Good Governance: 'It's All Hygiene' episode artwork

EPISODE · Nov 30, 2023

Good Governance: 'It's All Hygiene'

from Info Risk Today Podcast · host InfoRiskToday.com

In the constant struggle to manage the other five pillars - identify, protect, detect, respond and recover - security leaders often do not have governance at top of mind, said Netography CEO Martin Roesch, but he added, "Good governance is the root of having good security."

Episode metadata supplied by the publisher feed · Published Nov 30, 2023

Embed this episode

NOW PLAYING

Good Governance: 'It's All Hygiene'

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Welcome to Cybersecurity Insights, the podcast for the CyberEd.io learning community. Our goal is to bring cybersecurity practitioners the latest and most relevant education and training to upskill and dive deeper into topics that matter in today's modern cybersecurity world. Good day, everyone. This is Steve King.

I'm the managing director here at CyberEd.io, and today's guest on our podcast episode is Netography's CEO, Martin Resch, who's going to chat with us about the new addition to the NIST framework of governance. And Martin's a repeat visitor on our show, and you can see an earlier interview we did back on a few months ago. Martin's a very well-known guy in the space, has had some remarkable accomplishments and exits, and is now running this company called Netography, which is also very cool. So welcome, Martin.

I'm glad you could join us. Thanks, Steve. It's good to be back. Thanks for having me back.

Yeah, thank you. So let's talk about that, the NIST framework and the addition of governance or govern or whatever they're calling it, and how that presents both an opportunity and impacts the community at large here when thinking about and architecting and developing strategies for cybersecurity defense. Yeah, it's interesting. So governance is the latest addition to the NIST cybersecurity framework.

And it's interesting that they are finally calling it out. I've always looked at the cybersecurity framework. It's kind of very familiar ground for me because it echoes a lot of the thinking that I have had since the early days, you know, kind of late 90s, early 2000s, of when I was really getting going in security and started to interact with people back in the old days in my first startup. And I started to realize that, you know, there wasn't really a basis for kind of a framework that people had to hang their understanding of cybersecurity off of in many cases.

So I came up with my own framework, which is like a three bucket framework, and this framework is a five bucket framework. But it was very, very similar to, you know, considering what I had to do before an attacker showed up during an attack, and after you were compromised and cleanup cycle and kind of configuring your environment properly and things like that. But one of the things that it didn't talk about, and this is kind of interesting, is governance. And, you know, in the old days, I never really thought about it because I was always so focused on threat based detection and response and being able to, you know, see these attackers coming and things like that.

And I didn't really worry about kind of considered to be somewhat mundane, I would suppose, process of having good governance. But, you know, good governance is the root of having good security. So it's really interesting that they called it out in this framework now because it's now a top line item of, Hey, you actually have to pay attention to like what's going on in your environment and make sure things stay on the rails so you can, you know, maintain your security posture. So it's, it's great that they called it out and it kind of signals and sort of aligns with some of my own thinking on the topic as well.

Yeah. And well, you know, it's a heritage or it's a, it's, I guess, I guess that's accurate enough. Heritage is in, is in kind of a, you know, I don't know, boring compliance centric, you know, zeitgeist around GRC and so forth. And yeah, I don't know that Gardner has been instrumental in helping or disabling that any progress in that space, but it's got, you know, compared to a threat, it always sort of pales in terms of what people think about and want to pay attention to.

But yeah, I mean, it's obviously super important and I don't know why it's taken this long either. Well, it's funny, you know, when people don't have governance top of mind, then it kind of slips by the wayside. You don't think about it in a lot of ways. It's funny.

It got back on my radar in the Netography days working with customers and starting to, you know, see the things that we can see with our platform of, you know, being able to recognize things are going on in the environment that are hard to pick up kind of in the traditional ways. Yeah, we do vulnerability management or CSPM in the cloud. And we do intrusion detection prevention or now NDR and GFW and stuff like that. But those approaches are so focused on sussing out kind of, you know, in the kind of vulnerability management CSPM world of, you know, here's how you are configured and here's how you should be configured and giving you kind of this, the static view of this, the snapshot in a moment in time.

And then you have the NDRs and IPSs and NGFWs that are very focused on kind of, are there threats present? What are they doing? Have I been compromised? Am I, you know, enforcing my basic policies on network utilization?

But there's all sorts of stuff that can be happening that nothing is keeping track of. We started to see things like, you know, going into a proof of values, you know, this is like where we do a pilot deployment of our technology and a customer and, you know, we start doing the review at the end of the POV. And it's like, well, you know, your Bitcoin mining is going on over here. And people are like, what Bitcoin mining, what's that doing?

You know, it's a hygiene item. I shouldn't have Bitcoin mining, but what do you, what do you have that's actually going to find it? And, you know, the guys who were doing it knew the answer to that was probably nothing. Same thing with like, you know, Dev talking to prod and in cloud apps and things like that, where you have, you know, CSPM will tell you, Hey, you're configured so Devon prod are talking to each other.

You should fix that. And then you fix it and you know, push comes out of staging back into prod and all of a sudden Devon prod are talking to each other again. And you know, they don't have any real-time mechanism for seeing it. We can see it.

We do see it, but you know, it's all hygiene in that when we put it into our fancy security words, that's governance. Like maintain your basic hygiene so you can have a defendable network. Yeah. And you've you've been in the space a long time, Martin.

I know that, you know, from your point of view, have you ever seen this level of complexity in the past? I mean, you know, no, not really, not as pervasively, like it's everywhere now. We see it so much that we coined a term for it. We call it atomized networks, right?

Where these enterprise networks are scattered across multi-cloud plus on-prem. And it's kind of a result of the pandemic and everybody getting sent home and working from home, being told, you know, Hey, just get your job done. So all of a sudden we have all this infrastructure that's kind of poorly understood and it was poorly governed. It was being deployed because people just had to get their work done and they were working in kind of extreme circumstances.

And now I think a lot of enterprises are trying to get their hands around what happened and what have I got? What is it doing? And what's happening to it on a day-to-day basis and trying to understand that comprehensively and being able to kind of get a day-to-day understanding of it is pretty difficult with the architectures for doing security and governance that we've been using for the last, you know, 20 to 25 years. Yeah.

And then, you know, anytime you've got a no holds barred kind of a movement where, you know, you don't have much choice about having to accommodate a, you know, work from home scenario, then you know, really bad things happen, right? And you know, because people say, well, you know, I can't do it all. I got, if I'm going to provide this, we're going to have to take on some risk. Well, I think that's the, that's the slippery slope we all slid down here over the last three or four years.

And so, but you know, I mean, there's so many tools and there's so many APIs and there's so much, so many applications per server that, you know, it's just, I can't, it's so hard for me to imagine trying to, trying to exactly do what we're talking about and that's govern in, in that kind of an environment. And then, you know, we have severe resource constraints. What are your thoughts about about that? I mean, how do we do this?

Well, I mean, you know, you have to have for me, and maybe this is, maybe this is an artifact of my time at Cisco, but I started to think about it very architecturally, which is, and when I say architecturally, I mean, what do you have that can, or what can be done that can give us the kind of a broad ability to understand the composition of our environments and the activities of the participants within them, both at a coarse grain level of just fundamentally, like, have I got Bitcoin mining going on? Have I got, you know, people running gaming servers? Have I got, you know, all sorts of random apps that are running that nobody knows about. So you know, at a coarse level then getting more and more fine-grained as you, as you start honing in on what you've got, being able to start like looking at the trust boundaries in your organization and whether they're being adhered to or circumvented, being able to see configuration drift happening in real time and things like that.

You kind of, you know, our opinion, this won't surprise you coming from me. Our opinion is that, you know, you actually And which maybe brings us to generative AI, which we may as well say, the last time that you and I talked, ChatGPT either hadn't been announced yet or was just released or something and hadn't gone through that amazingly rapid, you know, beta cycle that it just went through. What's, I mean, in your estimation, what's the impact of that going to be on the sort of, you know, on the standard network and cybersecurity defense environments? Well, that's gonna be fascinating in a lot of ways.

I mean, on the attacker side, attackers are obviously going to leverage it. I think phishing is about to get a lot more fearsome as a result of it, but that's not really my realm. Until somebody gets compromised and goes off the rails. But I think the practical effects in security technologies, you know, we're working on stuff like building, using large language models as a bridge into our products.

So, you know, we have a custom language called Intography Query Language that's built into our product. And, you know, you have to get into it if you want to really be a power user of the product. But, you know, we're working on a bridge right now, so you can just talk to it and it will convert what you say into NQL, the Natography Query Language. And we're also working on mechanisms to look through our event sets and summarize events for you.

And, you know, when you click on an event, it'll give you an English explanation of exactly what, what's going on and what it means and how much you should care for your environment. So that's super cool, right? You used to have to be a total, you know, a real gearhead to really understand what these systems were telling you. But these things are getting us to the point now where, you know, you can very, well, I wouldn't necessarily say it easily, but where it's very possible to have the system explain to you what's going on in, you know, in real human terms and even comparing and contrasting to what's happened yesterday.

So we saw this attacker, we saw, you know, this many of this attack and it's a 47-fold increase of what it was a week ago. And by the way, as a result, or, you know, I should say correlated with that, correlations do not imply causation, but correlated with that, you've had, you know, a commensurate increase in outbound traffic to, you know, some ITAR country or something like that. Like having having the AI's kind of put the puzzle pieces together for you, I think could be really powerful. And, you know, we're certainly delving down that path to a degree with our approach.

Yeah, I know the upside is fantastic. The downside, however, is, it's very frightening, right? I mean, you've got people today, I mean, that have not made a policy decision or have not implemented a policy within their companies about the use of ChatGPT, for example. And every time that, you know, somebody does, they're creating their own sort of shadow IT risk center and sending data out into this, you know, very public large language model that may or may not contain customer information or what have you, right?

I mean, so not only is it, you know, is it the risk of both ingress and egress poisoning, but it's also huge privacy liability as well. And, you know, I'm just amazed at how our government officials act as if this is all safe stuff and it's no big deal. And one of the congressmen, I saw one of the congressmen make a comment that, you know, there's no, you know, it's not a real danger here. So I let my staff just kind of do whatever they want with ChatGPT.

I almost fell out of my chair. Yeah, yeah, I disagree. I mean, yeah, so we use the commercial-grade stuff, you know, we're in AWS and things like that. So we're using like the commercial-grade tools.

So it's not out to public, you know, ChatGPT and stuff like that. But it's a big problem, right? If you try to ban it, people are probably gonna use it anyway. And it gets to be, yeah, there's all sorts of problems with data leakage and exfiltration and things like that.

And also, you know, attackers are gonna figure out how to use these tools very capably. And just the downside risk of a lot of this stuff is pretty high. And, you know, obviously there's not a lot of understanding. There is a strong thread of, you know, we've got to figure this stuff out before our kind of geopolitical adversaries do, which is, you know, I think not wrong, but I think, you know, just blithely saying, no, it's all good.

You know, we should just use it freely and not worry about it is probably, probably not the play either. Yeah, I, you know, I hate to be the cranky security guy, but there's a cranky security guy in me always that's like, do you really want to hook this up to the internet? And, you know, that's doesn't get any better when it's, let's send all this data to this AI. I think we need more cranky security guys.

I don't know what happened to the ball. I remember when I was Dr. No, you know, yeah, but recently it feels like, you know, we've all turned into, yeah, sure, it's okay, whatever. That, you know, those are problems we're not gonna solve and that, thatography doesn't try to solve either.

But what, what to remind our audience, so back to Natography, what, what the major benefit to a company that uses your technology solution? So Natography is a network defense platform. And what that is, is a cloud native network analytics platform that can tell you what you've got, what is doing, what's happening to it across multi-cloud and on-prem without having to deploy anything to make it work. So we can tell you about compromises.

We can enable threat hunting. We can enable governance, which is obviously the topic here by letting you see kind of operationally what's going on minute to minute. So we can see things like configuration drift happening as they happen. And, you know, getting back to the, the problem, the post-pandemic problem of your atomized network tell you, you map out your network, let you know what you've got, what is doing, what's happened to it.

And do so continuously in real time with an architecture that is scalable because we don't have to deploy anything to make it work. And we operate cloud scale in our backend. So it's, if you want to understand what you've got, if you want to understand configuration drift, if you want to see compromise happening as it happens, if you want to be able to dig into it, that's, that's what we're there for. So from the governance topic of, you know, that we're talking about today, seeing things that you will see no other way because you have no way to look for them and seeing them at scale across your entire enterprise, which is, you know, scattered across all these different cloud companies as well as your legacy on-prem infrastructure, that's what we can do.

Yeah. And then why would anybody not want that kind of observability, if you will? What kind of pushback do you guys get? I mean, why wouldn't anybody say no to this?

Well, you know, when we do get pushback, so the other piece of it is that we can actually control as well. So we don't just see things. We have the ability to reach out and touch them or work with the security infrastructure or whatever. But, you know, you have a lot of people that are on the legacy architectures that are hard to get out from under to some degree.

So whether that be the legacy network monitoring tools like a StealthWatch or a Plixer or even a, you know, stuff like the old IDS with IPS is like I used to work on NDR. Those are all kind of architecturally obsolete. They have, they have their applications kind of from a point standpoint where I've got a very high value asset that I need to defend in a very particular way, but they have a really poor TCO metrics relative to something like us. And I think we're still showing people and convincing them of it.

And then, you know, then they've got cloud monitoring tools that are looking at their kind of what's going on in the cloud network environments that are almost all data lakes where they're just dumping data into a data lake and doing reporting and dashboards. We see things happen in real time. You know, we are very unique in that we are a real-time engine operating at the scale that we're operating across, you know, all this stuff. So when people say no, it's usually because either they've got an investment that they're not ready to part with yet, but I think the writing's on the wall for the kind of the old school way of doing things or they, you know, they're just not operationally prepared to take on a new tool.

And of course, there's all that, the budget scrutiny that's going on right now. And I think one of the things that we're really getting ramped up for now is to really show people the total cost of ownership TCO advantages that we have of this approach relative to the older architectures that don't scale, that are very narrowly focused in that really are not well-suited to the world that we're in now. Yeah, budgets should never be a reason to preclude advancing our position here against the inbound threat, particularly in light of generative AI and the bad guys will and are already, you know, using leveraging the heck out of that. And as you had indicated earlier, phishing attacks will, the old phishing attack will become suddenly really elegant and amazing and nobody will be able to tell the difference.

And that's true for

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on November 30, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!