Welcome to Cybersecurity Insights, the podcast for the CyberEd.io learning community. Our goal is to bring cybersecurity practitioners the latest and most relevant education and training to upskill and dive deeper into topics that matter in today's modern cybersecurity world. Good day, everyone. This is Steve King.
I'm the Managing Director for CyberEd.io. And with me today is Red Curry and Sam Curry, the Curry brothers, who are joining me in this continuing series of podcasts to discuss cybersecurity and its impact on society and its impact on war and its impact on our everyday lives, along with the impact of AI on cybersecurity. So Red is the CMO at Tasek and Sam is the CISO and Vice President of Zscaler. So thank you guys for joining me again today and why don't we get into it?
Thanks, thanks. Thanks for having me. One question that occurs to me as we watch this business unfold in the Middle East is why there haven't been, it feels to me like in the Ukraine war, there've been more cyber activities than there have been in the, in the, what do we call it, the Hamas-Israeli war? Yeah.
Why that is? Yeah, I'll take a stab at this. I think this is Sam speaking, so people can tell the voices apart. Being related, that makes it a little difficult.
I think it's hard to see that, Steve, because the Ukraine war is not over when it started. First of all, the cyber component of the Russia-Ukraine conflict goes back to at least 2014, and it includes NotPetya, the invasion of Crimea, 2017, of course, right up to and including COVID. There's also attacks on the, on the energy sector and the financial sector. And then, boom, combined arms effect as of February 2022.
And so there was really no normal as a backdrop against that. And much of the cybercrime community polarized. You had those, so, so not all of it, but you had those who sided, maybe perhaps because they were in Russia, many of them sided with the Russian side, like the Russian imperial movement or Conti. And then you had those who sided with the Ukraine, and then you had some neutral players still making money around the fringes.
That doesn't leave much to contrast what happened with the outbreak of hostilities between Hamas and Israel. It doesn't say, hey, it was a normal period beforehand, and let's take a look at what's changed. Most of the combatants you would expect to see take sides or, or some engage in activity were already engaged in activity, in my opinion. I think it's going to take a lot more data and a lot more time to be able to tease apart.
It's not like it's an empirical study. Red, do you have any thoughts on it? You know, I think one of the things I started to realize was a one-pronged approach or two-pronged approach wasn't going to be the way it was done. And the best way to get your plans executed is to have nobody know about it, right?
Don't have it online. Don't be anywhere people are going to see it. And so why you're seeing this probably play out a little differently is because the mission was to get something done and the mission is to keep getting things done and keep it offline so it can't be heard. Does that make sense?
Yeah, it does. Look, often there's two components. There's the noise campaign to hide what you're doing, and then there's the targeted campaign. And so with the outbreak of hostilities, you wouldn't get the first, because there's already a lot of noise.
And the second is very difficult to see very often, the targeted stuff, the what we used to call the APT stuff. So, Steve, I think, I think the answer is, we don't really know if there was an increase specifically around that because it was already turned up to 11, if you will. There's already a lot of activity going on, a lot of noise. You know, ransomware is up year over year over 60%.
We've seen, it's gangbusters out there on the APT front, so it's kind of hard to say whether it did or didn't increase significantly. Certainly, attacks are happening because of it, but what does that contrast to? Yeah, and I guess at the end of the day, it doesn't matter what level of, you know, attack velocity or frequency you engage in, you still, if Hamas is hiding hostages and, you know, assets of that nature in tunnels and amidst civilians, you still end up having to go door to door to kind of figure it out. I guess no amount of cybersecurity anything is going to help, right?
I mean, that's the endgame here, I suppose, right? Yeah, I mean, at the end of the day, I'm hard-pressed to think of any real conflict. I'm hesitant to say full war because even the label Russia's given the Ukraine conflict is a little silly. But I'm hesitant to say full war, but any serious war between states or even major non-state actors in states, in the end, there's boots on the ground.
Unless it's a punitive response to something, as we might have seen with General Soleimani in Iran a few years ago. But most of the time, when meaningful objectives are being gained, it has to be with land. You've got to go and you've got to look in the caves, you've got to look in the basements, you've got to look in the buildings. And let's not forget as well, the terrorists often have human shields.
It's horrible when there's captives and hostages, but very often they're taking society to hide behind hostages as well. Yeah, and you know, so as long as the rules of engagement are concerned with collateral damage, there is no way to, quote, win that engagement, I think, right? I mean, otherwise you could kind of do a hands-off, just shut everything down scenario and wait until everybody starves and dies, right? There's no surgical separation, right?
Sorry, Andrew. I was going to say, and that's exactly what you're seeing now, is a game of patience. And it's not a game, but it is a waiting game. It is an opportunity to see what shakes out and what happens over time, right?
Because you can tire somebody out. It's a horrible thing to think of, but that's basically why you're seeing this. You're hearing, are we delaying? What are we waiting for?
Why are we going in? Why would we be pulled into something when there's a trap set? So you're starting to see strategy and planning around how you wait that out and see what shakes out. Yeah.
How much do you know, Sam, how much influence our own cyber intelligence operations have on military conflict here yet? Who's the hour of that? When I say that, I mean CISA, Cyber Command, the United States. Yeah.
So I mean, there's a big important distinction between law enforcement and the military, right? So when you say CISA, that's actually part of DHS and that's law enforcement. And in fact, as an agency, it's actually not a law enforcement agency to be specific. But we should think of civilian versus military and whether it's law enforcement or not.
Cyber Command. So I think you mean, and they certainly have amazing capacity, but most of that's not publicly known. We do think of it as a command, though. We do think of, we do think of cyberspace as a full-blown field for military engagement, just like we do space now, by the way.
Right. Whether or not we fight in space, we recognize it as a place that fights could be fought. And of course, then we have the notion of combined arms. And we certainly are aware, for instance, that things like drones could be jammed and things like ships can be hacked or planes.
And we also know the reverse is true, that you can physically target the place where hackers sit or where signals are being pushed or rebroadcast or broadcast from. And so, absolutely. But that's been true, by the way, even for electronics, electronic warfare, even before we called it cyber. Before you had things like a stack and the World Wide Web.
So that's not really new, but the degree to which I think it's interconnected with what we do and the power of it, its ability to affect things like economies and lives and critical infrastructure is much, much higher. So by specifically by that is lives and energy and water and food. And I know Red has written on this. It's actually, you have to think in terms of what's the impact you can have with a cyber attack.
And it's far higher than ever before. Most folks don't understand what it is that people like Jenny Soi do, you know, that they, what CISA's actual role is. And some days it feels like a standards organization. Some days it feels like a cheerleading organization.
Some days it feels like a, like a leadership board. It's a leadership board. Like a policy organization or a spokesperson organization. You know, all that's true.
All that's true. But there is a cyber command, is there not? Like that we have a space force. I thought as a separate agency, is that not true?
It is. And actually, I think we just had our first space ranger. Red, didn't you point that out to me the other day that there's somebody who works now a weed in the space forces, by the way, full hats off to that, but it's having a cool title to have. But there is a space rangers.
Yeah, seriously. No, but I mean, like take Army Ranger in the space force, right? So I'm going to get in trouble some percent, but it's true. I'm sure we kept the link in this, no doubt, if we broadcast this.
But CISA, CISA, I was at Krebs said once, he said, we like security so much, it's a name Nor, by the way, did bombing Germany. Or is it C, to try to somehow affect some warfighting or critical capability at just the right time at a strategic or logistic level? And I don't think that doctrine's been written yet. And so the question becomes, maybe not, is cyber warfare just a thing we haven't seen yet?
But the motivation for why somebody would launch an attack like that, and it would be an act of war, is something we've yet to see. Now, terrorists have a reason to do these things. And they can achieve the same result with fear and getting the media around that attack as they can by actually doing the attack because their job is to affect policy change through fear and through being seen to scare. Does that make some sense?
Yeah. And you think back to Oldsmar water, JBS meat processing, some of the attacks that happened to some of those places, right? If you think about Suxnet. And these are all things in which...
Well, Suxnet was very tactical, right? It said, hey, we're going to slow down your bomb making. It was really the logistic was that second school of thought from my bomber mafia, right? It was the take out a critical warfighting capability.
Your other one read, though. I mean, again, that really did scare people that suddenly the food supply chain could be affected. Yeah, and affect the morale of the people and perhaps change political process. Add to it, add healthcare systems that have been hit, add gas pipe systems that have been hit, global oil companies, more nuclear facilities.
You got to go to Ohio nuclear. They're supposedly accidental military. I could list them all. India power grid, Norwegian vault.
I can go through a ton of them systems. San Francisco water, San Francisco water, Oldsmar, Florida. Just by changing the chemical makeup within that water processing plant, you could do some horrible damage. And that's terrifying to populations.
It comes down to tangible, right? Practical and physical as well as digital, right? Because those are felt by people, community, countries, not just businesses, not just governments, but by people. That's you, Steve.
That's me. That's Sam. That's our families, our friends. These are the things that make people here in the U.S.
stand up and go, okay, what are we doing? And then, Steve, I think you mentioned this in the beginning. I think it's time we stand up and say, okay, what are we doing? And what do we have holistically?
Are we looking at every aspect of every part of our process and our plan? And I thought back to it, right? IoT is a great example. I think we talked about that earlier, Sam.
IoT is not traditional. It's not a traditional. It's a new thing. It's coming online right now.
And traditional security probably won't be the only thing to secure it, right? There'll be lots of different avenues in it and a holistic approach from different layers, right? Physical processes, intelligent devices, control systems, operating systems, all the way through the network layer, business logic systems. There is no silver bullet.
So we've got to get better at understanding the processes and getting in different security at different layers, both physical, it's the sci-fi conversation we had before, and doing both equally and having each other talk. They have to talk to each other. We have to understand what's feeding what. Does that make sense?
Oh, yeah, it does. It absolutely does. But here's the problem with IoT. At OT, we rush to get it out there.
And that which is temporary tends to become permanent. There's a bridge near your house that I think was built in the 50s. It was supposed to be, what, 5 years, 10 years. It's still there.
What's that? The temporary bridge. It says right on it. Temporary bridge, 1950 or something like that.
And it's like, it's 2023. And every time I go over it, I hear the click, click. And I'm like, this thing is going to be here till it's not. It's in the bridge.
Right. And it's not because there isn't the money to fix it. It's because temporary things tend to become permanent. And so when you launch things like, you know, new IoT program, you know, because it's not secure, it's not becoming secure.
I have a student that I mentored and shout out to Rajesh Aryanpan. He was a sophomore and he was fascinated with cars. And he wanted to get a CVE number. And I said, hey, FYI, when people make things like this, they take an operating system off the shelf and shove it in the car or in the device.
They don't say, make me the perfect OS and wait for it. They just take what's on the shelf. And when they find a vulnerability, they patch it in that car. They often forget to go back and patch the source.
And we were doing a completely different project. And he went and found the next, like a later model car and to check for an earlier vulnerability and patch. And sure enough, he found it. And by the way, he got his CVE and he was hadn't even graduated from college.
Funny side note, Fox News found out and Good Morning America that he had worked with me and they gave me credit for it. I didn't do it. In the end, he had to go on Good Morning America. He hadn't graduated with a bachelor's yet and he did a great job, by the way.
But the perfect example, like, if it's out there and you haven't thought about it and you haven't got the processes to make this systemic and ongoing, that's the vulnerability is going to live forever. Yeah, yeah. Gosh, there's so many layers here. We talked too much, don't we?
And the problem is, we don't talk enough. You know, people, I'm shocked at how little anybody understands of what the threat funnels are here. And I think our audience, like, for example, you know, Red, what do you think those attacks were about on the meat distribution and on the on the oil and gas in the Northeast? Were those were those probes to see what we would do, what our response levels would be?
Or were those probes to see how much they could get away with or how easy or hard it was to get in for some leader? Or did they leave, you know, agents on the networks? So sometimes it's a combination, right? This is a lot to unpack here in this one.
Sometimes it's opportunity, right? So these attackers see, look, the likelihood of you paying. If I attack the water, so JBS meat, for example, or Oldsmar water, if I hold that ransom, the likelihood of you paying quickly to get stuff back online to serve the community, to protect, to prevent poisoning or to prevent even death catastrophic, right? The likelihood of you taking an action faster.
Look, my city was just ransomware. They took down first responders systems. This is important to get back up, right? For the safety of the community.
Look at what's happening, right? I mean, Sam, you could see that. It's maximum impact and how quickly are you likely to pay. Bad guys want that.
Disparate security teams, they know you don't have right responses. You don't have the protocols in place to respond to that. So reaching out to federal law enforcement is critical, right, to getting things back online and to finding out where things are and where they stand and how you get resiliency built in, that anti-fragility you spoke about. Why?
Think about the water. Think about the food. These are critical at seed to plate, right? You're disrupting life.
It's that life-sustaining, life-advancing, and life-supporting. And we've got a population of 400 million. You think about the impact to family and lives. It's horrifying to think of what would happen.
The Colonial attack was illustrative of a single level required to shut down an oil and gas distribution operation at the downstream level. And yet, as best as I can tell, TSA still has responsibility for assessing and evaluating our, you know, oil and gas distribution cybersecurity defense and protection levels and abilities. And TSA has no, I think they had six people in that whole organization at one point. It's not just looking through red's underwear at the airport.
If testing our responsiveness, our readiness, and I'll use Colonial. That's a great one, right? So what I understood from the breakdown, a great friend of mine and yours as well, Hector Monsegur. He illustrated that a lot of these attacks, a lot of the adversaries don't actually know what they're getting when they make the attack or how wide it's going to be until it actually happens.
Lowell, Massachusetts was hit. So were several cities across the U.S. with ransomware. They weren't sure to what capacity.
Houston, Texas, Sam, I think was one of them. Yeah. Oftentimes when a thing like Colonial happens, the organization behind it, whether that be the myriad of names out there, right? Twisted spider, lockbit, whatever it might be, right?
With it, there's so many people out there doing this. They don't oftentimes know what they're getting until they've got it. Yeah, a lot of them are horrified to find out the extent to which their reach, how big it is. I mean, most of it, a lot of this is a theoretical exercise or it's numbers that are hard to conceive of when you're sitting in a chair behind a screen.
Even if you're planning these things out at scale and suddenly, you know, there was, you know, most of us were thinking when Colonial pipeline gas thing went down, do they really mean they didn't know what they'd done? But there was a certain air of sincerity in This is what we work with every day, to take that security seriously, to have organizations take it more seriously, because once you've been breached, and I was just a victim of a ransomware attack, right Sam? Lolman, you're paying it because it happened, and what was the process in order to get us back online and get the city functioning again, like it was at the Wild, Wild West, because it was the wild, wild west for four or five months. And we needed systems talking to each other.
We needed organizations talking to each other within the city, and we needed state and federal communicating properly, and we needed to know that there was a plan in place. And so we were still recovering from it, but it's, I think we have to open all lines of communication, and we have to realize that if something like a hospital, a school, food systems, logistics, supply chain, value chain, those can be impacted, and it can cause massive amounts of damage, we got to be ready for it. Yeah, the challenge is to figure out how to get enough attention, you know, it's not a visceral, you know, colonial is not... well, colonial, the impact was visceral, but it ended quickly, and there was no harm, no foul, right?
I mean, people walked away with like, okay, well that wasn't permanent, so I'm all good now, right? And it was immediately forgotten, I think, in mass. But we all know that the threat is very, very real, and no one's watching out for it, and no one is doing anything about prevention, detection, protection around it, in that particular domain. And it's not like rising oceans or polar bears on shrinking, you know, icebergs and warm coastal waters, right?
There's no visceral evidence of an existential threat, but we all know, the three of us know, and everybody in our community knows that this is extremely existential, and that one of these days, very soon probably, now that the lid's blown off in the Middle East, that we're gonna see what nature has to bring us here, and it ain't gonna be fun, you know? I'll open this up to you, Sam, because Steve just made me think of it, and when Colonial Pipeline comes along, and then Monday it's all cleaned up and we spoke about it and we moved on again, right? Steve, as you just said, Sam and I were talking this morning, and I said, Sam, what if, you know, the bad guy's got to be right once cliche, right? But what if each one of these things is a setup and they're quietly getting in, and the adversaries are quietly getting in, and we bust a couple and we don't catch a couple, but they're building up in the back.
And Steve's right, it's building up and building up, and there's vulnerabilities, and there's people entry already in the system within the network. What happens then, Sam? You talked about this this morning, like, OK, wait a minute. Yes, Colonial, but what have we missed?
What already got through? What's just sitting quietly? Sam, you and I work for a company where somebody sat very quiet for several years. They're very patient, right?
Once they're in and wait. So I think there's a couple things here that come to mind. The first is, you got to deal with what you know first. And I know that sounds contrary to what you said, but there's so many things that can be done.
We could be scared by the fiction or the science fiction or the art of the possible for attackers. So we have to keep a close eye on what's possible. For instance, the threat against IoT is really climbing right now. Year over year, it's up almost before X, the number of attacks that we had last year.
So we have to really watch that. We build things that are vulnerable, so we should watch that one. But you allusioned read to what happened to us back at RSA. We can say it.
And to the advanced persistent threat, there is a term that I didn't think was a word at first, optionality. It doesn't sound like a word, but it is. And if you want to Google it, they can. What it means is having choices.
And governments like to have choices, especially in a dictatorship. Like if a dictator comes over and says, you know, what are my options? You don't want to be sitting there going, uh, we haven't really developed any for you, sir. Right.
And it's usually a fighter. And so what you want to do is you want to have developed access and control over government networks and companies that you can then use and provide options for. And so what they do is they do these low and slow penetrations and owning of networks that they can then activate. It's sort of like the electronic equivalent of moles in the Cold War.
You say, okay, we have options for you. And I think that that's what you were talking about. But even that leaves a footprint occasionally, you find them once in a while. And so my original advice to deal with what you see and only slightly in the future, I think is the right one because we can't cover every eventuality, nor should we.
We should be prepared with, with some natural redundancy, things like zero trust, things like minimal permissions, minimal functionality, right? At least privilege type of approaches. Absolutely, right? Good security hygiene, but then deal with the actual threats that we see emerging.
And I wish we didn't make the same mistakes over and over, like building systems that don't have security thought in by design or upfront or privacy. But that seems to be what we keep doing. So that's one of the reasons I like zero trust, right? It's one of those things that even if you built it poorly, you still minimize the access and exposure.
So that's my take. Unfortunately, you go to these shows sometimes, people scare you with the art of the possible. And then you think, I can't cover all those bases. The good news is you make a risk registry, you deal with the things you know to be true and most likely and, or have the biggest impact.
And then you, then you cover your bases and start to build in lower and things that lower risk generally and prepare for when things. Well, Sam, you know, I mean, 95% of the startups in our space in this goes back less than 10 years in my experience have been, the focus is three to five years and out, right? So if I build, if I build a minimally viable product and I can get it out into market and I can get a dozen people to sign up for a year's ARR and I can go raise enough money to build a sales and marketing team and push that product to market. By the time I'm thinking about, you know, getting the UX kind of better and kind of increasing the functionality to what interoperability and yeah, most of those customers, I'm ready to X.
And then the investment community is fully integrated with that thought process, right? So it's like, are you ready? Are you ready? Are you ready?
Wait, one of our startups, you know, I had guys from bank of America literally camping outside my office. I'd show up at 6 a.m. in the morning. There were three investment bankers sitting inside.
So what are you doing here? And so we're going to get you before you got gone. And then, you know, guys from Robbie Stevens show up half an hour later. Yeah, you know, and this band, and it's become the, it's, it's, it's so institutionalized in the cycle.
It's the, it's the Silicon Valley style of building businesses, you know, and you're right. You're right. And so very rarely does a business come along who is in it, you know, for, for the long haul, whatever the hell that means these days, you know? And so while we're doing that, we're not going to build products that, that do what we know they should do.
We're going to build products that do what we think the market wants to hear. So Steve, I got some warning signs myself. So the first thing I'll say is most industries where there isn't an opponent, right? So think of like ERP or office productivity or the things we've seen in the past.
What happens is you get this burst of innovation as they fill in features. And then when they've got them all, you then see a consolidation among vendors, especially when the only thing to differentiate on is price. That's a commodity. So then you get two or three vendors left, and until they get disrupted, for instance, Salesforce.com disrupted the big ERP players, right?
Until something comes along that changes the game. And that's really the introduction of a new differentiating feature that had been absent for a long time. Then, then the game is pretty steady and costs keep declining 20, 30% per year until they get around the cost of manufacture. And then other things become the things that they make money on and put on that platform.
That isn't true in cyber because we have an active component who's innovating, which means new features actually matter. And the problem is that large companies that do this consolidation don't innovate well. And when they're trying to cover all the bases. Now, those larger companies that still have a guiding principle, they can.
But as soon as they turn into that, I'm going to cover one of everything in cyber, then the way that they innovate is by acquiring. And that's the beast you're talking about. So the impetus to innovate to stop the latest threats now goes to the startups. And that's why the VC money flew there.
And so this three to five year, can you get to a two billion exit? It means that first of all, really valuable companies that are doing pretty well, but they're really only worth say 500 to a billion. They don't get enough VC and that's And you're right about those other things. One of the things that drives me nuts is what's our value to the customer?
What's our value to the customer? Has anybody ever stopped to ask somebody what their problem was, what they were trying to solve? And Sam, I like how you, one of the things about this chat that I think is important is that we offer people free, easy things to take away today. What can I go do, right?
MFA wherever possible. Strip limit, prohibit attachments containing things like executables, right? Test your employees. Raising talk of security.
Build security in as a pillar of the business. And you stumme this a lot. Build it as a pillar of the business so that it isn't an afterthought, the bolted on thing you just mentioned a minute ago. People don't even change passwords.
If you could see the passwords that are going around in education is a great example. My kids' passwords on their laptops that come home. And there's no wonder why even elementary schools are getting ransomware today. Averill, Massachusetts got hit.
There was a couple of towns in New York that got hit. Why? Because they'll release information on your children and you're more likely to pay. Steve, you mentioned it earlier.
Hospitals. I mean, that's another thing that they know when they shut the lights off in an operating room, right? They kill the power. You've got someone on the table.
You've got minutes to pay. Pay. And you will, right? So we've got to they have raised the sense of urgency.
Stop pitching products. Start helping organizations build trust with the people in our communities so that they take cybersecurity seriously. Yeah, something like two thirds of all IoT and OT attacks right now come from two botnets, one of which is Mirai botnet. Now the Mirai botnet, it began because it shipped with a default stupid password.
And the fact that it's still here today years later and it is responsible for so many attacks still is obscene. I mean, it's relatively simple for a manufacturer to not ship with a default password, to instead have a unique password scheme, or on upon purchase, plug it in and go through a registration process. We're talking about after the point someone's purchase. You just bought your camera or whatever.
You bring it home. You're committed to the purchase. You plug it in and it says, welcome, let's set up an identity for you. You got even use Google or Facebook or whatever.
But instead they ship with the default username and password that most people don't change in many cases. And that makes it eligible for being taken over and being added to the growing botnet. Yeah. And what do you want to get using it right away, Sam?
Of course you do. Of course you do. But my point is that no one's going to be like, I'm not buying that camera because it's going to ask me to set up an account. You've already made the purchasing decision.
But the shareholders don't care, Sam. They, you know, as long as that your share price is up, it's all good. All right, guys, look, I think we've been at it 45 here and you're saying they've had enough of us. I hear you.
No, it's been great. We could do this for hours as usual. And I want to thank you. And I hope, you know, we're going to continue doing this.
And, you know, whether people like it or not, I do. So they kind of have to have it more. They need more of curry and King hours. Curry and King hours.
Watch the foul language. And I tried not to talk a lot because I talked a lot at CADD. I have a button here that I buzz in whenever he swears. Yeah.
It's a shock collar, Steve. And we never use it on animals, just on red. You call it what you like. But yeah, I get it.
That's great. Okay. So thanks to thanks to Red and Sam. And it was a great session with the Curry brothers again today.
And until next time, this is Steve King, your host, signing off. Thank you for joining us for another episode of cybersecurity insights. You can connect with us on LinkedIn or Facebook or send us an email at social at cybered.io. For more information about the podcast, visit cybered.io forward slash podcast.
Until next week, stay safe and secure. And we'll see you on the next episode of cybersecurity insights.