Certificate Lifecycle Management Just Got More Strategic episode artwork

EPISODE · Apr 20, 2021

Certificate Lifecycle Management Just Got More Strategic

from Info Risk Today Podcast · host InfoRiskToday.com

“Work from anywhere” is a game changer, and it has significant impacts on certificate lifecycle management. Patrick Nohe of GlobalSign discusses the new, strategic approach security leaders need to take for CLM.

Episode metadata supplied by the publisher feed · Published Apr 20, 2021

Embed this episode

NOW PLAYING

Certificate Lifecycle Management Just Got More Strategic

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Hi there, I'm Tom Field, Senior Vice President of editorial with information security media group. I'm talking today about why certificate lifecycle management just got more strategic. Please welcome to the virtual studio, Patrick Nohey, he is the senior product marketing manager with GlobalSign. Patrick, thank you so much.

Take your time to speak with me tonight. Thank you for having me. So Patrick, we talk a lot about digital transformation particularly over the last year, but maybe not enough about its actual impacts. How would you say that the past year would the work from anywhere movement most impacted certificate lifecycle management?

I would say that just the rush to get to remote work arrangements and the speed with which many of these companies had to make decisions has potentially led to a number of organizations that down the line are going to be facing some challenges based on some of the determinations they made at the outset of this whole pandemic when we were all trying to just figure out ways to continue working, keep the doors open and the lights on. And it's understandable why some of these pitfalls are going to be awaiting some of these organizations. Generally, you want to make one of these digital transformations and you would work with a business consulting firm like a gardener. They would give you a multi-step framework that would take a number of months and would require you to really map and analyze everything so that you would make the smart strategic decisions.

And in this case, a number of the organizations that have now moved to work from home or now with people coming back to the office of high-grid work arrangement, they haven't necessarily been able to make some of those long-term determinations that would have saved the money or would have removed what I like to refer to as foot guns, things that you could shoot yourself in the foot with down the road from the implementation that they're using. So now they're going to start running into situations where it's difficult to potentially turn over certificates because you don't have a mechanism to get them to a remote employee or some of the policy decisions you've made are going to start weakening your security posture down the line. So really, now as we've got our feet under us and things are normalizing a bit, now is the time I think for organizations to really look at what they're doing with regard to CLM and make some adjustments so that they are in the best position, not just in the interim but moving forward. So Patrick, we're from anywhere.

It's clearly a game changer. What do you see some of these security leaders, critically overlooking or misunderstanding even, about CLM as they make these shifts to accommodate? Well, as I mentioned, in the rush to kind of get there, we've overlooked a number of potentially different, as I said, foot guns, but mistakes that kind of wait somebody if they don't necessarily make the right decisions. That can be across a range of different areas.

There's a lot of touch points when it comes to PKI and CLM. That could have to do with not necessarily having the right controls, so the ability to revoke certificates, the ability to store and recover keys. It could come down to a lack of visibility over all the certificates you're managing across your network. It could come down to what algorithms and key links are using, policy decisions.

Really we're being honest, even for a lot of IT teams, PKI isn't necessarily an area of expertise. The average limit, obviously, it's just a lot of acronyms and strange sounding words. Really is important to have knowledge and experience guiding you as you make a lot of these determinations. If you've done this on your own, if you've decided to do things in-house, a lot of times you're missing that and you're potentially setting yourself up for problems down the line.

I want to double click on some of these challenges. Patrick, what's wrong with some of the traditional ways enterprises have approached CLM, maybe before we get to work from anywhere? Well, the biggest one, and we've worked with a lot of customers to crunch numbers and really kind of try to extrapolate the actual cost of this, is a lot of organizations feel like they've got Microsoft Active Directory and they can just manage things all on their own. You've got the tools, I can figure this out.

What they end up doing is, and we've found over the course of about five years, we're an organization of about 1,000 employees, you're going to end up spending about $1.5 million more dollars managing things yourself and dealing with some of the mistakes that are going to arise and just kind of keeping everything moving. Then if you had just made sound strategic decisions partnered with the right companies, brought in the right experience and done things with a little bit more of a controlled approach from the outset. That's one of the things that we like to really hone in on when we're working with our clients and our customers is, how do we make decisions that are scalable and it sets you up to be able to continue to leverage PKI in a way that gets you the strongest security posture and also is the friendliest to your bottom line because as I just mentioned, this can get expensive if you make the wrong choices in the wrong places. I think I want to come back to something you were talking about a few minutes ago and that's why can't organizations necessarily do this on their own and what's the benefit of partnering with the company such as GlobalSign?

When you do this on your own, obviously you have to have the knowledge of PKI of best practices, you have to be able to implement across your network in a way that gives you visibility over everything that you're doing. You have to stay on top of crypto agility a lot and the ability to swap out crypto systems and be agile on your feet in the face of incoming new technologies. You're responsible for that. If you're spending your own PKI, you're doing things on your own.

Really, you're leaving yourself out in a state of vulnerability by virtue of the fact you don't have anyone there to call it things go wrong. You don't have anyone there to help guide you from a technology standpoint and give you the insights into these are the ways you should create certificate policies and these are the ways that you need to enforce certain revocations or lifecycle things. There's a number of different facets of certificate lifecycle management that don't necessarily even occur to most organizations until they're at the point in time that they're dealing with it and at that point, it's more expensive, it's probably too late. It's better to work with an organization.

As I said, this isn't necessarily the wheelhouse for most IT teams, it's not an air mix for these. It is when you're working with a CA, it is when you're working with an MSP. We do understand this. We can build things in a way that is intuitive, it allows you to have control and visibility but it doesn't require your IT team to devote hours and hours to tedious manual processes like replacing certificates and turning over keys and things like that.

We can help with the automation. There's just so many different things that working with a right partner can open up for you and can help you with both savings and efficiency that doing on your own would just be the cost prohibitive or you wouldn't have the internal experience and where with all people to do. So, increasingly today, we have enterprises of course relying on MSPs. What's the message then for the services market regarding CLM?

Well, once again, it goes back to the level of knowledge and even really the appetite of organizations to handle a lot of these things. If you're an MSP, the more that you can take off of your customer's plate, the more you can manage for them, that adds a lot of value to your offering and that's a great way to differentiate yourself. That's a great way to really help your customers and it also is just a net positive for the overall internet security ecosystem as well because when we've got more companies using PKI the right way and making smart decisions, things just work better. So, from the standpoint of an MSP, the more that you can do for your customers, the better.

We work with a range of different types of channel partners. We don't just work with MSPs. We work with integrators. We work with everyone across the spectrum.

But really what is important to us from a big picture standpoint is just making sure that when you are talking about PKI, when you're talking about CLM, that we really are working towards getting every organization to follow best practice, to automate where possible, to improve their security posture because as I mentioned, that's a net benefit to all of us. Patrick, when you can talk to me a little bit more about GlobalSign. I'm curious on how you're helping customers tackle CLM to improve their efficiency and their security posture as well as to of course generate cost savings. Well, I'm happy to do that.

We are turning 25 this year. Obviously, a big anniversary for us. We are globally trusted, publicly trusted. Certificate Authority, we're also a trust service provider in the European Economic Area.

So when it comes to trust, that's really kind of our wheelhouse. What we're really proud of right now, we released last year, our Atlas Cloud CA backend. It's incredibly powerful and it gives us the ability to service all kinds of customers from small one-off websites to the biggest service providers that are consuming hundreds of thousands of certificates. We have the ability to act as a pipeline for certain service providers and just get them the certificates, knowing that the management capabilities are built into their own workflows and infrastructure, or we can also provide that kind of assistance for our customers if they need that in the form of AEG, IoT, Eddral, we're working on a new CLM platform right now.

We are able to work with customers of all sizes and we're able to kind of get them that personal touch. We're not owned by some venture capital firm. We're not passing hands every single year. We've got a poor vision in place.

We know what we do. We have a wheelhouse and you get that personal touch. You get somebody on the phone when you call. If you have a problem, we're there to fix it for you.

And really, that's sort of the whole strength of GlobalSign is the fact that we're a big company with strong capabilities, but we're capable of providing the personal touch that each one of our individual customers requires. Well said, Patrick, thanks so much for your time and insight today. Thank you very much for having me. And you have just heard wide certificate lifecycle management.

Just got more strategic. Now, just spoken to Patrick Nohy, senior product marketing manager for GlobalSign. For information security media group, I'm Tom Field. Thank you so much.

Taking time to listen to this interview today.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on April 20, 2021.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!