Welcome to Cybersecurity Insights, the podcast for the CyberEd.io Learning Community. Our goal is to bring Cybersecurity practitioners, the latest and most relevant education and training to upskill and dive deeper into topics that matter in today's modern Cybersecurity world. Good day, everyone. This is Steve King.
I'm the Managing Director at CyberEd.io. And today, for our podcast, we have the pleasure of Antoinette Hoda's company. She's a Security Evangelist in the Office of the CTO for Checkpoint Software, also a Global Solutions Architect in IoT at Checkpoint as well. And as a broad and distinguished background in the space, otherwise you don't get to be what she is today.
So welcome, Antoinette, and thank you for taking the time to share with me and our audience your background, a little discussion on some of the issues this morning. Thanks for having me. It's awesome to be here. And I love this industry, so introduce myself real quickly.
My name is Antoinette Hoda, and I've been working as an engineer for over 25 years now. I like the world that we work in. It's very dynamic. It always brings new challenges.
I also have a personal mission, making internet a better and safer place for our children. And I like the OT realm as well, operational technology, because it's completely different compared to IT. But that's something that we are going to discuss a little bit later. Yeah, no kidding.
It certainly is. I wish everybody would, would hurry up and recognize that. You know, let's start. If you don't mind with telling us what a Checkpoint Evangelist is and how one earns that designation.
Yeah, I'm very honored to be part of that distinguished group. It's people that are spokespersons for Checkpoint, they will speak at conferences, and they will spread the word of Checkpoint. And I like our philosophy and our strategy because we believe that security should be simple with one consolidated management. And yeah, that's in a nutshell what it is, but you have to create white papers and things like that.
And all those things, it's so much fun to do. So I'm really happy to be part of this group. And I'm also a global solution architect. And in that role, I help customers with maintaining a very good security posture.
What do they need to do to eliminate potential threats from the outside and from the inside? We do some kind of checkups to see what mitigation is in place. We will talk later on maybe about zero trust network access industry for is also really challenging. So every day new checkages and a lot of topics and knowledge that should have.
And that's why I love my job. It's such a great job. And we have a great team at Checkpoint. We all have that passion.
We all will do the extra mile to help our customers because it's in our blood. It's in our DNA security. Yeah, no kidding. And there's no end in sight, is there?
I mean, you're going to have this job as long as you want it. That's for sure. You know, you guys published a cybersecurity report. I guess annually in your 2023 report talked about consolidating the entire cybersecurity posture, which you just mentioned as a step in the right direction toward improved resilience and cyber defense.
What do you mean by consolidating the entire cybersecurity posture and how does one do that? Yeah, good question. In past yet, all kinds of point solutions and now with the borders are fading. So see where is the perimeter?
Is that even a perimeter or is any asset in a network, the perimeter? So you should have consolidated management where you see all the loss of all your assets, your endpoints, your mobile security made easy. It's the short version of it because everything is now interconnected anytime any device anywhere. So every asset is holding sensitive information.
And it's a gold mine for people with bad intentions for hackers and attackers. Or they are using your assets in your network as jump host or they do propagation attacks. So you need security made easy and single pane of glass that will tell you exactly what is the security posture of your complete device feed from your endpoints, mobiles and IOT assets and everything within. I hope that clarifies a little bit the three C's as we like to call it.
Yeah, sure. But you know, it feels like with the pandemic that kind of brought a lot of this into focus, but has anything really changed since, you know, before and after? I mean, you could you could have made the same argument before the pandemic, could you not? Absolutely.
But that's what I mean with the borders are a little bit shifting. People tend to work from home and if I'm a hacker and I can access corporate computer, but I will exit it from home. Imagine what's all the assets I can effect as well or access to. So you see a lot of attacks happening on schools and educations because if you are in, it's also like a gold mine, social security numbers, names, things like that.
So in the past, you see that they are mainly targeting enterprises with weak security in place or internet connected devices that are not properly secured. And we see now shifting to the quick wins and things like that, like education, all kinds of IOT assets that are unsecured and connected to the internet. So yes, you could say it in the past, but the world is still a little bit different. We are returning from the work from home, but imagine your house.
You have a lot of assets in your house. If I count my devices here, I have at least 40 smart assets in my house. It's crazy, right? And imagine if that gets encrypted with ransomware or ISP will call me.
You are doing infections to other customers. We will block you for example that was happening in the past in the Netherlands. So yeah, it's crazy, but it's really, really nice and it's a nice world. But I think anywhere, anytime, any device, because everything is interconnected.
Yeah, and for sure, you're right. It's a blessing and a curse at the same time, I think. Of course, I think I have 11. I think I have less than I counted just in my office alone.
So yeah, it is a crazy world. I often see that a lot of companies have all kinds of policies in place. An end point should not be x amount of updates behind. But they are completely missing out the smart refrigerator or the smart TV.
That's directly connected and we are here to make people aware. You are as good as your weakest security unit work at my point. So you need to make sure that you have the right security controls on every potential attack surface that you have in your network. And a lot of times my customers are not even aware.
I don't have any visibility what's connecting to my network. How can I secure it? So that opens a new opportunity to discuss and to create awareness. To check if there are solutions in place.
And with OOT and IoT, it's completely different in OOT environments. My customers have no visibility at all. What's connecting? If I ask how many assets do you have, we believe we have 1500 PLCs, for example, and some robots.
But if we do a checkup, we find much more assets. We see a lot of OT administrators looking indirectly from the internet with no security at all. So that's often an eye opener. Yeah, indeed it is.
And I think at least in my experience, most folks don't actually feel they're competent enough to rock how to be the service desk, if you will, for all of their connected smart quote unquote smart devices. And because of that, people happily accept the default settings on everything. And that's kind of a bad place to start. But nonetheless, I don't know how you fix that problem.
That's a human nature problem. No matter how much education you provide people with the opportunity to consume. Whether that's going to ever change anything because, you know, information and knowledge are not the same thing. So I can, I can give you lots of information.
Yeah, right. I can give you, unless you transfer that internally, then it's just more information and you won't know what to do with it. So I have one tip. So if you are listening and you are thinking, Oh, I mean, my house and I have a lot of ideas.
It's connected to my network. Please put them in a separate field. Do some segmentation. So if shit hits the van, you are secured.
So that's our basic principles. And that's something I'd love to preach. Cyber hygiene, your cyber immune system. So you can do a lot of things with all kinds of solutions that you have.
But you do have to do segmentation, feeling on, making sure that you cannot connect from the internet to the inside. So there are a lot of things to eliminate a lot of threats that you have nowadays in your home. So just a side step. Yeah.
Sure. And you know, there's a certain amount of human behavior that sort of takes over the space a little bit too. I remember, you know, about a hundred years ago when I was younger and felt like I needed to be that tech support guy. You know, so if some family member spouse or child was having trouble with their, you know, connectivity or the devices or whatever, I was the guy that they called on it.
I happily did that because, you know, it was all about my ego, you know. And I think at some point in time, you got to give that up. Right. I mean, one of the safest ways I think to maintain a safe environment at home is to hire a third party, you know, to manage this stuff for you in the same way that a, you know, help desk or tech support function would be at your office.
And it's 50 bucks a year or something like that. And, you know, you just call a number and you say, Hey, I can't connect an email for whatever reason. And, you know, an hour later, it's fixed and you go on your business. And then nobody has to worry about keeping current with, you know, whatever version of the operating system you happen to be on.
Anyway, it's always been a stupid barrier for me. Took me a while to get over that, but I did. But I think there's a lot of that going on now as well. I don't know if that has any impact on OT and IT.
However, we'll use this. Yes. Definitely. But better times are coming.
I researched a lot of regulation and other negative effects. And if we see globally, a lot of mandatory regulations coming up, especially for IoT assets or smart internet connected devices. And the good thing is that vendors or manufacturers are now made responsible for putting security on the devices. For example, there should be a secure password in place.
Data privacy, things should be in place as well. And those key elements, because if you take a look at all the regulations worldwide, they all have key elements secure access control of vulnerability updates because who is responsible for a vulnerability? And, for example, I have a smart doorbell. Am I responsible for a firmware updates or a vulnerability patching?
Or is it the vendor that's all devised to me? Well, it's a new regulations coming up. The security posture will be better because they have to do certain things in the code to make it cyber attack-proof and zero-day-proof so those things are coming and that's really, really nice. But OT is still back in the 80s, if I may say, because there are machines in there that are running for years and years and the concerns are very different to IT because in IT it's accountability and things like that, the CIA trade.
And in OT it's completely different. It is concerns over downtime and should not impact any critical process whatsoever and safety concerns. So often in those environments you see robots, HMIs, PLCs that are 30 or 40 years old, so they are not ready for Industry.4 because they are connecting smart devices in the shop floor as well. And with that, we at Checkpoint and I always say the Purdue model is a real old model.
Do you know the Purdue model? Yes. It's a great model to use to work with all kinds of layers because with the levels you should do segmentation, you should do some kind of conference between IT and OT and if you do the principles of the Purdue model you have already some security in place. Because why does OT operate and needs to connect directly from Level 5 to a field device at Level 0, for example?
Yeah, and the problem with that is that I'm unaware of any technology that is in use today in OT environment, that those are the two qualifiers that monitors that telemetry down at Level 0. I mean, those are electromagnetic pulses that are device to device and that's where that attacks surface is. So it's interesting to me that the emphasis in OT from a network monitoring point of view has traditionally been the same emphasis as it has been in IT and that is level 2 and up. And so I wonder, you know, if you're not monitoring down at that level, I don't know how you would detect that threat.
Yes. You see, first part is that we work with, it all starts with classification detecting what is really connected to the network and then doing some kind of baselining, watching the network for a week and if the baseline is in place, then you can say, look, if there's an anomaly, then for sure we know there's an attack going on or there's something happening on the device. But yeah, there should be all kinds of security controls in place. That's just one of them, but I have to agree, it's it's challenging and not often they are not aware of the security threats or not open to it because they don't think they are attractive to hackers and just waiting for another attack to happen to be honest.
Yeah, and the ecosystem itself seems pretty porous to me as well. I mean, if you can, I mean, you know, there are any Wi-Fi firewalls, for example, in most plants that I'm aware of and, you know, that means you can kind of wander in and, you know, hook up to a Wi-Fi connection and you're beyond the network. I don't know why those things aren't part of the consideration. Yeah, absolutely agree.
So we still have a lot of work to do. As you can say. Yeah, not kidding. Checkpoint's business, though, is in OT, for example, maybe you can explain what their market really is from an OT point of view as opposed to an IT perspective.
For OT, we have certain things in place. We have third party integrations with clarity, for example, they do asset classification and you will get enriched information to which HMI is something connected to which lots so you can do anomaly detection and do reporting about it. It will tell you exactly if you are running behind with firmware versions and so forth. Then we have all kinds of gateways to do security gateways to do segmentation and micro segmentation.
Remember the Purdue model, you want to have segmentation at all because, for example, mask that was really big because there was no segmentation in place. Yeah. And our firewalls, we have something pretty cool. We do application control and we can inspect to our competition the most variety of protocols and OT protocols.
For example, let's take them up this. It's very often used in OT environments and we can detect if there's an OT operator, doing a write or read commands and you want to have visibility who is accessing PLC value, for example, and we can detect which should come on. It's being argued. So that's something you need that we can do.
Then we have our nano agent and our embedded nano agent can be loaded on any smart industrial device, at least there's one and B of ROM and CPU available. So we harden the device for within. We make a temper proof. It's completely zero day proof in air get environment.
So called OT environments. So making sure that the device keeps on working as intended. So we have a lot of solutions. Yeah.
So at a more abstract level, I guess, how do we convince the managers that there's an imminent thread and that we need to do some invasive things that means shutting the network down for some period of time to upgrade or change or evaluate or even just do an assessment in an inventory, you know, to find out what PLCs we're running and what their capabilities are, et cetera, et cetera. How do we get that message across to the guys that are responsible for operating these plans? I think it depends because you have very cool OT operators and administrators and shop floor managers. They understand it and they have pentas thing going on.
They are aware. But the other half is a little bit ignorant that they don't think they are a target at all. And I believe that regulations will be a main driver for critical infrastructure. So we see all kinds of obligations.
Supply chain attacks. You can be a victim of a supply chain attack as collateral damage. So with regulations and if you are doing critical infrastructures or manufacturing, there will be a relationship in place to fix all the half. I'm not sure if that will fix it all, but it will raise the bar for sure with a better security posture, minimizing that extra phase.
Are you referring specifically to the GDPR? And I ask that because this kind of goes back to our immediately prior discussion about consolidating cybersecurity posture, et cetera, that when you have IoT devices, for example, that you want to review the smart refrigerator or whatever you want to regulate in the states, each state has different security requirements, right? If I'm a manufacturer of a pick a thing, I don't care smart refrigerator, I've got a potentially manufactured 50 different configurations of refrigeration in order to satisfy each state's privacy and security requirements. To my opinion, that's not the case because if you have some worldwide legislative acts like the Cybersecurity Improvement Act, but you also have, indeed, the local ex and legislative experts, they all face key elements.
They all talk about security controls. They all talk about secure. So you don't have to have those 17 or 80 things in place. You should make sure that sensitive and private data is being secured.
Secure connections that your device is not connecting over, directly connecting to the internet, using telnet, for example, not secure at all. So yes, there are a lot of local experts, but in general, they have the same key elements, the requirements that they face. And I believe, and I think it's time also that critical infrastructures, OT environments, manufacturing, all kinds of factories should share information with each other, anonymized that they are in their tech to raise the bar. And there are regulations coming up as well.
I believe in the US too. Yeah. And you and I will probably go to our graves thinking that. I agree.
Of course I agree with you, but I don't know how that's ever going to happen. Moving on, however, we have an earth shifting. I don't think that's an interstate or an overstatement event that just occurred with the release of the current swab of generative AI products, CHEP, GPT. You know, three or four and five coming.
That has the very real potential to change the equation like we've never seen before and cyber security in a lot of other places as well. But, but specifically in security. And we know the bad guys are way ahead of us. You guys have talked about, or at least your research thread analysts have talked about an example of a full infection chain using CHEP, GPT or generative AI.
That doesn't require writing a single line of code. Can you explain that example that you guys talk about? If you could ask CHEP to create a cyber attack for you, and it will completely take care of it for you, it will write a code, it will launch it. But I would like to take it a step higher because I think CHEP will change the world.
And you can use it for bad and for example, the EU, we see now countries are banning CHEP GPT because there's all kinds of other concerns. But I think it's like any new technology. We should see how it's evolving. We should be very cautious.
You can use it for the good and you can use it for the bad. So yeah, you can ask it all kinds of things and it will do a complete attack chain for you, but you can use it for the good as well. If you want to have a remedy for a certain disease, for example, that's just a stupid example. But to get my point, you can use it for the good and for the bad.
Yeah. Let's stay focused on generative AI for a second. What do you consider when we go back to OT and the OT environment? What do you consider to be a big risk from a generative AI point of view around OT?
Good question. I like that question. I need to think about it. Let's use an example.
We have an old shop floor with machines and OT assets, HMIS fields, since running for a lot of years. And now they are connecting smart devices in the network. And they are not really aware of the security threats it will bring. And I believe that a lot of shop floors are connecting to the Internet without relative security controls.
And with AI, I think that would be a real danger. If, for example, hecticism, cyberwar, let's use the example. The Netherlands has provided some military goods to Ukraine with war in Russia. And that's Russia will say, oh, please shut down all the factories in the Netherlands, for example.
So that's a bad thing. That's a real concern, if you ask me. Yeah, sure. Does Checkpoint have a separate initiative around generative AI?
Or has it gotten that big internally yet? Oh, I'm sure we have, but I have to admit, that's not my expertise. So I'm sure we are only, but I'm really into OT and IoT. But it's a good question.
May I come back to you on that one? Yeah, sure. Yeah, anytime, anytime. So one of the things that we do here is education and training and specifically in cyber security.
So I guess kind of a closing question would be how big a role can education play in putting forward an effective defense against cyber attacks? And where should the emphasis be in terms of the kind of topics that we present and the kind of studying that people need to focus on? Yeah, I always close down my presentation with Robert Mueller, the former director of the FBI, he's stating there are two companies, those that have been hacked and those that will be hacked. I am adding a third one.
Those that have been hacked, they still don't know. So what is a calculated risk? Because you cannot secure your environment 100% completely. That's impossible.
So you can try to make it as secure as possible. But are you aware of the security holes, the threats that you are facing? And I believe that education can be a crucial part in cyberimmunity and cyber hygiene with basics like passwords and email, things like that, efficient to security gateways, protecting networks and things like that, and cloud security. So I believe that education is key.
Absolutely. Yeah. And so you mentioned cloud security. So the second part of this question really is complexity, right?
We know that I believe that over the last five years, let's say, that the complexity has expanded to such an extent that we, most of us, have no idea what we're doing any longer. And I mean that in the nicest way. I mean, it's not anybody's fault. It's just that, you know, if you've got, if you're implemented edge computing and you've got hybrid cloud and you've got Kubernetes containers everywhere and you've got an aggressive, you know, DevSecOps team that's doing, you know, 25, 50 pushes a day, you're using a lot of, you're using a lot of code.
You've got a lot of, you know, transitive derivatives. You've got a lot of API exposures. And that's what we have with that consolidated management and a consolidated security because we have security posture in the cloud. We can check a code practice with the CI, CD pipeline.
We can secure the complete chain of the customer's environments with our solution. But we see that it's complex. And we believe that security should be easy and that you should have, that's our philosophy with Horizon events, for example, you will see all the events happening in your network, making them with actionable alerts, the remediation and so forth, just making, drilling it down to, uh, from the complexity to a simple, overview that's manageable and will tell you with one single, uh, look at the dashboard, here, I need to take action and for the rest, I'm a good, for example. And so if I'm a CISO, all I need to do is call the checkpoint books and say, hey, give me one of those dashboards.
I need to understand what my attack surface looks like. Exactly. And then we can even do reporting, making you compliant with all kinds of regulations. You will get alert.
So absolutely. All right. Well, that sounds like it all done to me. So we could talk for a long time here, Internet.
I appreciate you taking the time out and talking to us from the Netherlands this evening, your time. And I hope we can do it again sometime, because it's been a real pleasure. Oh, absolutely. It was a pleasure to be here.
And I will go back to the question. I'm sure you will. And I can hardly wait. So that's great.
So again, folks, this is Antoinette. POTUS, the security evangelist in the office of the chief technology officer and global solutions architect for checkpoint software technologies with us today. And I hope that you enjoyed the session as much as I did. And we look forward to chatting with you the next time.
So until then, I'm your host, Steve King, signing up. Thank you for joining us for another episode of Cybersecurity Insights. You can connect with us on LinkedIn or Facebook or send us an email at social at cybered.io. For more information about the podcast, visit cybered.io forward slash podcast.
Until next week, stay safe and secure. And we'll see you on the next episode of Cybersecurity Insights.