How to Win a Cyberwar: Use a Combined Intelligence Strategy episode artwork

EPISODE · Feb 6, 2024

How to Win a Cyberwar: Use a Combined Intelligence Strategy

from Info Risk Today Podcast · host InfoRiskToday.com

In times of conflict, such as the Israel-Hamas war, intelligence becomes even more important than it is in peacetime. Red Curry, chief marketing officer at Tautuk, and his brother, Sam Curry, CISO at Zscaler, discuss the need for a combined intelligence strategy and better resilience in wartime.

Episode metadata supplied by the publisher feed · Published Feb 6, 2024

Embed this episode

NOW PLAYING

How to Win a Cyberwar: Use a Combined Intelligence Strategy

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Welcome to Cybersecurity Insights, the podcast for the CyberEd.io learning community. Our goal is to bring Cybersecurity practitioners the latest and most relevant education and training to upskill and dive deeper into topics that matter in today's modern Cybersecurity world. Good day, everyone. I'm Steve King.

I'm the managing director at CyberEd.io and today in our podcast we have an amazing pleasure of having the Curry brothers with us, Sam Curry from Zscaler and he's the CSO there and it's a long history of success and amazing accomplishments in the Cybersecurity space going back three decades as he likes to say. And his brother Redtree who's the CMO at TonTech and they're a kind of a startup early stage company that tracks my favorite thing which is ground level electromagnetic pulses from devices in OT security environments so that the things that the standard network monitoring systems can't detect can be detected. So welcome both of you guys. I'm glad you could find time today.

Yeah, so people can tell this part that this is Sam, Red, do you want to say something? Hi, I'm Red. Sam Curry's brother. But so people know Red and I have cyber experience and Steve, thank you for that awesome intro but what people may not know is that in addition to that Red has geospatial intelligence in his background uniquely and I also have a graduate working counterterrorism and I think people just know that those are additional things they may not otherwise know about us because we usually are seen in the cyber lights.

Yeah, sure. I usually talk about that quite a bit but you're right. Generally speaking people wouldn't know that. But the counter-terrorism stuff is super important to the topic of the day which is how kind of, you know, we're trying to explore what we can based on the actual day today which is Monday, what a week and three days following the attack on Israel.

How did that happen, I think, is a question a lot of people want to know. Israel's amazing capabilities in cyber security and yet it appears on the surface that, you know, the intel that they were using wasn't or weren't being used or what have you. Do we know anything more than what we see in the mainstream media? I think it's important to say, by the way, that neither Red nor I have any special insight from the idea for any intelligence organizations like that.

So I think I mentioned that because it's not like, it's not like we, oh yeah, it happened this way and we know. It's still very, very close. You said it's a week and a few days, we can two or three days. But and the reason I say that is because time will tell.

We will see post-mortem or post-mortem whichever is correct, plural. Facts will come to light and it would seem like it was, and the reason I mentioned Red's geospatial background is it would seem that people played the classic playbook from a field-craft perspective and it seems like it was more than just Hamas in play, but we don't yet know outside of intelligence agencies and certainly the war rooms, literally war rooms in a number of countries. We don't yet know which nation-states, which logistical supply chains and so on beyond what is being said in the press at this point. Red, did you want to have anything?

Well, other than you're right and keep moving every single minute, you can hardly keep up with what's going on and I don't think there's a place where anybody missed or failed or dropped the ball necessarily, but Steve, you and I talk often in the past about holistic approaches. We mentioned geospatial, we mentioned counterterrorism, we mentioned cyber security. I think we have an opportunity here to start bringing in different technologies from different spaces and places and have them better talk to each other so that verify what's happening on the ground in real time as we can verify what's happening in the cyber world. And really, I think, Sam, you and I talked about it over the weekend, having an opportunity with human to understand sentiment, to understand the temperature of something in an area, a place with a cafe, whether it's a store, a mall, a shop, whatever that might be, and you add that to the technology that we're using to understand the threats that we face.

It's not just a cyber approach. Steve, you and I have said it before. I've got to bring a holistic approach to these things if we're going to catch the things in rapid time and be able to verify them and support them. Yeah, Steve, this is super important.

When I was a human team in human intelligence, it's an abbreviation. There's also a lens for electronic intelligence, mass and physical intelligence. Those are all the ints, right? So, just like we used to talk about combined arms in warfare, where if you can get your infantry and your armored units and your area units to work together in concert, it's greater than some of the parts.

I think where Red's headed with that is that if you can get a combined intelligence effect that it's greater than some of the parts. Now, imagine you were in a Hamas. We think of them as in the Gaza Strip, for instance, but what if there were two, three, or even four countries, intelligence units at play with all of the various ints? I'm speaking hypothetically here, right?

So, what comes out, either what becomes clear behind closed doors or what comes out of the public eye, is why it tells a lot Steve over the next few weeks, months, and years? Yeah, well, it's pretty clear to me that when I say Hamas, I mean Iran and these aren't lightweight folks. These are really capable people and there's a lot of capable intel behind all of that. So, that doesn't surprise me.

What I find interesting, though, and to what your point is, is that we have a lot of sort of subsets of data collections around physical, geophysical, cyber, digital stuff on events like these. But they never sort of come together in any holistic way where we can elevate that mass of information to a level where we can say, here's a corpus of data that we can, we've parsed out to these five things that are critical about this. This is the thing that we should have done, that's why it happened, we can trace it back to, et cetera, et cetera. But I'm unaware of that capability if we have it today.

Steve, there's always a fog of war. So, you never have a complete picture. You're always acting in an imperfect information environment, certainly in real time. And the funny thing is, and I shouldn't say what funny, actually, the thing most people wouldn't expect, the thing most people wouldn't expect, maybe the more accurate way to say it, is that not only do the pictures determine history, there's very rarely a complete picture that comes out of the public consumption.

Often these things get hidden behind. The special secret acts, or they're still classified because they still affect current operations. And so, it's usually a, what do we know and what can we infer right now? Occam's razor gets applied, and as with most racers, people get cut very often.

Yeah, sure. At the same time, we have visibility into stuff that we kind of should have known about. Right? I mean, I'm not referring necessarily to the Israeli defense system.

I'm referring to, you know, even like open source intelligence and things like that. Yeah. That's what you're referring to. I'm referring to DNS vulnerabilities, for example.

We're rampant across our landscape. And yet, we don't do anything about it, because I don't think anyone understands it. And we don't consider it a real threat somehow. Well, humans are very poor.

Risk assessment. Creatures, right? We're not good at it. We're all poor.

It's funny. I was told once, when I was first managing a corporate budget, like it's your own money, I said, don't ask me to do that. Like, really? Yeah.

Far worse than my company. But this is why processes matter. This is, and there's always a certain shock that people go through when these events unfold. And this is why practicing.

Let's take out the physical context here in the events of, oh, we can have a go. This is why table talking matters. This is why practice matters. This is because what happens is we habituate ourselves.

And there was a study done, and I'll try and find it after this and find the reference for it, but those who had been through a disaster and survived a crisis tended to do well in future crises. And it wasn't just because they'd been through it once. It was because they could think about these things and gamed it out in their heads. And when you do that, you still suffer a fight or flight, but you are more likely to respond and not sit and loaf.

I think there was a famous case on the runway at Tenerife when two planes tragically collided. And some people got up and got off and others were telling them off for it. And those who got up and got off survived. And I'll try and find that link.

I know you're dying to say something. You guys are both maybe think about, Sam, you and I talk about unified reality, right? And we talk about holistic approach. I think times tangible realm and the digital domain for a full understanding.

I mean, you table pop exercise or you find processes and you bring complete solutions to the table to help us do that to see it. There are three things I've thought about, right? We use comprehensive ground truth, the combining of geo intelligence with cyber security. You get an understanding of the physical and digital discourse, the physical and digital discourse.

You go beyond borders with that kind of a solution, right? You can play that out. What does cyber intelligence and geo entail together specifically? They differentiate between internal sentiments and external manipulations.

What you're seeing unfold every day, Steve, you said in the beginning is it's happening minute by minute. Things are changing so rapidly. How can we speak about one thing now to be different in an hour? Well, that's one of the ways we can do it by being in those different places.

And working through those same your tabletop exercises. Anti fragile intelligence means that we combine the side by technologies and the geo in the cyber, not only detect disturbances, but verify, adapt and strengthen those infrastructures when sensitive regions. Does that make sense? Of course.

And that's what you described, Sam. That's the whole principle of anti fragility, right? And yet I don't see any movement there in our industry that tells me we're on the right path here. We're still stuck back in, you know, I don't know, trying, you know, making excuses for why the best we can do is resilience, you know, and that's a terrible position to begin from my point of view.

I think we need to be far more aggressive about, about figuring out a way to make these systems truly anti fragile and then leveraging AI and ML to get there. Yes. See, the devil's in the detail though, right? Because we tend to think of, you know, A plus B, the best of A plus the best of B gives us everything, but these things very rarely just come together and work.

And I think they never do. It's always an effort. There's always integration. There's always a refinement of tuning unforeseen consequences.

Always tech that in these things. I mean, that may sound defeated, but there's always the devil's in the details of these projects. And they're in order to get them right. You've got to get the operations right.

The bigger the scope and the more complex the harder it is to do. Now, if you're in the destructive business, you just have to break it. And so, you know, this requires a constant attention on the part of those trying to build things and defend things to be doing the chaos monkey thing and chaos engineering and saying, what happens if a piece goes away? What happens if a piece breaks?

How can that survive? But that takes energy and that takes leadership and it takes leaning into it and frankly making a pain for people every day. And that's hard to do. And it's hard to do.

Now, actually, what Red was talking about as well is this notion of, look, everyone has a view of reality. And the one that is most effective, most quickly, to get results is the one that will win. And we have so many different forms of intelligence that can come together well that if they did, we would win. But it takes effort to bring those together.

And it doesn't take anything like as much effort to tear stuff down. Now, what's interesting in this most recent example is clearly there was operational excellence and tradecraft in pulling this off on their side. And that is a new degree of sophistication from this actor. Speaking on speaking from my graduate work site rather than my professional work site, that I think is surprising to the public at large because this is not what we would expect from them.

Yeah. And I'm setting aside the optics and bringing it back to the challenge here, which you're your spot on, obviously. The only problem is I see no evidence of anybody taking a leadership position around this. It's easy to say, hey, it's really hard to do.

You know, you can't get these. We're really shitty at it. I know that. What was it?

I'm going to parrot it. It's just better than all those other ones. Yeah. Well, we have to be better.

We have to be better than that. These actions are not only deeply concerning, seriously disgusting. It's a global issue. And you're starting to see things like misinformation.

You'll see other groups in other parts of the world here in the US, false flags. You know, and say, I may have not even said that. You're fine. But I look at these groups and I'll use all right, white nationalist groups as an example, right?

I don't have to list them. We can get that online. But it's highlighting a problem that's not limited to one region. And Steve, to your point, if we're not ready to tackle this and really collaborate together among different intelligence groups, companies, organizations, across government and public and private, then we've got big problems coming.

So we've got to change the way we behave, stop valuing the product, start valuing the solutions and how you deal with other organizations. I'm really tired of hearing that we have an NGA and an NSA. And what I want to hear is both of those groups working, and I'm not saying they don't, working concert together to solve problems so we can feed each other that into them. And maybe they are, but I want to see commercial companies do it.

I want to see cybersecurity companies reaching out to different types of organizations to build stronger, better, broader, reflecting the values of the place we live, right? It's crucial to address it, and we have to do it in a comprehensive sort of, if we're going to protect and save lives, that's how we do it. The funny thing is, though, that I really want to inject two things. The first is certainly in the United States, we have to be very, very careful of fundamental rights.

Privacy is one thing, but constitutionally, the right to free speech is very important. It is actually not illegal to engage in hate speech. It is illegal to threaten or to coordinate attacks and those sorts of things. You have every right to, in fact, say nasty things about people.

That's always true in other countries. So understanding privacy, understanding what people's basic rights of the Constitution are, and protecting those are important, however red the rest of which you said I completely agree with, so we have to keep an eye to that. This gets even more difficult when you deal with things internationally, and those things take time to work out because different countries have different rights, especially privacy rights as an example. But I would you want to mention, I said counterterrorism, but there's another phrase, which is politically incorrect in some circles, and in others is very powerful, and that is the notion of countering violent extremism, CDE, it's called, and that is trying, once somebody decides to go and commit terrorism or cyber terrorism, which is actually a thing, once they decide to do that, it's very, very hard to stop it.

It usually requires a hard or military response because they're already in motion towards a target or about to carry it out. They're already effectively been radicalized. And so what we do is we look upstream from that, meaning what are the factors that drive someone to be radicalized, either pushed by society or pulled by a radicalization to public ISIS? ISIS used to have videos that they would try to entice, first of all, the videos they sent out to the West, which were horrific, right, because what they were trying to do was scare and create terror.

But the recruiting videos were things like ice cream, socials, and sing-alongs, and you'd think, huh, here's a place I can go, and I will be accepted, where I'm not accepted in a place I'm at right now. And this requires a dialogue with the targets for recruitment, so that they don't get radicalized. Now, somebody living in Gaza Strip is an ideal target for radicalization. That's a slippery slope until you're thinking about committing terrorism with a lone wolf or with a group.

The same is true here in the United States, right, that you were just talking about. This happens, but it is imperative that that first point I made about privacy and our fundamental rights as a culture be followed, because if they aren't, we become hypocrites when we try to put out a counter message to what the terrorist organization is. If the terrorist is sick, for instance, white nationalist paradise, or left-wing or right-wing paradise, you know, or jihadist paradise, or by the way, paradise, because we're a Christian terrorist, so I just want to put it out there. It's not any one group, and that's very important.

That message can't be countered by being part of a democratic pluralistic society when you're part of a secondary class of citizens, and your privacy rights are downtrodden and they're a secret policeman. So I just want to mention that because it's a lot to digest. Steve, did that resonate with you? Yeah, sure, but you characterized most modern quote democracies today, too.

That is the direction we're all headed in. We have to look at ourselves. Yeah, exactly. And the thing again, we've been talking about this a long time, right, and trying to defend against these things for a long time, and you must admit that the curve has changed.

The trajectory is much more aggressive than it has been in the past, and where does that end? You know, it ends badly, I think, right? I mean, you know, it's been, you know, a breach here, a breach there, but pretty soon it's going to be critical infrastructure. You know that.

You know that. Oh, yeah. From our adversaries around energy and electric grid and water. But you're right, because you know, during the ISIS states, right, 2014, 2015, 2016, tens of thousands of people were trying to get to Iraq and Syria.

They were trying to get there because they were recruited online. So I mean, the Internet wasn't just a tool for attack, although it has been used for that. It can be done in concert, so we talked about combined intelligence. It can be done now as another tool of war and combined with other things.

It was also a tool of recruitment and radicalization. And people from all over the world went to Iraq and Syria in order to try to join up with ISIS, because there was this vision that was put out there and they were pulled. And the UN passed a resolution to try to prevent that, and almost every country made it illegal during those years to travel. And they had to do that because people were trying to.

And so the Internet now is this. It almost hypercharges the ability for radical groups, not just jihadist groups, but political groups. It was called racially motivated violent extremism, R.M.P.E. politically motivated violent extremism.

P.M.P.E. Those groups also engage in this recruitment online and social media. This is the highway to recruit. And I have to think about it, Steve, because it comes down and says, right, I want to reemphasize what he's saying here, because it's very important.

It comes down to families, people, mothers, brothers, sisters. It's communities. Businesses have to stop talking about it like it's business and governments, like it's government, start talking about it like these are real people on the ground. And so to reiterate, look, we're not talking nations.

We're talking non-state actors or terrorist groups, Hamas, and increasingly acquiring these offensive cyber capabilities and exploiting asymmetric advantage of cyberspace. This is a non-state actor, right? This includes little ransomware gang groups that we face. I was just breached, Steve.

I just had a, I didn't know what I had a chase card open to my name, and cash advance was taken. And here I am sitting here as a cyber guy slash whatever, and going, how did this happen to me? But it's terrorist organizations throughout cartels. They're posing a challenge for the United States and our allies.

That's it. And these are not nation states. So it's very hard to combat them. Terrorist organizations that Samsung, they rely heavily on Internet social media for recruitment, fundraising propaganda.

And the US and our allies have to take steps to counter these activities. But there's limited attention given to these groups, right? Offensive cyber physical capabilities. They can influence public perception, political events.

And what's important to note, I think, from what I heard Sam say, and I really liked it was, it's developing offensive cyber capabilities along traditional tactics. If the bad guys do that, why aren't we using the traditional tactics of old? Sam, you and I talked about it, the old days of the old spine movies and the old spine that we need more boots on the ground, the traditional tactics work. Did we give up on them?

Did we rush to AI? Did we rush to ML? Did we rush to do? We're rushing to these things and forgetting what worked in the past.

Like the creation of the path, because the question I've had for some time, tell me if this doesn't make sense, right? Why did we? Why did we forget our past and moved? Oh, new technology, we don't have to look there anymore.

The shift highlights a trend of non-state actors. They're integrating cyber tools into their existing arsenals, right? With some states, Iran and others, state support. So we have to reevaluate what we do and make sure we don't forget what got us here.

So when Red says rush to AI, he's not saying we shouldn't be doing AI. What you're saying is, our love of technology and sitting at the desk and doing analysis in a thinking mode has sort of de-emphasized the importance of tradecraft and being in the field. You know, it's a walk through an area with a telephone, a state telephone with a mobile phone, the cameras on it. And the sounds recorded in MassInt, by the way, I mentioned it earlier.

So I'm putting it out there because I think people will be interested in hearing it. MassInt is recording of sounds from the world around us, but for example, industrial machinery. Such that if you receive, for instance, a ransom in our video or recording, by the background sounds, you can identify where it is, a helicopter engine, a piece of machinery in the background, because all of that has been indexed in an audio database. Now, if you go by the way, I agree, but to get that, you have to go there and you have to pay people for that, or you have to send out agents to collect that.

And there is no way that people are going to mount an invasion with that invasion or successfully defend an area if they don't have that, or let's say they won't be as successful if they don't have that, what Red Called Ground Truth information earlier. It is the first-hand information collected the hard way as one of the cornerstones of a combined intelligence strategy. Sam, I've got to say, far something sorry, Steve, but it's so amazing because what you've just said is, it helps us understand, is that hotel, a hotel, is that hospital, a hospital? How many steps to the window?

That window is that door door, and it helps us understand that. So that intelligence feeds back to the mission on the ground, and that's to get people home safely, that's to save lives, that's the focus of that intelligence. And if you have that ground truth, you know, the sentiment. Or is Hamas, I think, a hostage of a hospital, where they're firing a missile from?

That's a good one. No, no. And ISR can't do that. So the satellites are great.

The ISR drones are great. These are all great, but if you don't have the eyes on the ground and actually have somebody who supports and understands the sentiment, who can actually relay that back to you, you really are missing a huge piece of that pie. Yeah, and actually it's a combination of both, rather than just one or the other, you put the two together and it's more powerful than you throw cyber in as well. And you're in a whole different world.

For instance, in our cyber domain, my most of my career, most of my job is spent in cyber, right? For the most part, we don't bother with attribution, except in research, because it doesn't help in real time and you know you're not taking these people to court. But if you could bring in the context of the physical ints, some of that could tell you some really important things, especially, let's not talk about hackback companies, but if you're talking at the nation-state level, what's happening in Ukraine and Russia, that could actually be meaningful within the technical infrastructure. The IDF has been doing that for a very long time.

And if you go back, you can see they've been tweeted about it. So yeah, is this helping Steve or are we off course? Yeah, all of it's helping. Of course, you know, I think there are many people around who are respecters think that we've spent a lot of investment, both calories and money on on offensive security and surveillance security as a nation, right?

That we spend more time trying to figure out how to listen in, to watch people to get ahead of the inbound surveillance books on the adversarial side. And we haven't spent very much on defense, I think. And I would agree that's true. The other thing that brightens me maybe the most is when I look at Israel and their response to what happened here is, you know, you get all bunch of people who are very much similarly opposed ideologically within the country, very similarly to the United States today.

And yet that event brought them all together. And they all kind of rushed off and said, hey, you know, whatever, and whenever, and here I am. If that happened in America today, I'm not so sure we would do anything similar to that. And I'm not so sure to your point, Sam, about, you know, sitting in our destiny, you know, political work and being smart about this stuff.

I think that we are dumber now, generally not a people sitting at the door. Oh, I didn't mean they were smarter. I mean, that's a really, well, well, no, I think it runs our realization. I think we are smarter, but I think that there are fewer of us who are actually able to do that.

And that doesn't mean that I'm any smarter than the next guy, but I have the opportunity that the next guy might not have. And we have a lot of walking around, you know, dumb looking folks who think, you know, feasting on the stuff we feed them, we, meaning the marketing machinery that runs the consumer business here in America, and, you know, cars, manufacturing consent type of way. You mean like manufacturing consent to, you know, Chomsky or you mean something else? I have to poke a bit.

Is that what you're referring to? I'm referring to reality TV and to the kind of consumerism that is easy and plays so well to the kind of intellectually lazy crowd. And I don't think we've got the capability actually to respond in the same way that Israelis will respond to this attack. And that worries me, right?

It worries me also because I don't think our government is organized the same way as the Israeli government is organized around a central kind of whole cloth response to this kind of effect. And I think within the next 24 months, we'll probably experience a direct attack by our adversaries. I mean, why wouldn't we? I mean, if they, you know, if you can do what they do with colonial, if you can do what they do with that, with the meat distribution company, you know, they've proven they do this all the time, right?

It's like three or four of these. Yeah, it works. Okay, great. It's limited.

I think not that it was supposed to be limited to, but, you know, food and it's kind of like, hey, you know, whatever. So I have to, I mean, take issue with a few things, but with all due respect, because I actually respect what you're saying. I think we've always had a strong strain of consumerism goes with having a capitalist society and marketing rate, but I think we've always risen to that challenge. The question is, will there come a day when that doesn't happen?

Yeah, Pearl Harbor, 9-11, what have you. We tend to respond when kicked in a unified way now, whether the echo chambers and polarization of our society is going to make that, I think, in the past, I don't know. But Sam, Pearl Harbor, Pearl Harbor is very physical and are responsible, very physical. It's easy to pick up a 16 and fire it.

Well, it's not going to be a different rifle, but yeah, but I'm actually, I'm actually thinking now exactly that. These are not parallel examples. What happened in Israel is not how it will go down here. Israel has a fraction of people in a very different military oriented around a different set of ideas and the invasion.

It's not like we would get an attack out of Canada or Mexico, for instance. Now, we could get a physical attack, absolutely. You're mentioning a colonial pipeline, that now that, if that was intentional and if it was amplified and if it was coordinated with other things, it could be very bad. But actually, there is coordination among various parts of the US government, like fusion centers, for instance.

Are they ideal? No, to our point earlier, they could be much better. But then we have the notion of military response. We actually have more than one military in this country.

Each one is designed to be able to fight on all battlefields, right? The army, the navy, et cetera. So I think it's a very different, it's not an apples to apples comparison. And I think, yes, we could do a lot more to be ready for many kinds of attacks.

But I think that this came out of the blue for Israel. What comes out of the blue for us is one of those things that we might not be able to know what it's going to be, but we should be gaining more of it. I think I can agree with you on that. And we can agree to disagree on maybe how the society will respond.

But what matters is that we actually can weather it and rally, or better yet, suffer as little as possible from. How do we get to the state where, and I'm assuming you think this is a good idea, where we move beyond resilience to actually learning from these, having our systems learn from these attacks and repairing themselves in a way that gives them that antifragility state. I have an idea here, but I don't want to just leave on the answer. Did you want to go first on this one?

Yeah, you know what? I think it starts with not trusting in technology 110%, right? You can't just, because we've done it, because we use it, because it's there, and maybe it gives us lots of easy answers. I think we have to start by it, and I'll say it against sentiment mapping, grasping the pulse of a region, put your boots on the ground and go through your things out.

Then there's the power of educational endeavors, right? You've got to have campaigns based on local sentiments to bring new and interesting ideas to embed our people. And that's on every side in any place here in the US, too, right? How do we counter some of those extremist views on any side that could spark off some kind of a civil war at any moment?

You've got countering radicalization. That's the thing. Sam, you talked about a couple of times, and we've got to build better bridges, right? Like we've got to understand each other, have empathy and understanding.

That's how we start. Then you start applying technology, knowing the things you've learned on the ground from the people you've talked to. Sam and I grew up in Morocco, we lived in Spain, we've been in culture. We've been all over the world, and the one thing I can say for certain is we've met people from all over the world, and we found more common, less difference, and we've come together with more people.

Sam, you've broken bread all over the world about people and found common ground and ideas for growing. I think we start there, we understand people. Then we can start using technology to detect the threats that we face for rapid responses. And that's how you get that anti-fragility.

It's learning about the people in the places that matter. Steve, I 100% agree with Red. I think I may have told you this on point. In 2014, I sat in an IDC conference and saw some numbers for cyber, and information security was projected to hit a trillion.

That was expected to hit $135 billion in a year by 2016 or something. And I did some math, and I realized we'd spent a trillion dollars in a decade. And the next person on stage said, there's those who've been hacked and those that don't know it. And my brain just did the record skipping.

How does A and B be true at the same time? How are we spending more and more and more? And I remember when I started in InfoSec, it was 1% of IT. And I think the last official numbers I saw was 13 to 13.5% is probably higher now.

I remember when it passed storage, I was at RSA, which was part of EMC. We were the security division of EMC. And I remember when it passed storage at 8%. This was a landmark.

It was suddenly the biggest part of IT spent. And this can't continue. And so I thought deeply about it over the years. I'm going to make career decisions on the basis of things that change the one fundamental thing, which is that back I have to get it right once, and the other guys have to get it right every time.

And even then, there's no guarantee. And the sad thing is that most of the time the attackers are improving their toolkit and their proficiency to faster rate the defenders. And so I think that's because we play by the rules. And I'll take Metcats Law.

The value of the network goes up exponentially or non-linearly with a linear increase in the size of the network. Well, so what do we do? We just keep making it bigger. We connect more and connect more and connect more.

And while that may make sense in some ways, we aren't stopping and re-architecting it and asking questions that weren't asked when Arbonette and Milne were connected up and saying, so what if, like what John Kindervogg said, what if we have a zero-trust architecture? What if we look at how computers are architected internally at the endpoint and say, what if we build a little differently? And I really think we have to rethink things we take for granted. As we keep filling out questionnaires and audits and build to RFCs and say, what if I take this visibility of my stack offline?

I did this in the late 90s with my first company. We said, we don't have to put it listeners on. We can just remove them completely as odd as code in our stack. We had OpenBSD and we were like a VPN server.

We said, let's just take it out. We don't need a VPN server. We don't need a telnet server. In fact, when we really go shields up, we don't even need to answer ICMP beyond a certain range.

That's a ping for those listening. I don't know. But until we start changing the rules and just keep expanding connectivity, then we're really increasing the kick-me-sign size. And so certainly that's why I'm in Zscaler, by the way, because there are other companies that are competitors of ours that are in similar space.

But this notion of change the game or the outcome is going to keep being the same. We have to start thinking that way on the endpoint and identity and networks everywhere. Do you think our ecosystem is set up right now for the kind of cooperation? Yeah, that we really need to start thinking about really quickly, given the global state of affairs?

Well, this is why I talked to fellow CSOs. I'm always like, every RFP has to say the philosophy you expect for interoperability. You can't speak pushing for the future you want. You've got to make sure that, for instance, risk-based scoring systems are interoperable and open and policy systems that there's an API for that.

Otherwise, you're going to have these little bald gardens. And one of the things for sure and security we have is, I used to call it a barbelled industry because it was big companies buying up the middle and the middle was small. And at the other end, we had thousands, actually, of startups who were filling the gap big companies can't do because they can't innovate fast enough. And why?

Because the bad guy is an intelligent, adaptive opponent. And so if people are coming up and building each one of them, the great thing about standards is there's so many. Pick anyone you want. If we are to actually building standards, and a great example of the standard is SAML.

A good example of one that didn't go anywhere is SPML, which is a provisioning market language. There's a really good standard that the people are working on as a language in OASIS OCA group right now on indicator of behavior. And FYI, it isn't just renaming indicators of compromise or attack. It's about chains of behavior, independent of any signatures.

Bad behavior by actors and processes in sequence eventually give themselves away. And there should be a Yara-like language to describe that and to share it and to apply logic to it. Those are two things. You know, it's hard to find companies that are caring about it, and they don't care about it because we as CISO don't put pressure on them.

And I think we get the ecosystem we deserve, Steve. And that may sound terrible, but if we don't slow down and think about what should be done, we'll get what's handed to us. And mostly innovation is happening on vendors right now. You're absolutely right.

And you're right. We only have ourselves to blame here. Including myself. Of course, sure.

Yeah. Maybe I'm conscious of the time, guys. You've been terrific. This has been a great chat about this topic.

And before I go, though, I wanted to throw one more question out. This is more personal, I think. And maybe Red can chime in first because he's... No, because he's thinking.

He's in that. I'm the big back. That's what I said. Because he's a marketing genius.

That's why. So the Israelis are in kind of a tough position, right? They, you know, there's a lot of yada-yada around the world about, you know, proportional response and moral equivalency and all the rest of it. What do you do?

You know, they've been over backwards, I think, to allow the Palestinians to exit and help them exit and, you know, extend deadlines and all the rest of it. What do you actually, you know, do you blow everybody up? Or what do you... and then take the consequences?

Or what do you do? Let me give you the first answer, then I'll give you a good answer. All right. The first answer is there is no appropriate or proportional response.

That's not a real thing, right? You have one response just to keep people safe and out of harm's way and it's to remove an infectious ideological group that is taken, not only hostages from one side, but hostages from within. That group must be removed unequivocally from us and any other extremist violent extremist group has got to be dealt with. That's it, plain and simple.

You'll hear people with the whataboutisms. It's my most hated argument in marketing. Well, what about? Well, we're not talking about the whatabout.

We're talking about this. So if I say to you, Sam hates P's. And some of us will, he also hates broccoli. We're not talking about the what else.

Just focus on the P's. How do we get Sam to like P's, right? Hate to make that into the record. I like P's.

Yeah. I make a little light of a situation using P's to bring it down to the tone a bit. But yeah, what I'm saying, I hate when someone says proportional response or what about this or what about that. They have a sample earlier at the fog.

That's a very difficult situation to find. As I said, a geospatial belt is how do you find something hidden in a massive needle in a haystack? How do you get to the tunnels underground? How do you know where they are?

How do you find the hostages? How do you rescue people? How do you get innocent civilians to safety in Egypt? This is all something I think that they've been appropriate in their response and they've taken the time and they've done the leaflets.

Look at that's a physical activity. That was not a digital email because no one there has access to email. No one has access to social media. They dropped leaflets to help people move, but they're being held hostage as well.

So that's a tough question to answer. It's a hard question to answer. But the end of the day Hamas must be removed. What should we do?

Right? What we're asking is unified reality. We have to address the conflict handably and digitally, which is why I like the response of the leaflet drop. Sentiment mapping, they're going to have to get on the ground and capture that emotional ideological current and help to change and derive with actionable insight.

They've got to bring back that actual insight. So Israel has intelligence to use. And then anti-fragile intelligence, you said, create systems that don't just bounce back from disturbances, but come back stronger physically and digitally. So that's physical realm.

Ground zero of the conflict, right? Include places, protest and other events going on. Be there. Digital domain.

Be an online platform. Be digital forums. Be in cyber spaces where discourse and influence campaigns are held as a marketer, right? So I can help tell a better story, help tell a story to get people to believe in me.

So I think I said that really fast. I apologize. I'm very clear. Very clear.

No, I got it. You're right. Sam. Yeah.

I don't have much to answer what Red said. Honestly, you mentioned more like we once. My heart goes out to everyone in Israel and everyone who's part of a human shield in Gaza and Palestine, or however it's referred to, you know, as they want to be referred to. I do want to see peace in the area, of course, but the situation is what it is.

And I hope that same minds prevail and that peace prevails. Of course, it has taken a long, long time and we still are faced with conflict in the Middle East. Not a surprise. But, you know, I mentioned countering violent extremists earlier and I think this is going to be a very long time to get to a better place.

And yeah, my heart just goes out to everybody here. And I seriously hope we have peace and peace soon with as minimal damage as possible to those who are innocent. Yeah. All right.

Well, by the way, on a humorous note, Red, you mentioned peace and broccoli. I just hope for a world of peace. I'm surprised you didn't loop that in earlier. I tried not to.

I was curious until we got to the end of that. What about isms that just pissed me off when you're having a discussion about something. I was like, what about this? You're like, what was that about broccoli?

Well, I hate when you're right. Not as much in your eyes. Okay, what do you see? All right, folks.

This is the Curie Brothers Live and on a bridge. So I appreciate you guys taking the time. It was fun as always. And we're not having a fun topic here, but your insights are terrific as usual.

Let's see what happens and we'll revisit this in a month or so. Thank you, buddy. Thanks, Steve. Thank you guys.

Until next time, this is Steve King, your host, signing off. Thank you for joining us for another episode of Cybersecurity Insights. You can connect with us on LinkedIn or Facebook or send us an email at social at cybered.io. For more information about the podcast, visit cybered.io forward slash podcast.

Until next week, stay safe and secure, and we'll see you on the next episode of Cybersecurity Insights.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on February 6, 2024.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!