Episode 358, talking about security and the usual fun and excitement with Patrick Garrity episode artwork

EPISODE · Aug 9, 2020 · 1H 38M

Episode 358, talking about security and the usual fun and excitement with Patrick Garrity

from IT in the D

What is up? Thank you for hanging out with us. Once again. It's money night. It is time for the it in the D show. This is episode three 58 broadcasting live from our quarantine homes. This is Bob, the sales guy that is Dave. The geek Randy. I do the Twitters is doing the Twitter, his finest online it in the D dot comma. Do us a favor. Give us a like on the socials and subscribe to us everywhere. Fine. Podcasts are sold. Yeah. So, Hey everybody, I'm again, this is usually where we talk about our events and we're still not having any, so moving right along Chicka boom, Chicka, boom. He's a looking, I do not anticipate in August of any, even if it is outdoors.     Yeah. It's yeah. I mean, looking at everything going on. I mean, I'm keeping an honestly, I'm keeping a closer eye on what's going on, what door what's going to go on with schools right now, more than anything else. Um, but it's uh, yeah, I I'm, let's just say, yeah, it's not looking good. No, but the show must go on. And now we are joining where luckily joined. We were, we had him scheduled out right. When the suitors were still open. We had to come. I think this was back in March or April. Oh, that's right. Yeah. Yeah. And he's shot me a note and said, Hey, I still want me on. I said, yeah, it's not a bad time. So, uh, we're joined by the, uh, the illustrious one. Mr. Pat Garrity. How you doing, sir? Great. Thanks for having me on the show today. Yeah. Thanks for joining us. Appreciate it now. Um, before we get into it, now, you're the VP of engineering at blue Mira operations, operations. I oversee product marketing sales. Got it. I mean, do everything, whatever needs to get them Every, uh, every once in a while we run into, I run into someone at an event. They basically takes over my LinkedIn feed and I like to congratulate you on my LinkedIn feed. That's great to hear. Hey, it's not, you can attribute that. Not to me too, is a amazing, she does content marketing for, for a, I almost said duo, but blue Mira. Um, and, uh, yeah, it's been amazing. The work that she does and also like our security team is creating a ton of the content as well, and trying to make useful stuff for people, uh, in the security industry. So, so you're just putting it all out there, trying to look important and smart is what you're saying. You're not actually creating any of it. You're just, Yeah, I can't, you know, some bit idea wise, um, pointing people in the right direction, but yeah, the team, the team is truly the ones working on that and publishing some cool stuff and some free tools and whatnot. That's awesome. So one of the reasons I was intrigued about having you on the show is a, that I think blue mirror is doing some very cool stuff. And B you kind of have a long history with, uh, you know, with duo, which is kind of a, one of the big, big wind stories. And, you know, and see, I want to talk about what everyone is. Is there a shift in security focus with, with everybody working from home now and, you know, you can kind of reassess your place in the world. So I guess let's start there if your, your, your company X, and you've got half your company or all your company working from home, and you can kind of sit back and look at your, I guess, security strategy. Are you changing right now? Or are you simplifying, are you getting more complex? What what's on everybody's mind right now? Yes, sir. Certainly simplifying, um, is one of the big themes. I think everyone had these ideas of three to five year cloud migrations, um, moving from on premise to cloud. We see that everywhere. Uh, it's essentially accelerated adoption of all of that. And the reality is, is, Oh man, we didn't have security controls in place. And any on any of those things, we weren't set up for remote work. And now all of a sudden our VPN, you know, has a thousand people on it concurrently smoke. Yeah. Yeah. So, so even, you know, I look at it, it's like even a lot of people still don't have two factor authentication deployed. I mean, as simple as that, uh, very effective control, right? So it's accelerated a ton of the security market. That's set up to address a lot of those needs. What's the, uh, just real quick, like to IFA, whatever, if somebody wants to jump in and you know, what are you gonna look at? You're gonna look at Microsoft. You don't look at duo. What's a, I mean, that's kind of, what's on my top of mind. What's on yours. Yeah. So, so being former duo, um, I could say that, that I might be a little bit biased, but I can tell you, yeah, I can tell you as well, now that I left you, I'm using a lot of other products. Um, and what I can tell you is they work effective, but they're not as reliable or user friendly. And so I, you know, there's some products, I'm not gonna name names that like they're inconsistent and popping your log in up. You get frustrated as a user. Um, and so I can, I can with confidence, say like duo by far has user experience down on the MFA side. The other thing I'd say from an access security side is they have some really strong controls around access control, as it relates to corporate owned devices and BYOB devices, where now they have an agent that can be installed to posture that device. That's a really important thing to make sure things are up to date encrypted. And that there's a screen lock, especially when we're talking about someone using their home computer and making sure it's not windows XP. Cause the reality is there's still a lot of people running windows XP. Um, so yeah, those are the things I think of from an access security perspective. And then what's interesting is I spent most of my time on the two FAA side and, and protection, right? Preventative security measures. The other side is, well, how do we detect someone at bypasses? Those which happens everywhere. Um, in, in, you know, the detection response market is one, if you look at SIM, for example, it's complicated, it's difficult to deploy. And to be honest, most organizations don't have a good working detection response capability. So, uh, yeah, for me, I just saw the opportunity to actually extend some of the, you know, philosophy of what I learned and did at duo with Doug and Jonno and others and apply it to a different part of the market that really hasn't solved. Um, what I consider to be democratizing security or bringing it to be accessible to organizations of any size. Right. Yeah. I was just gonna say, I mean, you know, and I know Bob touched on this a little bit, but I think that's probably the biggest, I would think the biggest concern that people have right now, at least from a corporate security perspective is okay. We, we have completely stood everything on its ear and now you've got, you know, more and more of the workforce working at home. How, how do you, you know, make that shift? I mean, I know there are a lot of companies that, you know, we're kind of banging their hands and chews on the table saying, you know, we're, everybody's coming back to the office and now they're kind of leaning, you know, they're kind of laxing off on that a little bit. Um, you know, you're seeing, you know, the, just the ripple effect of, you know, Hey, the, the court, the, uh, excuse me, the, um, commercial real estate market is already starting to feel it a little bit as businesses are giving up their office space and looking to sell buildings cause they don't want them or need them anymore. Uh, so I mean, what are, I guess, you know, what are the quick hits from a, from a corporate security standpoint, as you know, they get pushed into that scramble. Yeah. So first off, I would say from a shift in market perspective, one thing to consider is people's preferences now that they've worked from home is to work from home. So work from home is not, is not going away. I'm not going into a office, whether there's covert or not, I'll tell you, you know, maybe I might consider every once every other week or a few times a week, but yeah, we proven that out. And another thing is, as people realize they're more productive working from home and corporations realize that as well for good or bad. Right. Um, uh, and so yeah, there is the aspect of making sure that your people have enough time to take care of themselves. They get offline, all those sorts of things. Um, but yeah, really from a security perspective, it's making sure that they have a secure connection in a secure device. Our number one, um, you know, so I, when I look at that, it's, it's, Hey, let's make sure we have certificates in place. We have encryption in place from a connectivity perspective. Like you shouldn't be already peeing into, uh, your company's, um, windows servers directly, but you know, how many people, But a lot of people are. Yup. Yeah. If you have already, you know, windows already, peer SMB enable, then it's accessible publicly. Like that's a bad, no, no, that's the number one way ransomware is deployed. Um, and so yeah, just getting the fundamentals of like making sure that you have secure access, whether it's to a, uh, or whether it's to a cloud application and then layering on number one, uh, user controls and then device controls to make sure you have that. So, uh, two factor authentication, absolutely key, no questions asked, um, pro preferably you use a hardened credentials. So something like YouTube, Fido, web authen push based authentication. Let me, let me take a step back just for, you know, cause we do, we do get our demographic. Isn't always as techie as we think it is. Um, so, so for those of you who are watching, listening, whatever, and aren't familiar with two factor authentication, so that's, you know, it can be as simple as, Hey, I'm logging into my Facebook account and Facebook shoots me a text message that I then have to, you know, with a code that I then have to enter, you know, this is okay. Yeah. This is me. Um, there are other apps, you know,...

Episode metadata supplied by the publisher feed · Published Aug 9, 2020

Embed this episode

NOW PLAYING

Episode 358, talking about security and the usual fun and excitement with Patrick Garrity

0:00 1:38:06

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of IT in the D?

This episode is 1 hour and 38 minutes long.

When was this IT in the D episode published?

This episode was published on August 9, 2020.

Can I download this IT in the D episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!