Hi, I'm Tom Field, Senior Vice President of Editorial with Information Security Media Group. I want to welcome you to our session today. I'm speaking with Roger Sels, Vice President of Solutions for EMEA with BlackBerry. And the question we're going to discuss today is, isn't it time we rebooted our approach to cybersecurity risk prevention?
Roger, thank you so much for joining me today. Great to be here, Tom. Roger, when many people think of BlackBerry, they think of the traditional mobile devices. Please explain for me the security connection that's very active with BlackBerry today.
That's a great question, Tom. And one that we hear quite a lot because people focus on the devices. And ultimately, I get it that that's what was most visible to the consumers. But most people don't understand how much engineering architecture goes into making such a product because obviously you want to protect the corporate data that is being shared on those devices as well as maintain the privacy of user data.
So we've always had a heritage of protecting data and security connecting devices. So we have 35 years of experience doing just that. Roger, let's go back to the question I opened this discussion with. What's wrong with how we approach risk prevention today?
I think what is wrong today, Tom, is that we've somehow along the way given up on prevention and we started to believe that this is not an achievable target anymore. So we are creating, adopting all kinds of point-to-point solutions that generate tremendous amounts of data, require humans to take action on that data, aggregate it, enrich it, process it, and then take a decision. And it's no longer a human skill problem that we're trying to solve today. And I think that's what's going wrong with the cyber risk prevention.
It's not so much about the prevention aspect anymore. And even if you ask a number of other CISOs their opinions, everybody will tell you, well, assume that you've been breached. Isn't that a sad state to find ourselves in? Roger, you and I have talked ahead of time, and you've talked to me about the issue of cyber chaos.
Give me your definition of what this cyber chaos is. With pleasure. So the cyber chaos that we determine internally is what we're seeing in terms of rapidly expanding threat surfaces, new emerging technologies that have to be interconnected and secured that weren't there yet. So all of these will require new solutions.
They come from typically new vendors. And that creates a landscape that's always evolving. At the same point in time, from the adversary side, you now have a lot of nation states investing in offensive security, trying to get an advantage, be it operational or let's say really in terms of IP that they want to have to accelerate a capability within their nation. That makes it a lot more difficult for the defending teams because you now have these very advanced players that are after their assets.
At the same point in time, protecting these various assets has become more complex. So that creates chaos. Roger, how is this cyber chaos complicated and even exacerbated by endpoint chaos? Great question again.
The endpoints, when you think about it, it's today where the data is living. It's being stored, processed and rich. And in our traditional defense mode of a mode and a castle, we had all of our assets within a perimeter. Now we have more mobility.
We have more diversity in terms of assets. So that chaos that we just saw within the cyber realm spills over to the endpoints. You have many agents being pushed to that endpoint. You have various types of endpoints that need to still connect and share data.
So that also makes it harder for security teams to respond to the threats. You have multiple consoles, multiple agents. You need multiple skills, certification and all these products. So I think that's adding to the total cost of ownership and making it harder for teams to get all the benefits from these technologies because you have to integrate them and also bring certain challenges with it.
Roger, given the complication of this landscape you've described and the speed of attack today, what are the potential costs of defending all of this at what we might call human speed? The cost of human speed, I think the main cost there is failure. Spending and people have already discussed the classic model of defense in depth as really being expensive in depth. It's well-documented.
So you're spending a lot of money, but the result is not guaranteed. I think that's the main cost of this situation. So you're always reacting and you're always, as they say, a dollar short and a day too late. So Roger, maybe two years ago when we talked about machine learning, artificial intelligence, it was a big marketing pitch.
But the solutions really have started to come of age and are very practical now. How can some of these AI-driven solutions help us speed up this response so that we aren't reacting at human speed? By taking all of this disparate data, ensuring that action is immediately taken without requiring that input, it allows the defensive teams to focus on other problems, problems that have more business value. That's just one aspect.
Now, I want to touch on the first thing that you said because, well, AI has only really picked up within cybersecurity in the last few years. That's true. But actually within silence, and silence, as you know, was acquired by BlackBerry, silence has a leading capability in terms of AI and actually defined the space in 2012. So in 2012, silence was the first company to start investing in this map and realize, well, we can really use AI and machine learning for cybersecurity purposes.
And then other players in the market started adopting some of this, but are today mostly playing catch-up. Roger, I'd be remiss if I didn't bring this back to BlackBerry. Talk to me about your company and how you're helping organizations take another look at their cybersecurity risk prevention. Sure, Tom.
We do this in a number of ways. So ultimately, you have to see it that we have a platform called BlackBerry Spark, which is the unification of our mobility and security suite. And the advantages of bringing these together is that across all of your endpoints, whether it's servers, wearables, mobiles, even IoT smart systems of the future, you can have exactly the same protection managed in the same way. So that reduces that chaos that we have been discussing.
But we focus a lot on productivity and reducing friction for the user in what we call the zero-touch and zero-trust architecture. Because ultimately, making the business operate in the most streamlined fashion while being more secure should really be the end goal. And that's exactly the way we've envisaged the platform and designed it. Well said, Roger.
Thank you so much for your time and for your insight today. Thank you, Tom. Glad to be here. Again, I've been speaking with Roger Sels.
He's Vice President of Solutions for EMEA with BlackBerry. For Information Security Media Group, I'm Tom Field. Thank you so much for tuning in today.