often the law is trying to keep pace with those rapid developments.

  • While there are some universally agreed upon characteristics surrounding security policy, there are some cultural differences that have prevented standardization from occurring in legislation.

  • NIST has a broad expertise when it comes to security, and in addition to producing federal guidelines in the US, they are responsible for driving a lot of the international standard-making efforts in collaboration with other organizations.

  • NIST has also produced important documents like 8259 and 8259A that outline technical IOT security baseline capabilities for all IOT devices, which is horizontal across the market.

  • There are six specific pillars identified by NIST that your IOT device has to support: device identification, configuration, data protection, electrical access to interfaces, software updates, and cyber security state awareness.

  • Having standards set in place helps policy-making efforts to keep up with the rapidly evolving technology landscape.

  • It’s important that legislation stays design-neutral to facilitate interoperability.

Some interesting quotes from today’s episode:

“Policy is not just proposed legislation and laws. It can also be defined by social practices, industry practices, technical reports, and standards, right? It’s a broad set of norms that are defining this landscape.”

“Generally speaking, the law often trails behind technology. The law is slower to be amended. Policies are sometimes slower to be constructed.”

“Yes, there are areas of policy like national security and other domains that we will see different approaches to security, and we will see differences in legislation. And that is one of the areas where we are often talk about the importance of trying to leverage public-private partnership and harmonize standards to avoid fragmentation.”

“I would say IOT is certainly one of the most evolving areas when it comes to proposed policies around the world, not just in the United States.”

“I think one of the things to call out is we often talk about the need to facilitate interoperability and leverage the standards. And that is in fact, one of the elements that you really see coming through the legislation; the legislation explicitly calls out alignment with standards and alignment with industry best practices.”

“We already see many players in the ecosystem picking up and executing on the definition that NIST basically introduced.”

“Because of the vertical nature and the complexity and the evolving nature of the IOT security landscape, we have to establish that common understanding.”

View Details

When gaming first began as a concept, there wasn’t any of the sort of connectivity we see today in terms of being able to play with others online; it was just a controller, a console, and a TV. Simple. Now, of course, the landscape has drastically changed. How has that affected cybersecurity?

On today’s episode of What That Means, Camille is joined by Matt Areno to dive into exactly that. Matt has a PhD in Computer Engineering, as well as over 10 years of experience as a hacker. He now leads the Security Assurance and Cryptography Team at Intel, and he’s an absolute wealth of information when it comes to the topic of gaming. Whether you’re a casual Animal Crossing fan or you’re flying through ultra-tough games on permadeath mode, this is a very interesting conversation that you don’t want to skip out on!

They cover:

  • The broad definition of gaming

  • How the landscape of gaming has changed over the years, moving from quite simplistic and non-connective formats to now very much interactive online experiences

  • The ways that government agencies and the military are now using gaming as a means for recruiting

  • How gaming companies make money now as opposed to in the beginning

  • What (if anything) you can do if your gaming account is hacked

  • The reality of bullying when it comes to “MMOs” (massively multiplayer online games)

... and more. Great conversation, don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • Gaming has massively evolved since its inception, including the ways in which the military and government agencies are capitalizing on the format as a recruiting strategy.

  • While the games of yore primarily made money off the sale of cartridges, in-game stores are now a staple source of income for developers.

  • With in-game stores there are cybersecurity concerns; because players can essentially pay to be the best or most advantageous, now accounts hold real-life financial value that hackers could try to exploit for virtual inventory.

  • People actually make black market careers for themselves playing video games to level up accounts and then sell them off, and there are also hackers who will steal others’ accounts to sell off without actually putting in any of the work.

  • While many gaming companies now flag suspicious activity and offer two-step authentication, if you are actually hacked (and it’s not a mass leak), it can be very difficult to prove your identity and resolve the situation.

  • Bullying (especially when it comes to free games) is super difficult to prevent; even if someone is reported, they’re likely to just create a new account and start all over.

  • And bullying is also influenced by someone’s funds within a game; because gaming companies want to make money through the in-game stores, they’re often reluctant to reprimand well-funded bullies for fear of losing income.

Some interesting quotes from today’s episode:

“I guess if I had to define gaming, I would say that gaming is interactive storytelling. You know, it can take on so many different forms—whether it’s a board game, whether it’s a dice game, whether it’s something like D&D (which I also play with several friends), whether it’s on a computer, whether it’s on your TV, your phone, your tablet. All of these games are based around a storyline that takes you from Point A to Point B and attempts

to engage you in various different aspects of that story.”

“A lot of the electronics world that we have today we literally owe to the field of gaming.”

“Because there’s been so much advancement in our technology, even the skills of playing video games has become useful. And you can see that literally in flying drones.”

“A lot of what we’re seeing in the military as things become more and more automated, it becomes more like a video game. And so they are very, very vested in utilizing this as a tool for recruitment, utilizing this as a tool for training and engaging with it.”

“So now as an attacker, a hacker, I’m thinking, “Well, geez, why don’t I just go up for Steam? If I can compromise Steam, then I could access all of these different accounts worth all this money that I can then turn around and sell in real life.” And so it really became this entire evolution of gaming and how gaming is structured that brought in these attacks from hackers.”

“There really is legitimately an underground black market for log-in credentials for this. Now there are some people who, and I kid you not, this is an actual profession for them.”

“It really depends on your ability to prove that you were actually hacked. Can you actually prove that the person who logged in to the game was not you; that it was somebody else.”

“When it’s a mass leak--when they know that the people have gotten on and compromised--they’ll work with players to try and get that fixed. But otherwise there’s really no legal obligation for them to help you at all unless you can prove that that the account was hacked and compromised.”

“Even if people report them, even if people say, ‘Hey, this person is being a bully,’ they look through the chat log, they detect that this is what’s happening and they deactivate the account, the person just creates a new one, because why not? It’s free or they move on to another game. So there’s really no stopping that aspect, especially with free games.”

“If the bully is well-funded, there’s just not much you can do about it.”

View Details

As technology rapidly evolves, there is an ever-growing list of vulnerabilities that companies should take seriously with regard to security. So, why are so many of them still so immature in their attitudes towards protection?

On this episode of #CyberSecurityInside, Tom and Camille are joined by guest Todd Weber, Operating Partner and Chief Technology Officer at Ten Eleven Ventures; he's spent over 20 years in IT engineering, operations, and cybersecurity. He lends some excellent insight to today’s conversation, so be sure to check it out.

They cover:

  • Some of the newer vulnerabilities that companies need to (but might not) consider in their approach to security

  • Why immature companies might choose not to be adequately prepared against vulnerabilities

  • Some of the factors that motivate companies to become more mature in their approach to security

  • Why having that motivation to change is so crucial for companies hoping to avoid costly setbacks

  • The crossover between automation and Artificial Intelligence (AI) and Machine Learning (ML)

  • How even purchasing considerations (down to the air conditioning units used in a company’s facilities) should factor in security

... and more. Give it a listen!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • As technology evolves, there are continually more vulnerabilities to consider with regards to security; many companies are immature in their approach, leaving them unprepared.

  • It’s important that security advice is tailored based on a business’ maturity curve and risk tolerance.

  • Financial companies tend to be more mature in their attitudes toward security because attackers are usually after money; this threat provides ample motivation for proper protection.

  • Automation is key; automate wherever you can in order to make things easier.

  • In order for AI and ML to holistically help communities, there will be a need for a massive amount of data that (to date) no individual company is able to provide.

  • Sometimes over-regulation (which you might see in hospitals regarding devices regulated by the FDA, for example) leads to more vulnerabilities since the infrastructure complicates things like patching.

  • Companies need to factor in security even when making purchasing decisions for their facilities; so many products are vulnerable to cyberattacks now, and the entire lifecycle of a device should be taken into account.

Some interesting quotes from today’s episode:

“You tailor your advice based on what maturity curve that they’re on.”

“That becomes very difficult for us to deal with in security because, let’s face it,

security isn’t all about user experience. It’s about controls.”

“Try to automate the things that you can, and then put the process in where you still have to.”

“For ML and AI to work at a fundamental level of concept, it has to have a massive amount of data.”

“Fundamentally, you can’t do the really heuristic level type stuff and the interesting stuff until you have this foundational component built.”

“We have to have that motivational change to understand that we may have to take some downtime to upgrade things or to patch things across these security vulnerabilities, because one way or another, we’re going to have to pay for that.”

View Details

Federated learning is relatively new, but it stands to have a huge impact on the machine learning landscape, especially as it applies to healthcare. On today’s episode of What That Means, Camille is joined by Olga Perepelkina, PhD, a Deep Learning Product Manager at Intel, to find out exactly how this field is projected to change the world.

They cover:

  • What federated learning is and why it matters

  • How it’s helping to protect sensitive data

  • How it differs from other machine learning approaches

  • The various ways federated learning can be used

  • How data is annotated in federated learning, and why it sometimes lacks quality control

  • Which components of the federated learning model are vulnerable to cyberattacks, as well as possible solutions to boost security

  • Whether or not you can have different kinds of input with the federated learning model

  • What the future holds for federated learning

...and more Great conversation, don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • At less than five years old, federated learning is a completely new area of research in machine learning.

  • In federated learning, there is no need to collect data centrally; it can be trained locally, sending only model updates to an aggregation server.

  • It is crucial to protecting sensitive data because it keeps that data local on the devices where it was born.

  • Federated learning differs from other machine learning approaches in that models are trained in parallel, rather than sequentially.

  • In addition to medical imaging, federated learning can be used for things like computer vision applications, natural language processing (NLP), and deep learning.

  • One of the problems with federated learning is that the quality of data annotation cannot be directly observed; in the future, there will be some monitoring tools that will help to resolve this challenge.

  • Federated learning can help curb biased data sets because there is more diverse data involved.

  • In the future, as federated learning expands, communication efficiency will be key, as will the protection of models to prevent leakage of private information.

Some interesting quotes from today’s episode:

“I think we can dramatically improve AI in healthcare.”

“As researchers, we want to use these models to improve products, to build new technologies. But at the same time, we need to protect the private information of people, and federated learning can help to do that, to provide access to data, and to protect the privacy of people.”

“In federated learning, we keep data private on local devices where it was born. And we only send updates of the model to one server and aggregate this model, and then send this aggregated model back to local devices.”

“In federated learning, we still have some problems because people can't directly observe the quality of annotation. And this is one more major issue and challenge for federated learning.”

“In our future products, we will add some monitoring tools not to absorb your data, but to collect some statistics to help you in your research and your experiments.”

For more resources, check out these links:

OpenFL: Intel opensource federated learning library: https://github.com/intel/openfl

Federated Learning in Medicine: A Nature paper - https://www.nature.com/articles/s41598-020-69250-1

Intel Federated Learning Slack: https://join.slack.com/t/openfl/shared_invite/zt-ovzbohvn-T5fApk05~YS_iZhjJ5yaTw

View Details

How do you get over the fear of betting on new trends? What makes a great leader? And how do you keep your chin up when your ideas are ridiculed? On this episode Tom and Camille go straight to the source and answer these questions with guest Mooly Eden - Board Member, Speaker, Former Intel Executive, and all-around fantastic innovator and leader.

Mooly has experienced first-hand what it’s like to have a world-changing idea laughed at, and is a prime example of why you should stick to your guns even if you feel discouraged at first.

He’s a wealth of knowledge and an incredibly entertaining guest, so you’re not going to want to miss it!

They cover:

  • Why employees need to be proactive and persuasive about their concerns, especially relating to cybersecurity, rather than silently stewing and placing blame on others

  • How all innovation requires a certain level of risk

  • Why you shouldn’t get too discouraged if your innovative idea isn’t received well at first, using Mooly’s involvement with Centrino and the development of Wi-Fi and pervasive connectivity as a prime example

  • How to improve your leadership skills by looking inward

  • Why it’s better not to sugarcoat things, even if that may seem counterintuitive to some

  • How it’s impossible to predict the future, but possessing a strong ability to learn and adapt puts you in an excellent position to thrive

... and more. Tune in now!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key takeaways:

  • There are essentially two types of people when it comes to thinking about cybersecurity - those who take it very seriously because they recognize we are very vulnerable, and those who take a more lax approach because they believe nothing will happen to them.

  • Blaming high-level management for problems or shortcomings is not the way; you can’t internalize these things. You need to be diligent and persuasive and explain the issues so that people will understand what jeopardizes the company.

  • Every innovation requires a certain level of risk, it’s just about finding a balance.

  • When you do present an innovative idea, people may likely ridicule you for it, but that doesn’t mean you are wrong or that you should be discouraged.

  • There’s no set formula for being a great leader because everyone has different strengths; if you want to be a great leader, you must understand your leadership style and capitalize on it.

  • Intellectual honesty is always the best policy, even if it’s not what people want to hear.

  • The future is impossible to predict, so a focus on being able to learn and adapt is critical, especially for school children who are likely to enter a job market full of positions that haven't even been invented yet.

View Details

Threat modeling is a vital part of the product development process, and it truly never ends. Camille takes a deep dive on today’s episode of What That Means; she is joined by Jonathan "Jonny" Valamehr, Principal Engineer at Intel, and Dina Treves, Senior Very Large Scale Integration (VLSI) Engineer at Intel, to find out things like which thought processes go into threat modeling, why there is no standardized threat model, as well as how the ever-evolving vulnerability landscape affects threat modeling.

They cover:

  • The meaning of threat modeling and why it needs to be done early and repeatedly

  • How to know what threats are out there, as well as how to prioritize them

  • The sorts of things that are helpful to design teams when threat modeling

  • Why it’s just as important to think like an attacker as it is to think like a victim when threat modeling

  • How combining things like biometrics with traditional password protection can really boost cybersecurity

... and more. Great conversation, don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • To understand threat modeling, you need to take three terms into account - assets (things like information you want to protect), adversaries (usually ill-intentioned parties with the skills to steal or damage assets, but adversaries can also occur accidentally through leaks, etc.), and attack surfaces (which adversaries use to get into systems and access assets).

  • Threat modeling looks at all three of those elements and tries to map out all of the “what if’s” to prevent or lessen the damage of future attacks.

  • Threat landscapes evolve along with technology, so threat modeling often differs depending on use case and product.

  • Threats are categorized as “in scope” or “out of scope”; the former refers to things we want to protect against that may likely happen in real life, whereas the latter refers to things that are less likely to occur and therefore receive less focus.

  • Every threat model is unique because each situation is unique; rather than opting for a blanket solution, which would create a lot of unnecessary work and potentially distract from protecting against the most relevant attacks, it’s important to consider each case on its own.

  • Design teams are greatly aided by research teams (both internal and external, such as academics) who do the leg work in identifying vulnerabilities, thus allowing teams to learn and update their systems quickly.

  • Malicious actors can also sometimes help reveal vulnerabilities by exploiting them in the real world.

  • You really need to be able to understand use cases to discover abuse cases.

  • And it’s important to note that while a lot of threat modeling focuses on the early stages of a product, the process continues throughout the whole life cycle of a product.

Some interesting quotes from today’s episode:

“When we have a product, we design a product, we think with a functional mindset; we want to make sure that our product does what it’s supposed to do. But when we think with a security mindset, we want to make sure that it doesn’t do what it’s not supposed to.”

“When we start a threat model, as you said, it should be in the early stages of the project, but it does evolve and you continue doing it even after you released a product, you revise your threat model. It never ends actually.”

“If you don’t know your use cases, you cannot really come up with the abuse cases.”

“As we define threats, we think about confidentiality, integrity and availability. And these are security properties that we want to protect, and there are all kinds of ways to attack them.”

“These charging stations that have a USB port and you just stick a USB key. I never use them. How did you know what they’re going to load into your phone or a laptop when you’re trying to charge?”

“I think that’s where the real magic happens, when you have all these different pieces going together, because that raises the bar for an attacker. They would have to basically get all that information, which is hard, whereas a password they may be able to get, because you know, you reuse a password and then some website leaks all the passwords to the internet.”

“Adversaries are people. And we need to think not just about their skills, but also about their motives.”

“Security should be part of everybody’s job, and everything that you do you need to think, ‘Is there security impact to what you’re doing, even if it doesn’t seem like that in the beginning?’”

View Details

Hacking is often associated with bad behavior, but there are some good guys out there who help to ensure products aren’t exploited by ill-intentioned parties. This is part of the offensive security research (OSR) process. On this episode of What That Means, Camille speaks with Jason M. Fung, Director, Offensive Security Research & Academic Research Engagement at Intel, who breaks down why offensive security research is such a crucial practice.

They cover:

  • The definition of offensive security research, aka hacking

  • Why thinking like a hacker is essential for effective offensive security research, and how not all hackers are bad

  • The various reasons hackers might enjoy offensive security research in the first place

  • What skills and traits the ideal hacker possesses

  • Why it’s important to include different perspectives, including those from outside organizations, when it comes to offensive security research

  • The various kinds of researchers involved

  • The development of Capture the Flag events

... And more. Tune in, you don’t want to miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • Offensive security research is almost like an industry euphemism - when we think about hacking, there’s often a negative connotation, but some hackers actually use their skills for good and help to uncover product weaknesses before they can be exploited.

  • Having outside perspectives from people like well-intentioned hackers can help development teams fill in blind spots and anticipate threats they might not have otherwise considered.

  • There should also be a holistic approach to offensive security research to ensure well-rounded solutions.

  • Several kinds of researchers are involved in offensive security research, including academics eager to find new innovations, those who come from the industry side and are employed by companies, as well as freelance bug bounty hunters.

  • Oftentimes the academic researchers are motivated by the hope that they’ll be the first to publish new findings; this can require a disclosure agreement to prevent certain information from going public too soon, so there is a level of patience required on academics’ part.

  • Regardless of why the various researchers get involved, their work provides excellent insight and opportunities for improvement when it comes to product development.

Some interesting quotes from today’s episode:

“We want to put ourselves into the shoes of the hackers and ask the question, what would they do?”

“We don’t want to be playing by the rules. We are going for the weakest link. And this is what offensive security research is about.”

“By having more people coming from different perspectives, it helps to kind of round out the blind spots.”

“I’m hacking my own product. I’ve been paid by the company to do fun things that I like, and I’m hiring the best professionals outside into my team to do the work.”

“You can be the bad guy that may be selling your learnings to the black market, but also, you can be doing all these fun things as a good guy.”

“I really enjoy the benefit of working with folks coming from different backgrounds and perspectives and helping one another to continue to learn.”

“One thing I really care about is not just about the skill set of the individual, but also their mentality. The mentality about being passionate, being curious, and also ready to learn more new stuff and collaborate well with one another”

View Details

Firmware-based attacks are some of the hardest to detect, which is what makes them so dangerous; once someone has control over your hardware, they can do just about anything. In this episode of Cyber Security Inside, CEO and founder of Eclypsium Yuriy Bulygin joins Tom and Camille to share his expertise on the topic, offering a comprehensive view of vulnerabilities and how threat groups exploit them.

They cover:

  • Why firmware attacks are so brutal, and how the known vulnerabilities are being exploited by threat groups

  • How people can tell if they’ve been a victim of a ransomware attack and/or if it’s gotten down to the firmware level

  • Whether or not ransomware attacks should be paid

  • How the new model of working from home during the pandemic has shifted the threat landscape

  • What advice companies should consider securing their platforms

... and more. Tune in for some next-level insight.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • Firmware attacks have become more and more common as user and software protection have improved; adversaries needed to find a way of going undetected, which is why they began to target actual devices and equipment.

  • In fact, NIST reports that device vulnerabilities have increased five-fold in the past four years alone.

  • One of the biggest problems with firmware attacks is that that ransomware can come back even after a device has been cleaned because that’s how deeply embedded things are.

  • While it’s not good to incentivize successful ransomware attacks, there are certain cases where it becomes necessary; for example, a recent hospital attack led to the deaths of patients, and that would be a scenario where it would make sense to pay.

  • With more and more people working from home, remote endpoints have become a major target for threat groups.

  • It’s crucial to be able to authenticate users, have a strong understanding of devices, secure the applications and software stack used on remote endpoints, and protect the overall remote infrastructure to prevent attacks.

  • Bringing visibility into devices and equipment is essential to be able to make risk-based decisions.

Some interesting quotes from today’s episode:

“They started looking for other ways they could enjoy being hidden, being persistent, not being detected. And we started seeing a spike of attacks against devices, against the actual equipment and everything that comes with that equipment that organizations use.”

“I think we, as an industry, should be adopting a risk and threat-centric approach where we’re going to cover the fundamental pieces of devices or the software, firmware on those devices that are actually high risk for being attacked.”

“A very typical example is that a ransomware has attacked one of the companies that we’ve talked to, and they cleaned up that ransomware, but after a very short period of time, it came back.”

“They shifted and started exploiting the remote endpoints -- the home devices that those remote endpoints are connected to and the network infrastructure that those remote devices are connecting through, like those VPN appliances and ADC appliances and so on and so forth.”

“There need to be new types of security solutions that protect those remote access infrastructure devices.”

“Some of these devices might need to be inspected for breaches even before they’re being used.”

View Details

You may have played capture the flag as a kid, but did you know it’s a term that also applies to cybersecurity? Capture the flag (CTF) events ask teams to hack into devices in order to detect vulnerabilities, and in this episode of Cyber Security Inside, Camille Morhardt gets into the details with award-winning academics Ahmad-Reza Sadeghi, who is a professor at TU Darmstadt in Germany, and JV Rajendran, who is an assistant professor at Texas A&M both are steeped in hardware security knowledge and research, and they demonstrate why CTF events are such a great intersection of industry and academia. A fascinating discussion that you should definitely check out.

We cover:

  • The meaning and history of “capture the flag” (CTF) in the digital realm, especially as it applies to hardware security

  • The structure of a CTF event and the kinds of tools and resources made available to participating teams

  • How people are trained to look for vulnerabilities, and how they might look for those even without a CTF event

  • The various classes of vulnerabilities, and why the trend of replicating them exists in the first place

  • How the pandemic has impacted CTF

... and more. Tune in!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • The purpose of capture the flag events is for great minds around the world to use their hacking skills to detect vulnerabilities that have purposefully been injected with bugs; that way, product security can be improved based on the findings.

  • Similar to the children’s game, CTF events are competitive; they’re all about picking up “digital flags”, trying to outscore competitors along the way.

  • CTF participants report back to judges to claim their points at the end of an event, and the results are then used to boost existing and future product security.

  • A fantastic outcome of CTF events is that they sometimes lead to the discovery of new vulnerabilities on top of those that have been injected into the codes at hand.

  • In addition to CTF events, academia is key in training students what to look for when detecting vulnerabilities in hardware.

  • When selecting devices to experimentally hack into, it’s important to consider the popularity of the device, as well as the device’s ability to connect to other devices.

Some interesting quotes from today’s episode:

“That's the beauty of the human mind - you can run a lot of artificial intelligence, but nobody has these flashy ideas that come to the human brain.”

“If a device exceeds a certain popularity, that means more people are using it, so we buy this device, and we hack into it.”

“Jason Fung from Intel came to us and said, ‘Hey, I want to have a discussion with you.’ He was pitching this idea of running the Capture the Flag competitions where he would provide buggy Verilog code, and ask students to find the bugs in the code and start exploiting them. And this was immediately great for me because I was looking for buggy Verilog code, and this guy from Intel comes and says he can provide that. And that's great, not just for training students, but also for my research. So that's how I got attracted to this line of work.”

“Sometimes they even find errors and vulnerabilities that we didn't inject into the code that we sent them. That's also the most important part of it. New vulnerabilities that teams find.”

“There are certain bugs that are more severe. That can be, as I said, remotely exploited even by an attacker who doesn't have the right privileges. Those kinds of attacks are far more serious. And our judges tend to value those attacks a lot more.”

“We cannot put it on a commercial platform because companies would not provide that. But this open source platform, on the other hand, is a good vehicle.”

“That has been a big influence, even for our research, because now we know like, ‘Hey, these are the bugs and the problems that the companies care about. So let's use those things to actually kind of reflect the real world scenario’.”

“Our lab aims to develop techniques to protect the designs against these kinds of attacks.”

“We do a kind of market research. If the device exceeds a certain popularity, that means more people are using it, so we buy this device, and we hack into it.”

View Details

As we continue to navigate a global pandemic, the security of medical devices and hospitals is especially pertinent. Camille explores this timely topic in the latest episode of What That Means; she is joined by three well-versed guests to dig in - Matt Russo, who is Senior Director of Product Security at Medtronic, a major medical device manufacturer, as well as Priya Upendra, who is Senior Director of Customer Success at Asimily, a medical device cybersecurity risk management company, and Stephanie Domas, who's Director of Security Communications in Intel's Product Assurance Division. Tune in for the full scoop.

They cover:

  • The various kinds of medical devices you might expect to find in any given setting, whether in a hospital, the home, or anywhere in between

  • How security is evolving as biology and technology become more and more deeply linked

  • The threats that come with increased automation and connectivity in a medical setting

  • What sorts of regulations governments are developing as it becomes impossible not to integrate cybersecurity with healthcare

  • How vulnerabilities are thought about and addressed as devices are developed and maintained

  • How an increasing trend towards telehealth and remote physician monitoring is impacted by cybersecurity threats

... and more!

Check it out!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • While most people think about medical devices in a hospital setting, there are many other places one might find them, whether in outside clinics, the home, or even inside the body as implants.

  • A big challenge hospitals and medical providers face is the potential for a creative hacker to exploit these highly connected devices.

  • You cannot have a safe medical device if it’s not also a secure medical device.

  • Because there’s no prescriptive approach to security, the guidelines are frequently changing and evolving on the journey to maturity.

  • Addressing threats needs to be a highly coordinated and holistic effort between manufacturers, healthcare providers, regulatory bodies and security researchers.

Some interesting quotes from today’s episode:

“We've seen a lot of those devices become much more technology enabled over time as we start to think about different types of therapies that those products are providing, whether that's diagnostic, just trying to monitor something, or trying to improve a patient's condition that be managing someone's pain, infusing a drug into their body that they need to get better, or even regulating their heart rate.”

“Now we have a set of hardware and software components that go into building a medical device. And what that's doing is taking in a lot of the physiological data at the patient’s bedside, and then making it available in a very seamless manner to the provider to make decisions about diagnosis, treatment, and also monitoring the patient's condition and well being.”

“Hospitals have the challenge where we have all this interconnectivity, but we don't have the right infrastructure or the right security controls to make sure that there are no backdoors into those legacy systems or those proprietary systems from a creative hacker.”

“What we've seen over the last several years is evolution and the acceptance that security is innately intertwined with safety, that you cannot have a safe medical device if you do not also have a reasonably secure medical device.”

“What you've seen is this evolving guidance where they're really trying to lead the industry through that risk based decision process without stifling creativity.”

“What we supporters of medical devices need to do is also coordinate better with manufacturers, with regulatory bodies, with security researchers, and then make sure that we're managing risks in a very holistic manner now.”

“Even if a manufacturer puts out a patch very promptly, if hospitals can't apply the patch in an equally prompt manner, we still have a fleet of unprotected medical devices.”

View Details

We’re all familiar with home and auto insurance, but cyber security insurance? It’s vital to have if you’re a mid-size or above company looking to mitigate risk. In this episode of Cyber Security Inside, Malcolm Harkins joins Tom and Camille again to unpack it all. Now the Chief Security and Trust Officer at Epiphany Systems, Malcolm’s over thirty-year career in the tech industry, gives him a unique perspective on the various facets to consider, so you definitely don’t want to miss it.

We cover:

  • What cyber insurance is and who might need it

  • How cyber insurance compares to other forms of insurance, such as home insurance or pet insurance

  • The kinds of expenses usually covered by cyber insurance

  • Whether or not cyber insurance providers employ requirements or stipulations

  • Why companies might or might not choose to report a compromise to the authorities and self-insure instead

... and more!

Tune in for some next-level insight.

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • In essence, cyber insurance is like any other form of insurance - it offers a method to pay premiums and mitigate some of the potential financial impacts of either a business interruption, a lawsuit, or expenditures specifically related to a cyber event.

  • There are various clauses with different conditions that appear in these insurance policies, depending upon what you're trying to insure against, be it ransomware attacks, business interruption, etc.

  • Some of these clauses can also reduce coverage depending on factors like whether or not you patch the system, whether the antivirus was up to date, etc.

  • Typically the kinds of businesses that have cyber insurance policies are mid-size and above.

  • Companies with large market caps may opt for a level of self-insurance as a form of risk mitigation.

  • Compromises rarely get reported to law enforcement, whether it’s because it’s a nuisance or because a company wants to maintain control over its liability.

  • But the main hope is that, like with other forms of insurance, safety standards and hygiene will ultimately be raised by cyber insurance.

Some interesting quotes from today’s episode:

“A company might want to maintain control over the investigation in order to limit their liability, and stay in control of the investigation versus having law enforcement come in with an unknown set of motivations and start doing things or seizing systems or collecting evidence that could disrupt the business.”

“Being vulnerable doesn't mean you're exploitable.”

“What we need to be able to start doing is start focusing on where we're exploitable, and not just where we're vulnerable; that will allow us to turn the dial on risk more efficiently, as well as more effectively.”

“If I'm worried about a compromise, and data theft, a redundant system doesn't stop data theft.”

“I think they [cyber insurance providers] will help push some level of hygiene and corrective action at the broad level.”

“There's a lot of connective tissue. And without understanding that connective tissue and that exploit path, you're going to be focused on the wrong thing. You're going to say, I'm going to patch all these things, I'm gonna do all the things. And you're still going to have a connection and a pivot point. Because you can't eliminate risk.”

“And I think people need to start thinking about digital extortion, well beyond just the typical unlocking of your system.”

“There's evidence that the insurance industry has made a tremendous amount of impact on improving safety on things. So I'm hopeful that that will occur.”

View Details

In this episode of What That Means, Camille is joined by Chloe Autio, who works in the Public Policy Group at Intel; she sheds light on the concept of responsible AI, a governance framework that takes ethics into account in the development and regulation of emerging technologies. A fascinating and timely topic, so be sure to tune in.

We cover:

  • What is meant by the term "Responsible AI," and why it’s phrased that way

  • Why diverse stakeholdership is vital to mitigate harm and make technology more inclusive

  • Who the technologies are responsible to

  • The kinds of considerations that need to be taken into account during the development process, including looking toward the past

  • Why AI shouldn’t be considered purely good or purely bad

  • The importance of transparency

... and more! Give it a listen!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • Responsible AI is essentially the idea that there is a shared collective responsibility in developing and regulating emerging technologies.

  • Having a diverse stakeholdership boosts inclusivity and fairness throughout the entire AI lifecycle, and also mitigates harm.

  • Thinking about the context in which a technology will be used or deployed is crucial to determine where the most significant impact will be felt.

  • It’s also important to understand the past so that we don’t perpetuate harmful structures in the future through these technologies.

  • Transparency is key to development, because it connotes a level of accountability.

Some interesting quotes from today’s episode:

“I feel like the term ethics doesn’t quite encompass all of the issues that we’re talking about when we’re thinking about governing or making AI more responsible. And for that reason, I really prefer the term responsible AI.”

“Safety, privacy, inclusivity, fairness. What I think is meant by responsible AI is everyone having a shared responsibility to think about all of those issues from the beginning to the end of the AI lifecycle.”

“I think part of this work is really trying to figure out and understand both the good and the evil to make the good all that much better and the evil all that much less.”

“When we’re thinking about responsibility in this space, as we move forward, we really need to think about and understand the past and how to make interventions and corrections to some of the structures and systems that have foundations that we, as a society, aren’t very proud of.”

“You can’t have the explainability without the transparency.”

“When we’re thinking about Responsible AI and, particularly the responsibility component, I think the term transparency is so much more critical, because it also has an element of accountability.”

View Details

At first glance, it might not seem like a sports background has anything to do with getting into a cybersecurity career. But according to Charlie Shreck, a former professional cricketer turned Head of Engineering for Redscan, there’s a lot of crossover between the two worlds. He speaks with Camille and Tom about the specific areas of overlap on this episode of Cyber Security Inside.

We cover:

  • Charlie’s sporting career and why he eventually decided to transition over to the world of cybersecurity

  • What kinds of athletic traits and mentalities are well-suited for an IT career

  • Why even people without much previous IT experience can make for valuable team members

  • What someone looking to pursue an IT profession should consider

  • Why it’s crucial to keep your cool in the workplace

... and more. Tune in!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • Although an athletic career might not seem to have anything in common with the world of cybersecurity, a sporting mentality teaches you to keep calm under pressure, to think creatively when faced with problems, and to persevere, all of which are great traits to apply to a cybersecurity role.

  • While the field of IT and cybersecurity does require quick thinking and learning, it doesn’t necessarily mean that someone new to it can’t come in and be successful; what’s most important is an open mind and fresh perspective.

  • Whatever problem you’re trying to solve, you’re probably not the only one, so be sure to take advantage of the many resources available to help you along the way, whether that’s Google, chat forums, etc.

  • Differences in thinking and opinion are valuable for problem-solving, and questioning the standard practices and routine can be beneficial.

  • Stress is contagious, so whether it’s crunch time in a sporting event or working to solve a cybersecurity issue quickly, it’s vital to maintain a sense of calm.

Some interesting quotes from today’s episode:

“I realized very quickly that there's the assessment factor and the self-analysis of what you do, and how you did it, moving into a security function in IT, or engineering. I mean, it can be in pretty much any job in security that you always have to analyze what they've done, or how they've done it, and then how you can negate that, and then get the upper hand eventually at a later time. So I enjoy that, I can relate a lot to that.”

“It's almost a competitive environment in the security world, as much as in cricket. Maybe more so because there's more at stake. You've got your customers that are at risk if you don't analyze and assess it properly and move quickly to create a solution, especially when a threat actor is actually getting into a customer's environment. There's a lot of crossovers.”

“When I was playing cricket, I was the geek, I was the nerd because I was the one that was fixing their computers, I was sorting out the home networks...if a camera wasn't working, they’d come and get me to fix it. Now that I've moved into security, I'm basically the jock. I'm the one that was the sporty guy that doesn't have all of the technical requirements, or didn't have it from a very young age.”

“Even if you have no experience in it, you can come in, you can figure it out, you can figure out the main techniques and the best practices that you would follow. They're all laid out for you.”

“That was an advantage I had coming in, because I wasn't aligned to the same thinking that everybody else was.”

“It's just an understanding of people. And there's a relationship that you have with them that I think won't change within the sporting world, within business, and especially security.”

“If they can't handle that, and they start spreading that stress and that anxiety, you can't really have them in your team in either team environment or in the business world, because you can't have your team falling over under that pressure.”

“If you're fearful of getting into this environment, it isn't as bad as you think as long as you stay calm and you can basically think clearly. And all you've got to do is resolve the situation. Trust that you can do it.”

“There's the adrenaline rush when you figure something out, and when you get it working it’s the same as being on the sporting field.”

View Details

In this episode of What That Means, Vernetta Dorsey, a Product Security Staff Engineer at Intel, and Diana Carroll, a Product Security Expert, get to the heart of the secure development lifecycle (SDL) with Camille. Whether this is a brand new topic to you or you’re looking to scale up your existing SDL, they give fantastic insight across the board.

We cover:

  • What the secure development lifecycle is and why it is so essential to get right from the beginning

  • Why forward-thinking, integrated partnerships are meaningful when it comes to SDL

  • How someone might effectively go about scaling up a secure development lifecycle across an organization

  • Additional support systems and processes to consider for your secure development lifecycle

  • The similarities and differences between SDL as it applies to hardware and software

...and more. Check it out!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • A security development lifecycle (SDL) is what companies in the industry utilize to make better products.

  • SDL is most effective when security attributes are incorporated from the get-go. However, even after your product has been released, you still need to focus on maintaining it due to the ever-changing nature of the industry landscape and emerging threats.

  • It’s crucial to know how long you want to support your product so that you can adapt as needed.

  • Companies should always be thinking about worst-case scenarios to prevent them from happening.

  • It’s important to form an integrated partnership between those developing the products and a security or product assurance organization so that no detail goes overlooked.

  • Automation can be a great labor-saver, but that doesn’t mean AI can do everything for you, and you have to be sure you’re putting in the proper maintenance.

  • Scaling up a secure development lifecycle should be a gradual and collaborative process because rushing it, especially if people aren’t aligned, tends to go poorly.

Some interesting quotes from today’s episode:

When we talk about the security development lifecycle, we're talking about certain attributes, assessment tasks or activities that one would want to include in their product development lifecycle.”

“One of the things that we've learned over the years is that it's much easier and more cost-effective if you start incorporating your security attributes in at the beginning, rather than trying to tack them on later, after the fact.”

“We find the most issues when people don't think about the ultimate, the bad case. And that's why it's critically important that this fits within the actual development and engineering teams.”

“Nobody knows a product better than the people that are building it. And that can be their biggest strength. And sometimes a weakness too, because the thing about not seeing the forest for the trees kind of comes into effect. Sometimes somebody is so focused down in the details, that they need somebody to help them zoom out and look at that bigger picture, that broader forest, of how it needs to interact with all these other parts of the ecosystem.”

“Automation can be very valuable. Because from a developer's perspective, or a validator’s perspective, I would often find myself in the spot where if I had to do something more than two or three times, I would rather write a script to do it for me and focus on something else.”

“One of the things I have seen is when somebody builds out this great automation system, and then they don't maintain it for a few years, it can go from becoming a great helper to a handicap.”

“If you don't have that expertise in-house, today, there are places you can go to help build that out.”

“If you try to go from zero to 100 miles per hour all at once, it's going to be a shock to the system. And that's often tended not to go so well. I would say pick a place to start and focus on incrementally adding and improving and expanding the scope of what you're doing.”

“You have to really know your company culture, know your development engineers, to understand which lever you would need to engage and to get everyone on board to where you want to go.”

“If you don't have the validation systems, and the ability to update products after you've shipped them out, or things like that, that impacts not only your overall quality, but also your ability to respond and improve your security and products as well.”

“It's really important to get your architecture right because once you burn something in, you can't fix it, versus the software where you have the capability to make updates and changes much later in the process.”

“Regardless of whether you're talking hardware or software, or even different types of software, context is key.”

“If we're not thinking about it, that means the hackers or the bad actors have more opportunities to take this thing that someone's making for the good of humanity and use it in a way that was not intended.”

View Details

Min Kyriannis, CEO and co-founder of Amyna Systems and managing director of EMD|JMK, is a wearer of many hats. On this episode of Cyber Security Inside, we get into all the details - we talk entrepreneurship, how cybersecurity relates to manufacturing facilities, the importance of giving back, and lots of other interesting tidbits, such as how Min grows her own Carolina Reapers in the backyard!

We cover:

  • How she got from Point A to Point B in her career despite a tough childhood

  • What to look for when selecting a trustworthy team for security and risk management

  • How COVID accelerated the need for better-protected infrastructure

  • The focus on giving back, especially regarding building a better future for #WomenInTech

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • There’s a collaborative effort that needs to happen between manufacturers, distributors, and owners regarding device security.

  • Selecting a trustworthy team is reliant on lots of gut checks and long-standing human relationships.

  • You should also ask the right questions of your team to ensure you’re working with quality people.

  • You can succeed regardless of your background, as long as you’re willing to put your mind and energy into it.

  • Despite how busy you may be, giving back to your community is crucial to shaping a better future.

Some interesting quotes from today’s episode:

“I actually broke three computers [while] programming because I couldn’t yell at it, and it didn't respond to me. So I smacked it and I think I broke the motherboard!”

“We’re creating a bunch of foundations, one specifically dedicated to underprivileged youths and gives them opportunities which they otherwise wouldn’t have. And also looking at veterans, seeing if there’s a way to help veterans who are just recently discharged from the military.”

“We raise funds to actually have organizations who are boots on the ground to help save children and women who are in forced labor.”

“With COVID, everything has been blurred. I mean, we’re all working from home. So the expectation is when you go home, you should be able to connect to your workplace and also work and perform your functions at the same time. So for us, we kind of view it more as an entire ecosystem. It’s not whether it’s commercial, residential, private, or public, it’s basically everything, all the devices.”

“One of the things that we’re doing is also quality control. We’re actually making sure that these devices are tested properly before they get shipped out, but we’re at the proof of concept stage.”

“The team is critical, and I think it’s not just a supply chain, but also the team of people that you’re working with needs to be also vetted and looked at properly. And that’s what we’re doing right now as we’re developing these components, the software, the box itself; we’re working with the right people and also the right companies.”

“The expectation is you’re going to have to put this somewhere secure where people can’t break in and tamper with the device.“

“Unfortunately people can lie, but with people that you work with for a long time, it’s harder for them because there’s a reputation there also.”

“You’re going to know if there’s something wrong; you can understand body language, you can understand how they work due to business dealings.”

“It’s a very male-dominated industry, even in security, physical security; IT has been very male-dominated. That being said, mentorship has been extremely difficult. So there wasn’t mentorship. You had to learn things on your own or really kind of claw some ways and read a lot to get to an executive level.”

View Details

In the previous episode of What That Means, Camille delved into the world of post-quantum cryptography. Today, she explores cryptographic services with Eduardo Cabre, who is a Principal Engineer with the Intel Product Assurance and Security Division; they discuss the future threats organizations will face and possible preventions.

We cover:

  • The difference between the two kinds of cryptography - symmetric and asymmetric

  • What exactly is meant by attestation

  • What “keys” are and how they’re generated

  • Why encryption is crucial for protecting things like biometrics

  • How much of a threat quantum computing could pose to public and private keys in the future

  • What kinds of new cryptographic services are in development

... and more

Be sure to tune in, and also check out WTM Episode 46 if you haven’t already for a great companion piece!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • Cryptographic services are essential to securing data in computing devices.

  • There are two types of cryptography - symmetric cryptography and asymmetric cryptography; symmetric cryptography deals with the process of encrypting data (typically in very large volumes), while asymmetric cryptography can be used (for example) to authenticate to a remote system using TLS or some other authentication protocol.

  • Cryptocurrency uses asymmetric cryptography.

  • Quantum computers are good at breaking asymmetric cryptography, quantum-resistant algorithms are in development through organizations like NIST to combat this threat.

  • The cryptography system is implemented at a very, very low-level hardware trust level, and is not happening in your CPU.

Some interesting quotes from today’s episode:

“Users expect computing devices to protect their data against unauthorized access, and to do so, cryptography is a very critical tool.”

“The device changes hands a number of times prior to being deployed, and so certainly attestation can be utilized to confirm that the device that you purchase is the device that you received. But in addition to that, attestation can really be executed at any point in time you want.”

“Certainly the private key is the most sensitive part of the key, and so you want to protect it as best you can. If that key leaks, then whoever obtains access to the key can then impersonate that device.”

“As long as the key that is used to encrypt that data resides locally on your device, the encrypted data could live anywhere.”

“Anybody that has access to the public key and a quantum computer will be able to reverse engineer your private key. And that's bad news when that happens.”

“Basically, most network security protocols are based on public key cryptography, and all of those will break effectively. Right? So no more TLS, no more MCTP. All those protocols that utilize asymmetric cryptography for the underlying security will break.”

“We're going to be going from hundreds of millions or billions of keys to dozens of billions of keys in the next few years.”

“The other thing is there is a new concept of platform root of trust, where the platform internally has the ability to interrogate all of its components, obtain evidence that each one of its components is operating in a trustworthy way before the platform boots.”

View Details

Trying to wrap your head around quantum computing and post-quantum cryptography? You’ve come to the right place! The brilliant Rafael Misoczki, Cryptography Engineer at Google, joins Camille for today’s episode of What That Means to shed some light, offering accessible insight into what might seem intimidating concepts.

We cover:

  • What post-quantum cryptography is

  • The usefulness and weaknesses of quantum computing

  • Why businesses should change crypto algorithms sooner rather than later

  • An underlooked form of cyber attack that could heavily affect people in the future

  • When we can expect quantum computers to become more mainstream

... and more!

Be sure to tune in!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • When you’re dealing with quantum computing, you’re visiting both nodes (0 and 1) simultaneously.

  • Quantum computing is great for solving some problems, but not all.

  • Changing a crypto algorithm takes a significant amount of time, so businesses should consider transitioning as soon as possible.

  • Adversaries may be harvesting encrypted data right now with the intention of breaking it later.

  • We could reasonably expect to see quantum computers adept at breaking RSA arrive on the scene within the decade; for that reason, companies should be motivated to start planning and transitioning.

Some interesting quotes from today’s episode:

“Quantum computing will be very good to solve some very specific computational problems, but not all.”

“It’s all about finding, detecting or creating new computational problems that can resist quantum attacks and then build crypto systems on top of that.”

“We are dealing with quantum phenomena all the time, right? But there are several layers of interpretation of this phenomena. And my understanding is that what the previous generation could see was only one layer above.”

“If you are using a quantum computer, you are essentially visiting both nodes, 0 and 1 at the same time. And if you keep doing this for several layers, you start gaining what we call an exponential speed up because you are not going at every layer, you're going from one node, to two, then four, then eight...all powers of two. And this provides an exponential speed up. You can verify many more nodes than you would be able to using classical computing.”

“Crypto agility is really just a set of techniques that make systems more easily updatable. And this is definitely something that architects now can do, no need to wait.”

“The process of changing the crypto algorithm is something that takes a long time. So these markets and industries should start looking into this transition as soon as possible, because it's a long process. It's a multi-year (if not a decade-long) process to change a crypto algorithm.”

“There is also another attack that actually is relevant, which is that some adversaries might be now harvesting encrypted data to break it later. That's what we call store-now-break-it-later.”

“This would be a crypto apocalypse, because we wouldn’t be able to trust our banking systems, our governments and information systems, in general.”

View Details

With the Tokyo Olympics on the horizon, we thought it would be incredibly interesting to explore the ways in which cyber security can impact athletes and the world of sports. 2x Olympic gold medal decathlete Ashton Eaton joins us for today’s episode of Cyber Security Inside to offer his point of view.

We cover:

  • Some of the specific security risks associated with big sporting events like the Olympics

  • Who might be interested in tampering with data, and why

  • Eaton’s career trajectory and how he wound up a decathlete

  • What a typical day might look like for an Olympic athlete in competition, from training to walking around the Olympic Village

  • What advice he’d give to the Tokyo Organizing Committee for this summer’s upcoming Olympic Games

...and more.

Be sure to tune in pre-Olympics for some great insider insight!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • Security is increasingly becoming a topic of interest in the sports world; as more and more athletes track their biometrics digitally, there is more risk for cyber attacks related to sensitive performance-related information.

  • There is growing concern that individuals or even governments of certain countries might tamper with results to benefit themselves.

  • Even things like blood panels and urine sample results from anti-doping tests could theoretically be exploited by hackers.

  • In addition to sufficient security, logistical efficiency and reliable, timely transportation play a key role for athletes in the Olympics, and it’s important for organizers to get those things right.

Some interesting quotes from today’s episode:

“You have to think, Well, what kind of information is being collated specifically for this event? And what could happen that could be nefarious or bad, necessarily?

“At the individual athlete level, you have everything from the data you're generating about your performance to perhaps your physiology--something as simple as notes from your physical therapist on your physical state to maybe some kind of app you're using to track your training, whether it be your times or whatnot, to a blood panel that you've taken to kind of assess your fitness.”

“I was thinking, I have no clue who has access to my stuff. As athletes gather more information on themselves, whether it be video or whether it be spreadsheets of information, whether it's their times or their nutrition or whatever it is, I think it's an increasing concern.”

“What would be more impactful is if you did have access to data from your competitors that basically showed that they were cheating in some way, shape or form.”

“Tampering with the event itself is becoming probably more of a security issue. Anything from timing, right? I mean, you look at something like swimming - oftentimes those world records or those races, when that hand presses that little thing underneath the water there, there are like hundredths of a second. How simple would it be for somebody with means to be able to just switch that sucker around?”

“I think the absolute key to make things successful from an athlete's perspective is logistical efficiency.”

View Details

In this episode of What That Means, Camille gets the definition, meaning, and importance of socio-technical systems from Intel Fellow and Chief Architect of socio-technical Systems, Maria Bezaitis.

The conversation covers important questions like:

  • Why does the overlap of social and tech matter?

  • How does it impact how we should be thinking about security and product design?

...and more! Don’t miss it!

Here are some key take-aways:

  • While socio-technical isn’t a new term or concept, it is new to tech.

  • For most of the developed world, social and tech are inextricably linked.

  • The brevity of some interactions (like those in the IOT space) is not new. What the Internet and the tech evolution have done is increase the diversity and depth of those encounters.

  • We love cities because they allow for more chance encounters, more shared experiences. But now, many of those chance encounters, those shared experiences, are happening online. We’re sort of co-creating worlds.

  • With the younger generations, there’s less of a distinction between the online world and the ‘real’ world. There’s less consideration given to what gets shared online vs. what remains offline. They see the link between social and tech much more clearly and the two are virtually inseparable in their minds.

  • We want to believe security and privacy can be concepts with fixed rules and regulations. But humans show us it’s not that simple. We’re constantly making trade-offs. So, what we need are real-time, responsive solutions.

  • We can no longer only think about what’s best for tech or driving tech forward. When making decisions, product design engineers need to think more and more about who they’re designing the product for and how it will be used.

Some interesting quotes from today’s episode:“The phrase has been used for years in areas like organizational design and workplace research. I'm bringing it to the fore for tech in part because our lives are no longer strictly social, nor are they exclusively focused around technology. And yet, technology companies, I think, are still working towards the importance of that intersection.”

“When we're talking and thinking about technical and technical requirements, we really need to understand the social as inextricably linked. And when we look at our own lives as social entities on the planet, it's really hard, at least if you're in a lot of the developed world, to really think about them as somehow without technology or outside of technology.”

“Which is to say, there are layers to this problem. Individuals exist in contexts, which include places and environments and other people. And technologies do as well. In order to understand how these things evolve, we really need to be looking at the intersection and the coevolution of people together with technology.”

“If you happen to have teenagers at home, which I do, you know that the people that they're interacting with aren't just people that they know.”

“This is why we love cities, because cities have always been these incredible environments for chance encounters, and for very quickly moving us into places and into moments that somehow are not foreseen by the trajectory of our lives.”

“That early moment of a potential for something new, and a potential for encountering something different, was absolutely present and important. And actually, I think that in some respects, we're likely to encounter that again, as more and more parts of our lives are sourced from what we're doing online.”

“I grew up in the 70s, and 80s, and we still operate with this notion that our lives are better without tech. There is a fundamental assumption that it's important to tell your child to park the device, put it away. That it's important to imagine leisure time or time off from technology. I don't think that that's mirrored at all in younger generations. And I'm not sure that's just because they’re teens or preteens. Technology is occupying a very different kind of terrain for them.”

“Their world is organized around communities and places and activities that are sourced from a digital world. And of course, COVID has deepened all of that for them.”

“I think we still see people making all sorts of trade-offs against privacy all the time. What we know for sure, is that privacy has never been and will likely never be a concept or a practice that has fixed rules and protocols for people. We are always negotiating our privacy in the same way that we're always negotiating our security, which is what makes humans and communities of humans a really great place to look for thinking differently about both privacy and security. Technologists would like to think that those things lend themselves very easily to rules and guidelines and regulations. I think humans show us that it's not that simple.”

“Once you remove yourself from the mindset that privacy or security is something that can be fixed – that can be defined and then implemented – and you move into this space where you can think about those concepts as much more dynamic and much more responsive, then I think you enter into a space where you're really thinking differently about the kinds of technologies that might make sense.”

“You're not mapping technologies anymore to behaviors or workloads that are fixed or rigid, but you're able to maybe identify vulnerabilities and holes in a much more responsive, real-time manner. And that, I think, creates space for thinking about change quickly, and in real time.”

“I'd like to see ethics move in the same vein that we're trying to move social research, which is that it's not something that ultimately lives outside. It doesn't necessarily require extra processes and tools and governing boards, but that it becomes much more integral. And I think anyone working in that space today would say that's exactly what we're trying to get done. But just like the general face of social science work in product development, and in tech specifically, that's going to take some time.”

“I think our job as researchers who are working in the tech sector, is to make sure that those conversations have a landing zone, to bring them inside our companies, and then work with the right partners inside our companies to change how things get made.”

View Details

Futuristic cities have always captured the imagination, and as more and more cutting-edge technologies are adopted in smart cities around the globe, we’re seeing a direct link to improved quality of life. But how much catching up does gender equality in the workplace have to do to match the advancements of tech? Kasia Hanson, Intel Global Director, Smart Video & Public Safety Chair Security Industry Association Women in Security Forum, weighs in on these topics and more during this insightful episode of Cyber Security Inside.

We cover:

  • The myriad ways in which smart cities are implementing new technologies to problem-solve across many sectors

  • The kinds of cybersecurity risks cities and their constituents face

  • How thought leaders are helping smart cities envision their futures

  • Why it’s crucial to promote gender equality in the workplace overall, and why boosting women’s visibility in the security industry is key

  • How men can be great workplace allies through mentorship and support

...and more. Don’t miss it!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • Transportation, sustainability, public safety and critical infrastructure are four of the biggest focus areas within smart cities.

  • Everyone can be a target for cyber attacks, which is why it’s so vital that cities are implementing safety measures through tech to mitigate risk to themselves and their citizens.

  • Smaller cities tend to be more adaptable when it comes to embracing new technologies, but that doesn’t mean larger cities can’t have a successful smart journey.

  • COVID accelerated the rapid adoption of new technologies in cities looking to protect their constituents around the globe.

  • Increased visibility for women in the security space is a key part of boosting representation, but it also requires teamwork and mentorship from male colleagues to make things work.

Some interesting quotes from today’s episode:

“I really think making a city smart is a journey.”

“Cyber is really becoming a number one topic for many businesses, including our government. And so it's something that we talk about pretty regularly is, what are the capabilities within cyber that you should be developing as part of your physical security implementation and so forth?”

“We know that everybody can be a target related to cyber, and putting mitigation plans in place and using technology to help you is very, very smart.”

“Bringing different perspectives, different experiences into an industry is I think really important. I think it's important for any industry.”

“Having both men and women working together and collaborating only benefits the industry as a whole.”

“I'm looking to really double the [women in security] community over the next year, and build out a way for us to connect, grow and impact.”

View Details

Even as some aspects of life return to “normal” in 2021, security modeling will never go back to a pre-pandemic state. In this episode of What That Means, Camille and guest Cathy Spence, Senior Principal Engineer at Intel, discuss the importance of zero trust adoption as more and more people work from home.

The conversation covers:

• The basic facets of the zero trust model, and how those can be compared those against older concepts like digital rights management and IDAM (Identity and Access Management)

• How the pandemic accelerated the use of more modern provisioning models, and why zero trust is so important when so many people are working remotely

• The kinds of vulnerabilities people face outside the firewall

• What the workplace could look like post-pandemic, as well as predictions about the future of AI

... and more! Listen in on the fascinating discussion!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

• As more and more people work from home, and management tools become more cloud-based than on-premise based, zero trust securities become especially vital; if one device becomes infected, you don’t want it to affect the entire network.

• Currently, threat modeling is largely “cloud-first”, but in the future, it’s likely to be “AI-first”.

• As new solutions are implemented, it will be key to find the right balance between tracking and preserving people’s privacy.

• The general consensus is that adopting zero trust models is the way forward for data and asset protection as the world becomes less predictable.

• Things will not go back to the way they were, and so it’s crucial to fully adopt and embrace new models.

Some interesting quotes from today’s episode:

“2021 is the year for zero trust, of people really fully embracing the zero trust kind of model, and it’s because of these challenges that are beyond basic security hygiene.”

“When the pandemic struck, it really accelerated a move to modern [management techniques], and some companies were better positioned than others to survive in this environment.”

“Security is always an arms race, because as you address certain security problems, the attackers find a way to get around those, and you have to keep upping your game. This kind of approach really provides a great foundation for you to protect yourself.”

“It’s really about setting yourself up so that you can take better advantage of AI. What the pandemic has taught us is that the world’s becoming less and less predictable.”

“We’re very sensitive about privacy at Intel. We have a process for that. We check ourselves, we go through a privacy review, and we make sure we’re doing the right thing when it comes to people’s privacy.”

“We’re not going to go back to working the way that we used to work, we’re not going to look backward to the old security models. If you don’t really implement the full model, and you let certain applications or certain things skirt the guidelines of zero trust, then it really does fall apart. You really want to embrace that.”

View Details

Have you ever wondered where the cloud lives, or what the inside of a data center looks like? Jake Smith, a director of Data Center Platforms Marketing at Intel, demystifies the answers to those questions and more in this fascinating episode of Cyber Security Inside.

We cover:

• The infrastructure of cloud service providers and data centers

• The kinds of security measures implemented to keep massive data centers secure, and what those facilities look like

• Whether or not we, as individuals, pose any security risk as we operate via the cloud, and how those potential risks are mitigated via continuous updates

• The biggest privacy and confidential computing trends we should be paying attention to over the course of the next three to five years.

.and more! Tune in to join the conversation!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

• Data centers are gargantuan, and they require heightened security across multiple tiers that can include everything from key cards to biometrics.

• Diligence is critical wherever the workload is being processed.

• With a server infrastructure where you have millions of servers, even small anomalies can be detected, which is vitally important in finding and detecting security vulnerabilities and reducing Defects Per Million overall.

• Security begins with the device.

• Software guard extensions and scalable applications that take advantage of SGX are crucial to the future of computing.

• And encryption is key.

Some interesting quotes from today’s episode:

You can’t argue, ‘Well, my on-premise environment is different than my cloud environment,’ because if the data is moving from the edge to the cloud, it has to be secure, encrypted and accounted for every step of the way.”

For many people it [the inside of a data center] looks daunting, maybe like something out of the movie The Matrix.”

The cloud has become a mirror of us as users on the outside, and I think we have to understand that.”

Security is a journey, it is not a point in time. It never ends. Hope is not a security strategy, and so we certainly don’t embrace hope. We actually embrace technology.”

“Encryption, encryption, encryption. Encrypt everything.”

“Only the paranoid survive, and only the most paranoid survive hackers at the scale that we’re seeing hackers come at us today.”

View Details

In today’s episode of What That Means, Camille speaks with Thomas LaLevee, Chief Internal Auditor chez China Construction Bank S.A. He sheds light on the implications of an increasingly digitized world when it comes to assessing cybersecurity risk in governance and audit, and offers great insight into what traits and discussions will be necessary in future board meetings.

The conversation covers:

  • What makes a good internal auditor

  • Why the tone from the top is important

  • The need for adequate information to be provided to the board in developing cybersecurity protection strategies and the kinds of discussions that are needed as governance models are developed

  • How digitalization trends will impact governance and audit

...and more Tune in and join us for this incredibly important discussion!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • While governance is one of the most complex topics in a company, in simple terms it’s about risk management, protecting the culture and reputation of the company, as well as protecting company assets. Internal audits, meanwhile, involve adding value to the company through the development of recommendations for risk management and mitigation.

  • While an out-of-the-box approach might seem like it doesn’t belong in the realm of internal audits, a mix of traditional and innovative risk thinking is key to being able to provide better information to the board.

  • Whether they like it or not, banks will have to adapt to cryptocurrencies for better strategic integration in the future.

  • As we increasingly shift towards a digitized world and automate processes along the way, we increase potential security breaches that come with huge sanctions. This means that each department has to have its own governance that must be audited in a specific way.

  • In selecting independent directors, it’s important to consider competence, but it’s also important to source people working in other companies that are trained in digitalization; this way, they have a good understanding of what’s happening in the world.

  • In developing governance strategies, it’s important to focus on the human impact of cybersecurity risks in addition to the potential financial consequences; reputation is often more difficult to recover.

  • Now more than ever, it’s crucial to bridge the language gap between IT and the board in order to convey the complex technical issues dealing with digitalization and cybersecurity.

Some interesting quotes from today’s episode:

“It’s really important for me, the CIA, to do a mix between traditional risk thinking and thinking out of the box in order to give better information to the board and also to help them make better decisions.”

“If you do not develop a good strategy now, notably if you’re working as a private banking industry, then you can definitely lose lots of clients in the coming years.”

“Definitely one of the most important topics is also reactivity, because it can be the response to cyber risk; as I mentioned, we work in a way more dynamic environment than before. The concept of risk awareness is definitely extremely important.”

“We have to adapt our risk analysis so that we’re sure our audits are adapted to this new world. I think one extremely important thing is that IT, more than ever before, will be a central function inside of the company.”

“One main word in our job is humility. And I think that more than before we’ll need the help of specialists to help us ensure that we analyze the company in the best way. Humility.”

View Details

In this episode of Cyber Security Inside, Tom and Camille continue their talk with cybersecurity expert, Managing Director at Allen and Company, and former Congressman and undercover CIA officer, Will Hurd. In Part 1, the conversation centered around AI, but this time around you’ll hear more about cybersecurity and the international threats out there, plus:

• Digital infrastructure

• The digital divide

• IOT

• Spoof robocalls

...and more. Check it out!

P.S. Go back and check out Part 1 if you haven’t heard it yet!

Here are some key take-aways:

• Our infrastructure plans have to include more than bridges and roads – they need to include a digital infrastructure.

• There are three elements to the digital divide: device, connectivity, and the knowledge of how to use the device once it’s connected.

• Studies show that nearly a third of our country does not have access to high-speed internet.

• Because we live in such a connected world, there’s an increased area for attack.

• Security needs to be baked into IOT and it’s not.

• We can’t only focus on what’s happened in the past. We have to anticipate the cybersecurity threats of the future.

Some interesting quotes from today’s episode:

“And for the last six years, I was saying that infrastructure had to be more than just bridges, roads, locks, and dams. You need a digital infrastructure. The coronavirus pandemic made us realize that.”

“You always have a sensor. And then there's always a potential defeat for that sensor. So how do you defeat the defeat?”

“The ability to corrupt the data, to allow somebody to do something. I think that's an area that, when you start seeing our adversaries get more sophisticated, we're going to have to be mindful of.”

“We know that the IOT environment we're already in is probably more corruptible than our digital infrastructure. We didn't learn the lessons from the development of the internet to bake in security. We're not doing that in IOT, which is sad. And so, in that increasingly connected world, there's more points of failure and more points of attack for attackers to get information.”

“But we have to stop thinking about the previous wars and we’ve got to be prepared for the wars of the future.”

“So, this notion of supply chain security is real. It's complicated. It's hard.”

“In this day and age, policy is never going to be able to keep up with the speed of innovation. So, when you're developing that widget, protecting security and protecting civil liberties should be at the forefront of any developer, any entrepreneur's mind when they're building their new service…at some point, if you get large enough and you're having an impact on society, people are going to be asking those questions. So, bake it in at the very beginning.”

View Details

Risk mitigation isn’t just about calculation, it’s about contemplation. In this episode of Cyber Security Inside, we speak with Malcolm Harkins, a Security Executive, Board Member, Advisor and Coach/Mentor whose thirty-year career in the tech industry gives him incredibly valuable insight into a whole host of key issues surrounding cyber security.

We covered many topics with an overarching question in mind - How can we collectively become better choice architects in the face of inevitable risk?

We discuss:

• The ideal skill set for a CISO/CSO, which should include a breadth of business, risk compliance and technical acumen

• The kinds of vital questions missing from board discussions, including moral and ethical concerns

• The importance of long-range planning when it comes to risk preparedness and damage mitigation

• What can be learned from a disaster like the recent Colonial Pipeline ransomware attack

... and more. Join us for this fascinating discussion, and become a better choice architect.

Here are some key take-aways:

• It’s physically impossible to completely eliminate risk, but you can ask better questions in board discussions to help manage it.

• Similarly, you can’t know everything, but with the right group of people and data, you can forecast a variety of different risk scenarios and become better prepared to minimize damage.

• Ethical and moral questions need to be coming up far more in board discussions - these issues can be a matter of life and death, and should not be ignored.

• When it comes to the language of board discussions, there should be more of an even playing field - non-technical members should begin to employ a basic understanding of security and tech nomenclatures, and vice versa.

• And while it’s important to train people to be on the lookout for ransomware attacks like phishing attempts, it’s not a sufficient strategy - accountability should ultimately be driven back to the security community across the vectors of risk, total cost, and control friction.

Some interesting quotes from today’s episode:

“I think it’s high time that we start expecting the non-technologist board members to at least be able to understand the basic nomenclatures in the security and technology space.”

“I think there’s an ethical and moral accountability that is missing in many of the discussions around risk; that’s a question that I can tell you has never come up in any of the board meetings I’ve ever been in, but one that should.”

“Before I had that dialogue with them, they were not looking at that data integrity with that lens, which would have potentially caused people to get sick or die, and it certainly would’ve had a substantial revenue brand or organizational implication if that were to occur.”

“I think we are doing bandaids, bubblegum and baling wire making up for dated security technologies and other technologies that don’t work.”

“We’ve got to start weeding and feeding our environment. Go look at the effectiveness and efficiency of control, and if it’s not effective and efficient, shut it off. Get rid of it and buy something better.”

“If technology companies spent more time making sure that every engineer who created code or developed technology understood security vs. just functionality, again, you would change the technology vulnerability dynamics by focusing on that training which we don’t do enough of.”

“I’ve always thought of my role as architecting choices for the business...if I architect choices the right way, we’ll make better business decisions.”

View Details

In this episode of Cyber Security Inside, Tom and Camille talk with cyber security expert, Managing Director at Allen and Company, and former Congressman and undercover CIA officer, Will Hurd. While we’re sure he has plenty of exciting stories from his time with the CIA, the conversation steered clear of that (If he told us, he’d have to kill us) and instead covered other exciting topics, like:

• Ethical use of AI

• Facial recognition and AI biases

• Artificial General Intelligence (AGI)

...and more. Don’t miss it!

Here are some key take-aways:

• AI is a global obsession for good reason. It can be used for everything from diagnosing cancers to saving water in agriculture and introducing us to new music.

• We have to be innovative and have the infrastructure and compute power in place to support AI.

• Like all technology, AI can be used for good or bad. We have to ensure we’re making ethical use of it and that it’s unbiased, not discriminatory.

• A growing focus within the AI and cybersecurity space is defending the training data from manipulation.

Some interesting quotes from today’s episode:

“And what undergirds all of this is cyber security. We’ve got to be able to defend our digital infrastructure to protect our intellectual property, to make sure that people aren't selling our secrets.”

“When it comes to certain technologies like Artificial Intelligence, coming in second place can't happen.”

“But then there's also going to be downsides, like with any kind of technology. We have to make sure of the ethical use of these tools. It starts with making sure AI follows the law.”

“We can’t allow algorithms to be biased.”

“We're already seeing Artificial Intelligence being used in a medical environment to diagnose cancers that the human eye hasn't been able to do. You can look at your iris and determine a certain kind of cancer and you catch it, months, if not years in advance, which prolongs life.”

“Most technology and most tools can be misused, but they also have an upside. What we have to realize is this tension between using the tool and making sure it's protecting our civil liberties.”

“I always get nervous talking about some of these sci-fi things. But we're closer than we expect. And it still blows me away.”

View Details

In this episode of Cyber Security Inside, we’re taking a look at cyber security through the eyes of TikTok influencer, Kevin “Keats” Jackman. Keats is a writer and actor with 1.4 million followers on TikTok. And with his background in tech/IT, we wondered: How does he view cyber security differently and what can he teach other influencers about its importance?

We talk:

• What influencers should be on the lookout for

• What can happen when cyber security best practices aren’t followed

• How to protect yourself against threats before they’re real

• How cyber security can translate into real life security for influencers

• How IT can help CIOs improve cyber security

...and more. Tune in – or check out the video – for a very engaging and important conversation.

Here are some key take-aways:

• The world of the influencer is still relatively new, but when you reach a certain level of notoriety, you have to think differently about cyber security. You have to consider what you’re putting out there for your personal safety and well-being.

• Another thing influencers must consider is password security. If anyone hacks one of your accounts, they can delete your content and even ruin your image.

• For password protection, a good rule of thumb is to use complex passwords/phrases and to change your password every 60 or 90 days.

• LastPass is a great tool for managing and remembering your passwords when you change them often.

• Younger generations that have grown up with technology and seen some of the things that can happen when good cyber security practices aren’t followed seem to have a better understanding of its importance. But an understanding doesn’t mean adoption. It typically takes a personal experience or a high-profile cyber security issue for it to become a real priority for individuals.

• You have to train your team and make cyber security real to them. One way to get people within your organization to care about cyber security before there’s a real threat is to show them how easy it is to fall for malicious emails. KnowBe4 is a program that will send out fake malicious emails to your team, and when someone clicks on a link, they’ll receive a report and training that explains what they missed. That way, they’ll realize how easy it is to fall prey to an attack and they’ll know what to look for, so they don’t fall for the real thing.

• The key to cyber security is to put multiple layers of protection in place, like two-factor authentication, Cisco Umbrella, and other tools and systems.

• If CIOs don’t know about new tools and systems, they can’t purchase and implement them. IT needs to keep CIOs in the loop.

• For more from Keats, visit his website keatsdidit.com or follow him on TikTok or Twitter @keatsdidit.

Some interesting quotes from today’s episode:

“You know, when you tell people you're going to school to be a rocket scientist, you get a lot of love. So, I had to really be confident enough in myself to step away from that and say, ‘Hey, this isn't me. I know it sounds great on paper, but I'm still going to be great. It'll take me a little while to get there and may be a little unorthodox, but hey, I'm an entertainer, they're going to see me.’ So, it's really nice to be able to still get that recognition from NASA, even though I'm not at the desk making the rocket.”

“Especially with COVID and everything, cyber security is more important than ever, because everything has gone virtual.”

“When you get a million views overnight, you have to change the way you move. You can't just post everything on your story and go out and just be there, because people, they can roll up on you. People can say, ‘Oh, I need to go there and see him,’ and people, they get crazy. We're at a time where cyber security can translate into real life security.”

“Coming from an IT background where security is the main focus, for law firms especially, I kind of had a leg up with understanding how important it was. But someone who's not from that background or doesn't expect it, you blow up on social media, you could be ruined real quick from lack of cyber security.”

“I think it becomes real when it happens to you, when something happens. Just like backing up your data, things like that. When you lose something, when that external hard drive goes, it's like, I need to back it up because I don't want this to happen again.”

“A lot of it is layering, because with cyber security, you can have all these things in place, but it really comes down to the people and your staff that have the ability to identify something and choose to act or choose not to act. So really training the people is the biggest thing.”

“It's always a cat and mouse thing, but the bad guys are always getting better. So, you have to always be refreshing.”

“I think the younger generation does have a better eye for spotting that stuff because you know, they see it all the time. They know what looks legit. They can tell that the logo got pasted from another source and that it’s not legitimate.”

View Details

In this episode of What That Means, Camille talks with Rhonda Foxx (Head of Social Equity Policies & Engagement at Intel) and Monica Mahay (Head of Cybersecurity, Data & Privacy Legal for EMEA at Intel) about social equity and the corporate role.

What do businesses need to be doing to ensure diversity, fairness, and inclusion in the workplace? Are we working towards an end goal or is this an ongoing journey that requires us to consistently monitor and adjust? The conversation covers:

• Code switching

• DEI (Diversity, Equity & Inclusion)

• Data protection

• Social, tech, and education equity

• Imposter syndrome

• Authenticity

And more. This is a must-listen for businesses in and outside of the tech space. Don’t miss it!

Here are some key take-aways:

Social equity is about ensuring that we’re all treated equally and fairly, and that we’re not discriminated against in some way because of the way we look, where we live, etc. It’s about fairness and inclusion.

• Data protection is responsible and accountable use of data that relates to individuals. This encompasses things like transparency and security.

• Diversity alone isn’t the end goal. We don’t just want all people represented in our companies – we also want all people to be treated equally, to be invited to the same table, and to have the same experience.

• DEI (Diversity, Equity & Inclusion) is an evolution, not an end destination.

• Technology is not the great equalizer because not everyone has access to the same technology. Many of us sit in a place of privilege and have advantages that others don’t. Data shows that women in particular are at a tech disadvantage and less likely to have access to the Internet.

• Because of disparities in access to education, Internet, and the technology needed to connect and learn in the socially isolating WFH/home-school environment brought on by the pandemic, those without the means are falling behind. There are programs out there to assist families and individuals, but help came a bit late.

• Tech companies are leaning into social equity because there’s a realization that if we don’t have tech equity, we’re going to leave people behind. When we lean into equity, it’s the right thing to do – but it’s also imperative for business.

• We need to be looking at our own technologies and making sure we’re not creating bigger divides. We also need to be looking at pay equity – ensuring we’re paying our employees equally and investing in suppliers, vendors, and businesses that align with our DEI goals.

• While things need to change at the policy level, we can’t afford to wait for laws to change. We have to do our part to push important issues forward because they matter to our employees and our communities.

• We also need to look at who’s setting the tone and culture in our workplaces. Is everyone represented? Our employees should be able to bring their authentic selves to work, but many don’t feel like they can. For example, in the Black community, there are concerns about how hair should be worn to work, and what’s considered a ‘professional’ or ‘unprofessional’ look. Our employees shouldn’t have to worry about fitting into a mold or reflecting an image that was created without them in mind.

Some interesting quotes from today’s episode:

“Social equity for me is fairness and it's inclusion, not predicated upon what I look like.”

“Well, I think at its fundamental core, fairness is about equity. You're not going to get to a place of fairness if we're not looking at how can we be more equitable, how can we be more inclusive to have greater equality?”

“The concept of separate but equal is a discriminatory thought in and of itself. Why on earth would we be separate? And if you are separate, how on earth could you be equal?”

“So, we've got to take people's uniqueness into consideration, and take diversity and inclusion and make it more about intersectionality of all of our different complexities to get to a baseline of equity.”

“DEI is an evolution, not just a finite.”

“Many of us will sit around, watch Netflix and listen to podcasts and eBooks, and we have access to next day, same day delivery of games, clothes, food, online gaming, and we can call family and friends through a video call and see their faces. But despite all of these advantages, we still suffer from feelings of isolation and mental health issues. But imagine going through the pandemic with no access to the Internet or with very limited access to the Internet.”

“Right now, there's still a huge divide in access to technology. And it is also generally worse for women…”

“We've got to double down on our commitment to be responsible, to be inclusive, and to be sustainable, because we have no choice but to, because it's the right thing to do. But it’s also the business imperative as well.”

“But now we’re going a step further and we’re saying, You know what? We're never going to have equity, we're never going to have diversity and inclusion goals met internally, if we don't go all the way back to the basics.

“We know you're never going to be on the right path to compete for tech opportunities if you're not given education on an equitable level at your earliest point.”

“[There’s] this perception that because something happens online, it kind of doesn't matter, you can turn the computer off, that it actually doesn't affect your ‘real life.’ But actually, impacts of online abuse are very real.”

“It's going to hit a point where, if we really want to get into equity and equality, we're going to have to knock down some systems and some structures and rebuild.”

View Details

In this episode of Cyber Security Inside, Camille and Tom get into what securing consumer devices looks like in a remote work world and why it’s so important.

Guest Carolina Milanesi, Founder and Principal Analyst at The Heart of Tech, joins the conversation to answer the biggest questions, like:

• What will companies and employees need to do differently moving forward?

• Is focusing solely on device security good enough?

• How do we balance employee privacy with company data and asset security?

...and more. Don’t miss it!

Here are some key take-aways:

• For years, we’ve been bringing consumer technology into the work environment. And now with remote work and WFH, there’s even less of a divide between work/home and less control over the devices being used.

• There’s now a greater need to understand where the weakest links are and what needs to be done to protect company data and assets.

• Post-COVID, not everyone is going to want to come back to work, especially not 5 days a week. Remote work is here to stay, so we need to approach security with this in mind.

• When COVID hit, many people were forced to work remotely without any previous planning or experience -- and the burden of making that overnight switch fell to the employee. Moving forward, the responsibility will likely need to rest more heavily on the employer.

• In the past, the concern was around bringing consumer devices into the workplace. Now, it’s about bringing work technology into the home. Some things that the IT department may want to do to ensure security on those devices may not be welcome in the employee’s home.

• One way to solve part of the security problem is to issue company PCs that have cellular connectivity built in.

• While it may be simpler to focus on securing devices, the better option may be to focus on securing the data.

Some interesting quotes from today’s episode:

“There's less control over which device we as humans gravitate towards, and therefore there's a higher need to understand, first of all, what devices we use and what we like to use, and where your weakest links might be when you talk about data security and asset security.”

“There's no question in my mind that the way that we are going to interact in the office is going to change. Work and office are not going to be the same thing. I don't have to go to the office to work. I'm going to go to the office to interact with people, which is what most people lament missing, being remote -- and in a more purposeful way than we did before.”

“People had to go and work remotely overnight. And the burden of that was on the employee. It can't be like that. It has to be on the corporate side.”

“Before you were bringing a consumer device into an office, so it was clear, you kind of have to go by the rule of the office. Now you're bringing technology in my home. At the end of the day, I see that as my home. And there are things that I might not actually be happy for my IT department to be doing.”

“One thing that we definitely have seen OEMs and enterprise ask for more is connectivity embedded in laptops. And that cuts out any of that idea of, ‘Okay, I have an IT department now in my home managing my network.’.”

“In 2020 there was a lot of flexibility put into the way that we were working…Once we are in the position to go back to the office and it’s a choice to be home, I think that flexibility is going to go away and there's going to be a set of requirements that organizations will have.”

“I think the device is the easier thing to fix, to be honest. And at the same time, I worry that focusing on the device might give you a false sense of security because the issue is the data.”

“I think what plays in our favor from a corporate perspective is that consumers are becoming more aware of privacy and security risks. And I think that gives them a better position to understand that in a corporate environment.”

View Details

In this episode of What That Means, Camille talks wireless communications with Vida Ilderem, VP at Intel Labs in charge of wireless communications research. Vida has 27 patents, including one on beam forming, and she’s the perfect person to get the definition and evolution of wireless communications from.

The convo covers:

• 3G, 4G, 5G and 5G+

• IOT

• Wi-Fi and Bluetooth

• Computing at the edge

• Interoperability

• Reliability

• Liable low-latency com

• LTE

• Beam forming

...and more. Don’t miss it!

Here are some key take-aways:

• Wireless communication is the transmission of information over networks, without the use of wires. It’s about communication and the connectivity needed.

• 5G stands for the fifth generation of communication.

• Wi-Fi and Bluetooth are examples of protocols for wireless communication.

• As machines come online, ultra-reliability and low-latency becomes even more important – especially in mission critical applications like surgery.

• The human needs and machine needs of wireless communication are different. Making wireless communication reliable means finding that balance of human and machine needs.

• The more things on your network, the greater your attack surface. The challenge of securing all of these things is an ongoing one that’s not as simple as we’d all like it to be. One reason is that we want our devices to talk to each other, regardless of what company they’re from. Making that inoperability possible while keeping everything secure is inherently difficult.

• Reliability is another challenge of wireless communications, because wireless, by nature, is not reliable.

• Introducing a new generation of wireless communication doesn’t mean you can stop supporting previous generations. Not all devices will rely on the latest generation and being able to fall back on another generation when a connection is lost improves reliability.

• Beam forming is a way of using antennas to transmit information directly to users by forming directional beams. The benefit is that it extends the distance, increases capacity, and increases the number of users.

Some interesting quotes from today’s episode:

“5G stands for fifth generation of communication. The first generation was analog -- you must have human communication. The second generation was about going digital on it -- there's voice communication. The third generation was when they introduced data -- more people loading images. The fourth generation was allowing people to do more streaming and added mobility. And fifth generation is about, not only getting higher data rates and throughputs, but also bringing the machine and instrumenting the devices -- so giving rise to Internet of Things. These all become possible because of wireless communication.”

“There can be licensed spectrums like cellular or unlicensed spectrums like Wi-Fi and Bluetooth.”

“Then there is the ultra-reliable, low-latency communication for very mission critical applications. And that's where the concept of edge comes in, because you need to bring the compute closer to the data. From the cloud computing all the way to the edge computing. Because the machines or the applications which are coming online now, they need that ultra-reliable, low-latency requirement you have to meet.”

“We want to make sure we get the data when we need the data -- anywhere, any device. That's the human side of it.”

“As you’re increasing the number of things which are instrumented (i.e., they have an IP address and they're joining the network), you're increasing the attack surface. I mean, look at your home. How many sensors do we have now that talk to the Wi-Fi router in your home? And many of these are not necessarily secure today. It is a big task and a challenge that is still being addressed.”

“Wireless link by nature is not reliable. We can drop it because the charge works through the air. So, you can lose the link.”

The other thing with wireless communication is, as you’re introducing a generation, you still are supporting previous generations.”

“There’s also a lot of re-use going on. Again, as I said, you're not throwing out the old to add the new. We still need the old -- you build up on that. So, it's more of an integration challenge.”

View Details

In this episode of Cyber Security Inside, Tom and Camille dive into how content producers and distributors are keeping content secure in a world of piracy and streaming. What makes it possible for us to safely stream content directly into our homes? How do we know what we’re streaming isn’t pirated in some way?

Avi Wachtfogel, Engineering Fellow and Senior Director of Security Strategy at Synamedia, is just the person to cover the evolution of media content security and share the latest threats and best strategies for keeping content secure.

The conversation covers:

• Macrovision

• VHS + DVD

• Torrenting and peer-to-peer sharing

• BitTorrent

• VOD

• Over-the-top (OTT)

• Hulu, YouTube, HBO Max, Netflix, etc.

• Credential fraud

• Deep fakes

• Content protection and service protection

• Watermarking

• Take down notices

... and more Don’t miss it!

Here are some key take-aways:

• With video being distributed more broadly and going straight to streaming, protecting and securing media content has become even more challenging.

• Hardware and software technologies have been used on the service protection side to solve the problem of bootleg cable and other content security concerns of the 90s and 2000s.

• Over the top (OTT) refers to the distribution of video content over a high-speed Internet connection. This covers streaming services like Netflix, HBO Max, etc.

• It’s relatively simple to start an OTT service, so it’s more important than ever to keep media content protected against piracy. If pirates get access to the content, they can re-stream/distribute it.

• Pirates also create distribution chains, selling to other pirates who then sell to consumers. You see this often with live events. There are even salesmen who go door-to-door selling these IPTV services. Content consumers are often confused about whether the content they’re getting is legal or not.

• Licensing agreements that limit when and where content can be consumed can actually drive consumers to seek out pirate streaming sites.

• Credential fraud allows people to access content without legally subscribing to a streaming service. This is another way service providers lose money.

• Using encryption to keep OTT video content secure is a tricky thing. You need to allow those with the device to access the content, but pirates may also be accessing the content legitimately. Protecting that content using encryption is not as straightforward as it is with protecting personal info against external attacks.

• The line between content protection and service protection blurs once the content is distributed.

• The phases of protection are Protect, Detect, and Disrupt. Protecting won’t always be possible, Detecting involves figuring out who’s distributing the content and where and how they’re distributing it, and Disrupting is taking action and putting a stop to that distribution.

• A major challenge with the streaming industry is that everything is so fragmented, and this fragmentation actually encourages piracy. After all, if we’re already subscribed to dozens of services and then a new service creates content we want, where do we draw the line? When do we start seeking that content elsewhere? At some point, these services will have to work together.

• If you find that your own content is being distributed on YouTube, Facebook, or on search engines illegally, you can approach the platform. They’re required to take down those illegal links.

• The challenge of countering piracy requires technological means (like watermarking and tracking pirate services), as well as legal means (like Take Down notices), and a group effort to make it easier for legal content to be consumed than it is for illegal content to be consumed.

Some interesting quotes from today’s episode:

“Because the technologies are out there that make it easy to start a [OTT] service, pirates can do the same. And it's just a matter of having access to the content… If you have any device that outputs content -- that can be a set-top box, that can be a PC -- and that content is being output, it can be captured, whether through the HTMI port, or using the screen grabbing software, or even, an extreme case of just taking a camera and having it opposite the monitor. You can capture that content. And once you can capture that content, you can re-stream it.”

“One pirate will take a stream, a live stream, say of a sports event, and then they will sell that on to other pirates. So, you have a whole distribution chain and then those pirates will sell it on directly to consumers. And there’ll be resellers who are taking that content and selling it further and further along. There’s a lot of confusion very often among customers actually, as to what they're actually getting -- whether it's legal or not.”

“A lot of these services, they call them IPTV services. We've seen in some countries, there will actually be a salesman going door to door. They'll knock on the door and I'll say, you know, ‘For $10 a month, would you like access to these 200 channels? We’ll set it up for you.’ They'll come in, they'll take a box of some sort and go plug it into your TV, and they'll set you up and set up the billing. Some of these guys have got 24/7 support -- pick up the phone and you have support -- and they look really legitimate. And then very often the customers themselves can't tell whether they're signing up for legitimate service or not.”

“Very often these kinds of [licensing] arrangements actually drive consumers to use pirate services… We're actually seeing that kind of tendency. People are looking for content. There's actually a rise in the amount of content that's being viewed over Torrents these days because of these kinds of limitations.”

“You can go on the dark web -- you can buy a set of credentials for a variety of streaming services and pay a lot less for those than you would if you were subscribing legally. And that’s also a major problem for the service providers today. There's a lot of money that they're losing to those kinds of attacks.”

“In the case of video, it's a much more difficult problem because you're trying to protect the content on the device from the person who's holding the device. The pirate actually has a legitimate device with the content on it. And obviously you want a legitimate user to be able to view the content.”

“There are different ways of capturing that content and then re-encoding. Today, just encrypting the content is really not enough.”

“Whether it's Disney+, HBO Max, Netflix -- these new services are appearing every other day. And we all talk about the ‘streaming wars,’ but at some point they're going to have to recognize that they need to sort of get together and solve, what is really going to be a piracy problem. Because people are going looking for the content. People aren't going to sign up for ten different services. And if they don't happen to be subscribed to the particular service where there's content that they want, they're going to go look for it on Torrents. And so, they're going to have to find some way to work together after this fragmentation happens to sort of re-aggregate the content.”

“Today, if you sign up for Spotify or Apple Music or Amazon, you're paying one monthly fee… You don't care what the label is behind the music. You’ve got access to all the music you could want. And when the video industry reaches a point where they make it easier to access content legally than it is to access it illegally, they will have largely solved a lot of the problems that they're seeing today.”

View Details

In this episode of What That Means, Camille has Abhilasha Bhargav-Spantzel, principal engineer at Intel, on the show to discuss Fearless Computing. In addition to her work at Intel, Abhilasha is also working with the kids who will be tomorrow’s engineers, and the conversation touches on:

• What fearless computing is

• Why kids are naturally better at fearless computing

• Fearless computing in the time of COVID

• Biometrics and privacy

• Identity, cryptography, and security

• Multi-factor authentication

• Virtualization

• Hypervisors

... and more! Don’t miss it!

Here are some key take-aways:

• Computers are no longer just tools for tasks – they’re an integral part of our lives. But there’s a lot of fear around being hacked or downloading the wrong thing. Fearless computing is about eradicating that fear. About making it possible to innovate, experiment, and try new things, without that constant fear.

• Kids are great with fearless computing because they question everything. Adults are often more trusting, but kids often start with a sense of distrust.

• Biometrics rely on more than just an image to determine legitimacy and authentication.

• Multi-factor authentication relies on multiple different things (i.e. voice, how you speak, how you type, etc.) for verification that you are, in fact, who you say you are.

• The cloud is already virtualized. Now, we’re working on virtualizing the client/computer. When you virtualize a PC, you can isolate your applications and workspaces.

• Virtualizing workspaces allows you to create partitions that prevent the spread of malware to entire systems. That way, you can try new things within workspaces with more confidence, privacy, and security. Virtualization also allows you to try new things, without being tied to a specific operating system.

• With remote learning, WFH, and telehealth, we don’t have big firewalls or intrusion detection systems protecting us. We have to rely a lot more on our PCs to do the protecting, which is why we’re (at Intel and elsewhere) starting to build more of these capabilities into the actual systems.

• To learn more about cybersecurity programs for kids – like the ones discussed during this episode – check out Fuse Breakers and Echelon Catapult.

Some interesting quotes from today’s episode:

“My experience, working with the kids, is that they start from scratch. They're not afraid of anything, which is what we want to continue.”

“I like to tell the kids, ‘Think bad, but do good.’ So, think what else could go wrong, but at the same time, see how you can protect yourself better and protect others.”

“It's about local authentication, not releasing this information. Your PC, for example, is in your control. It's not going anywhere and not too many people will have access to it and potentially use it in ways that you did not expect it to be used. But if that same information was in the cloud somewhere, just fundamentally, by design, you don't have control. You’re just trusting that the cloud entity that has collected this information is only going to use it for that purpose and nothing else.”

“Server-side, as you say, the cloud is already virtualized. And they did it primarily for consolidation and using applications in a much more efficient way, scaling the cloud. But on the client side, this is the new thing that is happening, which is: just like the server, we are working on virtualizing the client itself.”

“When you virtualize the system, there are actual partitions that allow you to work on different types of workloads and isolate them. Fundamentally, they're isolated. So, if something goes wrong in one, it doesn't impact the other.”

“It [malware] loves to spread. It loves to find its way into every application, down into the kernel levels and across the systems that it can reach. And if you isolate them fundamentally, its reach has already been contained.”

“Virtualization not only brings you the security through isolation, but it can also basically allow you to do a lot more experimentation and creativity, like we talked about. You can try new things and you're not tied to an operating system environment. And that's another benefit.”

“All of us became remote workers in a day's time. And a lot of the times, there was a break the glass scenario, where we just needed the users to be able to access these contained applications in some way or fashion. And that's not sustainable, because the threat landscape continued to grow. Nobody was waiting for things to stabilize before they can start trying to attack the systems.”

That's what we want to do is to build this next generation of citizens and engineers who have security mindset and [are] doing the right things for the community.”

View Details

In this episode of Cyber Security Inside, Tom and Camille discuss the ins and outs of penetration testing with Director of Threat Research at Akamai Technologies, Moshe Zioni. Moshe has over 20 years of experience researching security and brings a lot of real-world insight to topics like:

• Red teams

• Bug bounty programs

• How penetration testing and red teams differ

• What the perimeters are around penetration testing

• White box, black box, and grey box penetration testing

• HackerOne and BugCrowd

• Responsible disclosure

...and more. Don’t miss it!

Here are some key take-aways:

• Internal validation and penetration testing are almost opposites in a sense. The former is designed to ensure the product is working the way it should when used the way it’s meant to be used. You’re limited to a finite set of actions. The latter is designed to see what happens when you introduce the unexpected or unintended into the mix.

• A good QA person will always ask ‘What will happen if I do that? How can I crash the system?’. The difference in penetration testing and adversarial research is that the questions and curiosity won’t end there.

• Red teaming and penetration testing differ in that, with red teams, the company knows it’s being attacked and is looking to detect the attack while it’s happening. With penetration testing, the system is being tested individually, sometimes with firewalls and other security parameters turned off.

• Penetration testing may be white box, black box, or grey box. With white box, the person doing the penetration testing will be given any needed details regarding the technology and how the product works – both front end and back end. With black box, they’ll be given nothing, not even a footprint to the server or any permissions. And with grey box penetration testing, the amount of information provided will be somewhere in between.

• For first time penetration testing with a limited time frame, the recommendation is to go with white box, so you get a deeper, more useful and comprehensive report.

•Facebook just dropped out of HackerOne and started their own bug bounty program, which is now the biggest in the world.

• More and more companies are joining circles like HackerOne and BugCrowd, and their security is benefiting from that engagement.

Some interesting quotes from today’s episode:

“The breaking apart is not the goal. The goal is to see what will happen in erroneous input. And the next step, the really Holy Grail, is how can we defend against those kinds of attackers?”

“It’s been validated. That basically means the product is working the way you expect it to work. So you test things that are, sort of, things that the machine is supposed to do. In the security side, it's almost the opposite. You do things that are expressly not expected.”

“If you have two weeks or one month of man time to do this work, the question is, how effectful will it be for a team or a single person to do this penetration testing work for a week or two? Which, let's remember that a real attacker will not have this limitation.”

“If it’s the first time that you are doing any kind of penetration testing, the general recommendation will be go with a big white box. Because you want to have a 360 of your systems and you don't want to have just a shallow report on what can be seen from the outside, from someone that spends two weeks on your website with no real intention or no real realization of what he's looking for.”

“You can't do a denial of service, which are attacks that are trying to crash down those systems, for example, especially production systems. That's very dangerous for a penetration testing to do…Phishing attacks or social engineering attacks are also out of the question. To involve any employees of the companies is also out of the question for penetration testing.”

“Intentionally, some red teaming are also involving either physical attacks, meaning someone that gets into the building, or trying to social engineer their way through phone and to get some passwords, maybe even to try to do some phishing attacks and even exploitation in terms of malware. But those are the extreme cases of red teaming.”

“If you are on a bug bounty program, you are mature enough in terms of security posture to say, ‘I know of my basic bugs and I'm fixing them. Please help me find the really nasty ones.’ It's something that really signals what kind of company you are in terms of security.”

View Details

In this episode of What That Means, Camille chats with Suzanne Fallender, Director of Corporate Responsibility at Intel, about what corporate responsibility really is. Is it doing the right thing? Is it not doing the wrong thing? And is there really a business benefit?

The conversation covers:

• What corporate responsibility is (in 3 mins or less, of course)

• ESG, sustainability & social responsibility

• Transparency & truth

• Integrated reporting

• Inclusion & diversity

• Corporate responsibility goal setting

• What happens when you don’t meet your corporate responsibility goals

...and more. Don’t miss it!

Here are some key take-aways:

• Corporate responsibility is about more than just ‘doing the right thing.’ It’s a management approach that looks at and proactively manages things like diversity, inclusion, supply chain responsibility, environmental compliance, and more.

• There’s a societal value and a business value to corporate responsibility. Proactively managing these factors ultimately reduces risk and is ‘good’ for business.

• When setting corporate responsibility goals, it’s good to set goals that are ambitious. Even if you don’t meet them all, you’ll likely make significant steps towards meeting them. It’ll give your team something to strive for.

• Transparency isn’t necessarily a proxy for truth.

• In order to incorporate corporate responsibility info into your processes, you need reliable, accurate data and third-party assurance over your corporate responsibility reports.

• There’s a shift, an evolution in the corporate responsibility space. Companies are realizing that many of these things do impact the bottom line. They impact how customers feel about the company and how employees feel about working for the company.

• Global companies, in particular, have shifted their thinking. Many are introducing voluntary initiatives in an attempt to get out ahead of requirements that impact business.

• 10 years ago, leadership in corporate responsibility was about ‘doing less bad’ and individual corporate accountability. 10 years from now, it will be more about ‘doing more good’ collaboratively and leveraging each company’s unique skills for the greater good.

• Cyber security will play a role in many solutions to global challenges — like electrifying the grid, digital access, and autonomous driving — as well as in things like governance and risk management.

Some interesting quotes from today’s episode:

“One of the key things in corporate responsibility — and it's been developing for a number of decades now — is about transparency in reporting on your performance, but also about setting ambitious goals and then being able to report on those goals.”

When we set the 2020 goals that we've included in our most recent corporate responsibility report that's on our website, the thinking behind setting these goals is, you're setting goals that are ambitious. And I actually tell people internally, it’s actually, I think, more credible if you don't hit a couple of your goals, because it meant that you didn't just set out goals that you knew that you could meet.”

“The financial reporting standards and audit standards have evolved over decades. I think we have seen a similar conversation evolving on the ESG topics and the corporate responsibility reporting.”

"Now really it's all the leading financial services firms that have policies on ESG and are looking at this data. And for them to be able to incorporate this information into their investment processes, they need reliable, accurate data. So there is much more of a robust discussion happening about how do you standardize this data more? How do you make sure there's that third-party assurance over the data points?”

I think that there are a lot of these ‘non-financial’ factors that do impact performance and financial performance. It may be hard to measure and quantify exactly how those are impacting, or it could be a time horizon question. They may not show up really in the short-term, but they can really have significant hidden costs in the long-term.”

“We've seen this shift in terms of who do employees want to work for and how does this connect with employee engagement and kind of pride and engagement with who you're working for.”

“10 years from now…leadership will be about convening people together to drive forward on these issues, and really leveraging the skills and the expertise of different businesses in the right way.”

“I think if everyone just keeps doing things on their own, we're not gonna make as much progress as if we have that kind of industry collaboration or kind of that broader kind of innovation focus, especially around the role that technology can play.”

“For Intel, yes, we make chips. But our purpose is to create world-changing technology that enriches the lives of every person on earth. Really aspirational, really kind of hard to measure sometimes from a really data-centric and engineering company. But that purpose is really, I think, what guides these new global challenges that we set out.”

View Details

In this episode of Cyber Security Inside, Tom and Camille once again speak with Dr. Eric Cole, CEO and Founder of Secure Anchor Consulting. This time, the topic is insider threats. Some insider threats are a result of bad actors, while others stem from more innocent and unwitting insiders.

What can CISOs do to prevent, detect, and track down these insider threats? Let’s find out.

Here are some key take-aways:

• There are really two sides of cyber security: prevention and detection. Everything else generally falls under one of these two categories.

• You’re going to miss things with prevention technology, which is why you have to have a detection piece in place. And you have to focus on both inbound and outbound traffic if you’re going to detect both outsider and insider threats.

• One of the biggest issues with detection is a lack of resources. IT is being bombarded by sometimes thousands of alerts daily, and they’re simply not equipped to handle them all. The proposed solution is to tune down false positives and focus on the biggest threats.

• In situations where you can’t possibly address every threat, you have to make sacrifices and choose to address the most impactful threat.

• When determining a hierarchy of importance with server-based threats, malicious code that’s impacting the operating system that runs every time you restart the system will take priority over something that isn’t a threat when the computer’s turned off. With network-based threats, again, you need to determine which threat has the most impact and address that if you can’t address each.

• There are two types of insider threats: the malicious employee and the good intentioned employee inadvertently doing bad things. Both can cause damage, but how you approach each differs. With malicious employees, prevention through limiting and controlling access is the best approach. With employees who are inadvertently causing harm, the best approach is detection, because they won’t be covering their tracks.

• CISOs and CIOs need to understand where the damage is caused and use that information to build better security. Always have the mindset of “There’s a creative way to get this done.”

• Threat hunting is an approach that some businesses take — somewhat in the same spirit as a hackathon. With threat hunting, you assume your network is compromised and then find the adversary. The thing is: many times, businesses that do this actually end up finding an insider threat.

• Focusing on the base core components rather than the specific threats and exploits keeps you flexible and more open to see and spot potential issues.

Some interesting quotes from today’s episode:

“Most companies want to focus all their energy on prevention — on stopping the adversary. The problem is you can only prevent things that are 100% bad, 100% of the time. Which means if something is bad 90% of the time, you can't prevent it because that would be blocking 10% of legitimate traffic.”

“I call it the car alarm issue. When we used to be able to go to malls, and you were walking through a mall, if somebody's car alarm was going off, what did you do? You just kept walking. You didn't call the police. Because they go off with such high frequency we become numb to it. We totally ignore it. And that's the problem with detection.”

“I would rather catch the 10% that are most significant than miss 100% because of the noise.”

“Now this is where world-class security engineers get themselves into trouble because they can't help but say, ‘But they're both important!’ Yes, they're both important. But if you can't do both, greatest good. You sometimes have to make sacrifices.”

“When you're talking about the deliberate malicious insider, because they know they're causing harm, they're going to cover their tracks. So in that case, you really have to focus a lot on prevention. Limit the access that they need to do their job…Go with the principle that we call ‘least privilege’ — only give people the absolute minimal access they need to do their job.”

“If you go in and look at Edward Snowden, when you do the analysis post-mortem, 80% of the data that he stole that harmed this country, he did not need access to to do his job.”

“On the accidental insider — the one that is thinking they're doing good, but inadvertently causing harm — that’s where detection is powerful, because they don't know they're doing harm, so they're not going to try to cover or hide themselves.”

“What I find today is if somebody needs something to do their job and you just tell them no and block it, they're going to do it anyway and just treat it as a covert mission. So what I would do in that situation is, I would go to them and say, ‘Listen, what functionality do you need? Don't tell me, you need a USB drive. Tell me what are the actions that are needed’.”

“How specifically the threat works, how specifically the exploit propagates, I don't care because it would be too much work. I'm going to focus on those base core components. And once again, based on my experience, it works most of the time.”

View Details

In this episode of What That Means, Camille dives into the topic of carbon neutral computing with Director of Strategy and Business Development in the Server Group at Intel, John Miranda.

The conversation is a fascinating one, and covers things like:

• The three R’s of sustainable computing

• The unpredictability of supply and demand + the problems it poses for renewable energy

• Why you can’t store renewable energy

• What some companies are doing to try to reduce their energy footprints

• How a carbon-aware laptop might operate to use more green energy and less fossil fuel

• How time shifting can help with sustainability, while saving companies and consumers money

• Space shifting

...and a lot more. This is one fascinating convo you don’t want to miss. Have a listen!

Here are some key take-aways:

• In the future, our laptops and other devices in the home may be carbon-aware and able to assertively reduce fossil-fuel use and increase renewable energy use.

• One of the challenges in sustainable compute is that with renewable energy, there’s less consistency and predictability in terms of supply and demand.

• At scale, it’s too expensive to store renewable energy. But we can use time shifting and space shifting to ‘chase’ the sun and wind.

• The three R’s of sustainable compute: reduce, reuse, recycle.

Some interesting quotes from today’s episode:

• “Because at the end of the day, it’s not how much energy compute requires; it’s how much fossil energy does compute burn. ‘Cause that’s what’s creating the carbon footprint.”

• “As you make the grid substations more kind of intelligent, if you will, you can start forecasting weather conditions, and you can start empowering IoT devices, data centers, and so on and so forth, to understand what are the upcoming energy conditions — where they can then optimize their operations accordingly.”

• “It’s use it or lose it. If you can’t generate demand, the grid cannot accept energy.”

• “Imagine the idea that you can get paid to use power at certain times of the day. So now, if you can make your operations more agile and carbon-aware, it can translate into an OPEX savings.”

View Details

In this episode of What That Means, we’re talking crowdsourced security and bug bounty, and we’ve got a treat for you: double the brilliance with Katie Noble and Alexander Romero (RoRo). Both are Directors of PSIRT at Intel and both have extensive experience in cyber security as DC veterans (think Department of Homeland Security and the Pentagon).

Our convo covers:

• The flavors of bug bounties

• Crowdsourced security

• Vulnerability Disclosure Programs (VDPs)

• Security Technical Implementation Guides (STIGs)

• CSIRT & PSIRT

• Hackcidents

• Red teams, blue teams, purple teams

• IoT

...and more! Join me for an interesting and insightful conversation.

Here are some key take-aways:

• Crowdsourced security relies on the wisdom of the crowd to find vulnerabilities in systems that might otherwise be missed.

• Bug bounties differ from VDPs in that they’re more of an invitation to find vulnerabilities and report back to the vendor. With bug bounties, there’s also an incentive (sometimes financial, sometimes not).

• Bug bounty incentives can include money, airline miles, lunch with important people, pieces of hardware, and other things.

• Static bug bounty programs are often open to all products and all people. Proactive bug bounty programs may be time-sensitive and only open to specific products and specific researchers.

• Bug bounty programs aren’t for everyone. There are some steps you need to take beforehand, like deciding what you’re asking people to look at. You also need to have a strong VDP in place first, so you can deal with the submissions and effectively mitigate problems.

• Problems and vulnerabilities with products are reported to PSIRT. Problems and vulnerabilities with infrastructure are reported to CSIRT.

• There are legal coverage considerations that you must think of with a bounty. The scope should be well understood, but you also need to allow for the reality that you might not know everything that the system touches.

• If you start with an internal bug bounty program, you need to teach your internal team to have a different mindset, a hacker mindset. The mindset of a builder is typically much different from the mindset of a breaker.

• Until we get to a place where we understand that there is only one world now, there's so much attack structure that is being left unsecured.

Some interesting quotes from today’s episode:

“We had our own tools and our own way of looking at problems, but when you bring somebody from the outside in, they have a different view of the world, different frame, different lens, and that's very helpful at times to kind of see things from the perspective of an adversary or an actual criminal hacker.”

“There is this compliance checklist, for example. We call these Security Technical Implementation Guides — STIGs. And if you follow these, you should be secure. But that's not really always the truth. Sometimes there are other things, some other interactions between software or the services that you're using, that then lead to vulnerability.”

"But researchers had never really been given the opportunity to talk directly to the DoD in that form before. And it turns out they had other vulnerabilities that they were aware of, that they wanted to tell us about, but we didn't have a good way to accept those.”

“A bug bounty, for better or for worse, is going to pull attention towards your product or your company.”

“Bug Bounties are not appropriate for everybody. There is kind of a push, like a ‘fear of missing out’ kind of deal. Like ‘Everyone has a bug bounty and I want one, too.’ But that may not be appropriate for your business. There are other steps that you probably need to think about before you start with a bug bounty.”

“You need to be able to decide, what is it you want people to look at? Are you asking them to look at your products or are you asking them to look at you? That's going to be different.”

“I would say you need to have a strong vulnerability disclosure process in place…You need to be able to deal with those submissions. You need to be able to respond effectively, mitigate the problems. All of that takes policy, process, procedure, infrastructure. It's not something that is an overnight sort of deal.”

“You need to have a method of receiving that information, triaging that information, mitigating it, and then communicating back out to the researcher that you've done those things.”

“I would recommend that every organization start out with a sort of ‘internal bounty’ first. So have your engineers, have your folks who understand the system, try to find vulnerabilities. And if they don’t, still pretend as though they did, and then run it through your process that way — so you can find areas where your process might have holes, or you don't know who the system owner is, or who can take action on it. At the end of the day, that’s what you're trying to do.”

“A lot of times when folks have designed the system, they're looking at it from that perspective. And it’s hard to switch over to kind of an adversarial mindset, which is what these researchers bring.”

“Also, things change, implementations change all the time. So it wasn't necessarily a flaw when the product was designed, or a weakness — it was something that was meant to be that way. But then a product changed or was implemented in a way that the original engineer didn't anticipate.”

“The role of the PSIRT is to facilitate. It's to be the coordinator. It's to be the balanced voice in the room that's kind of trying to move things along. We're not tied to one perspective or another perspective. We're willing to be open-minded and see all the perspectives. And you definitely need all the perspectives.”

“The goal is always to protect the user, and it doesn't matter if you're in government or if you're in private sector. The goal is to keep the eyes on the prize, protect the end user, make this as strong as we can.”

View Details

On this episode of What That Means, Camille talks cyber security privacy and policymaking with Claire Vishik, an Intel fellow and Chief Technology Officer of the Government Markets and Trade division at Intel. Her work focuses on artificial intelligence, hardware, and network security, trusted computing, privacy enhancing technologies, some aspects of cryptography and related global policy and trade issues.

Claire is also on the board of directors of the Trusted Computing Group and TDL, otherwise known as Trust in Digital Life. She's co-chair of the IEEE effort on blockchain and advisor on numerous international research and policy initiatives.

This episode covers:

• Various definitions of “Privacy” shared by Claire to fuel your thoughts on privacy and security

• How different international standard bodies establish different frameworks and guidelines to protect individual’s privacy

• US vs. Europe: Both communities’ approach to privacy are very differently

Some interesting quotes from this episode:

“[Each standard body] is using their own definition of the privacy space that is necessary for them to work in this area. There is no disagreement and really no multiple views. What we lack is some kind of high-level definition that will define privacy in all these very different aspects.”

“In Europe the foundation is in the principle that privacy is a fundamental human right… In the US, we do not have a federal privacy law. We have a hodgepodge of different privacy regulations in states that aren’t harmonized approach, different areas of privacy.”

View Details

In this episode of Cyber Security Inside, Tom and Camille get into the logistics of securing connected devices and systems that exist outside of a firewall. To get the latest on preventing tampering at the edge, they tap into the experience and insight of Eran Fine, CEO and co-founder of NanoLock Security, a groundbreaking cyber security company.

Don’t miss it!

Here are some key take-aways:

• The challenge with securing edge devices and preventing adversaries from changing the parameters is that many of these devices are low in energy and computational power, and using a low-end operating system.

• In the world of connected devices and IoT, threats and adversaries can come in various shapes and forms.

• Things like smart meters have been manipulated for fraud and theft. Many times these types of attacks go unnoticed by standard protection methods because they’re inside of the device or built into the performance of the device.

• Many devices — IoT devices, PCs, servers, etc. — need routine updates. The key to ensuring the update sent over arrives without tampering isn’t encryption; it’s to give the update a specific signature.

• You need to take a multi-layer approach to securing devices at the edge. You need to protect the backend, you need to protect the network, and you need to protect the devices.

• The more powerful and open a device is, the more complicated protection becomes.

• AI and machine learning can help us recognize patterns and malicious behavior vs. normal behavior.

• The best advice for designers: have a multi-layer approach to security, assume that your adversaries are smarter, and apply a zero trust approach.

Some interesting quotes from today’s episode:

The target of the adversary is to change the parameters…What we're making sure is that the devices stay as the owner and the originator designed devices to work as.”

“Our assumption is that connectivity can come in various shapes and forms and adversaries can come in various shapes and forms. And our target is to protect from the known and unknown manipulations.”

“It's all the way from a simple manipulation and stealing personal information, to breaking the device, to making something which is harmful beyond the specific device itself.”

“So we're not trying to encrypt the data. What we’re trying to do is sign it in a way that what came out of the headquarters was sent over the air. When it got to the device, it has the same signature, the same parameters. And then we verify that that's our secret sauce. We verified with very low resources that the originated content is truly the one that was sent.”

It’s below zero trust. Zero trust usually has an anchor. I trust a processor. I trust something. We actually came with the approach of trusting nothing — neither the device, nor the processor, not the network, even the operators, the owner. We just don't trust anything within the flow.”

“And what we're saying is we don't know what we're trying to protect against. We're assuming the following: If this is not signed properly, if we don't recognize the signature, we will make sure that it never gets to the non-vaulted memory.”

So you can hack the network. You can even hack the processor. You know what? I can even steal your password. And still, even if I'm inside with all the credentials, we can still prevent catastrophic manipulation from occurring by the sheer fact that the commands you are sending will not get through.”

“Phishing is not an attack. Phishing is the first part of the attack. Phishing is the way to lure you into doing something. And if I ended up doing only this, okay, so I have the credentials. But then comes the second part where I have your credentials and I'm trying to make a change or own your device.”

“The edge devices that we're working with are single purpose devices. It's easier to protect those devices. When you speak about a server, you have so many attack vectors — some of them are physical network, applications running inside — it’s almost impossible to protect those devices. And more and more capabilities have to be developed.”

The assumption is that the adversaries are smarter. And if you think that way, you're better off. Designers of devices have to take into consideration that if there is a motivation, people will be able to penetrate your device. And they're always smarter than you are.”

View Details

On this episode of What That Means, Camille welcomes Ria Cheruvu on the show to discuss deep learning and AI ethics. Ria is the Lead Architect for AI Ethics at Intel's Internet of Things Group. She has a Master’s in Data Science from Harvard University and her research at Intel focuses on artificial security and ethics, uncertain AI robotics, deep learning for the Internet of Things, and computational models of intelligence.

Oh, did we mention that Ria is only 16?

Oh, did we mention that Ria is only 16? This is one convo you don’t want to miss.

The convo covers:

• How AI and DL are related

• Supervised and unsupervised learning

• Generative models

• Adversarial networks

• AI ethics

• GPT3

• Deep learning as it relates to cyber security

• Model extraction

• Red team penetration testing

• Differential privacy

• Model unlearning

• Federated learning

... and more!

Here are some key take-aways:

• Deep learning is a subset of artificial intelligence. There are different ways to use artificial intelligence and one form of deployment is deep learning.

• The goal of deep learning is to parallel or mimic human intelligence so that high-level functions can be performed.

• Deep learning includes multiple algorithms and sub-applications, like reinforcement learning, supervised learning, unsupervised learning, active learning, and more.

• Supervised learning requires that data scientists supervise and correct the computer as it learns. This enables pattern recognition and can be used for everything from cat/dog detection to self-driving cars.

• Unsupervised learning allows for an exploratory analysis of data, without a defined input/output. This type of learning does not rely on human correction. Some applications include: deep fakes, generative art, and 3D objection reconstruction/construction from a single image.

• The major difference between supervised and unsupervised learning is that in the former, the machine is trying to predict an output, whereas with the latter, the machine is trying to create an output.

• Even in unsupervised learning, there is a need for humans to be involved in the process, for ethical and safety reasons.

• Deep learning can be used to improve security threat detection and response by recognizing anomalies and patterns in user behavior.

• Hackers can use deep learning to identify the cyber security defenses of an organization, and also to break the IP of the AI and DL models that the organization is using.

• Ethics and security can be interconnected in some situations and contentious in others.

Some interesting quotes from today’s episode:

“To summarize it, deep learning is our best attempt at trying to mimic human intelligence using algorithms and computational models.”

“In the case of deep fakes, we have issues with AI safety and ethics. Who is going to control the creation of this algorithm? Where are we going to publish its outputs? How do we let the public know that this was generated by an AI algorithm and not by a human?”

“We're starting to build algorithms that don't require as much data, and that can work with small data rather than big data, and still form interesting extrapolations and find interesting patterns.”

“In this cyber security domain, especially, more data is very beneficial for tasks such as malware detection or being able to predict user behavior and anomalies, etc. In these types of situations, there are two different approaches that can leverage deep learning. One is detection and the other is response.”

“The idea here is that just by querying the system and by getting the outputs of the AI model and its confidence scores, you can start to reconstruct that model or even learn more about it.”

“If we can kind of anticipate those problems beforehand using these techniques like red teaming or penetration testing, then I think that that would be a great step forward.”

“I mentioned predictions in retail, which is kind of vague. But the idea is, you’re able to form marketing based on certain data that you're recognizing from your environment.”

"We want to make sure that this data is being encrypted. It's sensitive. It's not being sent to a server, but I'm still providing the user with the insights that they want to know or tailoring the product to their needs.”

“The whole idea with AI security is that we want an end-to-end security solution…All of these techniques could interact with each other, potentially, and are important for securing the entire AI pipeline.”

View Details

In this episode of Cyber Security Inside, Tom and Camille discuss the role that storytelling plays in communicating the importance of cyber security. Who better for this discussion than Simeon Quarrie, founder and CEO of VIVIDA, a company obsessed with using immersive storytelling to communicate complex ideas and drive change?

This is one episode you don’t want to miss.

Here are some key take-aways:

• Communicating cyber security’s importance and getting people to change their behavior requires more than just a surface-level, intellectual understanding of cyber security. Immersive storytelling is a great tool for providing ‘lived’ experiences that make its importance feel tangible.

• Immersive story can and should include things like video, animation, interactivity, virtual reality, etc.

• To create sustained behavioral change, you need to create an ‘inciting incident’ as best you can and then continuously drive the story home (think nudge theory).

• When using storytelling, it’s wise to keep the neurodiversity of your audience in mind. When everyone is looking at it differently, how do you make it matter to each of them?

• When creating materials as a company, it’s a good idea to involve others and get other perspectives.

• Typically, if more senses are engaged during the storytelling process, the subject matter will matter more and be more interesting to the audience.

• The power of story is that it’s able to create a narrative that people identify with, while simultaneously helping them to understand an issue or subject that may otherwise seem complex and intangible.

Some interesting quotes from today’s episode:

“It's hard enough to be safe, but then you have to try to convince people to change their behavior. And that is a very, very difficult challenge.”

“Now, of course we're going to real levels of innovation in order to be able to help people live the story. But right now, even in things like COVID-19, without the use of headsets, we're working at: How can we use immersive storytelling — the fundamentals — in order to be able to take a subject and then make it matter?”

“It's true that you could have a life experience that changes your outlook so fundamentally that your behaviors then change forever. I believe though, that that is very, very difficult to manufacture. The closest might be an immersive experience, but I don't think that there is much that can be done from an educational training standpoint that has that level of leverage. So what we need to do is…create the best inciting incident possible, which can leverage on story, but it has to be reinforced repeatedly over again.”

“I thought I was the anomaly. It turns out actually there are millions and millions of people like me, probably like yourself, that actually, if you had the preference, would love to have some form of utilizing more senses.”

“What this framework starts to do is start to give you and provide you with a vehicle that automatically starts to make things easier to understand.”

“When you've got that storytelling structure, all of a sudden you start thinking, ‘How can you add additional context to that?’ We use imagery. We use audio. We use all these different components and they really start to make a difference.”

“Can you utilize those principles, even in security training or in security awareness to help people understand and care about the subject of security?”

View Details

In this episode of What That Means, Camille talks diversity and inclusion in cyber security with Isaura Gaeta. Isaura is the Vice President of Security Research at Intel, a 5-time winner of The Intel Achievement Award, and an international speaker on diversity and inclusion in the tech workplace. Tune in for a great convo around:

• What diversity and inclusion is

• Why diversity and inclusion matter in cyber security

• Why diverse teams lead to better innovation

• What neurodiversity is

• The importance of updated and inclusive language in tech

And more. Don’t miss it!

Here are some key take-aways:

• Diversity refers to the unique attributes that we all bring to the workplace. Inclusion is about getting the mix of unique attributes to work together.

• A diverse and inclusive workforce allows us to bring more perspectives (and more solutions) to the challenges we face.

• It’s important to remember that one single approach is not going to solve every problem. An inclusive environment is a flexible environment that makes room for different points of view and different approaches.

• In tech, a curious mindset is common amongst team members. A manager’s job is to give guardrails and then let the curious minds get to work within those guardrails.

• Neurodiversity is about recognizing that we all have different abilities and approaches. It’s about being aware that the ways we prefer to work and the environments we need to do that work may be different.

• As a manager in the tech space, it’s your job to create an environment that allows everyone on your team to be successful.

• There are outdated terms in the tech space that can be triggering for many people. There’s a need to update engineering terminology to be more inclusive.

Some interesting quotes from today’s episode:

“By bringing people in that see the problem in a little bit of a different way, you may come up with something you hadn't thought of yourself or something that like-minded individuals may not come up with by themselves. As you bring in these different perspectives, someone might say, ‘What about this?’ Or ‘What about that?’ And suddenly, a breakthrough and new innovation can really come.”

“If you're a technology company, if you're doing anything in technology, you definitely want to make sure that you have a very diverse workforce, because it will lead to better innovation. And of course, better innovation leads to better products, better sales.”

“In cyber security, we really need professionals that know how to break things. It's actually a different way, cognitively, to approach the problem. So what are the weaknesses in this product that I just designed? What did I forget to think about? What did I forget to secure? What is it that is the weakness in this particular design? Someone that can approach a problem in that regard is highly valuable, because as an engineer, I don't see that perspective. I build it to the specifications and I'm done. And without that different perspective, I just don't know what I don't know."

“For me, the learning as a manager has been to not add too many rules. Just give guardrails.”

“People operate differently and in cyber security you might find a few more people that are neurodiverse than you might in the general population.”

“But as you expand and broaden the workforce, some of those terms feel different. So if I hear ‘master slave,’ and I came from an environment, for example, where those terms are very traumatic or it's tied to my heritage, to my family, when I see them show up in engineering terminology, it's hard for me to overlook it.”

“The terms that we're really trying to avoid are terms that hurt people.”

“I think 2020 really opened eyes for a lot of people of inequities that we have. We have inequities in the corporate system, inequities in society. And if we can feel comfortable to bring up things that we see that are not equitable, and when we bring them up, that management, that leadership is receptive to make those changes, then we're going in the right direction.”

View Details

You’ve seen bits and pieces of the SolarWinds story in the news, but what actually happened (to the best of our knowledge) and what can CISOs learn from it? On this episode of Cyber Security Inside, Tom and Camille invite Dr. Eric Cole, CEO and founder of Secure Anchor Consulting, onto the show to talk about the SolarWinds hack.

Plus, during Fun Facts:

• What’s an early sign of Alzheimer’s or dementia?

• What did people believe would kill you in 1954?

• Why was a donkey-less game named Donkey Kong?

Tune in to find out. This is one you can’t miss!

Here are some key take-aways:

• Large-scale data breaches all share one commonality: a lack of awareness about unprotected data.

• When it comes to asset inventory and patching configuration management, automation is key. Businesses can’t rely solely on humans to get the job done. There’s technology available that can recognize when a new asset appears, so businesses only have to respond when there’s a problem. They don’t have to be looking 24/7.

• The SolarWinds attack was a two component attack. First was the attack against SolarWinds to modify their source code for their Orion product. Second, was the distribution of a malicious update to all of their clients (which then created a back door).

• Unlike attacks in the past where a specific company is targeted, with the SolarWinds attack, it’s more likely that a list of companies was compiled. From there, the hackers looked for common denominators between those companies in search of a way in.

• There wasn’t a single point of failure with the SolarWinds attack. Source code shouldn’t have been directly accessible on Internet facing systems; checks and validations should have been done before sending out updates; and checking and testing should have been done in-house.

• If you have servers or software from a third-party vendor, that needs to be isolated on a separate segment and going through a firewall.

• Businesses should always be watching outbound traffic for anomalies.

• The SolarWinds hackers knew that it’s not uncommon for vendors to push out patches for software. So, they made their malicious code look like a patch update.

• Not all SolarWinds customers were affected. With this attack, you had to be running a specific version of SolarWinds in order to be affected.

• These types of attacks aren’t typically spotted by security departments. They are usually caught as a result of performance issues with IT equipment. The reason is the attackers are clever enough to fly under the radar with security, but they don’t understand the thresholds of the hardware.

• Even if you’re not a customer of SolarWinds, you need to work with your suppliers to ensure that they weren’t attacked through SolarWinds.

• What else do you need to do now? Design as if you were compromised and it will happen again.

Some interesting quotes from today’s episode:

“When you're looking at any of the large-scale data breaches over the last five years, anytime you're seeing more than 50 million records compromised, it's pretty much the same exact playbook. There is a server visible from the Internet that the organization isn't aware of. It's missing a patch. It contains critical data. And that data is not properly encrypted or protected.”

“The real big problem is companies don't have a hundred percent asset inventory and therefore they don't know what's out there and they can't patch it, protect it, or secure their data.”

“Anything that's based on a human is eventually going to fail. But computers are systematic and can be programmed.”

“In the past, if I wanted to target Company X, I break into company X. If I want to break into Company Y, I target them individually. But in this case, they went in and said, ‘Okay, we want to break into all these companies. How do we go after it?’”

“I will tell you how I would have done this attack when I was on the offensive side. I would have put together a list of the companies and government entities that I wanted to break into. I would then start looking at what is the common denominator?”

“They got access to one of those computers. They used that computer to set up what we call a pivot point. They did lateral movement into the network and ultimately found the source code computers. Then from there, they were able to upload malicious code into that source code…They then push that update out to all of the clients. And then all of those systems got infected, installed malware, and then set up outbound command and control channels to communicate with the adversary.”

“Now whether they broke into other vendors is yet to be seen. Remember, most organizations don't detect attacks for two to three years.”

“What they were going after on the source code is the ability to take control of the client computers that ran the SolarWinds software. So essentially what they wanted to do is have a command and control piece of code that, once it was installed on the system, would then be able to take control, make outbound connections, and give somebody access to those networks.”

“I believe they had a long list and they had specific reasons and goals for each of those. Because the malicious code that got distributed with the SolarWinds software, it didn't specifically gather data, exfiltrate data, or delete data. What it did is create access paths for the adversary. So all we know is that the adversary wanted to gain access to this list of networks.”

“That's the interesting thing with not only SolarWinds, but most of these other attacks that we've seen over the last three years. It's typically the IT department that catches it. It's not the security department.”

“At some point they make the false conclusion, ‘Oh, no one's going to catch us. We've been doing it for two years.’ And then they start cranking it up and they inadvertently go in and overload the computer systems. Because these attackers know how to bypass the security equipment, but they don't know the thresholds of the IT equipment.”

“It's often ‘Let's get access and maintain the access to see what we can do, so we can use it at a later point in time.’ Sometimes it's the cell access. Sometimes it's to ransom it back to the company. Sometimes it's to sell to a third party. But the name of the game now is whoever has access wins the game. And that definitely looks like what they were after with the SolarWinds attack.”

“The best bet is to assume that you were compromised and use this as a lesson learned. It will happen to you. You have software vendors, you have components. SolarWinds was not the first and they won't be the last. So you need to go in and assume that you were compromised. Be proactive. And then whatever you would have done to respond to an actual compromise, those are the things you need to put in place today.”

View Details

On this episode of Cyber Security Inside, Tom and Camille dive into a topic that’s on all of our minds: What does security look like in the new WFH and IOT era? Is it good enough to secure our devices or do we need to be thinking about network security as well? Mauricio Sanchez, Network Security Research Director at Dell’Oro Group, shares his insight.

The conversation includes:

• Shadow IT

• WFH

• IOT

• SaaS

• Network security best practices for the new era

• Data leakage prevention

• Cloud malware

• Phishing

• 5G

... and more!

Plus, they close with some interesting takeaways on tea origins, fire ants, and the astounding number of connections being built in a human baby’s brain every second.

Tune in. You don’t want to miss it.

Here are some key take-aways:

• In this new era of WFH and IOT, i’s not enough to protect our devices. We have to also think about how those devices are talking to each other.

• With the increase in teleworkers and the departure from the corporate confines, there’s an increase in threat exposure. The distributed environment makes it all too easy for data to be lost inadvertently or maliciously.

• When experience suffers, people find ways to circumvent corporate security and access the data directly. That’s where new threats come into play.

• There’s been an increase in attacks from a data perspective against SaaS-based applications. Hackers are realizing that, by cracking a SaaS application, they’re getting access to the same class of data that once lived inside the corporate confines.

• Once inside, hackers are focusing on distributing malware to get deeper into the corporate ecosystem.

• The network architecture of the past isn’t conducive to the new trends that have exploded over the course of the last 18 months.

• All IT teams are now having to participate in the overall security outcome of the enterprise.

• Enterprises need to treat the internet as an extension of the enterprise network.

Some interesting quotes from today’s episode:

“When you look at enterprises and how they conduct their business, what we are seeing is that this work from home phenomenon is here to stay at a much higher level than it was pre-pandemic. And so when you start thinking about that, that then has a number of ripple effects when you think about networking or security.”

“From a network architecture perspective, that classical model of sending backhauling stuff back to the data center and then squirting it back to the internet has a number of problems.”

“As enterprises move to a SaaS-based model and rely on third parties, it becomes extremely important to make sure that the network and the IT infrastructure in general plays a role in making sure that the right connections are happening between the right users and the right applications.”

“It’s all too easy for a user — really by accident, not necessarily maliciously — to push a sensitive document to the wrong spot in the internet, because all of these are internet-based applications, like One Drive or SharePoint. Then all of a sudden you have a leakage scenario come about.”

“They're now pivoting towards blasting corporate accounts that sit off on Google Suite or Office 365. Once they do crack the password and get access to the data, they're placing malware on those file shares that looks like legitimate files. And it’s becoming a way to distribute malware to get deeper into the corporate ecosystem.”

“From a network architect's perspective, the world was much simpler before the pandemic, before the ascension of large ranks of teleworkers, before the internet application — because everything was much more contained and monolithic.”

“The internet is becoming the enterprise network for a business. And this is a huge philosophical shift for those people that grew up in the age of being able to touch the box, know what fiber the packets were running on, and really own the end-to-end network themselves.”

“If a business was predicated on having their employees having to come into the office, and that enterprise wasn't really internet and remote worker friendly, then they found themselves having to catch up and make themselves a little bit more internet friendly.”

“Enterprises have to embrace the SaaS-based because not all workloads are going to come back as proprietary workloads and applications. But there are probably some applications that will be coming back on-prem, which then relieves a little bit of the pressure of having to go full SaaS model.”

View Details

In this episode of What That Means, Camille’s tackling the big and broad topic of orchestration at the edge with guest Abdul Bailey, a Principal Engineer with Intel’s Internet of Things Group.

Their convo touches on things like:

• What is included in the concept of orchestration

• What the ‘edge’ is

• How and why the security model changes with orchestration at the edge

• ATM’s POS, programmable logic controllers, windmills, oil rigs, and other uses

• Network connectivity issues

• Workload prioritization

• The Cloud Native Computing Foundation

• Machine learning

• Computer vision

And more. Don’t miss it!

Here are some key take-aways:

• There’s a complexity in an orchestration at the edge conversation that you won’t find in a data center style conversation because the security model is different.

• Orchestration at the edge requires greater security because everything isn’t protected behind a wall. Some resources are out in the real world, away from those secure data centers.

• A higher level of intelligence, reaction time, and redundancy needs to be built in with orchestration at the edge. So that when a ‘parent’ device fails, another device in the area can take over that role immediately.

• Orchestration requires something that describes the workload. But it’s the tools that take over and get that work done.

• You can’t apply the same security that’s used at the data center to the edge. You have to look at the differences and identify what needs to change.

• The edge orchestration software space is projected to grow to a $513 million worldwide market opportunity by 2023.

Some interesting quotes from today’s episode:

“Orchestration is everything really. It's the culmination of bringing together the compute, the networking, the storage, the software, the services, everything together, such that it can support that dynamic environment, where you can take workloads that have been containerized, and maybe the micro-services associated with those workloads, which have been containerized, and have the ability to distribute them across the environment.”

“The security model changes when you talk about orchestration at the edge. Because you've got the cars in the data center, you've got everything behind a wall, guarded, and there's plenty of security. But now you're talking about ATM’s that are sitting out in your local store. You've got digital displays that are sitting at the airport. So your security model has now changed.”

“You definitely have workloads that need to be done. But you need to have those workloads constructed in such a way that they're one, containerized — meaning that all of the resources needed to execute that workload are in that container and you don't have a heavy dependency on a bunch of patches to the operating system to make it work. And once you've got things containerized, you want to be able to have that flexibility to understand what those resources are at that edge, and then determine where to send them to be executed.”

“We talked about a windmill or an oil and gas rig that's sitting out in the middle of nowhere. If network connectivity goes down, do you want that workload—that analytics workload — to stop working just because it can't talk to something? No. You want it to be intelligent enough so that the windmills in the area or the oil rigs in the area can continue to talk and execute their workloads, and share the analytics across them so that everything just doesn’t come to a screeching halt.”

“When you talk about orchestration and a data center, you're typically leaning on more of a central server and devices connected to that central server model. But when you talk about it at the edge, you're talking about like you described — that distributed environment.”

“I think we are going to continue to evolve and grow the conversation and orchestration at the edge, so that we can get to that ant farm-like model that you just described. Where there isn't a need for a central device to constantly be telling everything in the environment what to do.”

“So you're talking about different security protocols, different methods of authenticating the security that's running on one device before it talks to another device. All of these things create a different security paradigm, and if you don't take those into consideration, you could introduce vulnerabilities into your network.”

View Details

On this episode of Cyber Security Inside, Tom and Camille have a fascinating chat with Paul Morrow Professor of Engineering Design and Manufacturing at the Pennsylvania State University, Tim Simpson. Their conversation may seem to border on science fiction, but they’re talking about the existing and soon-to-be realities of 3D Manufacturing. It just might blow your mind.

This is one you absolutely can’t miss. Listen now.

Here are some key take-aways:

• Additive manufacturing is the layer by layer creation of real components. These components can be made of a variety of materials and can serve many purposes.

• Additive manufacturing is being used in the medical and dental fields to make things like knee implants, hip implants, Invisalign braces, and more.

• Additive manufacturing can produce components that are as strong and durable as those made by traditional manufacturing.

• The Navy has even used additive manufactured components made of titanium on their choppers.

• A benefit of additive manufacturing is that it allows you to repair parts and print parts as you need them.

• Additive manufacturing allows companies to more quickly iterate on designs, turning out product in days rather than months, or months rather than years.

• Additive presents new security challenges we’re not used to dealing with in manufacturing. It’s not just about ensuring data security — it’s about ensuring quality.

• Blockchain is being explored as a way of ensuring the security of files and the legitimacy of additive manufactured parts.

Some interesting quotes from today’s episode:

• “The shift from what has historically been 3D printing to this notion of additive manufacturing is you are using an additive process to make a real part.”

• “Think about Jay Leno when he's repairing the old cars, the old legacy cars, or even some of the airplanes and military equipment that was designed 30, 40, 50 years ago. The company that made that bolt widget may not exist anymore. And so you could take that part and scan it or recreate it, and then manufacture with additives.”

• “I don't have to ship my tooling or my mold around the world. And all I need to do is ship a file.”

• “I think the real killer app for additive is just being able to print exactly what we need, when and where we need it.”

• “You could take a cell phone and just record the motors whirring and whizzing around. And from that, recreate what it printed with about 80 to 90% accuracy. So now, talk about espionage and counterfeiting of a part. I could just be sitting there holding my phone next to a printer, getting the beeps and boops and whirs, and turn around and do that."

• “But take a machine shop or a job shop. If they're plugging in a 3D printer to connect to the Internet, now you've got a new entry point for cyber attacks and hackers.”

• “From a design perspective, I can change the composition, I can change the material properties, all within a single part or component that previously I couldn't do, or it was too expensive, or I had to assemble a bunch of different parts together. Additive sort of expands your design space.”

• “I think it's going to allow you to go after smaller markets, after more customization, after niches that you have, by the economics of it, been forced to ignore or not pursue. That's where I think additive is going to have the biggest change here in the near future.

• “As you scale down production quantities, the data security needs are not going to change.”

• “It’s not an ‘if,’ it's a ‘when,’ in terms of when will we just take a blood sample or a skin graph from a patient and then turn around and print his or her new kidney or gallbladder, or whatever, and install that the next time we have surgery. It’s coming.”

View Details

In this episode of What That Means, Camille gets into the current uses and future possibilities of 3D printing — plus, what security might look like — with Dr. Irene Petrick, Senior Director of Industrial Innovation in the Internet of Things group at Intel.

The discussion covers things like:

• Where 3D printing is being used and what materials are used

• The hallmarks of 3D printing

• What’s hindering 3D printing adoption

• How design approach has to change with 3D printing

• The role blockchain may play in ensuring security and quality in 3D printing

• The shift in tracking and liability required with 3D printing

And more. Check it out.

Here are some key take-aways:

• For the most part, 3D printing, additive manufacturing & distributed manufacturing are interchangeable terms — but audience matters.

• A major advantage of 3D printing is that it reduces waste and scrap. Rather than having to invest in large blocks of costly materials like titanium and then cutting away what’s not needed, you lay down, layer by layer, exactly what you do need.

• When doing 3D printing, you can’t simply reverse engineer a traditional part. You have to approach design from a different perspective.

• The dental and medical fields are currently making great use of 3D printing, printing things like teeth, joints, and more.

• 3D printing is not about large scale production, but rather about creating small, customized “products.”

Some interesting quotes from today’s episode:

The difference between a traditional manufacturing and production and 3D printing is I'm really reducing scrap because I'm not laying down material I don't need.”

“The challenge becomes making sure that that layered by layered part has the same attributes as one where I've used subtractive manufacturing.”

“One of the things that's hindering 3D printing adoption right now, is there aren't enough engineers trained or designers trained to think about a different way of designing and a different way of using materials, to what's called ‘functionally graded’.”

“3D printing isn’t ever going to be aimed at large-scale volumes.”

“I'm basically shipping digital files. And so tracking the provenance of those digital files is going to be a bit different.“

"What we're talking about, ultimately in the industrial space, is a method of creating small numbers of parts that can be highly customized.”

View Details

In the latest episode of Cyber Security Inside, Tom and Camille chat with IBM Senior Technical Staff Member, Arnaud Le Hors, about the enterprise use cases for blockchain.

They cover things like:

  • The hype of blockchain vs. the reality of blockchain
  • Where blockchain fits with supply chain tracking and transparency
  • When blockchain makes sense and when it’s overkill
  • The network necessity of blockchain
  • Balancing transparency with privacy
  • And more

Plus, Arnaud shares real world examples of how blockchain’s being used globally and across multiple industries.

Check it out.

Here are some key take-aways:

  • The food industry was an early adopter of blockchain, and uses it to improve transparency and traceability in the supply chain.
  • Blockchain makes the most sense where trust, transparency, and control/access of data is of concern.
  • Blockchain in and of itself is not a solution. It’s a technology that can be built into a solution.
  • You can have privacy settings in place with blockchain, so that you’re controlling who can access the information.
  • The data is rarely stored on the chain. What is stored is proof that the data is accurate.

Some interesting quotes from today’s episode:

  • “I kind of think of blockchain as a way to store data amongst businesses that don't trust each other.”
  • “It's not a single player type of technology, right? You cannot just do blockchain on your own. It doesn't make sense. To make sense, you have to have a network of business partners who are going to use it.”
  • “The very key aspect of the system being completely decentralized allows us to have the system around the world, literally.”
  • “The blockchain itself is a way to actually store data. So it's not just about what's the most current or who's the owner, but it actually keeps all the data, basically since the beginning, as soon as you start tracking, and it just never ends. It’s a present day.”
  • “And that’s something that wasn't so clear in the early days. There was, you know, definitely proponents of the notion that everything should be stored on the actual chain. But it's clear that we're evolved from this now, where the chain becomes just like the universal source of truth, where you go as a backup to be able to back your assertions, your claims.”

View Details

In this episode of What That Means, we’re talking blockchain with the blockchain god: Mic Bowman, of Intel Labs.

We cover:

  • The differences between blockchain, Bitcoin, and distributed ledger technology
  • What people are arguing about in the blockchain world
  • How blockchain acts as a substitute for inter-organizational trust
  • What cryptokitties are going for these days
  • Hashing
  • What smart contracts are
  • When blockchain is the right decision
  • Blockchain in a box

And lots more. Check it out!

Here are some key take-aways:

  • With blockchain, you have to think about the application. What’s the problem you’re trying to solve?
  • Blockchain acts as a substitute for organizational trust and allows us to have an authority that’s outside any given organization.
  • With Bitcoin, whatever the record says is truth, whether it really happened or not.
  • There are trade-offs between trustworthiness and computability.

Some interesting quotes from today’s episode:

  • “Really there's no delete. There's no removing something from the record. There may be reversing it, but removing from the records very, very difficult.”
  • “The specifics of the technology have to do with the applications.”
  • “Blockchain is a useful technology for addressing some problems. But it’s not the solution for all problems.”
  • “Agreement is not always truth, but for the purposes of things like digital assets and cryptocurrencies, agreement is truth…”

View Details

In this episode of What That Means, Camille tasks Principal Engineer at Intel Labs, Rosario (Ro) Cammarota, with defining homomorphic encryption in three minutes or less. And yes, he nails it.

The convo is an interesting one and covers things like:

  • What homomorphic encryption is and why it’s considered the ‘Holy Grail’ of cryptography
  • What the security advantages of homomorphic encryption are
  • Where traditional encryption is vulnerable to attacks
  • How homomorphic encryption raises the bar of protection in healthcare and other uses cases
  • Why not all data would be encrypted with homomorphic encryption
  • How homomorphic encryption can be used in clinical trials to bring drugs to market faster
  • The barriers and challenges in the evolution and adoption of homomorphic encryption

And more. Listen now.

Here are some key take-aways:

  • The concept of processing data while in their encrypted form is not a new concept.
  • The advantages of homomorphic encryption are that: 1. The data is never decrypted through its lifecycle, and 2. The decryption keys that are used in traditional encryption techniques to access the content of the data don’t need to be stored on the system.
  • Homomorphic encryption is something that can be used in combination with other protocols, like blockchain and distributed ledger technology.
  • When multiple entities are collaborating on data, homomorphic encryption increases confidence that: third party data aren’t being leaked and that privacy aspects inherent with the data aren’t being violated.
  • The adoption of standardized cryptography is needed.
  • Because the ciphertext of homomorphic encryption procedure is so much larger than the original data type, you wouldn’t encrypt all of your data.
  • The term homomorphic encryption describes a family of cryptographic schemes. The most efficient homomorphic encryption schemes are based on lattice-based cryptography constructions.

Some interesting quotes from today’s episode:

Homomorphic encryption defines a set of encryption techniques and rules that allow you to perform a computation on the content of the encrypted envelope, without the decryption.”

“Homomorphic encryption, specifically, is considered the Holy Grail of cryptography, just because it has this capacity of computing on encrypted data.”

“Homomorphic encryption raises the bar of protection by protecting the data also from the tenant.”

“Any time you need to process data within a trusted execution, you need to decrypt the data.”

“Homomorphic encryption is very computational expensive. And just the encryption procedure compared to traditional encryption also is relatively inefficient.”

“This idea that you can compute on encrypted data without decrypting, may be puzzling, to say the least.”

“My guess is that in the future, we will see the deployment of a hybrid type of schemes.”

View Details

In this episode of What That Means, Camille invites Lisa Bradley, Director of Product and Application Security at Dell Technologies, onto the show to talk Product Security Incident Response Teams (PSIRT).

Their convo covers things like:

  • The job of PSIRTs
  • The relationship between PSIRT and Secure Development Lifecycle (SDL)
  • The difference between a weakness and a vulnerability
  • How PSIRTs measure themselves
  • What a CVD is
  • How response timelines are set
  • Transparency and trust
  • Where smaller companies should start when setting up a PSIRT

And lots more. Check it out.

Here are some key take-aways:

  • No company, old or new, will ever stop uncovering vulnerabilities.
  • You need to make sure your company understands the importance of security and that sometimes security updates can be more important than feature updates.
  • Establishing a good working relationship with researchers is really important.
  • Be smart about when you’re disclosing vulnerabilities, especially if there’s nothing a customer or anyone else can do about it at the time. A lot of customers will say, ‘We want to know about a vulnerability right away!’ But it's actually not a good industry practice.

Some interesting quotes from today’s episode:

“Security at times can be more important than doing feature updates. But that's very difficult for teams to hear, because they think that profit comes from features.”

“Lately, we're seeing a lot of customers that won't sign contracts or buy our product lines unless we have the right security practices in place. So security is somewhat a selling point, even though we don't make any money to address vulnerabilities.”

“I think that we're going to see this continued trend of actually more vulnerabilities, until we go to more of a flatline. But they'll never go away.”

“Do I want to say to every company that’s starting ‘Have security in the back of your mind, know that it's going to be there, know that you need to start early’? Yes. But is that the reality when you're financially not set to do more?”

“I would say if you were looking at a company, and they weren't putting any security updates out at all, that there's a problem.”

“It's really important to make sure if you're somebody who’s starting off, to have an email address, to establish relationships with researchers, to make sure they know how to get ahold of you. So that you could work with people before they want to publicly disclose something on you without having it patched.”

View Details

In this episode of Cyber Security Inside, hosts Tom Garrison and Camille Morhardt are doing things a little differently. Instead of bringing on a guest, they’re having a 1:1 conversation about the security side of product development and support.

They cover things like threat models, red teams, bug bounties, the role of PSIRT vs. PRT, no harm testing, SDL, issue mitigation, and more.

Check it out.

Here are some key take-aways:

  • When designing a product, you have to think about not just what you’re building your product to do, but also what it might be used to do.
  • Every time you learn about a new kind of attack or vulnerability, you want to bake those checks into your SDL process so you don’t repeat the same mistakes as a product is being designed. Automation can help, while also ensuring you don’t inadvertently open up an opportunity that you already learned about from a security standpoint.
  • If you only rely on external researchers to uncover vulnerabilities, you’ll leave yourself open to security threats and attacks.
  • It’s not good enough just to have a resolution. You have to make sure that the fix for an issue doesn't cause a problem somewhere else.
  • A challenge across the industry is figuring out how to communicate security fixes in a way that customers actually care about.
  • You have to think holistically about your product and you have to think through the security implications — all the way from when you’re initially designing a product to when it’s out in the wild and customers are actually using it. And it takes real investment along the way to do that.

Some interesting quotes from today’s episode:

“Prior to release, we want to go and attack that and see if we can find something ourselves or through a partnership with somebody who's going to let us know what it is. So we've got time to fix it before it actually goes live. And that's a real investment.”

“I think more companies are now becoming aware that this is not something that you can just rely on external researchers to do the work for you.”

“First thing is we have to figure out, is it really a problem? A lot of times researchers just make mistakes or they trip onto an already known vulnerability. And so what we need to do is figure out, is this new? Is it actually an issue or not?”

“You've got to make sure that those learnings that you had internally get recycled back into that Secure Development Lifecycle, so that people who are starting new products are now aware of this new discovery that you've made and are incorporating those learnings into the build.”

When the hole gets filled by the industry, then the attackers go find the next hole. And our job, by the way, within the industry, is that we want to be actually ahead of the attackers.”

“Security is one of those topics. It's very intimidating for people, especially people that aren't deep in security. And so as a feature, what ends up happening is it sort of gets lumped in with just a bunch of other stuff in a product that people don't really understand.”

“Where we are embarking as an industry is to point out that not every company does security, even the basics of ‘how do they support their products?’ There's no real unanimity across the industry in terms of how to do that. And those are things that customers really care about.”

View Details

On today’s show we discuss Human Factors--both in the traditional sense and in cyber security specifically--with Margaret Cunningham.

Margaret has a PhD in Applied Experimental Psychology. She's a member of Forcepoint's X-Labs as the behavioral scientist subject matter expert. X-Labs develops scalable human-centric, security solutions.

In this episode of What That Means, Camille has Margaret Cunningham of Forcepoint on to talk about the intersection of Human Factors and Cybersecurity.

They cover a lot of ground, like:

  • The intent of human factors practitioners
  • Where the fields of human factors and cybersecurity intersect
  • The questions guiding human factors practitioners
  • Why people break the rules
  • How human factors can be used to improve training
  • How you measure a person

And more. Have a listen.

Here are some key take-aways:

  • Human factors practitioners focus on the evaluation and design of everything, with the intent to optimize human performance.
  • Human factors can be broken down into different areas of interest like physical environments, cognitive function, systemic issues, etc.
  • Factors like culture, language, and geography can impact design.
  • The link between the two fields of cybersecurity and human factors is relatively new.
  • Human factors practitioners are now able to use behavioral analytics to highlight anomalous past behaviors with much more specificity.
  • We learn how to break the rules from other people, so behavioral analytics tends to uncover clusters of bad actors.

Some interesting quotes from today’s episode:

“We have to know the limits of people, whether it’s a cognitive or a physical limit doesn’t matter.”

“People are amazing, but we’re not really good at everything. So what can we understand about what we’re designing to improve human performance in areas where we’re weak, while also capitalizing on what we’re good at?”

“We really are starting to use behavioral analytics in a much more sophisticated way, where we’re building an understanding of people’s past rule-breaking or their past exploration that doesn’t really fit with their peers.”

“A lot of times, we learn how to break rules from other people. We learn what the implicit rules are versus the explicit rules from our managers or supervisors or our peers. And in that case, we can start seeing that there are clusters or groups of bad apples. And that can be very meaningful in terms of understanding organizational exposure.”

“I think that people who truly understand how to build metrics that can capture human behavior are going to be making great strides in this industry.”

View Details

In this episode of Cyber Security Inside, hosts Tom Garrison and Camille Morhardt talk PSIRTs with Director for Red Hat Product Security, Pete Allor.

Pete has an impressive history with PSIRT and the convo covers things like:

• What a PSIRT is and why you need to have one

• The dangers of falling into a technical trap when addressing product vulnerabilities or problems

• Evaluating risk and scoring vulnerability

• Why incident response requires organization-wide coordination and communication

• The Incident Response Services framework

• The role transparency plays

• And more

Plus, Pete’s got a book recommendation, Camille’s got a tip for musicians forced to play in the dark, and Tom’s got a trivia question that will get you free drinks, every time. Check it out!

Here are some key take-aways:

• PSIRT is designed to address vulnerabilities with the company’s own products. If you don’t have a Product Security Incident Response Team, you need one.

• Get to know your auditor well and figure out what your risk tolerance is internally.

• PSIRT should be proactive, not reactive.

• We need to talk vulnerability scoring, so we have a commonality, a base to work from. And we need to talk about severity, as in risk.

• PSIRT is a coordinated effort. You need to give everyone the information they need, which means removing the technical babble and simplifying.

Some interesting quotes from today’s episode:

• “So fixing everything is not really the smartest thing because it's not necessarily a problem.

• “Now we're looking at ‘how do we respond?’ It's not just disclosing to us. It's a matter of publishing to our customers. But what we are publishing isn't a vulnerability. We're publishing a response. And that's the change in discussion we need to have.”

• “A customer can't do anything with the disclosure. They do everything with the response. And it's in our name: Incident Response. So we're giving them the tools to mitigate, we're giving the actions to mitigate, and we're giving them the code.”

• “I think we all fall into a technical trap sometimes, which is we focus on the issue itself. You know, this is broken. It's a TLS issue. It's a DNS mask. It's, it's something like that. And so we look at it from a very technical aspect. What we lose sight of is that it's an engineering response.”

View Details

In our first ever episode of What That Means — the Cliff’s Notes companion to the Cybersecurity Inside podcast — Camille is tasking Rita Wouhaybi, Principal Engineer for Industrial Solutions in the IoT group at Intel, with defining Artificial Intelligence in under three minutes.

(Spoiler: she nails it.)

Plus, Camille and Rita cover:

  • The Turing Test + how we measure intelligence in a computer or machine
  • Explainable AI/Biases in learning
  • The questions we should be asking as consumers and/or implementors of AI
  • Deciding what AI techniques to use and what to use them for
  • The confidence levels of AI
  • The one thing to keep in mind about AI
  • Why AI is not going to solve all our problems
  • What AI competition is doing for the industry

Check it out!

Here are some key take-aways:

  • If you feed AI bias, it’s going to spit out bias.
  • AI is not definitive. Every answer that AI gives you is going to have a confidence level.
  • AI is not going to solve all your problems. So pick the problem that makes the most sense.

Some interesting quotes from today’s episode:

“It’s based on some cognitive ideas, where you see information, or actually you see more like data, raw data, and you distill information out of it. And as humans, as well as animals, we do that all the time. So it’s the idea of creating a computer program that is capable of doing it.”

“I would even argue that to a large extent, when you have a child growing in a biased environment, that child will be biased as a child. And it’s going to take them to go out of that environment and expand their horizon — either through reading or experiencing other individuals — to widen that scope and get rid of that bias and reexamine it. And I think that could happen in AI, too.”

AI is never 100% sure. The trick is, where is your tolerance? Do you want AI to make sure that if it sees something bad, to tell you about it, with the assumption that some of those might actually be good? Or the opposite? Which one matters more? So, if you are a medical doctor, would you rather have an AI that says, ‘Oh, I think this one has lung cancer’ higher and ask for further testing, or miss a few lung cancer diagnoses? Where do you want that error to wiggle? Do you want it to wiggle on crying wolf? Or do you want it to be very conservative and miss some diagnoses? Those are very important questions.”

View Details

Ever wished there was a companion series to Cyber Security Inside? Then you have to check out Camille’s new podcast, What That Means, launching next week. 

Each episode, Camille will focus on one topic or term related to what we’re covering over here at Cyber Security Inside. She’ll chat with top technical experts in the industry and get the definitions directly from those who are defining them. So you can get a refresher and go a little deeper with the best of the best.

What types of topics can you look forward to on What That Means? 

  • AI
  • Blockchain
  • Sustainable computing
  • Human factors
  • Gaming

Just to name a few. Be on the lookout for the first episode!

View Details

In this episode of Cyber Security Inside, Tom Garrison and Camille Morhardt discuss a philosophical question: “Is it safer to open up our system and monitor everything closely in a secured manner, or is it fundamentally safer to lock everything down?”

To explore this question, as well as the question of what’s even possible when “people are the new perimeter,” they invited Alan Ross, Fellow and Chief Architect at Forcepoint, to the show.

Cyber security from a human-centric view is Alan’s specialty, and in this episode, he talks indicators of behavior, time-series anomaly detection, privacy concerns, insider threats, who’s getting cyber security right, using data to inform models, and even what he’s learning from CrossFit. You don’t want to miss it.

Here are some key take-aways:

  1. Cyber security tends to focus on detecting malicious behavior of devices or network connections. But Alan explains that it’s also important to look at what humans are doing with devices. Changes in user routines can be signs of compromise as well. If you have enough data, you can identify and take action on potential risks you might otherwise miss.

  2. In order to understand how devices are compromised by user behaviors, you need to understand user behavior from a human perspective. When you understand users’ intentional or unintentional errors, you can spot anomalies and craft different paths of course corrections.

  3. One approach to establishing human-centric cyber security efforts is to build a long-term series of user behaviors. For example, identify: When does the person log on? How do they log on? What applications do they use? How often do they use them? Gather information, then create Indicators of Behaviors (IoB) by building a long-term behavioral analytic model. Find out how the models are built, how AI plays a role, and the type of companies leading the pack in terms of human-centric cyber security approach in this episode.

Some interesting quotes from todays episode:

“People are the new perimeter.”

“Users love to click.”

“All humans have routines.”

“There is a lot of gray in high-tech.”

“People who are trained to do espionage, they never color outside the lines.”

“There are some things that normal users just don’t do.”

View Details

On today's show our guest is Bob O'Donnell. Bob is President and Founder and Chief Analyst at TECHnalysis Research. He's widely regarded as an expert in the technology market research field and his original research and advice is used by executives and large technology firms all over the world.

I'd like to introduce my co-host Camille Morhardt. So hi, Camille, how are you doing today?

Camille Morhardt: Hey Tom. I'm doing great.

Tom Garrison: So what's on your mind today?

Camille Morhardt: Well, I know this sounds like a big topic. I was going to say artificial intelligence and compute.

Tom Garrison: Wow.

Camille Morhardt: But I wanted to start with something a little bit smaller: end devices. So when I think about the evolution of AI, the smartphone, particularly, with its built-in camera kind of gave deep learning such a boost. And then when I think about when I know what I'm going to do, and I need to sit down and get something done, I still go to my PC.

So, what I'm wondering is when I think of the development of AI, it's kind of through the smartphone as this end device. And then of course, servers on the backend for centralized learning models. And then when I think about the future, I tend to think IOT, preventive, maintenance and exciting things like that. But what about this basic workhorse that is the PC? What's happening with respect to artificial intelligence and the PC

Tom Garrison: Yeah, there's a lot to unpack there. In general, there's some pretty cool things about AI. Some of them sound boring, but they're, they're actually pretty game-changing and one of them sort of boring sounding ones is using AI to basically guess what you're about to do on the PC.

So if, for example, you're working away in Microsoft Word, and you've been going at it for a while typing, and then you pause for a moment and you start to move the mouse up, chances are you're, you're either going to be clicking on Save, or you're going to be clicking on Print or something like that. And using AI based on your, the things that you do--without even thinking about it--you can use AI to guess what you're about to do, and then make those actions something that's basically one click away or something that's just right there on the screen.

And it's kind of invisible to the user, but it gets us out of having to remember “which dropdown box do I have to click on this and then that.” And you know, like if in Excel, I don't know how many times in Excel I have tried to find the dang “wrap text,” little check box. Those are all things where AI can watch your behavior over time and learn your behavior and then sort of present the things that you're likely to do in a very easy to find mechanism.

Camille Morhardt: Okay. So you're talking about, you know, basic sort of workload, help my life get better kind of a thing. So what about on the security front? Is there anything that we're seeing there?

Tom Garrison: Yeah. So the first one was just one sort of simple example. And then on the AI side for security what's being looked at now is around using AI to see is the machine operating in a way that it doesn't normally operate. So knowing enough about the way you use your device, to be able to say, “huh, now I, the PC, and operating in a way I don't normally operate” and flagging that. Doing that in a way that doesn't induce a lot of false positives (or obviously false negatives too) but false positives are a real problem for security, because if you are sort of Chicken Little, and you're always raising your hand saying, “Oh, there's a problem! Oh, there's a problem!,” then pretty soon people start ignoring you.

And so the, the promise of AI is to be able to do that and see these anomalous behaviors that you should flag.

Camille Morhardt: I would like to learn a little bit more about that and find out what other people in the industry are seeing.

Tom Garrison: Yeah. I think that's probably a great podcast right there. What, what do you say we narrow in on that topic?

Camille Morhardt: Yeah, I like it.

Tom Garrison: All right, let's go for it.

Okay on today's show our guest is Bob O'Donnell. Bob is President and Founder and Chief Analyst at TECHnalysis Research. He’s widely regarded as an expert in the technology market research field and his original research and advice is used by executives and large technology firms all over the world.

So Bob, you are the perfect guest for us today. So thank you and welcome to the show.

Bob O’Donnell: Thanks for having me.

Tom Garrison: So our topic today is around Artificial Intelligence. And I wonder if you could just spend a moment and talk a little bit about your background and this topic around AI.

Bob O’Donnell: Sure. So I have been a tech industry analyst for a little over 20 years. And prior to that, I was in the music technology business--so writing and reading and playing with musical equipment (because I'm a musician for fun, as well). But so I've been following tech industry trends for a long time. And as we've seen the evolution of computing, we've seen the development of more sophisticated software tools along with more sophisticated silicon and those worlds kind of really coming together in a very interesting way with Artificial Intelligence. The idea being that you could start to see the ability to do things above and beyond what basic software would allow and enable, and then unique means of solving problems and then silicon being designed to accelerate that, cause it turns out not all, everything would just be accelerated by a CPU.

But long story short is as I've tracked these trends in devices and core technologies and software in the cloud, AI has all of a sudden become this huge issue. And I've done some independent research studies on it, I did a survey of AI use in the enterprise. I've done research on AI and consumer applications gaming and so it's just an area that I've looked at quite closely, because there's so much interest in fascination with it.

Of course there's so many different variations on it between machine learning and the different flavors of AI. And it gets very confusing very quickly, certainly, but at the end of the day, it's about being able to extend some of the core, basic types of software tools that we've created in ways that we may not have thought of before. And it's also a way, frankly, from another perspective, it's a way to make sense of data in a manner with which we haven't thought about it before.

So it's a combination of how do you create these algorithms? how do you interpret this data? and how do you put that all together into something that goes above and beyond what we've traditionally done? And it's a fascinating field, obviously, that has lots of implications all over the place.

Tom Garrison: Yeah, no, this is, this is a great, and, and I wonder through the research that you've done--and I understand you've got a white paper coming out as well--for the listeners here, what are some of the key sort of “ahas” or takeaways from your research?

Bob O’Donnell: Initially all the excitement, frankly, and all the action in AI was happening on smartphones, right? It was all about smartphones. A lot of it was we heard about computational photography, the ability to enhance image quality and do, uh, very clever processing in ways above and beyond what you could do with the traditional Photoshop filter types of things. And then we saw audio processing, as well, as some other things. But the PC was a little late to the game.

And now what we're starting to see--and what my research is on--is about AI usage on PCs. We're starting to see PCs be part of the equation. We're seeing a lot of adoption of AI in various PC applications. 90% of PC developers that we surveyed are working on some sort of AI machine learning or deep learning type of effort--either by integrating into a function within their application or building entirely new applications based on that. So that's huge, right? That's a huge amount of focus being placed there.

And at the same time, we've also seen of course, a lot of effort around both companies like Intel, as well as NVIDIA and others to build algorithms and software development kits that can leverage that and to build acceleration into some of the chips that they're creating. So, I mean, everybody is really focused on trying to bring some of that magic that we saw with smartphones a couple of years back to the PC, because there's a lot of interesting applications, especially nowadays when we're all using our PCs a heck of a lot more.

Camille Morhardt: Hey Bob, what is kind of one of the major use cases that people are actually doing with AI on a PC?

Bob O’Donnell: There's a number of things. So we are seeing some of the same kinds of things we saw in smartphones. We're seeing some of the filters, you know, for image filtering and audio filtering, especially now with video conferencing, noise reduction in the background is a huge deal, right? Because we've all had dogs and kids and, you know, loud noises happening in the background.

The other thing we've seen, actually, is workflow automation, processes totally radically different kind of thing, but using tools to leverage how data workflows are happening or process workflows. All those kinds of tools that are run on PCs are also changing.Also a lot on security and threat protection. We're seeing more and more automated tools to look for security threats.

You know, a lot of what AI does at a simplistic level is it Looks for patterns, right? You teach it a bunch of patterns--a lot of these AI algorithms--and then from that, it can determine other patterns. That's a classic, deep learning application. It was initially, you know, it was show 50 pictures of, uh, of, of dogs and then show some more pictures that they haven't been trained on and decide if it's a dog or not. Well, take that a million times further, here's a signature or here's an application that's functioning in an unusual way on a PC,

could that potentially be a security threat? And so you'll see a lot of AI based tools around security and threat protection also being used.

Camille Morhardt: Who's owning those models, then? If we're doing AI on the PC and looking for threat protection, in particular, I guess maybe, you know, is that the IT department who's owning the takeaways from that? or are there managed service providers that are collecting that?

Bob O’Donnell: I think we're seeing all of the above. Obviously in a lot of corporate environments, and even in our extended corporate view of the world with a work from home, IT shops will install, obviously, a number of security tools--there's the traditional MacAfee, Symantec types of things. There's obviously what Microsoft has done with Defender. But there's more advanced other technologies we've seen from Cylance and some of these other companies--some of whom have been purchased by some of the big PC vendors.

But there's a number of tools being deployed, sometimes by corporate IT, sometimes by individuals because, you know, the boundaries between personal and work of course have completely been obliterated during the pandemic. And so you have people working on personal PCs and they're installing those kinds of tools there. But you also, in fact, have service providers, uh, who are involved with this at a corporate level. You've got people who provide a managed security type services that are watching what goes in and out, past the firewall. Again, things are very different now because whereas everything used to be behind the firewall, now, literally everything is outside the firewall and that's changed the dynamic of what the things you have to look for, the types of threats.

So there's all kinds of services being offered from a variety of vendors. You're seeing it as well in network equipment, from the large networking companies. So folks who are in charge of the network at many organizations as a part of IT they might be monitoring. Um, so it's being approached and attacked on many different levels with AI being applied to almost all of these different security applications.

Tom Garrison: So do you see Bob then that the AI is basically just being integrated into many of the sort of existing products that are out there? And it just makes their products better?

Bob O’Donnell: It is. It's a good question, Tom. And yeah, I mean the bottom line is a lot of what's happening is not necessarily that the entire-- I mentioned that some people are trying to do entirely new apps with AI. But the vast majority of what's happening is they're taking a function or two, and they're integrating AI into that. Or they're building a couple of special new features and capabilities leveraging AI models or deep learning or what have you. So that's typically the way that we're seeing, developers on the PC, as well as other platforms do that, right? We saw the same thing on smartphones. There were always photo apps and camera apps on smartphones, but they just got a little bit smarter through the integration of some of these technologies.

And frankly, in the case of smartphones, Qualcomm had a bunch of software development kits and APIs and things like that, along with Android and the two worked together to create a suite of tools that developers could use. Now, we're seeing the same thing with Intel doing that with OpenVINO on the PC side, as well as Microsoft. So there's a lot of efforts. And then of course there's, you know, and then special instructions being integrated into the latest generation of CPU's again from Intel as well as from AMD. So lots of different parties working together to bring AI more to the mainstream.

Tom Garrison: We're certainly doing a lot of work in the hardware side, making sure that our platforms are, uh, highly performant doing AI type workloads. I wonder, from your perspective, is there anything that really has caught your imagination? Cause I'm envisioning now our listeners are listening to this podcast saying how is AI gonna impact my business?

Bob O’Donnell: Well, I think it's going to happen across a number of areas. Sort of a big picture one is around analytics. You know, we've talked about analytics and big data in the corporate world for, I dunno, 10, 15 years. It seems like forever. And the reality is that a lot of the initial analytics efforts, frankly, were not very successful. They were trying to dive into big chunks of data and try and discover patterns and, and they really weren't particularly successful in doing so.

The beauty of AI is you're unleashing algorithms onto these huge datasets and they are finding more success. So I think anything that involves traditional analytics types of applications, where you're searching for patterns in data--and that can happen across any industry and we're seeing that all kinds of places. We're also happening, see it happening in IOT tape type applications. If it's in manufacturing, you know, predictive analytics where you can not only be, you know, searching for data, but you can see patterns start to emerge of sensor data that might make you say, ”Oh, I think that piece of equipment is going to fail. We've got to deal with that.”

We're starting to see that as well on PCs, right? I mean, it was back from the old days of smart hard drives, right, where you have these sort of basic tools built into the hard drive, they would try and be able to warn you, “Hey, I think we're in trouble here.” Now we've got the same kinds of things happening on other components, right?--whether it be memory or other elements of a PC. So we're seeing those, that predictive analytics happening.

The other big area, frankly, than I think most people are starting to see is in basic office productivity. So now, for example, if you use your, either Office 365 or G Suite, or is now Google calls it Google Workspaces, you've got these tools, the editing applications that give you content recommendations, right? They'll say, “Hey, not only is it a spell checker, it's a grammar checker. Now it's even a content type of checker. Here's some suggested content for you.” One of the things I love in PowerPoint is a feature called Designer and Designer is an AI powered function that will create layouts for you. If you don't have your own in-house art department who designs all your slides, you've got to create your own. And even if you have a preset template that a lot of companies have, you still want to jazz it up and create some varieties and do some cool things with images. And the beauty of Designer is it can take some images and come up with some suggested layouts that look awesome and require very little effort on your part.

We're seeing things like the ability in video conferencing applications to track someone if someone's walking around, uh, or they're swaying, the camera can track the person and keep them centered in the frame. Uh, so all kinds of subtle-- and that we've also seen things like, you know, A little creepy, but you know, they raise your eyes up so it makes you look like you're actually looking at the person instead of looking down. Cause you know, a lot of times your camera's above your screen, so you really looking up, but sometimes you're looking down at the people you're talking to. And so it's a little weird. So it literally just tweaks the position of where your eyeballs are looking to make it feel like someone's actually looking at you as they're talking to them in a Zoom call.

So like I said, all kinds of different real world applications that I think pretty much everyone has started to see and there's creeping their way into the mainstream.

Camille Morhardt: Okay. So you've used the word “creepy” and “creeping” a couple of times. So I'm going to run with that just a little bit. What are we worried at all about privacy when we've got all of this kinds of tracking and voice, and now content suggestions? I won't even go there?

Bob O’Donnell: Yes. Look, people are a little worried about it, right? Analytics, one of the, one of the analytics that people are doing is personal analytics, as in it's tracking everything I do and then making suggestions on what I want, right? We've seen this with advertising. We see this with all kinds of things and so yes, there is obviously some concern with that.

The beauty of what's happening is we are now getting the intelligence and the compute power to do what's called Inferencing, locally. So, you know, the idea you've got training and inference when it comes to AI training is when you take a whole bunch of data and you create these algorithms by essentially training it what to look for, what to think of that's classic machine and deep learning types of algorithms. Then you apply those and you do inference by taking input and comparing it essentially to the algorithm and figuring it out.

Now in the past, you used to have to do that inference in the cloud, meaning everything you did had to be sent to the cloud, to someone else's data center and the data was processed there. By doing it locally--even though that sounds like sort of an arbitrary distinction--it's huge because it means all of a sudden, all of that inference work looking at my own data or your own data who's ever owned data happens on the local device. So all of a sudden that means my data isn't necessarily being shared out to the entire world and that makes a big difference to people, as well. They want the benefits of smart suggestions and content suggestions, all this kind of stuff. But, you know, they don't necessarily want their entire life out there, for the world to analyze. That's what I'm referring to there. But it's an excellent question and something that we do have to be aware of whenever it comes to AI.

Camille Morhardt: So just to clarify, you're saying, for example, if we're going to work on removing background noise in my audio on a video call, you can make a suggested edit to the algorithm and then send that back to the model, as opposed to sending, say, my raw audio file, which would include the specifics of my conversation?

Bob O’Donnell: That's exactly right. And so, first of all, they can do the analysis of that audio file, locally. But what they can also do is they can maybe come across a variation that occurred in your particular situation or someone else's particular situation, upload that data, in turn, refine the algorithm, and then that algorithm in turn gets re-downloaded onto your system. So it's a constantly iterating type of process. That's the ideal. We're not always, we're not quite there yet in all cases, but that's the concept is that you can get the benefits of AI, you can even get the benefits of an upgraded algorithm, without having to share too much of your own personal data.

Tom Garrison: We're starting a new segment. So you're the very first one of a brand new segment that we're doing in our podcast now. And it's basically what have you learned lately that you want to share with the podcast? Something cool, interesting. Could be something related to technology or it could be something in entertainment or something else you found intriguing and, I think, maybe our listeners might learn something from it as a result.

Bob O’Donnell: Well, I have two things and they're radically different, but I'm going to throw them out there anyway. So recently one of my personal musical heroes passed away and that was Eddie Van Halen. I discovered Van Halen--I'm showing my age here--but at a young age and he has always been an amazing rockstar and just such an icon to me. An interesting factoid that came out after his death that I never knew is that he was part Indonesian. He was actually part Asian. And he actually suffered a great deal of bigotry for being Asian. I never ever knew that. So that was an interesting little factoid, about Eddie van Halen,

The other thing, and it's again, totally unrelated, one of the things I've been doing with a little extra time during the pandemic is I-- I'm a car guy and I have a few car Lego sets and I've discovered that there are lighting sets. You can put lights into your Legos. And so you can turn on the lights on your legos. It's super cool. It's a totally nerdy geeky thing that not everybody's going to appreciate, but if you're into stuff like that, there are lighting sets.

Super cool!,

Tom Garrison: I, you know, I, I didn't know either of those two, but, uh, the Lego one that is a, that is intriguing. (laughs) Camille, any, uh, items you want to add?

Camille Morhardt: Okay, well, what I learned this last week, probably anybody who spends time by the ocean already knows, but, uh, I learned that the best time to boogie board is not exactly at low tide, which I had previously thought, but it's right after low tide when all the water is pushing you on shore, as opposed to dragging you out with that rip.

Bob O’Donnell: That would be an important thing to learn! (laughs)

Camille Morhardt: (laughs) Trial and error.

Bob O’Donnell: What about you Tom?

Tom Garrison: I am going to go into the world of entertainment. I'm always a big fan of these shows that I can just binge watch. And my son turned me on to a new show called “The Boys.” And let me just first tell everybody out there, do not watch this show with kids around. It is completely, completely inappropriate for kids. But it's a world where there are superheroes, but they're self-interested superheroes. They're not like the Superman or Batman that we grew up with that are all about the public good. These people are in it for themselves. And, anyway, it's, uh, it's a fascinating to me. It was a fascinating kind of re-think about the whole superhero genre thing.

I think it's very well done. There's two full seasons. Now you can get on it. But anyway, Bob, thank you again for taking the time stopping by, sharing what you know about AI. It was really interesting. And I appreciate your time.

Bob O’Donnell: Well, thanks, Tom. And thanks Camille, thank you so much for having me. I really enjoyed the conversation.

Tom Garrison: All right. And for all of our listeners, we look forward to sharing with you the next podcast, which will come out in two more weeks and we'll see you then

Subscribe and stay tuned for the next episode of Cyber Security Inside. Follow at @tommgarrison on Twitter to continue the conversation. Thank you for listening. .

View Details

In this episode of Cyber Security Inside, we explore what you need to know about Confidential Computing to protect your data. Our guest, technology analyst Jack Gold shares his insights on protecting your data--at rest, in transit, or in the cloud.

Tom Garrison: Hello, and welcome to the Cyber Security Inside podcast. In this podcast, we aim to dig into important aspects of Cyber Security, which can often be highly complex and intimidating and break them down to make them more understandable. We aim to avoid jargon and instead use plain language for thought provoking discussions. Every two weeks, a new podcast will air. We invite you to reach out to us with your questions and ideas for future podcast topics.

I'd like to introduce my cohost, Camille Morhardt Technical Assistant, and Chief of Staff at Intel's Product Assurance and Security Division. She's a Co-Director of Intel's Compute Lifecycle Assurance, an industry initiative to increase supply chain transparency. Camille's conducted hundreds of interviews with leaders in technology and engineering, including many in the C suite of the Fortune 500.

Hi, Camille, how are you doing today?

Camille Morhardt: Doing well. It's autumn., beautiful time of year in Portland.

Tom Garrison: It is. It's gorgeous outside. So I'm wondering, what would you like to discuss today?

Camille Morhardt: Well, Tom, I remember when people used to be afraid to put their data on the public cloud and it seemed like we had to make some sort of a trade off, right. Either I'm going to keep my data on my personal device, or if I'm an enterprise on-prem maintain complete control over it and know that I'm secure. Or I'm going to go with the convenience and the economy of scale, putting it on the public cloud and I'm going to worry about how safe it is.

And today increasingly I would, I would even say with COVID, I'm hearing more and more consumers and enterprises actually comfortable moving their data to the public cloud.

So I'm wondering first, what are the reasons today that people are interested in moving their data to the public cloud setting security side for a moment. And second from a security perspective, did something change that's making people more comfortable now or what should I be aware of if I'm considering moving data to the public cloud?

Tom Garrison: This is a deep topic for a fall day. So let's just think about this on a consumer use case and then we'll talk about corporate in a second. On the consumer use case, it's kind of interesting, cause I remember even myself years ago where we were talking about things like, you know, family pictures, wedding pictures, pick kids' pictures, and would I, or any of my colleagues ever consider putting a hundred percent of those pictures in the cloud exclusively. And without exception, everyone said no. And I think back then it was a sense of control.

You know, my sense now is that people are more comfortable with the idea that these cloud providers really know what they're doing and the chances that they would lose your photos or whatever is much, much lower than you would screw up your device or your device would die at home and you would lose your pictures.

Camille Morhardt: Right. You essentially have IT in the cloud, whereas at your house, you're your own IT.

Tom Garrison: Exactly, but then now you get to commercial. And with commercial, there's more complexities, right? You get the cost angle because if you're going to pay somebody else to do this, there's always going to be a cost to it. And can the other people manage your data in a lower cost fashion than you can do it yourself? And then there is this sticky issue of trust. Do I trust the data will be safe, especially for enterprises where the data is sort of the crown jewels of the company?

Camille Morhardt: But let's say that I want to be able to do that in a way that I can maintain either my privacy or my IP. You know, we had talked previously about not wanting to share and usage patterns of our compute devices, right. But if there were a way that my personal data could be protected and I could perhaps set the parameters for, to use or its disposal, um, and then there were a way for a company let's say a machine learning algorithm or something to come sit on my device, or maybe in the cloud where my data is also stored and run and do some learnings on that data while still maintaining protection of my privacy. I might actually be interested in that.

Tom Garrison: Yeah, I think most people would. That's sort of the Holy Grail when it comes to confidential computing in the cloud, where you can protect data from any unintended intended use. And so making sure it's secure and that hackers can't get to it or other applications can't misuse that data in some way. That's the value proposition behind confidential computing.

Camille Morhardt: And then there's this one other conundrum I’m thinking about it a little bit, which is, I know that a lot of enterprises are moving towards some services in the public cloud, like email say for their employees; part of the reason is they don't have to worry about the limited infrastructure that may be multiple concurrent VPNs is allowing it. Now it's just bandwidth directly from the employee to the public cloud.

On the converse, don't we still have to worry about as we're moving more and more to internet of things, just exactly that same concern: getting data from a thing to the public cloud is now posing a bandwidth constraint or a latency problem that wouldn't have been there otherwise, if I were processing onsite.

Tom Garrison: Sure, you're absolutely right. That is the sort of perennial challenge when it comes to huge data. Yeah. I think that's the episode for today. So I think we've got it. You good with that?

Camille: I’m great.

Tom Garrison: All right, let's go for it.

Our guest today is Jack Gold. Jack is Founder and Principal Analyst at J Gold Associates, LLC. And has a wealth of experience and expertise in the computer and electronics industries. He conducts analytical market research and advises numerous clients on many aspects of enterprise systems, including business analysis, strategic planning, architecture, product evaluation and selection as well as enterprise application strategy. So is perfect guest for us today.

I’m trying to think back, Jack, how long you and I have known each other and our best guess was about 15 years we've worked together.

Jack Gold: Yeah, Tom. I think it's been that long. Of course we're all six years old when we started so it's not much of a problem.

Tom Garrison: That's right. Oh boy. Yeah, it was pre-gray hair, I know that for me. We're here really wanting to talk about the concept of being able to create enclaves within the hardware that are safer relative to the rest of the system so you can do confidential code execution and other things inside these enclaves as well as the more broad topic about confidential computing.

So I wonder Jack, if we just start with, you know, environmental scan on confidential computing, like where do you see it playing a larger role, an outsized role in terms of the kinds of users or usages around SGX and confidential computing?

Jack Gold: Yeah. Tom, confidential computing is one of those terms that kind of means different things to different people. When we're talking about data--data about you and I, or corporate data or financial data--generally, when we talk about that data being safe because it's encrypted. And that's true. It is encrypted. It's encrypted at rest. When it's in a database it's encrypted while it's traveling over network. But generally speaking, once that data starts being processed, it's no longer encrypted.

So it's available--if you can get into the processor--you can see that data essentially in the clear. Confidential computing, to me, means two kind of circles if you're looking at a Venn diagram, right?--the two circles we were just talking about encrypted data at rest, encrypted data as it's traveling over network, but the third circle needs to be safe, data being processed. And we need to be able to, to assure that well, that data might be somehow in the clear while it’s in your computer. If I have access to your computer or access to your app, or it's just a bad app, that I don't all of a sudden have access to what was encrypted data that's not right out in the open and I could make use of. So confidential computing is really all of that.

Tom Garrison: That's interesting. And do you see particular users or, or industries that are embracing the concept of confidential computing more so than others or do you see this as kind of a broad appealing capability?

Jack Gold: The appeal of confidential computing really is across industries. It's everywhere. When you think about what gets processed in a company that isn't confidential anymore; my social security number, my driver's license number that I give to somebody, healthcare provider has all my medical details, that's worth a lot of money to people.

So we're kind of talking about servers and data centers and clouds just now, but also at the front end think about all the data that we have on our PCs and even our smartphones. So it's a broad concept that really needs to fit in the entire life cycle of computing, not just in one area.

Camille Morhardt: Is this something that we worry about for just on-prem or you described, you're talking about public cloud concerns? Do consumers need to be concerned, as well?

Jack Gold: Oh, absolutely. There's absolutely a need to have this in the cloud. Look, in most cloud environments, data that's running in an app is being shared on the same piece of hardware via virtual machine has probably tens, dozens, hundreds of other applications running on that same machine. And if there's no way to segment out those virtual machines to protect them from one another, if I have a bad app running, somehow I get it to run in, pick your favorite cloud, can it get access to an adjacent virtual machine and get the data out of that machine that has of great value?

So when we talk about confidential computing, we're talking about individual computers, whether it's a personal computer or whether it's a server in a corporation, but we're also talking about public cloud and private cloud as well.

Camille Morhardt: So basically, anybody--enterprise or consumer--who's storing any kind of a data on a public cloud or a hybrid is using a hybrid cloud environment, needs to consider what the public cloud provider is doing with respect to this protecting data, as you say, while it's being processed.

Jack Gold: Yes. Look, people want data about you and me. They can get real value out of that and sell it for a lot of money. So if I don't have a way of protecting that, there's a lot that people already know about me, but there's a lot more that they could garner. So I need to be aware of where my data resides. If it's in the cloud, or if it's in Google cloud, AWS, Azure, how do I know that that data is safe?

And if I'm an enterprise that has access to that data and that data gets compromised, I'm going to feel the pain in a number of ways. First of all, there are a lot of regulations against disclosing data. Look at what's going on in Europe with the privacy laws there compared to the U.S. There's some real fines going on.

Secondly, if there is a data breach, IBM and the Ponemon Institute, did a study showing that in the U S a typical enterprise data breach cost that company over $8 million to mitigate. That's pretty significant amount of money to have to put out because of having a compute system that isn't completely protective of the data,

Tom Garrison: You know, in preparation for this podcast today, you sent over a couple of your reports and I read through them and I just pulled out a couple of data points that I thought were fascinating and they came from the Verizon Security Report. But it said 39%t of companies have reported in 2020 that they were breached and up 6% from the year prior. But even more interesting was these behavioral, all aspects around security. 62% admitted that they sacrifice security due to expediency; 52% sacrificed due to convenience; and 46% admitted to sacrificing security because of profitability.

Jack Gold: Yeah, Tom, I think the real issue with security in general is that it's hard to do it's complex. And if you're in a hurry and you need to get something out there, you're going to put it out there and probably bypass some of the best-in class security measures that you should be doing simply because of expediency.

Especially because of COVID, companies needed to roll out 20,000 desktops in two days or a week, you bypass a lot of stuff to keep your company running. But even beyond that, even other companies that had the time perhaps to do it right, haven't really done it right. And the reason is because typically large companies can have two, three, 400 different security products running in their networks and in their data centers. How do you possibly manage all that stuff? The industry has made it really hard for companies to do security well.

Camille Morhardt: So I guess just to get really simple, if I'm IT, what am I looking for to see if the hardware is protected?

Jack Gold: So if you're IT, what you really want to know is whether the hardware that I'm working on has a vaulted area. It's called different things by different vendors--SGX with Intel, Trust Zone on Arm, it's other things with other guys. But what you really want to know is whether that's available, whether that vault is even built in.

The second thing you want to know is, is the operating system interacting with it? Does Windows know that that vaulted system is there and is it working to make sure that anything it's executing in Windows is actually running in that vault rather than running in main memory, un-encrypted.

It's a little harder when you're running in the cloud because you don't actually own the hardware. You're using somebody else’s hardware—you’re using Amazon's hardware or Google's hardware. And so you have to rely on them to tell you whether that's there or not. How many people are actually asking for that right now, I would guess are probably a pretty small number. We have to raise the awareness that that's even available. And then have those companies know that knowing that it's available, ask for it by name.

Tom Garrison: Having this be something that is on their radar to ask for is something that would be a value for, for the listeners here.

Jack Gold: If you're not asking for it, you're putting your company at risk. It's really that simple.

Camille Morhardt: Hey, Jack, you're described like this Venn diagram of the three different places that data is right--at rest, in transit, or in process being processed. Why is it that we don't already have everything covered?

Jack Gold: That's a great question. And the holdup has been that if you don't do it right, it really hurts it a lot. And so adding hardware that builds that protected vault, that enclave, that area where no one can get in--where bad apps aren't able to penetrate side channels, aren't able to get in--means, that you've got an area within the chip that is really kind of its own processing area. And so it has to have, has to be able to get data in and get data out and process at the same speed as the rest of the chip. That's a hardware problem. That's also a microcode problem. It's a software problem. And so it's complicated.

In the past, I think a lot of people have tried to do this. TPM chips were a great example. The reason they never really took hold is because there were separate chips. They had to go over a bus. They had to go over an interconnect. And the performance hit that you took, the latency on processing that data was, was pretty large. And so if you're, if you were just processing a couple of chunks of data, it's no big deal. If you're processing a big Oracle database, it's a big deal. I think we're getting better at it. And so I think you'll see it in a lot more chips and the impact on processing will be relatively minor.

Camille Morhardt: Are you saying you're going to ultimately see all of the applications that are running while they're being processed in essentially a vault or an enclave? Or are we always going to be selective about what is running in the enclave?

Jack Gold: Honestly, it will depend on how good a job you do at creating the hardware and how good a job do you do at the OS level. Until we get to that point, there probably will be some selection of, “do I run it in the vault or do I not run it in the vault?” based on the performance that I need.

Tom Garrison: Right. So what other opportunities do you see within the next say year or two, you would recommend sort of best practices or something along the lines of, of what we're talking about here with, you know, hardened security. Are there any other things that the listeners here should take away advice that you give them?

Jack Gold: Yeah. I think there are a few things you need to think about. Number one is you need to look at the entire compute chain. You need to look at it, not just from the hardware side, but also the OS and the application side. I want to go talk to SAP or, or Oracle, or Salesforce or whoever your primary vendor is. I want to go talk to them about the fact that I understand that there are now, there is now a possibility of running in a protected, vaulted, confidential computing environment. What are you doing to support that? Do you support it today? And if you don't support it today, when will you? and how do I get my applications into that vaulted environment?

The second thing I would say that you need to think about, people often have servers in place for five, seven, eight, 10 years. But those aren't the ones that are running the, you know, the heavy duty databases. Those are the email servers that kind of filtered down through the channel from high end to low end, as they got older. And people just kind of ignore them, getting new servers these days are not that expensive. And so if you're really going to run stuff on-prem, you really need to be thinking about how you're going to bring up a confidential computing environment on-prem.

If you're running it in the cloud, you need to ask your cloud provider, whether they support it. And eventually, longer term, what all companies should be thinking about is having these kinds of confidential computing, vaulted systems, trusted execution environments on every piece of hardware from smartphones, through PCs, through servers and into the cloud. Cause ultimately, that's the only way you can get maximum protection.

Tom Garrison: So I'd like to transition to one of these fun things that we do with all the guests. It has to do with our favorite virus, called COVID-19 now. What have you either come to love after having to go through this whole sort of working-from-home--work changes and personal changes--that you love? and, or something that you absolutely just cannot wait to get rid of?

Jack Gold: Great question. So look, it's nice to be able to work from home. It's nice to be able to get up in the morning, commute about 12 feet and get to my desk--whether I had my pajamas on haven't had my coffee yet, didn't call my hair, no one knows. Now the downside of course, is that it also means that I'm sitting at my computer potentially sitting at my computer at midnight because I just thought of something I needed to do and I might as well do it now. So the balance is kind of gone. My dog does remind me every once in a while that I'm home and that he needs attention. So that's probably okay. It gets me up and walking around.

Honestly, the part that I'm really getting unhappy about is the number of Zoom meetings (laughs) it's getting to be I'm Zoomed out. Look, it's just not the same as you and I sitting in a room face-to-face over a cup of coffee and. So I've, I've actually just for the most part, I just turned my camera off and just kind of do my thing (laughs)

Tom Garrison: Nice. You know, it did, it did occur to me. You mentioned your dog. Imagine how neurotic our pets going to be when we finally do all go back to work? Furniture is going to get torn up, the carpet is going to get ripped up, you know, Lord knows what else is going to happen (laughs). So I think there's a business opportunity there about whether it's dog daycare or whatever it's going to be, but we have some pretty pampered dogs that are going to have a rough reentry when we finally go back to work.

Jack Gold: Absolutely. I agree with you. And you know, the one nice statistic about it is that if you look at shelters, shelters are for the most part are out of pets because so many people are adopting them, which is actually wonderful. I mean, I for one--kind of a commercial message here--cause our, our guy is, uh, adopted from a shelter. So that's the good news. My fear of Tom on the negative side is that when people go back to work, they start bringing those pets back to shelters. And I sure hope that doesn't happen.

Tom Garrison: Yup, agreed. Well, Hey Jack, thank you very much for spending time with us. I know it's been a great conversation and, I think there was a lot of really good insight that was included in what you shared with us. So thank you for your time and for all of our listeners, we will catch you again and a couple of weeks.

Subscribe and stay tuned for the next episode of cyber security inside. Follow @tommgarrison on Twitter. To continue the conversation. Thank you for listening.

View Details

In this episode of Cyber Security Inside we'll learn how Lenovo is strengthening the supply chain to further protect its customers by introducing smarter end-to-end security through new services. Our guest is Rebecca Achariyakosol, Executive Director, PC Services Global Marketing at Lenovo.

Tom Garrison: Hello, and welcome to the Cyber Security Inside podcast. In this podcast, we aim to dig into important aspects of cyber security, which can often be highly complex and intimidating and break them down to make them more understandable. We aim to avoid jargon and instead use plain language for thought provoking discussions.

Every two weeks, a new podcast will air. We invite you to reach out to us with your questions and ideas for future podcast topics.

I'd like to introduce my cohost, Camille Morhardt Technical Assistant, and Chief of Staff at Intel's Product Assurance and Security Division. She's a co-director of Intel's Compute Lifecycle Assurance, an industry initiative to increase supply chain transparency.

Camille's conducted hundreds of interviews with leaders in technology and engineering, including many in the C suite of the Fortune 500.

Tom Garrison: Hi, Camille. How are you doing today?

Camille Morhardt: Surf's up! I'm doing well, Tom.

Tom Garrison: (laughs) Nice. That's right. You're at the beach. The benefits of being able to record anywhere in the world. Camille what's on your mind today for today's Security Matters segment?

Camille Morhardt: Well, Tom, I've been thinking about trust. And I've decided that trust is something that you can't actually offer. It's only something that can be bestowed upon you. So given that, what elements go into trust? Is that the same when we're talking about a company or we're talking about a relationship? And you know, what kind of actions could a company or government, say, take to increase your chances of trusting them since it's something you can only bestow upon them?

Tom Garrison: Interesting. So trust, I guess you can decide to inherently trust somebody, but ultimately it's something that you either are adding to the trust or you're taking away from the trust based on your actions.

Camille Morhardt: Yeah. And you don't get to decide whether somebody trusts you or not. You can only offer, I would submit actions, some sort of an action, like being upfront about your intentions or your mistakes potentially would increase trust, say in a romantic relationship.

Now, how does that translate when you're talking about the government? Do I trust the government or a company? How do I know whether I trust a company?

Tom Garrison: Yeah, that's a, it's a good topic. So let's say let's stick with companies. So how do companies increase trust?

Camille Morhardt: Well, I think one of the main ways the company can increase trust is to tell you honestly what they're doing. And I think that one way to do that when proxy, I would say almost for trust, is transparency. A bit of a buzzword these days, but that gives you visibility, not just visibility, but actually a complete view into what's happening. Transparency, everything from the, your intentions, which I think in most public companies are maximizing profit. There may be additional intentions or motives. And then after that, how are you going about producing your product?

Tom Garrison: You know, it occurs to me that there's a lot about products in general, that we don't know really much at all. We know who we bought it from. We hopefully we trust that company that they're doing the right things, but there's a lot of yeah of information that could be made available to the customer, the end customer about the devices that they're buying today.

Camille Morhardt: Yeah, is it my business? Do I just get to put trust into a company? Um, and that's good enough. I believe the company, they have a big name. They've got a good brand, you know, do I really, do I have some sort of a right to know more than that? I can buy from whoever I want.

Tom Garrison: Yeah, I think, I think you do. I mean, you know, maybe there's a debate to be had here, but I, I think as the customer, you have the right to any information that is going to have an impact on you the customer moving forward. And that might be things like, you know, maybe a more detailed understanding of what goes into the products that you're buying. And, based on that knowledge, you, you have a better understanding of what risks are involved from a security standpoint.

I think you have rights to any information that has to do with the way you're using the product. I don't think you necessarily have rights to the vendor, whoever you chose to buy it from. They've aggregated all the data about all of their customers. I don't think you as a customer have rights to that, but I do think that if you bought 10,000 of something, you have the rights to the aggregated 10,000 that you own.

Camille Morhardt: So do I have a right to know exactly what's in those devices that I own. I mean, if there's sub-vendors that are traded out, uh, we have, now we're using it as a screw from a different company now. Do I need to be burdened with that information?

Tom Garrison: Well, first I think there's a question of how much value do you get from what screw they use. But if you were to say instead, maybe the line is intelligent devices, things that are running software within maybe your PC or within your server, within your IOT device, for a couple of different reasons.

Let me just share sort of my view. If there ever turns out to be a security problem down the road with one of those devices, then you want to be able to know about it right away as soon as possible. And so if you already know what are these subcomponents in your device, then you should be able to aggregate your entire installed base of PCs or servers or whatever, and say very quickly, “I just saw about this vulnerability about this component. Do I have that component anywhere in my infrastructure?” Yes or no. There's a huge value in having that.

If you have to wait for your system provider to tell you that there was an issue you might've lost two months, three months, six months down the road.

Camille Morhardt: That's seems like bringing some alarms. That seems like a tremendous amount of collaboration which may exist in some industries. I think we have pretty good forward and backward traceability in the food industry in certain parts of the world to protect against bacteria and trace that. But is that level of traceability really necessary, you know, in a pair of running shoes? Maybe it is in a car or in the food that I eat, but are you adding or demanding unnecessary costs in even for the service of understanding, whether I have something, a problem with the thing that I'm using right now.

Tom Garrison: So, I think this is an episode. I think we could narrow it down to platforms. So say PCs and servers and our T devices. And I think this discussion is what we should cover today in today's podcast.

Camille Morhardt: I like it. Yup. Sounds good.

Tom Garrison: Let's go for it.

INTERVIEW

Tom Garrison: In today's discussion we'll learn how Lenovo is strengthening the supply chain to further protect its customers by introducing smarter end-to-end security through new services. I'm pleased to introduce our guest Rebecca Achariyakosol Executive Director, Global Marketing, responsible for product marketing and sales enablement for Lenovo IDG services.

Rebecca, please take a moment and tell us a little about your role at Lenovo.

Rebecca Achariyakosol: Sure. Hi, Tom. Thanks for the introduction and the opportunity to speak with you today. I've been working scene for Lenovo for almost three years now, and I am responsible for services, product development, marketing, and enablement for our IDG business.

So IDG stands for Intelligent Device Group, and that includes all of our laptops, desktops, workstations, and any of our mobility devices like tablets and phones. I don't create products. My job is to build solutions that can solve customer problems.

Tom Garrison: Well, that sounds interesting. Um, can we maybe just jump right into it and talk about some of the new services that Lenovo has introduced?

Rebecca Achariyakosol: So the supply chain is really an area that traditionally has presented some vulnerabilities that can be exploited. The window after devices leave the manufacturer before they reach the end user, that really creates an opening for someone to tamper with the PC. They can remove or replace components and it's really hard to detect that that's happened.

So Lenovo is directly addressing this problem within the security supply chain, with two services that we call Transparent Supply Chain and Trusted Device Setup. With these two services changes not only to the hardware, but also to the software can easily be detected.

Tom Garrison: Interesting. So maybe let's start with Transparent Supply Chain. Can you talk more about what Transparent Supply Chain is and how it works?

Rebecca Achariyakosol: Sure, absolutely. So Transparent Supply Chain is exclusively available for PCs with select Intel platforms. And it allows us to detect any hardware changes that were made between the factory and the customer. So it enables the visibility and the traceability of the hardware components so that customers can be confident that the system and hardware is exactly as it left the factory. So what they receive is exactly what was shipped.

Tom Garrison: Okay, so that makes sense. And, and you also mentioned Trusted Device Setup. What does that do?

Rebecca Achariyakosol: So that's kind of the other half of the equation. So Trusted Device Set up. It's a preload verification process. We seal the software at the point of manufacturing, so that any tampering attempts that occur after it's been sealed can be detected and prevented. So it's the second half -- Trusted Device Setup gives you the software security pieces from the software perspective and the Transparent Supply Chain is the hardware half.

Camille Morhardt: Hey, so Rebecca, I'm curious, transparency doesn't actually prevent a problem, right? It just, it just allows people to understand if a problem has occurred. So why do you guys value transparency just to back it up. Why are you pursuing it? How is that important?

Rebecca Achariyakosol: We have our Trusted Supplier Program and that's where we thoroughly vet our vendor and we do audits and inspections and things with our vendors to make sure that there's nothing in the supply chain up to the factory. But we also wanted to further expand how we've used security and provide an additional level for kind of end-to-end protection.

So Transparent Supply Chain and Trusted Device Setup, they kind of extend that past the factory through the entire supply chain, to the customer. And with these, we can make sure that the devices are truly what they should be receiving and they don't have any kind of security, risks or concerns because something's been tampered with.

Camille Morhardt: Sometimes as an industry, we tend to throw technology at the problem and forget to adjust processes or training to add the human element and intercept problems or potential problems that way. How are you guys balancing that risk?

Rebecca Achariyakosol: The pieces that we have with our Trusted Supplier Program, you know, that's kind of a little bit more of the, the people element side where we verify with process and, and people in such that, you know, anything coming into our factory we have more control of that and so we can put those pieces in place. But we really don't have any control once it leaves our factory, right? It's really up to how the customer is consuming that product, what route to markets, who they're using and in partnership to help with different pieces of and provisioning, et cetera. And so that's where we really have to lean on the technology piece.

Tom Garrison: I think that's an interesting point that the technology almost serves as a backstop so that you can try to put all the people processes in place, but ultimately the, the last check is the, is the hardware and the, and the services you put on top of that.

I wonder if you can maybe just expand a little bit on the fact now people are working from home and workforces in general are more distributed than ever. How does that play into your offerings here?

Rebecca Achariyakosol: In a recent study conducted by the security firm Barracuda Networks, 46% of surveyed global businesses said that they've encountered at least one cyber security scare since shifting to this more remote working model with COVID--and in the first quarter of this year. So that's pretty staggering. Almost half of these companies. And that's due in large part to the security risks that these remote workers pose. Right? So, you know, these services, it makes it easier, more secure to send devices directly from the factory to the employee, which is more what companies are moving to.

They don't have the luxury of that coming into the office and being touched by their IT person. So this makes it easier and more secure to send those devices directly from the factory to that end user employee. And they can still have the confidence that it hasn't been tampered with.

So this helps increase productivity, it reduces downtime, you get their end users up and running more quickly. And in some cases it really improves the efficiency for the customer's internal IT staff. So, we see this as maybe a continuing trend.

Camille Morhardt: Yeah. Hey Rebecca, do you think we're going to go back?

Rebecca Achariyakosol: Most of the companies that we've talked to, a good majority of them do see this aas somewhat of a permanent shift. Of course some workers are going to go back to a more traditional office, it's not going to be everybody working from home.

But this had already been a little bit of a trend, um, where you'd had a more distributed workforce. And I think, you know, this has just become an opportunity, it's accelerated sort of, some of those timelines. It’s become an opportunity for customers in companies to implement a more distributed workforce a little more quickly.

So I don't think it's going to go completely back. So that's why things like these technologies are going to remain important.

Tom Garrison: Now you can ship devices instead of going through sort of an IT cage to do the provisioning and so forth. You can just ship directly to the user themself.

I wonder if you could talk a little bit about how you, as an IT shop, how you roll out systems with integrity.

Rebecca Achariyakosol: So there's different pieces that you have to go through to make sure that an end user can just receive a box and get up and running. There's lots of technologies that we could kind of talk about, in the provisioning space, that allow customers to be able to get onto their networks seamlessly and very quickly and access all the things that they need.

So, we've kind of been on this journey to turn an employee like a laptop into a cell phone experience, right? So you get your new cell phone and it'll log in. They know who you are. You can be pulled down with our apps and things you need, you don't need somebody to get you up and running. This is very similar. And so there's, there's lots of technologies in that space.

And then of course, like I said, there's the security pieces, which is a huge part of it. So it's, you know, we were talking about Transparent Supply Chain and Trusted Device Setup and how that plays into it to make sure everything is trustworthy as it gets there. But then there's just kind of the monitoring, patching, all those other types of elements that our customers have to think about as well. And, and we're happy to help them with those pieces too.

Tom Garrison: I wonder if you could speak a little bit about The customers in this space and what customers are interested in Transparent Supply Chain and Trusted Device Setup?

Rebecca Achariyakosol: I mean, honestly, any company that wants to protect their devices through the supply chain can benefit from these services, right? It's also companies that want to drive higher levels of automation in IT Like we were just talking about and they need a mechanism to ensure that what the end user's receiving it hasn't been tampered with.

But additionally, specifically, you know, IT and government accounts are particular in who could be interested in those due to, you know, they're obviously highly IP sensitive nature of the work they do and the information that they handle.

Tom Garrison: Yeah. Can you talk more maybe about those classes of accounts--the highly sensitive IT accounts and government accounts?

Rebecca Achariyakosol: Sure. There are emerging standards within IT and government that they're attempting to meet, right? So these types of organizations, they typically require better visible visibility into how and where and with what their computer products are. Belts. The data is valuable for asset tracking and patching when vulnerabilities are disclosed.

So it's really about them needing to be sure that everything on their system is secure and that there's nothing been put on there that can help somebody steal or leak out their information.

Tom Garrison: I'd like to transition now a little bit into the future and pick your brain a little bit, Rebecca, if you don't mind. So what do you think are the major shifts and in the next year or two?

Rebecca Achariyakosol: I think that the narratives of today, they're really going to continue forward. I mean, even before COVID-19, we'd seen customers interested in moving to a more modern IT solution and which includes, you know, security pieces. And this was to facilitate them moving to a more distributed workforce and then also to help free up their iIT staff.

So these are things that we've been talking about to customers for a while. And I think all COVID is really done is it's accelerated that timeline. Um, and increasingly companies are reporting that even post COVID-19, as we talked about before, or the move will be to have more employees remote. So you're not going, we just see this big shift where everybody's going back into the office. So, it's not going to be business as usual and, and companies are going to continue to invest in modern IT security offerings to facilitate this new normal.

I really think the next year or two, as you asked, it's gonna be more of what we're seeing today. Customers are putting stop fixes in place, you know, because COVID happens so quickly, but now they're going to be focused on really streamlining those processes and preparing to have the more distributed workforce.

Tom Garrison: Yeah. I've, I've said to people that have asked me similar questions, that the thing that COVID has done is it changed people's perception about how productive people could be working remotely. Cause it wasn't that long ago where people assumed that if you were working remotely, you weren't as productive as you are in the office. And I think being forced to work remotely, like we all have, we've been able to change that perception pretty significantly. And so going back to the way it used to be, I think is a, is a fantasy. I don't think it's going to happen.

Rebecca Achariyakosol: I've been a big work from home proponent and you can be very productive and there is a lot of benefits to it. So I agree with you. I think it has changed the way people are viewing it. Those that haven't had that opportunity, the world in the business world is, is going to be very different when we come off the other side.

Tom Garrison: I'm going to change gears just a little bit here and maybe have a little bit of fun. I wonder if you could maybe share with us, what's one thing that you've changed to accommodate COVID-19.

Rebecca Achariyakosol: Certainly I'm not on the road. Like I was before, you know, excitement today is defined as a walking in my neighborhood and maybe picking up some takeout. Um, but I've really enjoyed having this time to be home with my family. We've had a lot of changes.

We're very much into martial arts and doing our classes via Zoom. They've recently started having some outdoor classes at the gym. So there's, you know, absolutely nothing like being outside in a hundred degree heat with a mass on exercising. (laughs) But you know, it is a chance at least to see some people. Um, and my, my oldest son, uh, every night he ends his prayers by praying COVID goes away, so he can go to his favorite sushi restaurant. Um, you know, he's really focused on all the important,

Tom Garrison: and then there's always takeout sushi, you know, don't, don't, uh, that short.

Rebecca Achariyakosol: We have done that twice now. And although, you know, I have to explain to my son that sushi is not the cheapest meal to do. Um, but he really always that experience where, you know, you, you try things and so if you like something you can continue to kind of order the different pieces that you like. Right. Versus, you know, he's got to think upfront of everything we might want to have from the restaurant. Um, but yes, we're absolutely have done on some special occasions some takeout, sushi.

Camille Morhardt: That sounds like a flexible supply chain.

Rebecca Achariyakosol: (laughs) Exactly. Absolutely. He definitely is always that flexible supply chain at a sushi restaurant. You just can't replicate that at home. I guess I could try and hide some of what we brought all and bring it out to them little by little. (laughs)

Tom Garrison: Great. Well, Rebecca, it's been nice to get to know you and thanks for coming in today and talking about. Lenovo's service offerings around Transparent Supply Chain and Trusted Device Setup.

I think it was educational for people to understand what's possible and, and the kinds of protections now that can be built into the platform directly. So thanks for coming in.

Rebecca Achariyakosol: Well, thank you for the opportunity. It was a pleasure to get to know you as well.

Tom Garrison: That's a wrap. Thank you so much for listening. I'll see you next time.

Subscribe and stay tuned for the next episode of cyber security inside. Follow @tommgarrison on Twitter to continue the conversation. Thank you for listening.

View Details

In this episode of Cyber Security Inside, we'll discuss what we're calling "the Next Security Frontier." It's a new take on cyber security that argues for taking the mystery out of the supply chain.

Tom Garrison: Hello, and welcome to the Cyber Security Inside podcast. In this podcast, we aim to dig into important aspects of cyber security, which can often be highly complex and intimidating and break them down to make them more understandable. We aim to avoid jargon and instead use plain language for thought provoking discussions.

Every two weeks, a new podcast will air. We invite you to reach out to us with your questions and ideas for future podcast topics.

I'd like to introduce my cohost, Camille Morhardt Technical Assistant and Chief of Staff in Intel's Product Assurance and Security Division. She's a co-director of Intel's Compute Lifecycle Assurance, an industry initiative to increase supply chain transparency. Camille's conducted hundreds of interviews with leaders in technology and engineering, including many in the C suite of the Fortune 500.

Hi, Camille, how are you doing today?

Camille Morhardt: I’m doing well Tom.

Tom Garrison: So what's on your mind for today's Security Matters segment?

Camille Morhardt: I'm wondering what kind of data we should be collecting about our own products and is there any inherent risk in collecting that data?

Tom Garrison: Hmm. And we talked about in our last podcast, we got started talking about, you know, supply chain data and so forth. What elements are, are you thinking about now in the context of data?

Camille Morhardt: Well, I'm interested in, I think a lot of companies can stand to learn a lot about their products by collecting data on how products are used. What's happening then in collecting the data is you're inadvertently or on purpose, collecting and storing potentially data on the users.

Tom Garrison: Let me ask you, let me ask you a question. When you, when you buy products and you have the infamous little checkbox, do you share data to help the company improve their product? Do you check yes or no?

Camille Morhardt: Uh, I checked, no. I, the only place I checked yes is actually probably the most private when it comes to health, when a hospital or something is, you know, can we submit a part of your tissue or whatever, to some broad sample that they anonymize it?

Tom Garrison: Yeah. I always check no too. You know, why do we both check no? We’re both in this industry and yet we check no for making products better. Why is it? I have my opinion, but I'll share in a second. Why, why do you have the no?

Camille Morhardt: Fear and the lack of trust. Is that data stored and is it traceable back to me?

Tom Garrison: Yeah. Interesting. So I'm all for making the product better, but I think that they're watching me. And it's, it's more about, not about the product it's about, are they using this data in some way, either intended or unintended to watch and listen to me. That's not okay.

Camille Morhardt: How many Intel engineers do you know who put a band-aid over the camera on their computer.

Tom Garrison: Yeah, sure. A band-aid or a piece of tape or lord knows whatever else.

Camille Morhardt: Yeah, exactly.

Tom Garrison: So that is, that's interesting because we're in the industry and we know that that kind of information--the information about how a device is used and what works well and what doesn't work well and maybe what features people actually value and use all the time versus ones that we put a lot of effort into putting them in place and nobody ever uses them--that kind of information is super valuable to product designers, product engineers, making the experience even better.

But yet, you and I at least as data point of two, we choose not to do it because we're afraid our information is going to be misused.

Camille Morhardt: Yeah. Or maybe I want something out of it rather than just a better next generation of the product. Maybe you've got to give me some kind of a kickback if you're going to start watching me or collecting my information.

Tom Garrison: Uh, so Camille has a price. You have to, you have to pay Camille for a day.

Camille Morhardt: That’s right, if I've got 30 different devices in my house and I'm getting, you know, 1 cent, every time something's collected, then maybe it would be worth it to me.

Tom Garrison: If you could absolutely guarantee there was no data about you, the user, would you be willing to share, for example, how many hours a day you use the device? Would that be information you could share?

Camille Morhardt: Yes. I think it would be information that I guess I would consider more generic. So if my car were collecting information on how much I drove it, you know, in a week, that would be okay, but not if they collected information on where I was driving or what specific time I drove, even though I suppose that could be even more valuable to them.

Tom Garrison: Right. Interesting. So I think within the technology space, we have a similar set of decisions to make about what kind of information we use and what kind of information we share. For example, last week in the podcast, we were talking about supply chain and that kind of information. You know it occurs to me that that kind of information doesn't really have anything to do with the user at all. It's really about the device. To me, that's information that's valuable from the manufacturer to the user. So that the value is actually not going from the user back to the manufacturer. The flow of value is going from manufacturer to the user.

Camille Morhardt: Yeah. You're flipping the direction of the flow on that one. Um, and I think that's good. I just think that's only good. I think that provides, um, the user of the device with as much information as they want--we're talking philosophically here, right? However much information they want, they should have access to about any way a product was made or designed or any kind of the specifications or capabilities, or even collecting patterns of that device.

As a user, I can choose to not read that or not care about that if I don't want to, but if you don't need to make it available, then I can't trust you, right? If you've, if you've made it available for those people who care more about that and I choose not to, I still feel better about it knowing you're being watched.

Tom Garrison: Well, and I think we're used to it in a different industry in the auto industry, right? We're used to who manufactured the car, but then also the, the car facts of that car over its life, you know, we're used to having that kind of information. We don't necessarily have that when it comes down to pieces of technology.

But I think this conversation, in general, this is an episode. This is what we should do for this podcast. Moving forward. You agree?

Camille Morhardt: What do we collect and why?

Tom Garrison: Great.

INTERVIEW:

Today's podcast is titled The Next Security Frontier: Taking the Mystery Out of the Supply Chain. I'm happy today to introduce our guest Mike Mattioli. Mike and I have a long history working together. He is a longtime member of Intel's Client Board of Advisors, but also he has a role as the Hardware Engineering Lead at Goldman Sachs. He's responsible for the design and engineering of the firm's digital experiences and technologies and is also responsible for the overall strategy and execution of hardware innovation, both within the firm and within the broader technology industry. Mike, welcome to the show.

Mike Mattioli: Thank you for having me.

Tom Garrison: There’s a little bit of a story behind today's podcast. We were at one of these Client Board of Advisors sessions and you and I sat together at lunch and we started talking about supply chain security and, and how we thought it was an important capability that needed an industry solution. And so I thought maybe it'd be good to start back from that lunch and maybe give some of the background of what led us together to working on the white paper that we coauthored.

Mike Mattioli: It's funny. It was only six months ago, but it was a totally different world compared to where we are today. We were talking about just hardware security in general. And then one of the things that we kind of landed on was it was a very simple question. If somebody were to take a component and put it somewhere on a board or inline somewhere on a piece of hardware, how can you tell if that was done--at any point in time--whether it is done in a factory somewhere it's done in transit done while it's in your own data center? And then ultimately we, we connected with Baiju and we started writing this paper and, you know, at the heart of the message is hardware security. And how do you really have secure and trustworthy hardware systems?

But the purpose of the paper and the supply chain was to highlight how there's so many opportunities throughout the entire supply chain that you're exposed to a variety of different attacks in one form way or another.

Tom Garrison: The conversation, as you said, we're talking about the article that was written a Bloomberg article, where there was rumored to be a chip that was added to a board. And it does turn out to be very difficult to find something that's been added to a board.

But, as you pointed out, our conversation led to this broader challenge. And so on one level you can say, you know, what, if somebody adds something to my board, but on the most basic level, the question is, do I know what is in my platform--whether it's a PC or server or whatever? And it's a question that should be answered, but today, it's really, really difficult to do that. In fact, really the only way to do it is through either a combination of visual inspection or specialty services that are offered by certain manufacturers.

There are some people that are absolutely on board saying they want to endorse what we're saying, and really get behind an industry solution. And then there's other people that say, “This isn't a problem at all. This is a technology looking for a solution.” So I wonder what your response is to that latter group.

Mike Mattioli: So I think the people who don't see the problem, don't understand the problem. They feel that they're not exposed and that sometimes are the class people who, um, they look at a certain attack, whether it be hardware, software, or otherwise, and they say, Oh, well, that'll never happen to me. Or I'm just John Smith. No, I'm not important.

But the, the truth is, is that you don't have to be a government or a high powered company to be the target of an attack. It can happen to you just as he can to everybody else. Everyone is subject to these attacks and everyone deserves the same level of trust transparency.

Tom Garrison: I think you may have already partially answered it, but why is the supply chain security important in general? And to Goldman Sachs?

Mike Mattioli: Hardware is in many ways, the foundation for all of the electronic transactions that we perform today--whether it be financial medical, anything in between. And if there's something wrong with the foundation for those transactions, everything above that is at question. If you're exposed at the foundation, how do you know that everything on top is truthful is honest--it actually is what it says it is? For the firm, more specifically, we're trying to build out what we refer to as our “financial cloud.” And this is one of the building blocks of that. This is how do we transact securely with our clients and our customers?

But more generally speaking, moving back to the industry in general, I think that this year is a very interesting year for two reasons. The apocalypse is upon us and we all have to now work from home. And so in the midst of that, everybody started ordering hardware in droves from Amazon, CDW, Best Buy, wherever it may be. And all these people ordered hardware and started doing business transactions, or now they're even doing a health tele-visits with their doctors.

They're doing all these things more and more remotely in physical places that are unknown and untrusted over networks that are unknown and untrusted. The only thing that you can have, even some semblance of trust in is the hardware that you're using. But does anybody really know if it's secure it if just came off the shelf on Amazon? Not saying that they've done anything wrong, I'm just saying, how do you know?

And then on top of that, this dovetails very interestingly into the election this year. And a lot of people are talking about remote voting, absentee ballots and things like that. And a lot of those things are still done on paper or they're analog, if you will. How do we do voting or elections or ballot submissions, if you will, using secure hardware?

Camille Morhardt: Hey Mike. So could you talk a little bit about, you seem to be addressing kind of who is maybe going after our hardware at this point. And I'm just wondering if you could talk about how you've seen threats to hardware evolve since you've been in the business?

Mike Mattioli: Sure. So I think that hardware has for a long time been overlooked and I think in recent years it's become much more prevalent. Spectre and Meltdown, when those came out a few years ago and then multiple variations thereof, all these different attacks--and while today they're very, very primitive--I think that we all have to realize is the game has changed.

People are attacking in a whole new way and we need to be prepared because we have no-- we have some defenses--but the defenses that we have are very, very primitive. And as those attacks get more and more advanced, if we don't keep up, then we're not going to have anything to defend ourselves with.

Camille Morhardt: So the next thing I guess I'm curious about is you had mentioned a few minutes ago that there can be attacks at various points in the supply chain. It seemed like you were extending the supply chain past the point. The product had shipped. Can you say more about what kind of threats you think exist in where a supply chain might have exposure and sort of your definition of a supply chain?

Mike Mattioli: Yes. So all the way in the beginning, when you design ICs, there's many things that are designed by hand or designed by the designers themselves like memory controllers, for example. But there are lots of different components that are part of a design that gets sourced from companies like Cadence or Synopsis. So, right off the bat, how do you know that whoever's doing the designing--the in-house component, like the memory controller--how do you know that there aren't bugs in it? Or how do you know that somebody didn't do something malicious like they put a trojan in there?

Or when you source that, you know, third party IP, how do you know that there's not a bug in there or there's a trojan in there? And then go further down the line to the foundry, right? When you send your design out to the foundry to be fabricated, how do you know if anything was changed?

And then let's say, you know, you trust your foundry, you trust your designers. Now moving a little further down the line, once they're fabricated and they get sent off to the ODM to be assembled, how do you know if something happened over there?

Finally, goes onto the courier and it gets shipped out--whether it be a boat, a plane, a train. Couriers are interesting because there's a lot of different ways that they can interact with systems. They can swap out hard drives, they can swap out memory chip, they can swap out fans, right? There's all sorts of different components that people can play with. Point being is even when the courier tries to take it from the factory to the reseller or your home or your data center, even there's exposure there.

And then while you're using it, right, while you're operating and using it, I'd say somewhere down the line, a fan fails and you need to replace it or a hard drive fails, you need to replace it. Whoever goes in and, you know, physically touches the device, how do you know that they didn't do something malicious at that point?

Moving even further down the line. Once you go and sell it or you recycle it or refurbish it, or you give it to somebody else. If you're the person buying it or receiving it, how do you know what happened to it? How do you know its history? And we sort of, you know, we verbally, we were talking about, about the analogy for almost like Carfax for PCs or, or electronic components or, or some way to, to have like a history of every single thing that happens to that device along the way of his life, and it’s immutable. Like you can't go back and erase it and you can't go back and change it.

Part of what we're trying to express the people is that even if you can't stop something, or even if you can't prevent somebody from doing something malicious, at absolute least you should have transparency. So if somebody was able to compromise something, at least you know and then you can go and take that out of service or you can unplug it or do something. But, but at the very least, knowing is very, very powerful.

Camille Morhardt: Okay, so how does that happen when obviously supply chains--especially in the compute space--are complex ecosystems and sometimes competitors need to collaborate with one another? So you'd mentioned carriers. I would say definitely third party logistics, handoffs--especially across international borders--it's going to be a place where you have competitors collaborating. So what are options for establishing or maintaining that trust and the transparency of data in these scenarios?

Mike Mattioli: Whoever's making entries into the ledger or whoever is actually saying these events occurred, you're placing trust in whoever it is that's saying that. Now on the flip side, you know, you're trusting hardware itself--which I'm personally more of a fan of--that ideology sort of describes a way in which components on the devices themselves are actually the ones that are saying, ”Hey, this happened or that happened,” or “this is talking to this thing” or “I'm receiving the signal from there.” The platform route of trust or self route of trust approach, while it takes out some of the transparencies that others can’t see it, you have a much more clear cut, defined approach to the information that you're getting.

Camille Morhardt: So can devices actually self-report these days?

Mike Mattioli: Yes, but at a higher level. And I think what we're trying to get to is a much more lower hardware level. That's where the attacks are starting to come from. They're starting to come from that foundation that everything else was built above.

Tom Garrison:I know at least from my perspective, hardware is, is obviously if you've got trusted hardware, then you can start building a solution on top of that. With active components, meaning firmware-bearing components, the hardware itself may be operating exactly as expected. But the firmware that runs on that device has actually been somehow manipulated and corrupted. And I wonder if you could just speak for a moment about that class of attack?

Mike Mattioli: It's very easy to manipulate firmware. And one of the benefits of one of the proposed solutions that we put out there was, if you at least know that the firmware that you have is out of date, was changed was modified, has been tampered with whatever it may be, at least by knowing then you could take action upon that. And I think that's what Camille was referencing earlier.

The idea here is you're not trusting a sole entity. The proposal that we had here was, you have a bunch of different components--classify them as active and passive. And all the active components that you have in your system are able to communicate with one centralized, call it, master component, if you will, on the board. And that master component reports back to you and says, “Hey, these are certain attributes”--let's call them date of manufacturer, place of manufacture, firmware version, et cetera, et cetera, whatever those attributes may be. And at least, you know, “Hey, I'm expecting to see these things,” or “I need to know what these things are.” And if these things aren't what I expect them to be, or they aren't what I want them to be, then I need to act on that or I need to mitigate that, or I need to do something about that.

Tom Garrison: Right, yeah. It's not about having the end-all be-all solution that does everything automatically. It really just is as simple as “do I know what's in my system?” I think that's pretty powerful.

Mike Mattioli: I think people will start to think, think about this in different way. Like in the, in the paper, we, you referenced a PC or a compute device, but we do so in very, very generic terms because people relate to PCs or computers and servers and things like that.

But the reality is, is that this can happen to anything. This can happen to your power grid. This can happen to the autonomous vehicle that's driving your children to school. This can happen to a self-driving tractor-trailer, truck, that's hurling down a highway. People are going to have to start thinking about this holistically and widening the scope outside of just my laptop or my iPhone.

Tom Garrison: So I want to change gears here a bit and maybe just have a little bit of fun. We've been doing this with our first several podcasts. And so I'd like to get your take on this one, Mike. And it has to do with this COVID-19 and all of the changes that we are interacting differently now, we're supposed to be at home. And I'd like to get your take on what—in this new world that we find ourselves in--can you not wait to get back to the old way of doing something? And then also, what is it that. Now that we're in this new world, you don't want to lose it?

Mike Mattioli: Um, so the one thing that I definitely want to get back to, and actually this really disappointed me a week or so ago when they made the announcement, I believe they announced that CES 2021 was going to be canceled, or rather, I should say it'll be a virtual event. And I know you and I have a love-hate relationship with CES. Every year it gets worse and worse. But I think that is definitely something that I'm looking forward to in 2022.

And then the one thing that I, I don't want to lose, I would say is not having to get all dressed up for work every day, kind of getting to casually kind of do whatever. You can only see me from the torso up. So I think that's an advantage (laughs).

Tom Garrison: (laughs) I can comment firsthand of all of the different t-shirts that Mike wears. He is the connoisseur tour of wild t-shirts!

Mike Mattioli: I'm waiting for the glow in the dark one you said you we’re going to send me with LED lights? Maybe you can put a, maybe you could put a Silicon wafer in the center, right?

Tom Garrison: It’s on its way! Well, hey, thanks Mike for joining us today. And I think there's a lot to really dig into when it comes to supply chain security. And I do invite all of the listeners to go on to the intel.com website and we have the supply chain white paper that I referenced at the beginning available for download. It is something that was co-written between myself and Mike and also Baiju Patel, who is one of the Intel fellows.

We spent a lot of time trying to dig into the details of why supply chain matters and what things should be on people's minds as they think about their hardware purchases moving forward. So hopefully there's a lot to learn from that as well as what we talked about here in the podcast. So. With that, Mike, thanks for joining us and for everybody else, join us on our next podcast in two weeks.

Thank you so much for listening. I'll see you next time.

View Details

In today's podcast we're going to explore the key elements of cyber security that you just can't ignore. And for that topic, we've got a guest I'm really excited about: Maribel Lopez. She is a founder and Principal Analyst at Lopez Research focused on digital transformation.

In this podcast, we aim to dig into important aspects of cyber security, which can often be highly complex and intimidating and break them down to make them more understandable. We aim to avoid jargon and instead use plain language for thought provoking discussions.

Every two weeks, a new podcast will air. We invite you to reach out to us with your questions and ideas for future podcast topics.

I'd like to introduce my cohost, Camille Morhardt, Technical Assistant, and Chief of Staff at Intel's Product Assurance and Security Division. She's a co-director of Intel's Compute Lifecycle Assurance, an industry initiative to increase supply chain transparency. Camille's conducted hundreds of interviews with leaders in technology and engineering, including many in the C suite of the Fortune 500.

Camille, welcome today.

Camille: Hello, Tom, how are you doing?

Tom: I am doing well. So for those of the audience here, our first segment in each podcast is called Security Matters, where we discuss items that have caught our eye or peaked our interest in some way. So Camille in our very first podcast, what's on your mind for today's Security Matters segment.

Camille: What I'm interested in is really what is a security mindset and is it something that can be developed? So just to explain that a little bit, I'm thinking, I hear terms like, “Hey, this company has security in the DNA of its organization.” Um, and then I hear, “and that company really treats security, like a check the box exercise.” So what I'm wondering is if a company hasn't organically developed this sense of security in the DNA, is it possible for them to get there?

Tom: Interesting. So what do you mean by “security in the DNA?” I think that seems like a, one of those buzz terms that might mean something different to whoever you talk to?

Camille: Yeah. To me “security in the DNA” means that there's no question in anybody's mind within the organization or anybody who encounters the organization that security is always at the forefront of anything anybody's doing. And it's always something that is held in high regard. So it's never something to be dismissed.

So for example, like I can tell Intel, uh, to choose a slightly different topic: safety. There's never a question. Safety is always top of mind for everybody to the point where it borders on the ridiculous, right? You can walk up a stairwell at Intel and it says “Are your hands free? Be sure you can grab the railing,” you know, “get a cup holder for yourself.” Or even “it's summer time, but sure you've got sunscreen on. It overflows to beyond what's even reasonable, right? There's no question that matters.

Tom: No, I laugh. Because I've seen those signs. So it is absolutely built into the culture.

Camille: And I think beyond that, there's no question that say any executive you might happen to find in the stairwell is also following that behavior.

Tom: That’s right.

Camille: So it's not something that people preach and then it only grassroots; it's really embedded top to bottom in an organization. And anybody new who comes in, you know, quickly realizes that it's not a joke.

Tom: Right. And I think that's true on a safety sense, but we started off with security. So what would that look like? If security were to the same extent that safety was built into the way everybody thinks, what would that look like?

Camille: I'm not sure that you can guarantee security in the same way that you can guarantee safety. So in other words, you have a controlled environment in many safety situations. Let's say not probably if you're driving down the road or something, but if you're operating a manufacturing facility, you've got a pretty controlled environment. You can make sure that people are never walking where a robotic arm is swinging or something like that, right?

When you talk about security, particularly in the compute space, you're by definition, you're releasing that product out into the ethers and then one step worse, you're connecting it to the internet. And if you're not doing that, you're probably not leading on the sophisticated end of things anyway, right? So if you want to be, you know, internet of things, or even just generally operational these days, you're connected to the internet to some degree. Well, how do you guarantee that? Because there's no perimeter security, right? You can't lock the door and everything's safe. You are accessing the outside world. So how did you go and do that?

Tom: It's a bit, not almost, non-deterministic like it's a never ending and journey with regards to security in that sense, like how paranoid do you need to be? What are the threats that you are concerned about? And it seems like that list would be at least always evolving, if not, never ending.

Camille: So how, how do you get your organization to put security first if it's not doing it already?

Tom: Well, I think, you know, you're raising a good question. There's no single answer for sure, but I think first and foremost, people have to realize security is everybody's business. It's not the security team's job to keep the product safe. It's everybody's job.

It starts from initial product inception all the way through manufacturing and even out into the customer real world. And then the other element I think is, yeah, maybe, you know, the stick approach, you know, the keratin stick, the stick approach is just, dollarize what happens when you're not secure and what happens to your brand reputation and what happens to, you know, the costs that you incur as a company they're significant.

Camille: I like it. So submit your, your budget of “I'm going to need this much money because we've had a breach.”

Tom: Yeah.

Camille: As opposed to…

Tom: Yeah, write the headline the day after the breach, and that might motivate people. This is a good topic. We should talk about security and what people should be thinking about and maybe what isn't so obvious. I think that's the podcast for today. Let's, let's go with that as a podcast.

Camille: Sounds good.

Tom: In today's podcast we're going to explore the key elements of cyber security that you just can't ignore. And for that topic, we've got a guest I'm really excited about: Maribel Lopez. She is a founder and Principal Analyst at Lopez Research focused on digital transformation. Maribel Lopez founded the Emerging Technology Research Council, which is a community of business and technical leaders in Fortune 1000 companies focused on driving innovation and business value with mobile and other emerging technologies.

So welcome Maribel.

Maribel: Thanks, Tom, excited to be here.

Tom: Could you tell us more about this research council?

Maribel: The research council is a group of technology leaders. They come together to talk about best practices and deploying technology. Some of it's emerging tech, but some of it's tech we've talked about a long time that just continues to change.

Tom: That's interesting. So, you know, in today's topic, I mentioned earlier, we wanted to talk about the items about security that people just can't ignore. I wonder if you could talk a bit about the overall security landscape.

Maribel: I think one of the things that's really interesting about security is that I look at it as a layer cake. There are multiple layers of security that you need in an organization. And sadly, there's no one-size-fits-all. You have to basically block and tackle every single layer of that. And we hear that from the customer base. They're continually asking us, “Hey, do I need to deploy this? Should I be looking at that? There are all these new tools. I don't know which ones I should really be diving into. What do you think.”

Tom: Can you say more about how customers view just standard security?

Maribel: I think they want what everybody wants. They want a silver bullet. They want to just throw in one tool, it'd be one and done maybe two and done. But if you look at the average corporation, there's somewhere between 40 and 80 security tools. There's definitely a sense of fatigue, particularly as we continue to get more and more new threats that seem to have an never ending set of tools. It's like how many security widgets is enough already?

Tom: Uh-huh. No, I, I definitely myself, in talking to customers, run into all the time, the, just the complexity of how one security tool impacts and influences another security tool. And just keeping that as you call it, the layer cake upright is a huge challenge.

Camille: Hey Maribel, it’s Camille here. So is it just networks that we need to be concerned about or also in points?

Maribel: Actually, that's a great point, Camille, because you know, the, one of the other real security challenges we've seen--particularly as people have gone to remote work--is this concept of aging PCs devices that don't have a trusted security stacks on them. They could be tablets, they could be PCs, it could be mobile phones. So really the end point has become very wide open and open for attack and compromise.

Camille: Do you have advice for companies now everybody's working from home, how they can boost security in those home environments?

Maribel: Yeah. So the first thing I think we have to figure out is are they using personal hardware or not? Is that hardware compromised? Because let's just say you give somebody a VPN and they're tunneling into your network, but their actual machine is compromised. You've just let somebody into the network inadvertently.

So. finding ways that you can test the health of the device, finding ways to manage devices that are personally owned, but in a way that you can separate the corporate data from the personal data, I think is one of the low hanging fruits. And then hopefully getting to the point where you actually have hardware that you provided to your employees that you know, is safe and secure and that you can manage and having that ability to manage.

But I think the other thing we have to think about as patching in general, Just making sure that everybody's machines are passionate up to date. And then finally, I'd say we forgot about security training. A lot of people were sent home very quickly and they just didn't have that set of best practices of knowing not to click on links or other things. Particularly a lot of people are getting caught in the early days with the concept of, you know, click on this link to hear more about COVID and what it means for you. A lot of machines were compromised that way.

Camille: So there's depth, right? And then there's also breadth, which we may not have considered so much in hardware until recently. True? I don't know, Tom, are you seeing product portfolios starting to address system health after manufacturer, after we ship?

Tom: We have. Actually, what we're seeing is a realization that a device has multiple phases over its existence. It has really the build phase, which there's a lot of focus on the build phase. And then there is a transfer phase when a device moves from its manufacturing location to ultimately to the user of the device; then there's the operate phase; and then finally the retirement phase. And security means something different in each of those phases.

And so we're starting to see customers. Paying attention to what kinds of capabilities does the platform you need to be able to support in order to stay safe in these various ranges? Like for example, understanding has the device been tampered with before you provision it and put it on your network? And increasingly we're seeing companies work in this case with Intel to do that.

Another area is around IOT. The devices don't have users attached to them. So they sit on a telephone pole or in a factory somewhere; they don't have a human sort of managing them and looking for anomalous behavior. And so IOT is a whole category of use cases that is very much concerned about physical security, because somebody can tamper with the device physically and just making sure that the device is operating the way we would expect it to be.

So Maribel, I wonder what kinds of protections are you seeing customers implement on IOT besides the ability to update?

Maribel: Yeah, so the first thing I think we have to actually do very basic things, like change the names, change the passwords. Well, let's just assume you did that. What would you be looking for next?

You'd be looking for, you'd be looking for encryption. What's the behavior of that device intrusion detection and make sure that that bias hasn't been compromised and taken over and being used to send traffic that it shouldn't be sending. So those are a few of the things that we've been talking to people about is like go the first mile, but then go the second and the third to make sure that you’re really assessing the behavior of those devices and understand what they should be doing and then understand what they are doing. And if there's a difference between those two, make sure that you're turning on the right kinds of security stacks to make sure that those devices don't get compromised or remediate them if they have.

Camille: What risks should companies be looking at in their supply chains that they might not be tuned into right now?

Maribel: Great point, Camille. I mean, the supply chain is sort of the initial thread factor before it's even at the person. So when we talk to people about the supply chain, it's important that you understand several things. First is like, what are the components within that supply chain? And can we verify that those are actually the right components--that they've been signed by those individuals saying, yes, this is the component. It's the right component.

The second one that we need to think about is your suppliers themselves. They could be compromised. And if they have your data, then that compromises you.

The third we should be looking at is I know, particularly now--while there might be hardware shortages or where there might be some sensitivity to budgets--we see organizations starting to buy in different channels that they might not have purchased in before. And they in fact might be getting counterfeit hardware.

You know, there have been examples, many examples of, for example, networking equipment that people saw that they were buying a specific brand of networking equipment, but it turns out that they were buying a very compelling fake. And imagine that, you know, in the deep part of your network, you have hardware that is not the right product. What could that do if somebody put software that to take over your network, steal all of your data?

So you really have to think on a component level. Or if you're purchasing who you're purchasing from and being able to validate that that whole system is the whole system that you bought or validating specific components of it. So there's a lot in the supply chain that I think we have to think about that we didn't necessarily consider before.

Tom: So I, I wonder if maybe we transition just a little bit here and look now into the future over the next several years. I wonder if you could talk, maybe a little bit about some of the major shifts you expect to see over the next year or two.

Maribel: Well, I think the big shift that we've been talking about for a while now, but has not really permeated into organizations is around this concept of “zero trust.” And so this is where you're doing a user behavior analytics or in the user could be a person or it could be devices, but think about creating a profile of what your known behavior is and then being able to say--using machine learning and deep learning--saying that behavior we're seeing now, it doesn't look like normal behavior for that user, for that entity. What should I do now? Well, usually you want to quarantine that person or thing, and then do some security checks to see if she'll allow them back into the network.

That concept of what normal user behavior is, is a bit topsy-turvy in a world where people are working remotely or even worse they're going back and forth between work and home, some other place. So when that happens, predicting what “normal behavior” looks like can be difficult, but that zero trust concept seems to be where we're going right now.

Camille: What are some of the issues that IT departments might be facing right now, as people are struggling to figure out how to get things set up in a kind of unusual environment quickly?

Maribel: So they've had a couple of challenges. One is obviously figuring out how to support remote work, you know, how do we get devices into hands? How do we VPN clients scale? Do we want to do things like virtual desktop so that we can have better security? How do we think about that whole portfolio then?

Then I think we're going into a secondary layer of when we're starting to think about zero trust or when we're starting to think about connecting more devices, how do we construct roles? How do we construct policies around those roles? What looks like normal behavior?

And then I think we're also looking at, I need intelligent hardware that has intelligent software so I'm not drowning in alerts. You can see a world where people are drowning in alerts continually, particularly with more tiny devices, sending lots of information.

So we're now being tasked with finding solutions that will be more predictive and prescriptive on behalf of us and say, “Hey, I think there's a problem that might be happening here. And here's what you should go look at to see if there's an actual problem.”

So we talk about automation, but we're not necessarily automating the human. What we're trying to automate is getting the right information to individuals so that they can act accordingly.

Tom: Yeah, I think there's also the other element on top of that, which is the experience from the user standpoint has to still be good because if it isn't good, we've known for years and years now that employees will go around the IT solution and effectively sort of create their own platform, their own set of how they get things done maybe as like a shadow IT problem.

Maribel: Yeah, we're seeing shadow IT. Shadow IT is real. And what I think it really gets to is that user experience part that you talked about. So now I think the imperative for business leaders is to say, “Hey, we know that people are going to be using a set of their own solutions. Let's make sure we know what they're using. Let's make sure that we protect the data that shouldn't be in. Say some. Third party documents, storage that shouldn't be in some third party, email client.”

Really, it's also one of the things that I think is so important about the postcode world work. We have an understanding and a need now to say, “we have to support multiple platforms. How do we do that in a secure way?” Because we also have the data imperative where we have to make sure that we've secured the data because. There are penalties around that there's regulation around that. And we have to be able to marry the user experience and the regulation and the security

Tom: To me, this seems like we're just at the beginning of a fairly significant transition when you think about security forced into it in the near term and COVID, but we'll likely in my opinion, at least continue on behind that.

Tom: Let's, let's try to have some fun now and talk a little bit about what do you think are some of the things that you just cannot wait to get away from now in this current COVID-19 scenario? And then I'm going to follow it up--I'll just tell you right now--I'm going to follow it up by what are the things that you hope to preserve that were maybe some surprises from having to work from home or all the other things that we're doing with COVID?

Maribel: I think we need to have a more balanced meeting where it's some video audio, and sometimes it just might be some messaging cause you don't need to see anybody that day (laughs). So that’s one.

You know, on the security side, one of the things. I don't think we'll get away from that we're sort of forced into, but maybe it was a good force. And that's the concept of, he's got to check the settings on everything. So things like we saw in the video conferencing area, where we had, you know, video bombing, so to speak, where people were coming in and where it's supposed to be coming in.

There's a lot more sensitivity now of making sure that you have your settings. Right. And then when things update, your settings are still there. So things don't turn on automatically or you've put in the right security so that people can stay out of your meetings. Things of that nature, I think are good.

Tom: That's a good list. I have a couple of things, myself. One thing I can't wait to be done with at some point is the fact that every time I dial into either a video meeting or now audio meeting or whatever, my computer cannot remember what audio and video device, it thinks it's talking to, it just drives me crazy. Like, why can't we solve this problem? It seems like such a solvable problem.

And then the thing that I really, really love about this time is I don't have to drive to work. I love that video for me is, yeah, it's a substitute for actual face to face contact, but I have a hellacious commute and I love the fact that I don't have to do it.

So Camille, you have anything?

Camille: I think we're going to see more and more communications or interaction, style apps emerging--both for fun. Um, and also education and also work related. Everybody's got this issue with video. So what kinds of interesting things are we going to see emerge? So I'm very much looking forward to that.

And I'm also concerned as Maribel said that we are able to make sure we have, we maintain privacy and appropriate security and confidentiality with those new emerging apps.

Tom: The one thing's for sure is that we won't be going back to the way it was pre. COVID-19 there's definitely going to be changes.

So with that, I think we can draw this podcast to a close I'd like to thank Maribel for joining us. Your insight today was great. I think it gave us a perspective on customers and, and in particular, some of the things that people aren't necessarily thinking of when they think about security. So Maribel, thank you again for joining us.

Maribel: Thank you.

Tom: We invite people to please subscribe to our podcast. It is going to be published on an every two-week basis. So we'll have topics that are relevant for cyber security coming to you every two weeks, a subscribe, wherever you get your podcasts, and we will see you next time.

View Details

Hi, I'm Tom Garrison and I'm Camille Morhardt. On Cyber Security Inside we explore with you and security experts, emerging trends, including threats and new technologies, along with established best practices and techniques. We examine the trends in security that you need to know about.

Guest: That concept of what normal user behavior is, is it topsy-turvy in a world where people are working remotely. But that zero trust concept seems to be where we're going right now.

We also go behind the scenes with experts to dissect recent security events.

Guest: SolarWinds was not the first and they won't be the last. So whatever you would have done to respond to an actual compromise, those are the things you need to put in place today.

We get the definitions directly from those who are defining them.

Guest: Homomorphic encryption, in this case, would allow healthcare type of services that can perform analysis on sensitive data related to patients without revealing personal information.

And Camille and I make sure to have fun along the way.

Camille: Former Deputy Director of the NSA said, “frankly, the number one threat experience to date by US electrical grid is squirrels.” (laughs)

Join us every week for Cyber Security Inside and walk away smarter about cyber security. Follow us wherever you get your podcasts.