Cyber Security Dispatch brings you to the front lines of cyber security. In our podcast we interview leading experts and practitioners who are fighting attacks, securing systems, and exploring the cutting edge of cyber security and cyber warfare.
An Interview with Arun Sood, CEO of SCIT LabsCyber Security Dispatch: Season 3, Episode 2Show Notes:
Welcome back to the Cyber Security Dispatch. This is the first in the new series of interviews focused on innovative technology in cyber security where we talk about new solutions to protect our data and systems. Today on the show we welcome Arun Sood, CEO of Self Cleansing Intrusion Tolerance (SCIT) Labs. He is the co-inventor of all six SCIT technology patents that are based on the research undertaken at his research center. In this episode, we are setting the clock on why controlling time matters. Arun is an expert on moving target defense and building resilience systems. He offers a refreshing perspective on how controlling time can give security teams a key advantage in stopping attacks and limiting the impact of those attacks. It is a really fascinating perspective and one that can help you see things differently. For all this and much more be sure to tune in!
Key Points From This Episode:
Arun on LinkedIn — https://www.linkedin.com/in/arunsood/
SCIT Labs — http://scitlabs.com/
George Mason University — https://www2.gmu.edu/
Drupal — https://www.drupal.org/
WordPress — https://wordpress.com/
Introduction:
Welcome back to the Cyber Security Dispatch. This is the first in the new series of interviews focused on innovative technology in cyber security where we talk about new solutions to protect our data and systems. Today on the show we welcome Arun Sood, CEO of Self Cleansing Intrusion Tolerance (SCIT) Labs. He is the co-inventor of all six SCIT technology patents that are based on the research undertaken at his research center. In this episode, we are setting the clock on why controlling time matters. Arun is an expert on moving target defense and building resilience systems. He offers a refreshing perspective on how controlling time can give security teams a key advantage in stopping attacks and limiting the impact of those attacks. It is a really fascinating perspective and one that can help you see things differently. For all this and much more be sure to tune in!
TRANSCRIPT
[0:01:05.5] AS: I am Arun Sood and I am a professor at George Mason University but currently, research at George Mason has led to six packets and at one stage, we decided to start a university startup, we are a group affiliated to George Mason has equity shares in the company so there is a close relationship between the two things. I’m the founder of this and currently in the CEO but I see we have a chief architect, we have lots of people who are helping with us and how this is going to evolve is only time will tell.
[0:01:46.7] AA: Yeah, I think, you know, one of the things that was so interesting about what you got up to is you’re sort of focusing, you’re focused on moving target defense so that’s a concept we’ve talked a lot about on this show but for those who kind of aren't familiar with moving target defense, you just want to kind of talk about what it is and how you kind of how you kind of got involved in it.
[0:02:07.3] AS: Right. There are many ways to look at this but I’m going to try something slightly different based on my experience recently at a conference in Tampa. Think of the following issue. Server security is something which everybody needs for their systems but it is becoming more and more clear that people also need resilience. Server security means the bad guys, when they come in you make sure they don’t stay in so you may have to shut the system down but that is not good enough for people who have to have continuity of operations.
The resilience requirement is that you have to have continuity of operations. Now, if the two systems if you design your systems to be static, now you have a problem. If the system is static and you shut it down, it loses all the continuity of operations. We need a potentially need a dynamic solution and the moving target defense as we see it, as we have used it, as a mechanism, which it creates balance between these two things.
[0:03:16.9] AA: Yeah, I think if I understand you correctly, there’s that this sort of opposition between two things, right? If you imagine, what a lot of systems are measured on is all the time, right? We are continuously to make it simple like deploying popper, right? We need to have the five nine’s right? 99.999% of the time where the system is on and then the classic way of thinking about cyber security is to actually shut things off because there’s problem there.
How do you sort of square that circle? Is that, am I understanding it correctly?
[0:03:48.7] AS: That’s exactly right and I think we got to make sure that we understand a resilience system is not only, has to operate continuously but it Is expected to perform even in the presence of an attack. Many of our systems are, which are operational, they may have bad guys sitting in them but they keep operating. Because of the read me generation and so on and because of the importance of the system, their continuity of operation is critical, you’re actually right.
This provides a challenge, the challenge is, if you have a static system, that system is not changing and you, somebody comes and sits on it, if you shut it down, you’re in trouble, you don’t get continued service.
[0:04:32.3] AA: Yeah, I’ve seen some interesting kind of models, different graphics where you’re, when you’re thinking about system design. You know, thinking about essentially redundant pathways, you know, multiple methodologies for delivering a service or allowing whatever is information travel and then essentially as you look at that design, understanding essentially assessing it based on how much of the system could be compromised and you can still essentially still deliver service or accomplish the mission, the task, et cetera.
You know, I’m not a systems engineer, that’s not my background but that seems like not a concept that the majority of systems or at least many systems are built with at the offset.
[0:05:20.0] AS: You're right. Many systems I see, they don’t have security as one of their requirements, it’s sort of bolted in at the end of the process, which is, makes it a challenging situation. But the idea is quite straight forward, less designer systems in such a fashion that you realize it is going to be compromised, because it is going to be compromised, we have to do something to handle the compromise and yet maintain continuity of service.
There are in my view, there are two basic ways by which people provide higher levels of security and one is through diversity and the second one is through this whole idea of redundancy. The redundancy idea enables you to actually maybe can help you achieve both things that you’re able to switch things around so it’s not static. If you make the system none static, there’s a higher probability that you can achieve security as well as redundancy.
[0:06:31.2] AA: Yeah, I think. Walk us through on a simple, how individuals are doing that? If you think about either together, diversity and redundancy or one and then the next. How, when a person kind of understands that those are beneficial qualities. How can you add those two a, to a system?
[0:06:52.9] AS: Right. I’m going to talk a little bit how redundancy can be used in the case of diversity, we have a particular challenge and I’ll come to that in a second. Let’s talk about redundancy. The idea basically is if you want to get high availability, what do you do, you use redundancy, you want high availability, you have to serve the customer in sort of just relying on one box you may have two boxes or three boxes or let’s say you’ll have multiple servers or even if they are on the cloud, you can have multiple servers and those servers, if one of them goes down, the other one takes over the load and you are not having continuity of service all the time.
That’s one paradigm. If you do redundancy now and from the view point of security, you have this redundancy, you can do continuous checking and say okay, is one of these boxes busted? If it is busted, they’re basically, you can take it offline and you can have continuative service. Fair enough?
[0:08:05.5] AA: Yeah.
[0:08:06.5] AS: Okay, now, let’s go to the other one to the whole idea of diversity. Diversity, you can apply at lots of levels, all the way from the application to the operating system, down to the hardware and that is in my experience, talking to CSO’s if you try to do diversity at a high level, they look at this as a very expensive proposition, there have been people who have tried to do this to elegant mechanisms but this has been a constraint so far.
There are ways by which for example, is a large kind of approaches, which can provide diversity at a lower level and it is not as effective as if you were to do a diversity to higher level but it may be good enough for many situations. Is that a reasonable explanation?
[0:09:06.6] AA: Yeah. I think you’re hitting upon the challenge that I think a lot of people encounter when they start thinking about adding diversity and redundancy, they’re concerned about perhaps certainly the additional cost, probably in dollars but also in kind of in investment in knowledge and expertise that their people need to have, they’re worried about, I barely –
I think if behind closed doors, when you talk with a lot of sort of senior leaders in the security space, they’re like, “We’re barely kind of treading water trying to keep up with what we’ve got, adding additional complexity, you know, only scares me. I feel like I definitely be drowning that.” How do you kind of think through that, that additional expense or complexity?
[0:09:58.1] AS: Yeah, I think that’s a very good question. The question is that you can have different types of complexity. As you increased some complexity then the cost is higher and some of the kind of complexities the cost may not be so high.
As I gave you this example, if you’re in your shop, you decide to use four different operating systems then you have to train everybody on those four operating systems, this can become a very costly operation.
[0:10:28.4] AA: Yeah.
[0:10:28.9] AS: On the other hand, If you were to look at diversity, you have to then balance the question of what level of security are you seeking? The way we have tried to post this thing more recently is to talk about this whole idea of dwell time. You're asked a question, how much dwell time can you tolerate? If you can allow for higher dwell time, the cost that is the level of redundancy you require goes down and the cost will go down.
If you want very good systems and hence you want, you have a – your risk profile is very high, in that case, you may want to have a lower exposure and that will increase the cost. The after I translate some of these ideas into cost of implementation so that a user can make adjustment. “Okay, I think I probably have four hours before the bad guys can do much damage. Let us change things every two hours.” You see the logic of what I’m trying to get at this. Use that logic to decide on how you’re going to do this but there is one thing that is very important in my view point.
If you do a redundancy based approach, you have to make sure that you do not change the implementation, you do not go on changing the things like the application, things like the operating systems. You don’t go on changing these things for each implementation because that increases the cost.
That’s what we have focused on is trying to see if you have – if you are using something, do you want to be able to use that same platform over and over again?
[0:12:19.9] AA: Yeah, let’s take in a little bit on SO, for those listeners who kind of don’t think about or as familiar with the idea of dwell time, that’s basically just the time that an individual is connected or inside a system. Now, that can be just so we’re quite pointed is dwell time measured for every user or we measuring it for only users that were perhaps concerned are negative or a threat.
[0:12:49.4] AS: Okay, the dwell time is really a measure of how the server is performing., what we are doing is reducing the dwell time on the server. Maybe, let me sort of conceptualize this from a higher level. f
[0:13:05.9] AA: Yeah, I think they’d be helpful.
[0:13:08.3] AS: Okay, if you think about this, a cyber-kill chain has basically got three steps of it. You can divide them further and more detail but the three steps are easy to understand and easy to explain. The three steps, the fourth step is somebody has to get it. This is usually done through a phishing attack. They get into somebody goes to their desktop and they click on something and the phishing attacks starts. That’s the first thing, get it.
The second step is, once you get in, you have to do a lateral move to get to where the data is. If you got into some user’s laptop, that’s okay but it’s not – that’s not, we have the damage is going to be done, the damage has got to be done inside the, on the place where the data is, which is usually a server.
After you get in, you go through what is called a stay in step. The stay in step means that you will do migrate to where lateral moves and so on and migrate to where you want to do damage. The last step is the whole step of act. In act, for example, if you’re entrusted in stealing data, you want to do data exfiltration so the action is data exfiltration.
There’s some rules about data exfiltration. If you try to do the exfiltration of the highest speed, you’ll get detected very quickly. When you do this data exfiltration, you have to do this at a fairly low speed so that means it takes more time but you have the time because you are resting there and you're sitting in there. And you can take days, weeks and months to do your complete exfiltration. Get in, stay in and act.
If we can manage to reduce the amount of time, somebody stays in and the time for act, we are going to make sure that the losses are significantly minimized. That is what we call the dwell tech, that’s the amount of time you are giving the attacker to stay in the system.
[0:15:23.2] AA: Yeah, I think kind of like rough industry statistics are like the average dwell time that people realize after they’ve had an incident is kind of somewhere in the neighborhood of six months, right? Someone is in there has been at work for quite a long time, right? This isn’t like, I was in for two or three hours, right?
The ability to kind of reduce dwell time to a few hours, a few minutes, it look like your goal was to take it as low as like 90 seconds. Am I understanding that correctly?
[0:15:58.2] AS: One of implementations we have got it down to 90 seconds but you're absolutely correct I think in many cases, something like a dual time of two hours maybe adequate. The point is that the lower the dwell time, there’s a cost impact on the whole thing. We basically recommend a dwell time, which is consistent with your need.
We had something called tellos, which is some testing for DOD insulations, we have them attack our system, which is an ecommerce system and which – they have complete access, we took a three couple time, put it on a system and basically told them, “Look, this is the name of the file, this is its location, there is no firewall, there’s no IDS, no IPPPS, no DLP, none of this is there, go get it. “
When they try to get that file, the discovered that they could get in the system in less than five minutes but extraction of the file was a problem because we were doing rotations every 90 seconds and they can just complete the process in that time. They called up and said, “Look, this rotation is making it more difficult for us,” by the way, this is on their website and n our website described here, this project is describing.
[0:17:18.5] AA: Yeah, I was reading this assessment, it’s really interesting. I will make sure that we link to it in the notice for this podcast so listeners can grab that right on our website.
[0:17:27.5] AS: The point was, if I may just complete the story, they asked us to do an – allowed them to do an automated test. They did the automated test and they came with the same problem because it is way difficult and the second part of this issue is to, want to look as evolving. If somebody attacks us once, it may be difficult to find them but if somebody is forced to attack us twice, three times, four times, five times, it becomes easier and easier to find them.
It is basically if they come in once and do the damage, you may have given another notice there. But if we are forcing them to do this thing multiple times, then our parameter defense systems will know that something is going on. In that sense, that’s an example of how getting stay and act, works with the parameter defense systems, which are really preventing the get in stage itself.
[0:18:27.2] AA: Yeah, we were talking about this before we sort of recording the episode. You know, looking for a single solution is kind of, you’re not going to find a single solution that sort of solves all your problems but when you start to layer different potential approaches on each other, that becomes really interesting, there’s very positive inter play.
Yeah, I can imagine if you are an administrator at an organization and you see, right, the top person connecting is probably like one of your busiest employees but then there’s this other item that keeps connecting, right? What is that? Essentially, by reducing 12 time you were making someone attack constantly, they’re going to quickly bubble up to the top of being a very active account or process. Is that how I’m understanding?
[0:19:19.4] AS: yes, you’re right. We basically use a redundancy operation, a redundancy based system and our system is called SCIT. We use SCIT and we have recently added a component, which examines the system regularly so that we can actually say, “Hey, we don’t know how it happened but you have something, which have changed in your system.”
That has been our approach. Try to find out what has changed, try to establish rules on, which the data should be infiltrated at a particular rate and all this kind of stuff so the thing is, when we are in this process, we are trying to add components, which solves specific problems to give a whole overall solution to the system.
[0:20:15.1] AA: Yeah, is this what you – we were trying to throttling, you're sort of throttling connections, is that potential? Yeah, I think that those are very complimentary. Essentially, you re connecting it now, it limits someone from exfiltration more than a certain amount in a certain period of time. For those kind of more technical listeners, walk us through a little bit of how the system works. If you’ve got a server and you install SCIT on top of it, how does it actually do what it’s doing?
[0:20:43.0] AS: It’s relatively straightforward. All our implementations are based on the whole concept of virtualization and that is broadly accepted now so we are done of virtualization or VMware kind of stuff as well as we have done it on the cloud. So rationalization has become a bread and butter if you like that’s what most of our installations are based on. So what we are basically saying is that we are going to spend more VM’s than you need and what is going to happen is that at regular intervals we are going to take some of the VM’s off, examine them and see if they have a comprise, send out an alarm and go so on.
So that’s how our system works and we try to keep the number of standby VM’s to a minimum and how is that minimum defined? If I am going to have for one hour then maybe I need to have a standby VM only for five minutes. So we try to reduce the amount of resources required to complete our process.
[0:21:54.7] AA: Got you, so essentially you may, if I am running a server but to use your example for an hour, I then maybe in the last five minutes you are going to spin up and additional VM and then there will be some sort of an handoff between the two virtual machines at the end of that hour to assure continuous…
[0:22:15.9] AS: That’s right.
[0:22:16.9] AA: Right, okay and then how do you handle and that is all happening at the application layer, what layer is that happening? I mean I know data, how do you think about where the data lives and as you think about spinning up a system and destroying the old one, how do you think about data living longer?
[0:22:41.4] AS: So effectively, you can think of data and do it three different ways. There is a distinct, which ever called persistent data and persistent data is stored somewhere. We strongly recommend that you have a backup mechanism and our approach actually will enable you to have a backup mechanism and ultimate test that what the backup is actually works. So there is this persistent data and then there are also things where after all in today’s world SSD’s are very common.
So you can get very faster performance but if you want even faster performance, then you have a shared memory approach. So any one of these works with our system.
[0:23:26.9] AA: Got you, so essentially data is kept in this. You have a backup system in place but then also essentially as I understood, the files are not necessarily refreshing. It is more of the application operating system. The file structures get separately.
[0:23:45.4] AS: Correct, we are basically focused on making sure that there is our systems are operating in a pristine state and where we don’t have the bad guys resident in our system from more than the authorized dual time.
[0:24:03.4] AA: Got you and you know, when you create these environments are you – is it essentially where can you deploy something like this? Does it have to be application by application when you’re doing an implementation? Is there additional sort of custom engineering that happens there or what needs to happen to actually deploy?
[0:24:23.9] AS: So to just give you an example, we have started down this road off of building system that are very specialized to the requirements of the Navy, they asked us for some things we built and showed them how this worked. Then we basically said, “Hey what we’ve done right now is we have looked at things like Drupal and WordPress and there are a lot of users there so we have actually built sample systems using Drupal and WordPress as a demonstration of what we are able to do with these kind of systems, which are very widely used,” and hopefully we are going to work with some people to adopt them in their systems.
[0:25:02.5] AA: Got you, what happens if you are like in the middle of a number of users are in a middle of a session and the VM’s need to flip, right? Let’s say we’re streaming video or we are in a middle of a conference call or we’re a trader where there’s this continuous flow of data back and forth. How do you handle that? =
[0:25:26.0] AS: So we just have to make sure that there is no loss of data, that’s all and our system is built to make sure of that.
[0:25:32.2] AA: Got you, so there is some sort of buffering that happens.
[0:25:34.9] AS: Yeah, we do a bunch of stuff to make sure. It is a challenge but we have demonstrated that it works.
[0:25:41.9] AA: Yeah, let’s switch gears a little bit from the technology to sort of the environment overall. I mean I think I have been surprised by sort of the resistance or the lack of awareness about resiliency as a framework or a paradigm to think through. What if you encounter it in the space also what do you think sort of potentially stopping things from moving more quickly in that direction?
[0:26:08.6] AS: Well I would say that until about two years ago or something, tables of general feeling, “Hey guys, we know how to do detection. You’ve got at all these fancy ways of doing detection. Detection is going to work why do all this stuff,” you know? I think people are now beginning to feel that it is not working. I mean it works some of the time but not all the time and when it doesn’t work then we have a problem.
So there was that kind of reluctance but there is a problem that people do have built in infrastructure. So somebody is having 10 layers of or 20 layers of detection working. Now they basically say, “Hey listen, these are things. Why am I going to do a new level of complexity or a different layer of complexity?” so there is that reluctance. It is for us to come forward with solutions and demonstrations and proof of concepts and be able to do and we are trying to do all this stuff.
To basically convince people that we can actually provide this in a cost effective fashion. I submit to you that if you have several layers of defense, many of these layers may be actually contradictory to each other. If you use our approach, you may be able to drop some of these layers and hence, all our cost will actually go down. So there is this kind of – it is an ongoing effort.
[0:27:32.2] AA: Yeah and I think you know, I certainly feel from a lot of individuals they do feel that complexity is just their drowning, right? But I think you are right where if you accept that you do have that water shed moment where you realize, “You know what? We can’t keep doing what we are doing” that is the definition of insanity, right? We have been trying this for a while and it’s not working. Well, let us try something else.
And then when you start to unpack what the potential for that moving target or refreshing systems allow you to do, you realize that it is actually the idea of just starting a fresh every day makes things a lot simpler, right? Every day or every hour or whatever that dwell time target that you are shooting for, right?
[0:28:20.6] AS: Right and so many times in their presentation, I ask a simple question. “How often do you restart your servers?” because one sure way of getting rid out of malware without having to do detection is to restart the server. So I ask the question, “How often do you do this?” and invariably the answer is very infrequently.
[0:28:42.6] AA: Yeah, never would be mine.
[0:28:44.7] AS: Yeah and the reason for that is there is a cost of back store and there is a legacy issue attached to it. If you look at this 10, 15 years ago, you brought up a server, you never knew what state the server is going to come up in. So starting, restarting a server is a big deal but it is not unusual though. So those kind of things have to be able to grow out of it. So now basically, we start the server with fairly high level of reliability.
So those are the kind of things, which have stood in the way but you’re not do decline with this, developing and there is going to be more people doing this kind of stuff and they are actually five or six companies now, which are based on moving target defense and you seemed to have talked to some of them also so.
[0:29:26.7] AA: Yeah, definitely. Yeah and I think in the world of cyber security and we’re often used the terms around disease a lot. We talk about viruses and malware and infections and compromise and all of these sorts of things that helps of systems and I think we are advancing in the business, in the industry and I think the more we move towards the complexity of systems and the approaches that you see effectively in medicine and in nature itself, right?
I mean I think the idea of – I mean certainly a hospital, a cornerstone of their approach to battling disease is disposable stuff. I mean gloves and needles and surgical instruments, they realize that to keep things clean the easiest thing to do is not to try and figure out where all the diseases or viruses are but just to throw a lot of stuff away, which perhaps environmental issues with waste and whatnot but certainly has been very effective.
And the more that they do that, the better they do from an infection perspective and it actually becomes quite a bit simpler, right? If you don’t have to think about scrubbing everything to the Nth degree. You should just use it once and toss it, right?
[0:30:50.0] AS: I agree, this is a very good example. Many times, it is not worthwhile to do a complete diagnosis. I mean the way I look at it is suppose you are driving a boat. You are in a boat and you spring a leak, what do you think you want to do? Try to find out and do an in depth analysis of the leak or try to plug the damn thing?
[0:31:09.8] AA: Yeah.
[0:31:10.5] AS: So that you are trying to recover from it, recover from it and so only after you have had a chance to get back to shore will you do a deep analysis. That’s what we are recommending.
[0:31:21.6] AA: Right and I think to six frame on that analogy right? I think this is a little bit like working in the tech space, right? It’s like you’re out on a lake in some sort of canoe. If you don’t, you don’t know when your canoe is going to spring a leak but as long as you know that you got a lot of friends in other canoes that you can jump into, you’re probably going to be okay, right?
[0:31:43.8] AS: That’s right.
[0:31:45.1] AA: And so yeah, the most important thing is to either have a lot of friends or own a canoe factory, right?
[0:31:52.3] AS: That’s right but this is an example of we use these ideas. It is not that we go into with this ideas but we have to translate them to this cyber security space is what we need to do.
[0:32:03.8] AA: Yeah, definitely. You know to sort of build on the advancement of this sector overall and I think one of the things that I am stunned by is the lack of really clear measurements for success of any of the approaches that have been up there. I mean I think if you think about detection, when you think about blocking attacks, you actually ask a lot of practitioners like, “What are you measuring when you get a huge amount of diversity of answers?”
And in many cases, the answer is nothing really very precisely or accurately or things that are meaningful. I think one of the interesting things of how you approach is that you are focused on dwell time is something that is quite measurable. Talk me through how you think about measuring success and whatnot.
[0:32:59.2] AS: Yeah, that’s a very good question. The point basically is many of the detection approaches, the point is you have to take a lot of things on freight and by the way, this is okay. We do this on a regular basis but the point is, if you are going to use AI techniques there is a problematic character to them and that problematic character many times you are not able to quantify them adequately. I have been driven by the notion that we should be able to say quite explicitly what we are doing not making it fuzzy.
And that is the reason we have talked about all of these idea. We are being very explicit. “Okay, your dwell time is going to be so much. Your throttling time, the time it’s going to take, the throttle will take based on such and such way." So all these are deterministic ideas but they have pretty low value and if we can combine them with ideas, which are more problemistic, I think we’ll have a good joint effort in this case.
[0:34:01.6] AA: Yeah and I think being so explicit about what are we trying to improve here and what are we giving you here. You know, whenever someone says that they’re meeting 10 I mean gosh, seven, eight, nine things right? Let alone like you when you start thinking about we’re aligning to 23 different things. It is sort of like more than I can count on maybe one hand and maybe not even using all the fingers there that seems reasonable, right? If you have so many things that you are trying to focus on typically you are not doing – you are not really moving the needle on most of them, potentially all of them.
[0:34:41.4] AS: Yeah but it is acting, that is a valid part but have on the justice, yes. The complexity is even more of a problem. So if you are the US Government, you can go around having 20 layers of defense. Okay, then what about this guy who runs a company, which has got $10 million of revenue a year? He can have these levels of defenses right?
[0:35:04.3] AA: Right.
[0:35:04.9] AS: So what are we going to do? Are we going to protect these guys or what? So I am suggesting is and that is why many of these have migrated into the cloud. So that is why the rationalization and what SCIT does should be helpful. So we have actually tried to do some of these, we are talking to a few people who have several who’s customers are small and they have Drupal websites or they have WordPress websites. And so we think that that maybe some place, which we want to explore. We can be doing much more for the bigger customers but we also want to support the guys who are smaller and are growing. Does that make sense?
[0:35:45.5] AA: Yeah and so just to be really clear, if someone is undertaking this approach, what would you point to as saying, “Okay here is where you were now. Essentially your dwell time is potentially unlimited” or whatever you’re going back to kind of your – should you ask how often are you restarting these servers, right? Your restart with this force in a reconnection from everyone, right? You are saying, “Okay I am going to move your dwell time to whatever the refresh cycle is that you have chosen.”
A day, a few hours, whatever that target is potentially as low as 90 seconds and then also you can throttle the flow of data to whatever you think is reasonable for those business. Those are the main measures that you would say these are the things that we are targeting to a brew or are there others outside of this?
[0:36:39.8] AS: I think especially for small customers, small users I think those are the two principle things, which we would still recommend that you start with. So as we learn about these things more, we will act to these set of things but that’s where we think we should start.
[0:36:56.8] AA: And let’s talk about what it takes to undertake this approach. So your technology is just at the software layer, right? Does it necessarily require any additional hardware?
[0:37:07.5] AS: Correct.
[0:37:08.4] AA: And we have talked a little bit, you had mentioned the level of use of the different servers like how much utilization they were seeking.
[0:37:15.6] AS: You’re right, so if you want to talk about end premise systems and let’s say you are using VMware, which is utilized and stuffed and let’s say that you’re utilization of the server is less than 60% then you will not require any more hardware to implement what we do but if your utilization is more than 80%, then you may need additional hardware. But most places, which we have talked to they don’t have – they are closer to 50, 60% rather than to 80% that’s actual.
[0:37:54.6] AA: Got you and then from a throttle perspective, you are just choosing that throttle based on what typical usage is, right? Or whatever the –
[0:38:03.2] AS: Yes.
[0:38:03.7] AA: Got you.
[0:38:04.4] AS: So you’ll effectively – you are user, the guy who designed the system knows that you will be getting to a separate website, that is going to tell you how much of data is going to be downloaded on any query from there, you can tell how much of bandwidth you need and then you can choose your throttle time in consultation with the customer.
[0:38:25.2] AA: Got you and then you think that there are certainly they’re like the normal patterns that you see in organizations okay, right? Most of the time where we’re just doing 10 megabits per second or whatever it is but maybe let’s say you are holding a big event and so suddenly you’ve posted a lot of materials on your website that people are downloading. How do you think about assist and then now people need to download this much larger files so that traffic is really spiking?
[0:38:56.9] AS: Yes. I think what you are basically saying is that you may need multiple parts into the system, one part for the conventional user but then there could be some people who are doing their additional work and because they are doing additional work, they may need to lure download bigger files and you need to get them another part and on that part, your throttle times will be different.
[0:39:20.9] AA: Yeah, exactly or just the experience is not normally distributed, right? If you think of a retailer where all of the activity happens in the holiday Christmas season, right? So bandwidth is just exploding, usage is exploding in a certain few or like Amazon day, I forgot what it is, Prime day right? You think through that. How do you think through that, is this designed in the system in that way? Can you just as simple to toggle of the volumes on a certain day or are there other options? =
[0:39:54.4] AS: Well, I think this one idea of a throttle has to accommodate what the user requirements are. So you may have a bunch of users, you may be able to do something by which you tell them the throttle to the user. A user comes in, “You know that this was going to go to this website, this website, this website.” So the throttle would be different then somebody has to go to another website. So you can do all of that. Our implementation currently is a single throttle time but these are the kind of things which we need to extend our system to.
[0:40:35.1] AA: Yeah, well Arun, I want to be thoughtful about time because you have been great in terms of walking through a lot of different questions about how your technology works and the application of it really enjoyed you doing that. If people want to learn more about what you’ve been up to and other resources about resiliency and moving target defense, anything that you’d recommend we can put links to stuff on the show notes.
[0:41:00.4] AS: So you can go to scitlabs.com is our website and this is scitlabs.com is a website, which you can go to. We have links to several whitepapers. We have analyzed for example the worst breaches in the last decade and tried to show how our approach would have worked in those cases. There is a lot of stuff there and of course, you could always get hold of me and I can answer more questions.
[0:41:29.7] AA: Cool. Well, Arun thank you so much. I really enjoyed this. Yeah we’ll check back in and see how things are going over the coming months and years too. Thank you so much.
[0:41:38.5] AS: Very good, thanks very much. I surely enjoyed this. This is fun.
[END]
Key Points From This Episode:
How Christian came to study both Medieval History and Computer Science.
Learn more about Christian’s unique PhD in German Mysticism.
Christian shares his unique passion for global cyber security theory.
Are their links between Medieval history and what is happening with the internet today?
Discover more about the balkanization of the internet and net neutrality.
Parallels between Medieval social connections and internet social connections.
Christian’s view on open source and how the ModSecurity Project fits into that.
Christian explains how a firewall works and the two main types of firewall.
Top five things that might make traffic look malicious or none malicious.
Whitelisting, blacklisting and IP addresses: Can they really be trusted?
E-voting: Why Switzerland is going all in while the rest of the world backs out.
Is it possible to fully secure identification in an E-voting system?
Why the world appears to be falling back on a physical verification process.
Christian walks us through what an E-voting process looks like.
Learn more about Christian’s strategies for reverse proxy and D-DOS.
And much more!
Key Points From This Episode:
How Stephanie ended up in the cyber security profession.
An introduction to the challenges that face cyber security in the healthcare sector.
The intersection of the individual, the governmental and the business sectors.
Major differences between GDPR and HIPAA.
The competitive element to the monetization of data across industries.
Interstate influence with regards to healthcare regulation.
Building uniform national and international standards for healthcare data.
Implementation of the NIST Cybersecurity Framework.
And much more!
Key Points From The Episode:
Erfan’s professional background and how this sets him apart.
The problem with businesses’ drive towards interconnectivity.
Creating a hardened, layered defense as opposed to merely a perimeter.
How these concerns fit into a real life utility configuration.
The importance of institutional architecture beyond personnel.
Shifting common mental models of security and how it relates to confidentiality.
The benefits of prioritizing ‘hyper-quiet’ networks.
The influence of existing hardware on the design of current security.
Erfan’s first instructions to consciousness CISOs wanting to create a securer network.
How Erfan views the current state of cyber security and its biggest impediments.
Properly measuring the strength of a network and its security.
The rise in popularity of the term ‘resiliency’ in place of ‘security’.
Erfan gives us his definition of resiliency.
And much more!
Interview with Richard Ford Chief Scientist at Forcepoint:Cyber Security Dispatch:Show Notes:
In this episode of the Cyber Security Dispatch, we talk with Dr. Richard Ford the Chief Scientist of Forcepoint. Dr. Ford has been in the industry for quite a while and he has seen the industry through the lens of many different job descriptions, which gives him a grounded perspective of the entire business. Through his grounded perspective he talks about the current problems that plague the security space and how some of these problems are the exact same ones that we’ve had 25 years ago; Dr. Ford advises that before people get into complex security concepts such as resilience we ought to nail down these basic problems that have been put off for 25 years. We continue on about how the industry has too high demands in expecting the entire population to think in security-oriented manner. Rather we should be trying to move toward security systems that accommodate humans habits rather than the other way around. We end on what human-centric implementations of security look like and even hear an example from Dr. Ford.
Key Points From This Episode:
Links Mentioned in Today’s Episode:
Dr. Richard Ford — https://www.forcepoint.com/company/biographies/dr-richard-ford-0
Dr. Richard Ford LinkedIn — https://www.linkedin.com/in/dr-ford/
RSA — https://www.rsaconference.com/
Forcepoint — https://www.forcepoint.com/
Virus Bulletin — https://www.virusbulletin.com/
Sapir–Whorf Hypothesis — https://en.wikipedia.org/wiki/Linguistic_relativity
Morris Worm — https://en.wikipedia.org/wiki/Morris_worm
Introduction:
Welcome to another edition of Cyber Security Dispatch, this is your host Andy Anderson. In this episode, Human-centric Security, we talk with Richard Ford, Chief Scientist of Forcepoint. In this episode, we talk about what human-centric security is and why we should move towards it’s implementation. We also talk about back to basics and why it is a necessary movement. Here’s Dr. Richard Ford.
TRANSCRIPT
Andy Anderson: Just introduce yourself for the audience that don’t know you - they should but maybe not yet.
Richard Ford: Sure my name is Dr. Richard Ford. I feel like I’ve been doing security forever; on my RSA badge they even gave me a little tag which says “seasoned” - and I’m not really sure how to take that. But I got into security around I don’t know 89-90 and that’s been my whole life - it’s been a lot of fun. A little bit of time on the offensive side of the house, a lot of time on the defensive side of the house.
This is really my passion and I do this because I love it. So I’m the Chief Scientist at Forcepoint, and in that role I’m steering technology across the whole company. It’s a blast because I get to do the sort of fun part of research and then sort of hand it off to somebody else to implement and we all know it’s that last 20% that’s the hard bit.
AA: I was talking with somebody last night and they were said: “My job is to create the dream and then its this dude’s to” and he points to his friend “make it happen.” You know? I wanted to be the first guy - I don’t wanna be the second
RF: Absolutely correct that last 20% to make it operational that’s the hard part.
AA: But - I mean you’ve been in security for a long time, but not always on the vendors’ side right? You were a professor for a while, you’ve been a journalist as well. So talk about kind of some of those roles and the different perspective that kind of gives you.
RF: Yeah actually - I really liked the way you phrased the question because it really is about a different perspective. So my first job in the security industry was pulling apart viruses apart as a journalist - it was great. I was still a student and they’re like “We’ll give you X pounds for every virus you disassemble.” So I thought ‘This is free money this is great’ - I do this for free. So I went from there into being a journalist really - being the second editor of Virus Bulletin, which is a great publication still in business today.
That experience of actually working on that side of the table was probably some of the valuable time that I’ve had in the security industry. Because it taught me how to write, but it also taught me to figure out: always put the user first. Right? You take the user perspective - you don’t take the vendor perspective in that role = that’s really important.
And, yeah, it’s been a long and varied career and some of the high points for me - working at IBM Research - is a time in my life that I’ll never forget; IBM Research is an awesome place to go and hang out. It was like being a kid in a candy store - we’d site around and you’d just bump into people in the corridor and find out that they are working on the coolest thing that you could imagine - that was a fantastic role for me.
And, yeah, you know we hit it fairly well at one point and I retired into academia. I spent all of these years in commercial - started off a journalist - went into commercial and the research side of the house. And then I moved into academia and that was a very rewarding time in my life. I’m still in touch with so many of my students - if any of my students see this: I’m easy to find on LinkedIn students, you know, I probably still remember you. I think that they’ve left more of an impression on me than I have on them.
Eventually it was one of my former students who called me and said “Dr. Ford how would you like to be Chief Scientist at this company we’re standing up.” I said “Sure, Brian, but you’re going to have to stop calling me Dr. Ford” And he was like “Okay, Dr. Ford, I will.” So that’s sort of how I ended up at Forcepoint and the reason that that was attractive was that Forcepoint was trying to things a little bit differently. So I mean you’ve been around the show floor a lot and I mean this with no disrespect to the folks that are down there but it’s pretty samey, right? In some ways. There’s a lot of buzz in security and there’s clearly a lot of money flowing around but it’s not very well differentiated - everyone is going to stop you and go “We can solve you blah-blah-blah problem.” So we’ve got a universe full of point products and that’s not very excited to me - I went into academia because I wanted think deep thoughts. And the reason that Forcepoint was a fit for me was the we were going to shake things up a little bit so that’s been kind of fun.
AA: Yeah I mean I think that there’s a number of reasons that you’ve got all these different solutions but I’d love to talk about what is - even if it’s not been realized in terms of actual usable products that are well-known and utilized throughout the space - it does sound like there are some interesting things - particularly coming out the academic, some the defense community - in terms of, particularly, like the cyber resiliency is an area that I am excited about since it does seem like that is talking, at least thematically, strategically, about doing things differently. Right?
RF: Yeah so I think that resilience is a really important topic and it has been woefully underexplored, right? Especially in the commercial world; there are a few vendors that have been wandering around the show floor talking about resilience.
But often the way that we talk about it is not well-formed, since we don’t define the word very well. So often you’ll start to you’ll start talking about something else - talking about resilience. And what they’re actually talking about is robustness, so if something is very strong - you can’t bend it - you can’t move it - that’s robust - you can’t break it. But if something is like a blade of grass - you tread on it, you take your foot up, and it springs back up - that process of recovery, of coming back - you can bend me but I don’t break; I spring back to shape - that’s resilience. And I think that one of the challenges in this industry is that we are very sloppy in how we use our words - this is something that I was a pain at to my students.
AA: Well you’re an Oxford grad. You have the OED right - Oxford English Dictionary. You care about words, right?
RF: I do care about words, because I think that it’s also the Sapphire-Whorf hypothesis, which says the words that you shape - words are thought it’s basically. I mean, linguistically relative to the - am I totally sold on that? Not necessarily, but there’s some truth to it. If you can’t express it in words there’s a chance that you don’t think about it cleanly, because words are the language of thought. And so, yeah, words really matter.
And so being really crisp around the words that you use, so you and I can communicate, is really important. So, yes, resilience is interesting but only when we talk about it in the context of: I took a hit, I got hit, and then I came back up; that’s resilience, and that’s interesting.
AA: Yeah. I just use the word hard-to-kill, right? With the three words, yeah.
RF: Yeah I like that. “Hard-to-kill”; It’s visceral.
AA: Cause it’s not only the - it’s about recovery but it’s also I think - and that makes sense and it makes me think of cockroaches and rats, right? And it’s not just one right. One you can step on it, right? But there’s also millions of them, right? And so that - dynamism, diversity, all of these other things that fall under resiliency. Where are you seeing that - I know academically it’s been talked about a lot - but where are you starting to see maybe resiliency begin to form in the sort of -?
RF: Right, so of course, in defense world there’s been considerable interest in resilience - the idea of, yeah, you know you survive. The system survives, possibly in a degraded state, but it will come back up. There’s also been very good academic research. The challenge of moving resiliency, sometimes, into the real world or the commercial world is: we’re still messing up the basics. Right?
I mean we’ve still got people with bad passwords out there. We’ve still got bad password reset policies. We’ve still got companies that will send emails saying “Your password will expire in seven days. Please click on this link to reset it.” And it’s a real email - it’s not a phishing attack. So resiliency is important, but the problem is that you’ve got this massive skill difference between the agencies that do cyber extremely well and the agencies that just make the most basic mistakes. And some of these problems that we’ve been finding today have been around forever. First piece of ransomware - when was it? Take a guess. Is it a new problem? I mean, seems?
AA: I don’t know; like Morris Worm era?
RF: Yeah. You’re exactly right. We’re going back to-
AA: Like early 90’s or-
RF: AIDS Trojan-[inaudible]-gap, which was a hand-mailed, snail-mail piece of malware that was on a disk-
AA: Like with your AoL disks, right? Those CDs?
RF: No, no. They actually sent you a disk. And it was sent around to I think - now I’m going from fallible memory - I think it was about 5,000 was the first round. And what it would do was somewhere in the U-lay it said if you don’t pay money we will make your system unusable or words to that effect. And we’re still dealing with that problem. Wanna-
AA: It’s the newest thing that’s come out.
RF: -WannaCry was exactly that problem right? It just didn’t use five and a quarter inch disks. It was a little bit faster.
But it’s exactly the same problem set so if we’re still fighting the battles that we were fighting - what almost 30 years ago, 25 years ago - my question to you is: is this community really ready to step into the complexity that resiliency brings? Because, you pay for resiliency - if you study biological systems you will see that the most diverse system is usually the most resilient - that diversity of species leads you to resiliency. And so there is a real challenge there because what is another word for diverse when we are talking about differences - it’s also a word for complexity. So when you have systems that can sort of move and adapt, those are potentially more complex systems and currently we’re dealing with a world where people are still getting nailed by 25 year old style attacks.
So there is a tension that I don’t think we’re honest enough about in the industry to say look there is a huge difference in capability between end and the bottom end - and I say bottom end with no disrespect to people or organizations that I would put at that bottom end of security; because they shouldn’t have to care about security. Right?
“I think this idea that suddenly everybody has to be part of the security solution - to me that doesn’t speak to human nature. I think that we have to build much more human-centric systems - systems that actually accommodate how you and I actually work rather than going: ‘Well Richard is going to be completely logical at all times. He will step into the security world.’”
— Richard Ford
When you drive your car sit there and go “Huh I know exactly how the timing chain is working or the ignition.” You don’t think about the mechanics of it you just drive your car. And so I think this idea that suddenly everybody has to be part of the security solution - to me that doesn’t speak to human nature. I think that we have to build much more human-centric systems - systems that actually accommodate how you and I actually work rather than going: “Well Richard is going to be completely logical at all times. He will step into the security world.”
AA: Right. I mean it’s sort of bananas that we talking that humans are fallible - this is news to anyone? I think that the car analogy is one that is very good. The experience of - I mean humans are intricately involved in the driving of cars - although maybe not as much heading forward - but the systems around them got much better in terms of helping that person stay safe and when they make mistakes there’s airbags and seatbelts and all of those sorts of things. And I’m not seeing that tolerance for mistakes in the security space as much-
RF: Ah and it’s the word, right? If we change that word from security to a much nicer word, to me, which is “safety”, you start to design things in a different way. You don’t design a car going “I will make my car secure” - although, having seen some of the talks, maybe we should be doing more of that. You design a car going “How do I make is safe”: how do I accommodate the real fallible human nature of people like: how people get distracted when they drive, so maybe I’ll make the steering wheel rumble when they get to the edge of the lane.
That’s designing for safety rather than designing for security, and I like the difference in mindset very much, because I think that when you switch to a safety mindset you become more human. You go: “What’s the human really going to do?” Rather than saying “ You must be sitting and thinking about security at all times,” because guess what - you don’t. And you shouldn’t have to right? Security is a means to an end.
AA: So you’ve been in this a long time thinking about it deeply on all kinds of levels when you see people starting to think from that cyber safety perspective, what are they doing? What are the of top three, top five things that if you’re thinking from a safety mindset they’re doing?
RF: Well the first thing is that you recognize that people are people, and - blunty - the next four things are all: recognize that people are people.
AA: Look back at number one, right?
RF: Yeah exactly. That is the key to a safety-based system is that: you should make the default safe; you should make the default usable for what the person is trying to accomplish too. So if the car wouldn’t start because it’s “so safe” that’s not very helpful. So it’s really this very human-centered design that looks at how you and I will naturally operate those machines, and how we can use that as a way of accomplishing a task.
Remember, again - we’ve talked about this - security is a means to an end; it is not an end in and of itself. I don’t do security because I’m doing security; I’m doing security because I’m trying to keep my people and my data safe. And again there is a lot of that security culture - it’s like the cult of security, where security becomes “the thing”. And I’d like to remind people that security is a way of getting something done.
You don’t sit down at your computer to do security, typically, unless you’re one of maybe one of ten people in an organization. What you do is you sit down at a computer to do business and security is an enabler to that business but it’s not your primary focus.
AA: Yeah. I think that I’ve heard it a lot kind of talked as a measure of quality just the way we measure other things security particularly in the software development world. Security should just the way it does next to performance or the ability to do the tasks, right? Security should be right there in the mindset and I think that’s true in every one of - sort of pulling security into the business, right? The business should really be the owner of the security.
RF: Right because security is a business function because it is a business enabler, and what do is it not remove those risks, because business is risk. That’s what we do; we go out and sell a product on the market, that’s risk; you get behind the wheel of your car, that’s risk. You accept it and what you do is you mitigate that risk.
So we sometimes get into this “We’re going to make it completely secure. We’re going to make it completely safe.” - Nah it’s all risk. It’s about managing risk in an intelligent way to let you do what you want to do.
AA: So, you know, just to bring it down to a concrete level, on this show we kind of like to talk about things that we likes and things that we thought were cool. Where have you encountered like “Hey somebody was really using that mindset and they come up with something that made me thing ‘That’s a cool way to kind of think about safety’ or human-centric kind of - ”
RF: Right. So I mean, of course, us. Right, I mean that’s the reason that I’m here. But-
AA: Well how do you do it then. What are the ways that you do it in your own product.
RF: Sure so a lot the design work that we do starts from the user interface. It starts with: ‘how is this product going to engage with the user’.
So one the pieces of research that I did with a colleague when I was back at university - so we bought an eye tracker and eye trackers are so much fun, right? So it’s a little dual camera that sits at the bottom of the screen and it will show you exactly where the eyes are looking on the screen. What we did was we got a bunch of students - and I think we paid them in pizza which is like the universal student currency - what we did was we had a little competition.
They had to complete some tasks with a timer how fast and how accurately you can do the tasks, and that wasn’t the experiment. The experiment was, half-way through, some security warnings came up from the machine and we could see exactly how long they looked at the warning and what they were looking for and what they were looking for was the cancel button.
They didn’t generally read what the warning was - like “Let me get rid of this annoying box so I can keep on with my task” right? “Is there a close button?” No, really. It went to the top right; it was a scary piece of research. What you have to do is design your interactions with a security product with the human in mind. So here’s an example. If I’m going to interrupt you in a task with a security warning; if it’s: ‘Your Flash is out-of-date. It needs updating,” let’s say. If you’re not on the web, wait until you switch tasks it's a much more human way of doing it rather than: you’re working on a script or a word document or whatever and suddenly this box pops up.
It’s getting in your flow. If I can put that distraction off to later in a way that provides you the same level of protection - make it human-centric; it’s a very simple example. Also, start looking at risk-adaptive rather than risk-static. So one of the announcements we made at the show was: dynamic data protection or risk adaptive protection.
The basic idea there is: in the human world we don’t just let somebody in the door in through our house and then just pay no more attention to them. You keep an eye on what they’re doing and you adapt based on what they’re doing. It’s not: ‘Here are the rules for entering my house’ and, you know, that’s that.
So this idea adapting to user risk so we can better protect the user is really important. You’re not behaving like you, maybe I should be doing protection around that. And it’s not just about maybe you’re bad, it also maybe you’re compromised. I think part of the mindset around this is that you have to change the lens; when you start talking about those kinds of systems it’s all about “the bad user”. No, it’s all about user protection it’s about maybe your machine is compromised by malware and we should take care of that for you. What else -
AA: Unfortunately, I think we’ve got to leave it there based on time. But Dr. Ford this was awesome.
RF: It’s a pleasure.
AA: Now, I’m like a student too. I’m still going to call you Dr. Ford.
RF: Well thank you very much.
AA: Awesome. Appreciate it!
RF: Thanks.
Key Points From This Episode:An introduction to the work of Michael and Digital Shadows.
Explaining the dark web and how it functions.
Recent developments in the dark web market places.
The service that Digital Shadows offers to its clients.
Looking at file storage and the problems that these services create.
How Michael’s organization goes about protecting other organizations from threats.
Removing the criminal value of identifiers such as SS numbers.
Some of the interesting ways customers are testing their security.
The latest tactics of cyber crime for market place impersonations.
The illegal work of ‘rippers’ and how they are flagged.
The life cycle of cyber criminal personas.
And much more!
Interview with Eve Maler of Forgerock:Cyber Security Dispatch:Show Notes:
On today’s episode of the Cyber Security, we welcome Eve Maler, VP of Innovation & Emerging Technology at Forgerock’s Office of the CTO. Eve and I talk about all things data. We start of with GDPR: why it is such a widespread Data Regulation, how different people approach it, and how it can be treated as either a way to accumulate penalties or an opportunity to gain customers’ trust. Then we talk about the steps one can take to build trusted relationship with customers and use their data to benefit both the consumer and the corporation. Next we talk about data protocols and how some of them are breaking the status quo, while promising real benefits with the enforcement of GDPR. Finally we talk about how revolutionary ideas within cyber can not only help security and data protection, but also data privacy and usage in the larger sense. This episode is full of information and advice about GDPR and the larger realm of data.
Key Points From This Episode:
Links Mentioned in Today’s Episode:
Eve Maler Linkedin – https://www.linkedin.com/in/evemaler/
Forgerock Linkedin – https://www.linkedin.com/company/forgerock/
GDPR penalties – https://www.gdpr.associates/data-breach-penalties/
OAuth – https://en.wikipedia.org/wiki/OAuth
User Managed Access – https://www.forgerock.com/privacy/user-managed-access
RSA Conference – https://www.rsaconference.com/
Introduction:
Welcome to another edition of Cyber Security Dispatch, this is your host Ashwin Krishnan. In this episode titled, Three Pillars of Data: Protection, Transparency, and Control, we speak to Eve Maler, VP at Digital Identity Forum, ForgeRock. With past lives at Forrester Research and Paypal, Eve now works to develop digital systems that enable user controlled and compliant data sharing. It’s actually putting consumers in the driver’s seat when it comes to managing their own online information, and she’s the real thing when it comes to GDPR.
TRANSCRIPT
Ashwin Krishnan: Welcome. Today on the Cyber Security Dispatch my guest today is Eve Maler. I’ll have you intro yourself and then we can get right in.
Eve Maler: Sure I work for ForgeRock at our CTO (Chief Technology Officer)’s Office and I drive ForgeRock’s privacy and consent innovation agenda.
AK: Privacy and consent. I’ve heard that before - it looks like it’s very topical these days. So let’s talk about something that is “trending” - I want to say: this year, looking at the crowd - is GDPR (General Data Protection Regulation) so for our viewers I think if you just described in layman’s terms what GDPR means. But more importantly - I think what we were discussing outside before the interview - is: what are some of the nuances of GDPR that are either getting lost or getting pushed down with all of the other noise.
EM: Sure. Well let me talk about - first of all - to talk about the context in which I see the General Data Protection Regulation. So ForgeRock is about digital identity - for consumers and customers and patients and citizens - so kind of for people that you’re not the boss of, if you’re a business. And so we really see an identity-centric view of forging digital trust with all of those people. And so one of the ways that we see GDPR is: as kind of a viral mechanism, a viral regulation for spreading trustworthy mechanisms for businesses to forge that trust.
So one of the things that it achieves - for virality - is kind of a triangle of relationships among: individuals, data subjects; data controllers, so the organizations providing digital services directly to them; and then data processors and others - so one removed or more than one removed. And so if an EU resident is a data subject, or an organization has business operations in the EU, or a data processor has operations - any one of that triangle of relationship has got an EU relationship - suddenly GDPR gets pulled in. So that’s what I mean by viral.
AK: Yeah so it’s interesting because there is this notion of ‘EU: GDPR, EU: GDPR’ but it’s not just the EU it actually -
EM: It sure isn’t.
AK: - has tendrils all over. So maybe let’s talk a little bit about that.
EM: Yeah. So if you find yourself with - you know you’re a multinational or global corporation and you’ve got business tendrils in EU, or you’re marketing your services to EU residents suddenly you’re in the game as I’ve described with this triad; or you’re marketing your services you’re one removed and you’re working with companies that sell to EU residents. I think a lot of US companies have been caught short a little bit. Maybe not now in April - one month removed from the enforcement deadline.
We are close to the deadline so a lot more companies are aware but I was talking to companies, four months ago or five months ago, who were US based but had operations all over including the EU, who were still a little bit surprised. I’ll give you one example: We were talking about jurisdiction and how it’s becoming a dirty word.
So we have some customers who are in the hospitality business and let’s say you have a cruise line where: you have customers who get onto a cruise ship, you have employees who get onto a cruise ship - and by the way employees are people too - they can be data subjects- and a cruise ship docks at ports of call, so you get to a port and within three miles of a port you’re within a jurisdiction - where the ship is registered is a jurisdiction when you’re out at sea. And data that is getting collected and used on the part of serving those customers is part of the proposition, so a lot of jurisdiction is getting involved and I think not all companies are aware of really what’s involved in the - data doesn’t know about jurisdictions but companies have to care about jurisdictions.
AK: So let me ask you something else because this is something that the more I talk to organizations and individuals there seems to be a bifurcation of thought processes. One is: 4%, 20 million Euros right? Fearmongering. The other one is: what you mentioned earlier, which is digital identity is: using this as a almost a jumpstart to a competitive advantage in doing the right thing.
EM: Yes. Yes.
AK: So are you seeing that bifurcation of ‘okay let’s see who gets penalized first and I’m not this fan of the noise about 4% and 20 million that’s just too much so let me get back into my shell,’ and then these forward-leaning companies, which are going the other direction. Where is this all going to end; are we going to have a bifurcated world of hate GDPR and pretend it doesn’t exist and others who are using this as a proprulsion mechanism.
EM: Well I think it’s bifurcated and will remain a bit bifurcated, but it’s because we have different stakeholders in the same organization. We have people whose job is to be incentivized towards risk-based thinking, and people whose job is incentivized towards opportunity-based thinking and it’s the responsibility of folks like me to kind of bring them together. And so I’ll give you an example of four steps that we lay out in our work towards helping companies forge trusted digital relationships with their consumers and their customers.
Step 1 is to identify the intersections between digital transformation opportunities - to use a kind of a hashtag - it’s the new version of air quotes right - and user trust risks or gaps. So your new Data Protection Officer or your Chief Privacy Officer is incentivized to think about all of those risks and your business owners are going to be thinking about the digital transformation opportunities - that’s what all that data is there to do: is to help provide new services for users, things like that. But there is an intersection where you’re going to get in trouble. There have been really cool Internet of Things companies that have gotten as far as putting out a product and then been chased out of the market by angry people and ‘.orgs’. And that’s a shame if you get all the way to market before that intersection. So that’s step one.
Step 2 is to as an organization conceive of personal data as a joint asset with your end users. GDPR will say, well look, its a human right and it’s totally the asset of the data subject and a DPO (Data Protection Officer) can think that way, but a business owner is thinking what they can do with that lovely data to make more product. So it’s a mindset shift and I hear you’ve written a lovely article about this being an existential thing.
AK: Yeah so I wanted to continue because I have some ideas over here - the way that you’re talking about this.
EM: Maybe if we have more time we can - nothing but an over-the-beer conversation.
Step 3 is: lean into consent.
AK: Yeah.
EM: Now GDPR has six legal bases that it’s identified for legal data processing, and consent isn’t always appropriate, but consent can often be appropriate when risk-based thinking would say “don’t choose it”; because with that choice comes new rights that an organization has - new responsibilities but new rights. And it invites your end user in and that can invite a customer in and demonstrate some trustworthiness to them.
And then the 4th I would say is: take advantage of identity and access management for building those trusted digital relationships for make it easier and to reduce friction by doing the right thing.
AK: Right. No those are great steps. So a few things. One is: the top of consent, right?
EM: Yup.
AK: We can have an all-day conversation about companies literally -
EM: Let’s do that some time.
AK: - within 30 miles, right? Our so called ‘New Age Companies’, but when I got to their website and I look at consent and it’s still driven by legal.
EM: Yup.
AK: You look at this and say on the one hand you’re trying to force this trustworthy relationship with your customer. On the other hand if you’re consent is not transparent, easy to understand, and it’s not a 70 page eulogy - the iTunes, which no one can understand any of it right? Are you seeing companies which are forward-leaning which say ‘we are going to make this easy’.
EM: Yes
AK: We are going to make this easy so that I’m going to build trust with you and therefore stand above everybody else.
EM: Yes I will give you an easy answer to how that needs to be fixed and how some really forward-thinking companies are thinking about it.
“So [UMA is] a particularly - I think- interesting standard for a new kind of consent because it enables a person to in a demonstrable auditable fashion become a kind of offerer of access to their data rather than just being a passive agreer to access. And I’ve been talking to a number of companies about how to put this in place because it can demonstrate choice and control - a phrase that appears all over if you look at ICO guidance for GDPR for example. And so if you want to be trustworthy as an organization, that’s a way to flip the script.”
— Eve Maler
So GDPR is interesting and innovative as a regulation in another way because even though it says “Data Protection” in the title; the Europeans say Data Protection when they mean Data Privacy at large, right? So to me the phrase Data Protection means don’t accidentally let data out, right? It sort of means the security of privacy, but they kind of mean that phrase to mean everything. But what I see the elements of in GDPR are are data protection - the way I normally mean it: the security of privacy, don’t accidentally let it out. Also data transparency - tell us what you know about us and tell us what you want it for and all that stuff - so the two-way street. But it also has really strong elements of control - giving people control. It’s just transparency to say “Here’s our Terms and Conditions” so people can’t do anything about the terms and conditions, that kind of consent is -
AK: Correct. Exactly right -
EM: - particularly disempowered-
AK: - that kind of consent is a one way thing -
EM: Yeah. What can you do really? So new tools to understand what you’ve agree to are nice, but it’s not a particularly great way of taking control. So one of the things I’ve involved with - I’m kind of a standards wonk from way back- we were just mentioning SAML (Machine Learning) (Security Assertion Markup Language) the identity standard that I’ve been involved with. I was involved with the creation of XML; long, long story. One of the things that I’ve been involved with for some time now is a standard based on OAuth called User Managed Access, or UMA. So it’s a particularly - I think- interesting standard for a new kind of consent because it enables a person to in a demonstrable auditable fashion become a kind of offerer of access to their data rather than just being a passive agreer to access. And I’ve been talking to a number of companies about how to put this in place because it can demonstrate choice and control - a phrase that appears all over if you look at ICO guidance for GDPR for example. And so if you want to be trustworthy as an organization, that’s a way to flip the script.
AK: So it’s interesting you mentioned that - because one of the ideas I mean I keep vacillating between talking about a consumer and an enterprise. From the consumer’s perspective if I’m a YouTube Red subscriber or a Netflix subscriber.
EM: Right.
AK: If my per month charge keeps varying, sometimes it’s free, sometimes I get cashback, sometimes I get 100$ a month. It really depends on data I’m generating for that. So the average consumer knows that ‘Hey why did my 99 bill just drop to 0?’ It’s because you guys were binge-watching, and where you paused, and where you stopped, and where you flipped over is actually valuable information. It’s not rocket science so you look at it and say Netflix is probably the poster child of AWS (Amazon Web Services) usage, and they have all that data but they aren’t using it for actually engendering trust with their customers, they’re using it for their own purpose.
EM: That’s right.
AK: There is no copout over here. I mean you have all of the data, you have all the mechanism, you have all the analytics -
EM: More transparency -
AK: Yeah, exactly!
EM: - and more control would be exactly fascinating.
AK: And I mean I’d be a fan for life if they did that.
EM: Yeah it’s true. So you know it’s interesting you're making a case for protection - yeah - more transparency combined with more control would be - I mean that’s the area of business models, not basic security. And so business models are now up for question and so I think consumers combined with some government, some ‘.orgs’ are inviting companies to say ‘Hey how about it?’ If you want to engender trust you gotta examine - it is an existential crisis, right - ?
AK: Right, right, right, right.
EM: For some.
AK: So I know we’re kind of running out of time, but any last takeaways as to what you would - I know it’s still day two, we have two more days to go -
EM: So much more
AK: Right - but given the amount of foot traffic over here, the number of people over here clearly security is top of mind, right? So what would a really mind-blowing RSA for you look like. Coming out on Thursday, Friday saying “Hey, this was a great event if A, B, C happened.” Just… Food for thought.
EM: Oh God… Well you know I’ve always been gratified when they added a half-track for identity. And I think it’s time to recognize the core role that identity has in security, privacy, and consent, and in trust.
AK: Wow okay.
EM: So I think… I know I have identity-colored-glasses but more identity and I’ve talked to others who agree.
AK: Right, yeah. That’s cool. So you can’t have a conversation without blockchain, right so?
EM: I invented a drinking game for this! When someone says blockchain you drink.
AK: Alright I’ll be going binge drinking already. No but do you think ultimately that actually gives control back to the user. I mean last - yes or no. Or do you still think we are far away from -
EM: If I had to give a one-word answer I’ll say: “No”.
AK: Alright good. We’ll talk about that later.
EM: Another time I hope. A pleasure.
AK: Thanks for this it’s been a fascinating conversation. And it’ll be viewed GDPR, but hopefully we’ve given the audience something to think about over here - which is actionable.
EM: I hope so too.
AK: And hopefully enterprises - the forward-leaning one’s that you talked about will are using this as an opportunity to actually elevate themselves for new business models. Thank you for your time.
EM: Thank you.
Key Points From This Episode:Find out more about Scott and his background in the industry.
Using newer technologies to mitigate risk issues.
The importance of measuring vulnerability and patch programs.
Speaking in business terms versus technical terms.
Addressing patching and hardening caused performance issues.
Resolving a CISO’s mandate versus the line of business mandate.
What are the guiding principles of organization collaboration?
Getting the business to realize that they are the brakes on the car.
How do we define world class security?
Why the best security is secure but transparent to the end user.
Why CISOs have to start explaining problems in business terms.
How a CISO can still stay relevant knowing that a threat is out there.
Find out why CISOs need to start acknowledging their weaknesses.
How CISOs can make the shift from tech heads to business leaders.
Companies are realizing they need a more business minded CISO.
Managing CISO fear and how to ensure a long-term position.
The common trait that Scott sees in successful CISOs.
Why unsuccessful CISOs don’t want to be the bearer of bad news.
Are we really facing a cyber skills shortage?
And much more!
Key Points From This Episode:Vendor tools: Who should we be routing detections to?
The importance of giving the right information to the right people.
Tips for dealing with technical superiority and buzz word trends.
How small companies can establish their own technical superiority.
Why no one really believes how great you tell them you are.
What the next generation of software programmers are looking at.
How cyber security has become a cross-disciplinary concern.
What it takes to educate the next cyber security force.
Finding new tools to teach security in new ways.
Diversifying cyber security culture as we move into the future.
The benefits of hacking competitions and events.
Why a CISO is just like the goalie in soccer.
How do we get credit for the attacks that didn’t happen?
Evaluating pain points and the result of not solving them.
And much more!
Key Points From This Episode:Martin’s background and the current climate of privileged access management.
Managing the changing roles of privileges within hierarchical organizations.
How the inevitable shift to the cloud is changing cyber security concerns.
Who watches the watchers? What is the freedom of a super-user?
Points of friction within and without organizations around admin roles.
The increasing space of AI and what that means for job creation.
The lack of development in cyber security skills due to increased AI roles.
Data regulation and balancing freedom with control.
Comparing Europe and the US and the influence of GDPR.
Who should be considering the option of security privileges?
And much more!
Interview with Scott Petry, CEO of Authentic8:Cyber Security Dispatch:Show Notes:
On today’s episode we are joined by Scott Petry, the CEO and cofounder of Authentic8 and Founder of Postini. Scott Petry’s work on Postini is quite impactful since the company became associated with Google eight years after it was created. In this episode we talk about silo and Authentic8’s goals of ensuring customer privacy. We also discuss how some companies use complex and technical words to deceive customers into buying products that they are told will “cure-all”. As Scott disagrees with this mentality, he seeks to keep the idea of silo simple to say even to non-technical people and simple to explain. Finally in line with this, Scott advises to many people seeking cyber security that they stick to the basics.
Key Points From This Episode:
Links Mentioned in Today’s Episode:
Scott Petry on LinkedIn - https://www.linkedin.com/in/scottpetry
Scott Petry on Twitter - https://twitter.com/imscottpetry?lang=en
Authentic8 - https://www-eng.authentic8.com/overview/
Postini - https://en.wikipedia.org/wiki/Postini
RSA Conference - https://www.rsaconference.com/
Cloudflare 1.1.1.1 - https://www.cloudflare.com/learning/dns/what-is-1.1.1.1/
Introduction:
Welcome to another addition of cyber security dispatch. This is your host Andy Anderson. In this episode “The Cloudbased Browser” we talk with Scott Petry, CEO of Authentic8, John is now on his 2nd security startup, and has a disarmingly clear eyed view of the security market these days. With all the complexity the current security landscape Authentic8 sells a refreshingly simple solution. A browser that runs on virtual machines in Authentic8’s cloud infrastructure rather than a customer’s network or devices. This vastly reduces the potential for both attack and surveillance. Simple but really effective. Now on to Scott.
Key Points From This Episode:Learn more about phishing for awareness and what this entails.
How Joe helps companies set up phishing engagements against their employees.
Incident response and why phishing attempts are never going to be 100% effective.
Assuring those who have been phished that their credentials aren’t necessarily useable.
The difference between pen testing and red teaming in light of Haroon Meer’s work.
Why less black box pen testing and more white box red teaming could be the way.
How are organizations measuring both potential vulnerabilities and risk taking.
Compliance versus privacy versus security: Why GDPR is winter and winter is coming.
Learn more about national and international regulations for cyber security response.
Find out more about the threats out there today (like IOT) that are terrifying Joe.
Seriously, why would you need a Bluetooth controlled water heater in your home?
Hear more about the $29 Amazon home router that Joe easily attacked.
Why we need to go back to protecting people before protecting business.
Joe gives a few simple steps toward better cyber security in the home.
Learn more about using deceptive technologies and disinformation to secure yourself.
Disinformation, trolls and bots and their influence on the on the US election.
A current update on various state approaches to cyber security laws and bills.
The positive movements that Joe is seeing in the field of cyber security today.
And much more!
Interview with Jason Brvenik, CTO OF NSS labs:Cyber Security Dispatch:Show Notes:
On today’s episode we welcome Jason Brvenik the Chief Technology Officer of NSS Labs. He has spent 20 years in practicing a wide variety attributes within cybersecurity and has played a major role in his previous company, Sourcefire. We talk about a central development from NSS, EDR: Endpoint Detection and Response, and perspectives from a business related cybersecurity company. Jason explains the two engagement styles that NSS offer businesses: the group test style and the direct style. We also discuss how previous topics, such as resilience and layered defense, relate to NSS’s services, and why its service is not often found in combination with such forms of defense. Finally, Jason talk about the nature of safety in short and long term, and how system security is not tangible to the customers, which can lead to difficulties. Jason provides great insight into cybersecurity topics from a business perspective while also being personally aware of all the technicalities of the field.
Key Points From This Episode:
Links Mentioned in Today’s Episode:
Jason Brvenik - https://www.nsslabs.com/company/executive-team/jason-brvenik-chief-technology-officer/
Jason Brvenik on Twitter - https://twitter.com/vrybdpkt?lang=en
Jason Brvenik on LinkedIn - https://www.linkedin.com/in/brvenik
NSS - https://www.nsslabs.com/
NSS Endpoint Protection - https://www.nsslabs.com/security-test/endpoint-security/
NSS Security test - https://www.nsslabs.com/security-test/overview/
Introduction:
Welcome to another edition of Cyber Security Dispatch. This is your host Andy Anderson. In this episode, Treat the Disease, we talk with Jason Brvenik the CTO of NSS. He shares his opinion on security tactics we’ve discussed previously and NSS’s dual basic and reactive type defense.
Key Points From This Episode:The current privacy landscape and an introduction to GDPR.
Unpacking GDPR and what it will mean.
The future of terms, conditions and consent forms.
Locating the issue of privacy within a larger context of human rights.
The privacy issue and the distance it has to go to catch up with other social concerns.
The role of industry in the progress of the privacy issue.
Imagining an affirmative, multifaceted approach towards privacy.
Privacy’s relationship to identity and data.
The evolution of the rules of the privacy game.
The important decision we all have to make with regards to privacy.
And much more!
Key Points From This Episode:An introduction to our guests and their roles at ESET.
What brings our guests to RSA.
High detection, low maintenance and avoiding false positives.
Resistance to the cloud and what the slow migration means for security.
The obvious relationship between cyber security and the Internet of Things.
Practical and safe application of IOT in the home.
Targeted attacks and specific ransomware.
Looking at how these products in our homes can be leveraged by cyber criminals.
The benefits of complexity and putting the pieces together.
The reflected complexity of the criminal tactics.
The ongoing struggle even as security technology develops.
GDPR, cars that start with your phone and the future now.
Creating a ‘naughty list’ of companies to avoid?
And much more!
Key Points From This Episode:The beginnings of ShieldX and the time leading up to this.
The arrival of the cloud and the effect of ‘east-west’ security.
Implications for the lack of orchestration for traditional systems.
Reducing the total cost of ownership in addressing these scenarios.
Transferring the security of on-premise systems to the larger, cloud scale.
The logistics of migrating your security to any of the large cloud services.
The futility of an agent based approach to cloud security.
Compatibility and the platforms with which ShieldX corresponds.
Customer experience and how the service has been most widely utilized.
The three dimensional problem that ShieldX solves and secures.
Some information on ShieldX’s investors.
And much more!
Key Points From This Episode:
Learn more about the 2012 KPN hack and its impacts on cyber security today.
Riding the security rollercoaster: How to sustainably manage vulnerabilities and incidents.
Dealing with the known knowns, the known unknowns and the unknown unknowns…
How KPN works to reduce the window of opportunity for a potential hack to take place.
How does KPN ensure that security becomes embedded in different organizations.
Jaya shares more about the impact of cyber security when it comes to saving lives.
Why companies need to get their basics right before adding on more security services.
KPN’s risk mitigation strategies and why Jaya believes that risk acceptance is pretty evil.
Learn more about KPN’s “dumb” tool and the information they decided to make open source.
Jaya shares more about the KPN CISO app and where you can download it for free.
Jaya’s candid advice to fellow CISO’s and cyber-security product buyers out there today.
And much more!
Key Points From This Episode:An introduction to Gary and his professional life.
The tragic turn that Gary’s company took after it was hacked from the inside.
How Gary and his wife handled the crimes that were committed against their company.
The change of career that followed the downfall of the company.
The hacks that persisted ten years after Gary left his original career.
The decision to turn his lack of cyber knowledge into a lesson for anyone.
The birth of the Cyber Heroes comic!
Looking at the motivations of the employees who hacked Ben.
The actual, legal ramifications of hacking.
Thinking of new ways to strengthen the general public against hacks.
And much more!
Key Points From This Episode:Discover how Lisa entered the field of cyber security.
How Lisa came to work as a “bureaucracy hacker” at the Pentagon.
Learn more about the aims and direction of the DARPA program.
Lisa shares more about DARPA’s flagship program titled PlanX.
Find out more about the intricate links between Cybercom and the NSA.
Hear what Lisa believes is the problem with standards and compliance.
How to ensure mature cyber security ecosystems today? Lisa’s thoughts.
Hacking the Pentagon: How, why, when did this happen? Because it did.
Also, hacking the defense travel system, the Army and Air Force (twice).
How Hacking the Pentagon saved over a million dollars in defense.
The effects of the demonization of hackers in popular media today.
Why you cannot tell the world you are secure if you aren’t!
How Hack the Pentagon created a culture shift in security practices.
Lisa shares her view on vulnerability disclosure and policy.
See something, say something: The importance of reporting vulnerabilities.
And much more!
Key Points From This Episode:The latest product John and King & Union have launched called Avalon.
Avalon’s target market and the space it occupies in security operations.
What differentiates Avalon from other similar products.
Entering a crowded market and integrating into existing systems.
The architecture of securing information for a large company.
Housing these systems and the cloud services Avalon uses.
The experience of venture capitalism and the start-up game.
Building the team at King & Union and the benefit of shared experience.
The location of the company and its branding choices.
And much more!
Key Points From This Episode:David’s current position at Nuix and his background in the US Secret Service.
Some information on the Black Report and it’s defining characteristics.
The biggest realizations David has had working for Nuix.
Underestimating the human factor in current cyber attacks.
Better understanding the profiles and motivations of hackers.
The evolution of the mind of the attacker and how things stay the same.
Possible ways to go about testing and preparing for attacks.
David estimation of the social cohesion of hacker organizations.
How the security protocols and processes could be streamlined or sped up.
And much more!
Key Points From This Episode:Learn more about Mike, his background in the industry and his role at ZeroFOX.
Find out why security never appears to be top of mind when it comes to social.
Are people more welcoming of digital intruders versus in-person intruders?
Mike shares his views on social interaction from an enterprise perspective.
How ZeroFOX assists companies who are being harmed by behavior on social.
Why is crypto mining such a big issue right now and are consumers at a security risk?
Is the home becoming a new target for hackers and how consumers can protect themselves?
Discover whether Mike sees a battle between
AIML and data privacy.
And much more!
Key Points From This Episode:Some of Simon’s background and the areas in which he has worked.
The work Simon did at Bloomberg the and role of financial services in security.
The rising value of data and how this fits into an organization’s security.
The continuous role of a CISO in maintaining security over time.
Balancing risk preparation with cost effectiveness.
The easy ways to make sure your company is not very exposed to attack.
Matching your security practices to your company and it’s customer’s needs.
Disclosure of bugs and vulnerabilities to clients.
Taking responsibility for the risks you may be aware of within products.
The danger of incremental risk and putting an end to this growth.
The dimension that cloud and multi-cloud adds to these security concerns.
Simon’s perspective on the history of the RSA conference.
And much more!
Key Points From This Episode:
Arthur’s background in International Relations and role in the Obama administration.
The new challenge that cyber security poses to the state commission.
Highlights from the important process of Connecticut cyber security report.
The meetings that followed this report process and what contributed to its success.
Differences between public utilities and the general business sector.
Responding to the ongoing and evolving challenge of cyber crime.
The idea of cyber resilience replacing that of security.
Better communication and cooperation across the board to aid this issue.
Responding the potential foreign threat and timely recovery to these.
And much more!
Links Mentioned in Today’s Episode:
Arthur House — https://csi.uconn.edu/cyberseed-speakers- 2017/arthur-house/
Connecticut Cyber Security Report — http://portal.ct.gov/Office-of- the-Governor/Press-
Room/Press-Releases/2017/07- 2017/Gov-Malloy- Releases-Cybersecurity- Strategy-for-
Connecticut
C2M2 — https://www.energy.gov/oe/cybersecurity-critical- energy-infrastructure/cybersecurity-
capability-maturity- model-c2m2- program
Eversource — https://www.eversource.com/content/
Avangrid — https://www.avangrid.com
Connecticut Water — https://www.ctwater.com/
Aquarion — http://www.aquarion.com/CT/
Dr. Ron Ross — https://www.nist.gov/people/ronald-s- ross
NIST — https://www.nist.gov/
Belfer Center — https://www.belfercenter.org/
Key Points From This Episode:
• Dr. Ross’ job specifics and NIST’s role in cyber security.
• The current climate of cyber danger and how this relates to the internet of things.
• Cyber resiliency as compared with the idea of cyber security.
• Counter measures and tactics that typify cyber resiliency.
• The characteristics of diversity and homogeneity in security systems.
• The idea of deception as a tactic in defense.
• Dynamism and reconfiguration in the ongoing battle against adversaries.
• Minimizing the time that a cyber criminal has to operate within a system.
• Utilizing virtualization and shielding in the framework.
• Accelerating dissemination of the information available on cyber security
• And much more!
Links Mentioned in Today’s Episode:
Dr. Ron Ross — https://www.nist.gov/people/ronald-s-ross
NIST — https://www.nist.gov/
NIST Cyber Resiliency Framework — https://www.nist.gov/cyberframework
Dr. Ron Ross on Twitter — https://twitter.com/ronrossecure
Cambridge Analytica — https://cambridgeanalytica.org/
On today’s episode we host a conversation with Roberto Clapis and Stefano Zanero from Secure Network in Milan. We tackle the issue of IOT device security and try to break down just where companies and users are at with this issue currently. We get a background to Stefano and Roberto’s work and their interest in security as well as little peak inside their presentation from The Black Hat Convention. One of the main takeaways from the discussion is the idea of communication between security and other sectors, something that our guests suggest would greatly improve the strength of security. Listen in to hear what they have to say!
In this episode, Air Gaps Are Like Unicorns, we talk with Galina Antova. One of the co-founders of Claroty, a fast growing security startup in the world of industrial control systems. She shares her experience working to protect these critical systems and the journey that led her to found Claroty.
Key Points From This Episode:
Justin’s studies, consulting work and path to his current role at Zenefits.
Calculating risk return for defense and attack and how Justin approaches this.
Why better general security at other companies benefits everyone.
Justin’s approach to defending against advanced persistent threats.
Why security needs to talk more about the less sexy sides of their work.
The hottest new strategies and technologies according to Justin.
The role and appropriate time for automation within a security protocol.
Zenefits' ambition for their security and how far this extends.
The role of CISOs in the conversation about security within a company.
Cultural change at companies and how this leads to sustainable security.
The difficulty in hiring currently within the security sector.
And much more!
Links Mentioned in Today’s Episode:
Justin Berman Website — http://www.justinbermanphotography.com/
Justin Berman on Linkedin — https://www.linkedin.com/in/jmberman
Justin Berman on Twitter — https://twitter.com/justinmberman?lang=en
Zenefits — https://www.zenefits.com/
FS ISAC — https://www.fsisac.com/
Phantom — https://www.phantom.us/
Equifax — https://techcrunch.com/tag/equifax-hack/
Well Rick, thanks for joining us. Just introduce yourself.
My name is Rick Moy. I'm the chief marketing officer at a company called Acalvio Technologies. We are a Deception 2.0 company. We are creating a distributed deception platform that brings automated deceptions at scale and authenticity to organizations of any size. The goals is to make it easy to manage, deploy, and implement deception strategies in the network in order to do a better job of detecting attackers who have gotten past the prevention that is deployed on the perimeter and on the endpoints.
Yeah. Such a great background and experience and fit for some of the conversations that we've been having. We're seeing the realization in the market that static systems aren't secure, they're just not. If an attacker can see what you're doing, they're going to be able to penetrate it.
I know you guys have been around a while. Walk through where Deception and changes have happened. What that history looks like.
Yeah. Well, so first of all, to set the context like I talked about in my talk this morning, deception has been around for a long time. It exists in nature. You have the Venus Flytrap, the angler fish, you think of those fun things. So, nature's got them. We've used deception in warfare, kinetically, so military use smokescreens, false retreats, fake units, right, during D-Day, we created some inflatable tanks to fool the Germans.
In cyber, it really started around 1989 with the German attacker who was breaking into Lawrence Livermore. A guy named Cliff Stoll is one of the first documented deception campaigns, where he actually created fake systems, fake files, and even fake departments logically in the company, and a fake secretary who he gave an account on the system in order to mislead the attacker. So, deception is part of our world, whether we realize it or not.
Attackers use deception against us in phishing campaigns, in malware, polymorphic malware. We use deception to sinkhole botnets. We use it to gather threat intelligence externally. The field of honeypots, which most people think about, has been around for 20 years, and that's great. A lot of open source, community level projects. It solves a certain problem, but the change we've noticed over the last few years is that making those enterprise ready, right. What does that mean? No one has time to manage another platform. It takes time to figure out well what kind of campaign do I want to run. There's some manual effort required.
The new phase of deception, we call Deception 2.0 has a couple key principals. It's got to be manageable. It's got to be automated. It's got to be authentic. It's got to interoperate with your existing infrastructure fabric. All those things have to be true. That's really only become viable within the last 12, 18 months I would say. There's a lot of Deception offerings that I call more point products. They solve a specific part of the problem, but they aren't as fluid and dynamic as the modern enterprise would like. Keep in mind, developers have been talking about Devops for five years or so now, so that's really become part of the mantra within the CIOs organization. We've gotta be Agile. We've got to adapt to a digital transformation, that's still ongoing.
Yeah. You brought up so many good things there. I think that pain point that you talk about where you're already seeing 10,000 threats a day, maybe a million incidents a day, and if you were going to create another system where you're going to create even more incidents. You already are overwhelmed. The idea of how do I handle more when I'm already drinking from the fire hose. How do you guys, both your own technology but what do you see in the market in terms of that filtering, that understanding what is noise on the network and what is the really high-risk elements.
That's perfect, right. It's true. There's organizations I've worked with that get millions of alerts a day. That's exactly the problem with the prevention or traditional detection type of technology. Where deception comes in is really a great blessing for the organizations. It's a totally different philosophy.
With prevention you're trying to find the bad guy hiding in the crowd. With deception, you've set out fake assets, decoys that will attract them. By definition, anyone whose interacting with that decoy is not following business process. If they're an employee, they're not following the business process. If they're an attacker, they're looking for some data to either steal or ransom back to you.
“Deception 2.0 has a couple key principals. It’s got to be manageable. It’s got to be automated. It’s got to be authentic. It’s got to interoperate with your existing infrastructure fabric. ”
— Rick Moy
The definition of deception is it gives you high-fidelity alerts, so a very small number of them because, in general, they don't occur very often. They're designed specifically to detect lateral movement. Someone who has gotten a foothold on a workstation or a server inside an organization is now trying to pivot and find some of that important treasure to, again, steal or ransom back to you. By doing that, trying to figure out what machines are next to me, what services are in the environment, how do I connect to them ... all those activities could potentially reveal their existence if they connect to them. That's where we come in. Deception's a great compliment to a very noisy existing infrastructure that most organizations already have set up. These two things can be complimentary and used together.
Yeah. When you think about when you're creating a network and, essentially, trying to replicate something that looks like your existing environment and putting assets there. How do you do that in a way that's efficient, easy, and that also is believable to an attacker. In many cases, sadly, a lot of organizations don't even know what their network looks like and what's on it. How do you stand one up that's an image of it, a copy of it, that's real ... at least real enough to an attacker?
That's a great question. That's exactly one of the shortcomings of the previous generations of honeypot technologies. Modern approaches will allow admins and organizations to use gold images.
You can take systems that are actually deployed, dirty images. We call them gold, but a lot of them call them their copper or pewter or their fairly tarnished. They're not necessarily a precious thing. That's exactly what you want. You want to replicate and mimic the actual systems in your environment. If it's too clean, it's going to be suspicious. If it's too locked down, it's probably not going to be a good lure for an attacker. It needs to have the same kinds of flaws that your other systems have.
Not to get too technical because we have an audience that spans the range from security professionals to individuals who are tangentially involved, but can you dig in a little bit to one layer deeper in terms of how you do that? Is that done through virtual machines? What's the way you deploy a network?
To be honest, there are some that are out of the box that are just standard. There's a whole matrix of different types of deceptions you can deploy. Out of the box, you would get some basic things like SMB file shares, certain Windows operating versions, Windows 7, Windows 8, and Windows 10, Server 2012, etc. Those generally we provide. Others can be virtualized or containerized. We call it in our lingo, "service reflection." The process of wrapping an image that's already in production and then mimicking its existence on different VLANs. We have technology that really simplifies that. It's all about making it easy for an organization to roll out a deception campaign.
So you're deploying stuff both on prem as well as in the cloud? How is the deployment typically?
“There’s a certain investigative, James Bond nature to it ... what’s going on, who’s inside the castle walls, what information do I have, how can we lay some traps to have that person reveal themselves. ”
— Rick Moy
Acalvio is a cloud first company. Everything we design is meant for organizations who are going to be moving to the cloud or deploying from the cloud. That same engineering discipline allows us to deploy cloud-ready apps on premises in a very efficient DevOps manner. We've done the design for the hard stuff first, but are also deployable on prem.
Where are things going? What's new? What do you think people should be really excited and trying out in this phase? What's cutting edge in deception right now?
Cutting edge, I'd have to say it's probably the boring part of just making it operational. A couple of years ago, cutting edge was putting up a lone honeypot on the outside of your network and getting external threat intelligence. Well, that's something that a lot of people know. If you put something on the outside of your network, within about 5 minutes, you're going to start getting attacked, right?
What's really critically important to the organization, as well as kind of fun I think and so maybe this is the definition of cutting edge, is finding the bad guys who are already inside your network. There's a certain investigative, James Bond nature to it ... what's going on, who's inside the castle walls, what information do I have, how can we lay some traps to have that person reveal themselves. You get into this detective mode, and you start to think well what tools do I have to do that. There really isn't anything more exciting in my mind than the deception arsenal of tools that you have.
The honeypot is your actual server, you can put services out there that maybe just like a FTP service, which was used, for example, in the Sony hack. File sharing ... you can put fake spreadsheets out there. You can have false, misleading data in database servers that would, if that data was ever used in public you would know that you had been breached. There's really creative ways that you can think about marking content that if it's touched or used somewhere else will be an indicator. It really forces you, as the security guy, to think a little more holistically about what business are we in. Are we in healthcare ... is it patient records? Are we financial services ... is it bank account information? Are we a R & D shop designing semiconductors, so then it may be IP around a particular laser etching technology or layout of a microprocessor. I would want to have different strategies around each of those. That's what's interesting, and frankly invigorating, for a security person who maybe last week their top priority was applying a patch or responding to some malware on Jane's computer. Now he gets to think more strategically about the business and the threats that it faces. It's something that's typically reserved for the C-level suite, but in reality it's the people who are hands-on that have to implement that.
I think it's a great opportunity from many perspectives.
Sounds very cool. As people are thinking about adding deception to their strategies, what would you say is the best way to climb the curve, to educate themselves? Are there some resources out there? Are there some books they should check out? What sort of way to get involved there?
Actually it's a great question. It's almost a setup. We actually have a couple of books that we've written.
Cool.
You can go on Amazon. There's a couple historical books you can look at. The Cuckoo's Egg is one. Kevin Mitnick has written a book about deception.
We have two free books. One's a Dummies book, Deception for Dummies. It's a very short read. It's actually quite entertaining.
You don't have to be a dummy. It does a really good job of explaining it. Then we have an advanced field guide for the advanced practitioner whose had more experience with some honeypot technologies.
Awesome. Thanks for taking the time. This is your opportunity if you've got a soap box ... what would you like the community to know if you had 30 seconds, a minute, to say, "Gosh, you know you really need to be thinking about this."
I would encourage the community to recognize that deception is all around us. We use it every day, and it's used against us every day, whether it's in advertising, social relationships, and in cyber it's used. Let’s use deception to change the dynamics. The attackers are using automation and forcing us to do manual review of the problems they've created. Deception is the only platform that allows us to lie back to the attacker and change that dynamic and make them do some work.
From that perspective, when you look at the technologies at your disposal ... huge points for that. When you also consider that it's lower cost to deploy than a number of other technologies and more effective and lower noise, there's a lot of reasons to look at it. I'd encourage people to have an open mind and to read up on what Gartner says is the number three of the top technologies for the next year.
Yeah. Awesome. This is great. Thanks so much.
Thanks for the time.
Key Points From This Episode:Andrea's journey from academia to cyber security.
Why cyber security is also a retention challenge.
How companies can protect their employees from burnout.
What happened to the utopian idea of the internet?
State sovereignty and the balkanize internet or splinter net.
The implications of China’s new social credit system.
Learn more about GDPR and the control over your own data.
Does Russia’s internet look different to the rest of the internet?
The effects of the crypto currency movement on cyber security.
Learn more about the Russia-China authoritarian model.
Will GDPR be successful in helping democracies move forward?
Discover what Endgame does and how it operates on a daily basis.
Find out what it’s like being a woman in cyber security today.
Fake news and cyber hacks and their effect on the political climate.
And much more!
Key Points From This Episode:
• Learn more about Joe Slowik and his non-traditional CS Background.
• Joe gives his overview of the current thought around industrial controls.
• Find out how we defend industrial control systems today.
• How can attacks be actualized to impact an ICS environment?
• Script locking and reevaluating credential storage and credential use.
• Adopting a strategic perspective and designing network defense.
• Discover more about the Perdue model and what this means for defense.
• Tackling the misconception that the attacker only needs to get it right once.
• Who are getting industrial control systems right and what to aspire to.
• Why we need to develop a more analytical approach to threat behavior.
• How to empower individuals to respond and react to threats as they arise.
• Learn more about the Dragos company motto of safeguarding civilization.
• And much more!
In this interview, we talk with Steve Orrin, CTO of Intel Federal and take a deep dive into how government agencies are speeding up and changing their process for adopting new technology.
Yeah. So, if you can just introduce yourself, your name, where you're from, and where we are just so we can have it for the tape.
My name's Ray Mastre. I'm a director with Price Waterhouse Coopers, and I'm at the San Francisco ISACA Conference.
Awesome. Thanks. I heard you've been with PWC for a while.
I've been with PWC for almost 14 years. I'm a little bit of a PWC dinosaur.
Lifer.
Exactly. Lifer.
Always curious how people ended up in cyber security.
I was an IT guy at Penn State, and when I was coming out of school, I think consulting was really attractive to me because I got to see problems many different ways at a lot of our clients. It wasn't just looking at one thing and trying to make it better. It was looking at 20 things and realizing that there's probably common solutions throughout all of those problems. It's taken me all over the world, and I've gotten a chance to live in Europe and in many cities in the U.S. It's been a good ride.
Yeah. You said you were in Switzerland and a couple other places.
Beautiful Switzerland, the Swiss Alps, skiing, chocolate ... it's great stuff.
Yeah. I've been a little bit myself, but not lucky enough to live there yet.
It sounds like you've focused in on SAP as your coverage practice. How did you land there and what's exciting in that space right now?
SAP was a little bit of luck of the draw for me, but I think one of the things that was most interesting is just the amount of data worldwide that flows through SAP. In my presentation today, I talked about the percentage of business transactions that will touch SAP is astounding, worldwide. For me, that level of data was always interesting, and then being able to go to multi-national organizations in many different industries has given me the chance to just see SAP in ways that I don't think everyone gets to see it. Security has always been my focus, but it's just broader SAP that's interesting to me, as well.
I think for individuals who aren't running companies or running large systems, they may not realize how prevalent some of that stuff is running in the background and underlying the structure of making companies work.
As you think about where attacks are happening and how the potential for damage, destruction, theft, all the different elements that keep people in cyber security up at night -
Yep.
It seems like the critical infrastructure and backend systems have risen to the surface as an area for concern. What's driving that? Are there specific incidents? What's pushing people to realize that?
“It wasn’t just looking at one thing and trying to make it better. It was looking at 20 things and realizing that there’s probably common solutions throughout all of those problems. ”
— Ray Mastre
As I just mentioned, a very high percentage of business transactions worldwide are happening in SAP. Because of that, SAP really holds the crowned jewels for many organizations, right, their financial data, their supply-chain data, their procurement data, their customers, their employees. All of that is contained within SAP, and there's people out there that want that data, whether it's Nation States or hactivists or what have you. That's always been a target. Now the thinking behind SAP has always been that it's behind the firewall. It's not really a problem, and historically there never was that risk. Well, starting in 2012 with an anonymous hack in the Greek finance ministry, it's happened, and it's happened continually to larger degrees. It just continues to get worse.
In 2016, there was a Department of Homeland Security U.S. memo that, essentially, let the world know, first one ever, that there is a huge risk to SAP and the data within it, and companies need to start thinking about systems like SAP because even though it's behind the firewall, that data is accessible. Like I said, it's critical assets, and you want to make sure you're protecting them well.
I think it's interesting. As you think about cyber security, you know the typical life cycle of the software might be a year or two, and the typical lifetime of some equipment ... if it's well made, may be measured in decades. There's this natural mismatch between the life cycle of the two and thinking how do you protect critical systems that were cutting edge when they came out, but that thing was built so well it's running 20 years later.
Yeah.
How are you, whether at PWC or in your clients ... and you don't need to use any names specifically ... how do you handle that problem?
With the idea that SAP has been around for a very long period of time, and some of these threats are new ... like I said, I don't think the threat ever was imagined. I don't think people really thought that SAP was on their list, and now all of a sudden it's on their list. Companies are being forced to perform many structural upgrades when it comes to their software. Specifically with SAP, the new craze is Hana, so every company is required to move to SAP Hana in the next 5 to 7 years as an SAP requirement. Because that's a new system and it's not as mature, there's a lot of security concerns with Hana, and Hana continues to be, every quarter when SAP releases its security threats and vulnerability profiles, Hana continues to be at the top of that list of new enhancements that are needed to protect companies. It's a target, and I think from our side, PWC has been able to go in and help clients to ensure that, for example, they're including those patches, that they're using solutions that help to identify what those risks are, and help get those patches in.
There's actually a lot of vendors onboard, as well. There's a solution called Onapsis out there right now that Onapsis is the leader right now in making sure that companies are aware of what those patches are and what needs to be implemented so that they can integrate Onapsis into their cybersecurity program, which contains SAP.
Yeah. You know, I would love to hear specifically what you're seeing. The security in the design of programs is the ideal way it happens, right? When you're designing the software, you're expecting security to be built in, but in this environment you're sort of backward looking, trying to understand these older systems. What are the ways that people can protect those legacy systems? Are they just air gapping them or are they literally unplugging them? What do you see people doing?
I mentioned it in the presentation that I did today, but it's people, process, and technology and aligning those three. That isn't always so easy. If technology doesn't support the idea of security, then you've got an issue. I think SAP, at least the core ECC system, supports the ability and gives you the flexibility to control what users can do in the system.
And I think that's good. You have the capability, but what we see in the industry is that the focus is not necessarily on that application security. What happens is overtime, it may start out on day one as it's working fine, but as that system is in place for 5, 10, 15, 20, 30 years, you start to have a problem.
So, I think what will happen is there will be an intense focus on Hana with this new transition, and people will get it right, eventually. The question is, what processes do you have to have in place to identify new threats and also continue to keep your current security design up to speed.
Yeah. It's such a challenge because you've got some of those equipment critical infrastructure, and we'd love to say that everything's going to come up to Hana, but you've gotta plan. You've got a piece of machinery that works and it's gonna continue to work, and the price to buy a new one is pretty astronomical.
Do you just sort of expect at some point that that's gonna fail? How are people handling that?
I think that SAP is a software company, right.
They're not a security company. Just like PWC is professional services. We help to consult on SAP, but we're not a software designing company. In my mind, I think the best thing companies can do is really understand the capabilities that are out there, really do an analysis of what they're trying to protect ... so what's their critical assets - why are we trying to secure this period ... and then, ensure that the technology is used, the people are up to speed, and there are processes in place. That's basically all you can do. Just knowing what the risk is and then looking at creative ways to continue to ensure that people are responding in the right way.
Yeah. I think in one of your slides, you had understanding the different levels of threats and the different levels of access you need. You may have some vulnerabilities that you can't take care of, but as long as they're all lower level, you'll get to them but they shouldn't be your first priority.
Yes.
Okay. Cool. So, let’s have some fun questions.
What would you recommend people read? What do you think, in terms of value? I know you had a couple of pieces that you recommended.
You know for me, I love to read, but reading in the SAP securities space ... generally the books are like this thick, and it's a lot. I think there's a lot of really strong resources that are available at conference level. Normally, I don't even recommend conferences, but conferences really are a place, especially in the SAP space, there's a cyber security and a governance risk and compliance conference that is thrown by SAP every year. It's excellent. I try and speak at it every year, but also a bunch of my colleagues in the industry do, and that's even a help for me to ensure that I'm staying current because the market's ever changing and the requirements are, as well.
What's keeping you up at night?
Right now, my dogs.
What's keeping me up at night? You know, the biggest fear for me is not staying current. In technology as a whole, it changes so much and SAP Hana, they release a new version of the software support or the patch level behind Hana every year at least, every nine months. Having to understand what's there, what are the changes in security, how are our clients adapting to it, and what type of threats and penetration and hacks are we seeing ... to me, that's what keeps me up at night and that's where I spend my time.
Yeah. This is awesome. That was great.
Cool.
Really appreciate it.
Thanks.
About Raymond MastreRaymond is a Director at PwC based in the San Francisco office. For twelve years, Ray has specialized in SAP Application and Cyber Security and the implementation of Governance Risk and Compliance (GRC) solutions for SAP. He has completed eight global SAP security redesign projects and multiple end-to-end implementations of the SAP GRC Access Controls suite (v10.1) and the customization of client specific Segregation of Duties (SoD) rule sets. Ray also completed a 3.5 year exchange program with the Zurich, Switzerland PwC office; where he led the business unit dedicated to proving compliance solutions for companies running SAP (SAP GRC, Approva One, Security Weaver, etc.). Ray has worked for clients in various industries including: Retail, Public Sector, Insurance, Consumer Electronics, Entertainment, Pharmaceuticals, Manufacturing and Defense.
Paul's perspective having been leading some of the efforts that shaped how the modern internet works today. We talked about how such complex and multi partied ecosystem is always going to create problems and issues we couldn't imagine and how we as a global community are still struggling to solve them.
Cyber Security Dispatch sat down with Alya Gennaro and Elena Elkina to talk about the current state of privacy. Alya and Elena run the Women in Security and Privacy organizations and are cofounders of Aleada Consulting which focuses on helping clients understand and manage their privacy challenges. We covered some of the emerging issues in privacy including GDPR, and what individuals and companies can do to control their privacy.
Full Transcript coming soon!
Alya Gennaro is a co-founder and Partner at Aleada Consulting, where she advises clients on privacy, data protection, and information security issues. Alya has over 13 years of consulting experience in data privacy, risk management, internal audit, compliance, and operational process improvement. She strategically advises companies on minimizing risk, and meeting compliance and financial objectives, without disrupting operations. Alya understands that implementing best practice standards to reduce risk and meet compliance requirements requires a custom approach, appropriate to company size and maturity. She has managed numerous consulting and privacy engagements for national and global clients, across a wide range of industries, including technology, healthcare, financial services, insurance, transportation, real estate, and retail. Prior to joining Aleada, Alya worked as a Director responsible for opening and leading the San Francisco office for Sunera LLC (now Focal Point Data Risk), a national technology consulting firm. She also served as a Director for KPMG LLP, leading its North Florida IT Risk Advisory practice. Alya is a co-founder and Treasurer of Women in Security and Privacy (WISP), a non-profit organization that aims to advance women to lead the future of privacy and security. She also served on the Board of Directors for ISACA West Florida (Secretary) and Jacksonville (Vice President). Alya received her Master’s of Science in Decision and Information Science (MSDIS) from the University of Florida. She is a Certified Information Privacy Technologist (CIPT), Certified Information Systems Auditor (CISA), Certified in Risk Information and Systems Control (CRISC), and Project Management Professional (PMP).
IT Vulnerabilities – What an IT Auditor should be thinking about and why vulnerabilities are such a hot topic, what the risks are, things to think about when designing an audit approach including vulnerability identification, prioritization, remediation solution selection, ongoing sustainment controls and reporting.
Check back soon for the full interview and transcript!
Securely,
CSD
Raj Patel Chief Information Security Officer, City of Palo Alto ISO 27002-ISMS, COP, CRISC, CGEIT, ITIL Multiple award-winner and innovative information technology executive with 30+ years of experience in public and private sectors (at the City of Palo Alto, Oracle Corp., Sun Microsystems, Solectoron Corporation and Kaiser Permanente) in leading cyber security and digital innovation, Since joining the City of Palo Alto in 2012, he has institutionalized 3 years IT strategy with a bold vision & the strategy “To build and enable a leading digital city.” which has resulted in winning the “Leading Smart City” award for three years in a row. This recognition is based on his forward-thinking IT strategy. In addition, Raj has established an Information Security Steering Committee comprised of executive management, and developed an information security strategy and roadmap for future activities. In support of the strategy to ensure the confidentiality, integrity and availability of the information systems that support the operations and assets of the City, he has implemented an ISO 27001-based (Information Security Management Systems) security framework and created a new Information Security and Privacy Policies. Beginning his career in the manufacturing sector, he established a Six Sigma-based Quality Manufacturing System (QMS) that resulted in the Malcolm Baldrige National Quality Award. Raj is a Certified Principal Auditor for ISO 27002 ISMS (Information Security Management Systems) Standards. He is also a Certified Outsourcing Professional (COP), Certified in the Governance of Enterprise IT (CGEIT), and Certified in Risk and Information Systems Control (CRISC).
Check back soon for the full interview and transcript!
Securely,
CSD