Supporting CISA - The 'Focal Point of Our Defensive Efforts' episode artwork

EPISODE · Dec 6, 2023

Supporting CISA - The 'Focal Point of Our Defensive Efforts'

from Info Risk Today Podcast · host InfoRiskToday.com

On Nov. 8, Tenable Chairman and CEO Amit Yoran wrote a letter to Congress in support of CISA. In this episode of "Cybersecurity Insights," Yoran calls the agency the "primary focal point of our defensive efforts" and discusses why the country needs to stay unified on defeating cyberthreats.

Episode metadata supplied by the publisher feed · Published Dec 6, 2023

Embed this episode

NOW PLAYING

Supporting CISA - The 'Focal Point of Our Defensive Efforts'

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Welcome to Cybersecurity Insights, the podcast for the CyberEd.io Learning Community. Our goal is to bring Cybersecurity practitioners the latest and most relevant education and training to upskill and dive deeper into topics that matter in today's modern Cybersecurity world. Good day everyone, this is Steve King. I'm the Managing Director here at CyberEd.io and today we have the pleasure of Amit Jouran's company to join us and talk about what we're calling the letter, which Amit has organized and authored and put together as well along with a lot of very serious Cybersecurity professionals to Congress to request that sees the funding not be reduced as proposed, and we'll get into that in a second.

But those who don't know Amit, he's the Chairman and Chief Executive Officer at Tenable. I think he's been there since 2017. We've known Amit for years as back at RSA where he was President of that company as well. And it joined RSA from Net Witness, which he was CEO of, and that was acquired by EMC, RSA's parent company.

Prior to that, and importantly, Jouran was the National Cybersecurity Division Director within the Department of Homeland Security, which he served for what appears to be about one year as the first Director, I think, of the U.S. cert. And was one of those startup guys who had a company acquired by Symantec along with many of us a few years ago and has been on the board of several smart cybersecurity companies along the way. He's a graduate of the U.S.

Military Academy at West Point and has served as one of the founding members of the Department of Defense's CRT, the Computer Emergency Response Team, as a Master's Degree in Computer Science. So, welcome Amit. We're delighted that you could join us today. Great student, thanks for hosting and excited to speak with you.

Well, thank you. Why don't we start at what prompted the letter to begin with? Well, if you look across today's political environment, there's no shortage of things to get fired up about and excited about and despondent about. Cybersecurity has been one of those few items, one of those few topics, which have been really unifying us.

It's had pretty broad-based bipartisan support. Everybody sort of recognizes over the last several years from briefings of the Director of National Intelligence and the National Intelligence Estimates, that cyber is really one of the biggest threats to our country to our way of life, and we've got to do something about it. And so, it's to date received pretty broad-based bipartisan support. People reaching across the aisle trying to do the things that need to get done before disaster strikes.

And so, I think in recent days, as you see some of the partisanship threaten that, it just sounded like it was an opportunity to speak up and make sure that without going after this party or that party, that we as an industry and as practitioners and as foreign national security officials view the world to at least lend our voice to the conversation. Yeah, so you think that there's clearly been a unifier with regard to what you said. Do you think that people really believe that this represents a serious threat or like an existential level threat, which is the way I see it or not, because it's very hard for me and I'm in this up to my neck every day all day long. It's what I do and it's amazing to me what happens here and our response to it as well.

And there are lots of different paths we can take. I'm sure we're on all of the right ones at the moment. What's your view of that? We're definitely not on all of the right ones.

I sort of share that there's a cause for pessimists over there, but I'll also say this is in an extraordinarily important topic. I agree with you that it poses existential threats to so many organizations around the world and around the country and even has some systemic concerns about how it might impact us. You saw modest examples of what the impact of cyber could achieve with colonial pipeline and some of the cyber to physical consequences, which are possible as more and more of our critical infrastructure come online. And so I think there's definitely cause for alarm.

There's a call to action. But I'd say not everything is what we're not pursuing all possible paths. I'd say we are doing a lot and there's a lot of activity occurring, certainly at SISA, but also across other parts of government, FBI, and NSA, and then even more, perhaps even more importantly, a lot of activity happening with the SEC and Security Exchange Commission, which plays a pretty significant role in regulating public securities in public markets in terms of setting requirements around transparency and accountability. And so as all of these organizations raise cyber on their agenda, that's where unified call for action is moving us forward, I think, as a nation and as a society.

Yeah, of course. And I've had a lot of well-intentioned attempts at various things that have gone on recently and other regulatory levels we've seen from the FTC and the SEC. You know, you could argue that the SEC regulation causes more harm than good, and the Joe Sullivan verdict also causes more harm than good, but I have to believe, because I'm an optimist, that it was with the best intentions that the folks that engineered both of those outcomes were trying to make a positive difference as opposed to a negative one. But boy, in both cases, I think it set back our cause here a few years.

But we're not here to talk about that today. You, or somehow you guys assembled a pretty amazing crew of folks to co-sign this letter. Nick Cash at Palo Alto Networks and your predecessor to RSA, Artkobiello, and Dave DeWalt at Night Dragon and Ron Green at, you know, CSO at MasterCard and Kurtz at CrowdStrike and Seshra, et cetera, go on forever here. Did you personally recruit these guys?

I mean, how did that all come about? I reached out to a number of folks with, you know, some competitors, some allies, some colleagues, some former colleagues, people that I had worked with and around in what is, you know, over the last 30 years, what was a very small community and growing, and folks who I believe are a position in their own careers, where I think their voice carries weight and is worth listening to, but also, you know, they have strong personal conviction, very deep understanding of the space and the nuances and the dynamics and so, and also the willingness to speak up on a nonpartisan basis to say, hey, this is something that we believe is right or wrong and worth doing, worth investing in, worth maintaining and growing. So I did reach out to a number of them and others kind of came through some of those folks, but, you know, we tried pulling this together in a short period of time. I'm sure if we opened it up to the broader practitioner community, we could have, you know, many hundreds, if not thousands of CSOs standing up and saying, hey, the work that Sysa does is important.

It's important to us and to our organizations and how we think about cyber risk and how we protect ourselves, what we prioritize and what we get done. Yeah, I know Joe Sullivan pretty well here. If you followed, didn't follow that case. I really believe that the letter writing campaign that we all became part of, or that influence that judges sentencing, certainly, and so, you know, people actually do care about these things.

So on the one hand, you say, well, you know, it's just a letter of chairs, but I think, you know, you hopefully will strike a chord and get people to reconsider. You know, we're talking about a 25% decrease in funding. Is that what you told me earlier? Yeah, I think that's what, you know, some of the saber rattling has, you know, made it sound like we're going to reduce, or attack to reduce Sysa's budget by 25%.

And, you know, the role that Sysa plays internally in helping to protect government systems, but also key leadership role that plays in identifying things that private sector needs to do, critical infrastructure operators need to do to better protect themselves in terms of what tactics, what techniques adversaries are using or leveraging, what are the critical vulnerabilities that they're going after and that organizations, you know, know, and exploited vulnerability, a catalyst that Sysa pulls together, maintains, publishes, whether it's on critical operational technology systems or in IT systems, is really a very powerful tool and a lot of, you know, a lot of the, you know, 45,000 customers that Temple works with around the world, you know, they love that. And Sysa, you know, I hear from that frequently that, you know, that really helps them prioritize the work that they do to make sure that they're meeting and acting responsibly to reduce risk in the face of threat landscape. It's constantly evolving and constantly changing. So, you know, the work that Sysa does is important on so many fronts, and as we see the threat landscape continue to accelerate and sharpen their own both techniques and aggressiveness, I think, you know, the thought of reducing funding to our primary, the organization who is the primary focal point for our defensive efforts just seems, let's call it nonsensical, but it just seems counterproductive to our national interests and the interests of the American people and arguably the world.

Yeah, and it is nonsensical, was why Sysa is reporting in through the Department of Homeland Security, you know, it seems to me that I think the TSA organization within DHS gobbles up about 25% of the entire workforce at DHS and has a single threat vector focus, airlines, airplanes. Yeah, and technically, I suppose, has responsibility for cybersecurity in the energy sector in some weird way that Sysa does not, but here you've got an agency that has, you know, broadly responsibility for the entire spectrum. Why would that agency be reporting to DHS? Who's later, by the way, has no idea about anything about cybersecurity?

You know, listen, it's certainly something where both sides of the argument could put reasonable, you know, rationale for this to organize this way or that way. Podcasts are always fun when you get challenging guests. I'm sort of, I'm happy to provide point downer point, you know, thinking here. I can think of there's some value in, you know, Sysa being a part of DHS, or we're closely intertwined with DHS.

Yeah, DHS's mission is obviously much broader. But I do think, you know, cyber is a cross-cutting aspect of protecting the homeland is fundamentally important. So as DHS works with critical infrastructures on issues more broadly than cyber, it's important to have the cyber, you know, topic have a seat at the table. And in the, and as DHS goes through and thinks through its regulatory authorities, it is important to have cyber thinking with a seat at the table.

You know, there's definitely, you know, good arguments to be made, you know, this way versus that way, and vice versa. But ultimately, I think the important thing is the leadership of Sysa, the clarity and rule, the operational execution of the mission and whether that happens within the department or it's set up as an independent agency, you know, again, I think there's pros and cons either way. But I don't think being part of DHS inhibits or prevents or retards Sysa's ability to accomplish its mission. Well, I was well said.

Here we are, so it's 2023. We live in an entirely digital world universe. Why wouldn't Sysa, in your mind, be the 16th cabinet, you know, agency with its own cabinet secretary? Well, you know, listen, there certainly are arguments to be made if you believe that the threat to our nation are as strong as you and I believe that there certainly are good arguments to be made.

So this should be a cabinet level agency. I don't think that, you know, Sysa is cut off at the knees or doesn't have the ability to accomplish its mission without being, you know, at the table, so to speak, is a cabinet level agency. You know, not kind of forgetting that Sysa is a five-year-old agency. It's a five-year-old entity.

Certainly the Department of Homeland Security is about 20 years, and it's only now. It's 20 to five. It's, you know, stride. You know, these things don't happen overnight, personnel and everything else.

You know, could it evolve in that way over time? I think that's logical. Do you have it as a cyber only agency or do you have more technology more broadly represented there? Because, you know, there's obviously a lot happening in the world of technology that is or isn't just cyber security, so our use of technology.

I think AI and the sort of revolution that AI represents, you know, are you going to have separate policy and decision-making around AI? Do you include, you know, cyber and AI in a technology oriented, you know, more technology, a technology-savvy agency, and then even, you know, looking more broadly than AI are, you know, other forms of competitiveness and innovation in technology. So if you're going to think at a candidate level, do you lose, you know, perhaps some of the, you know, do you make it more a strong technology policy orientation? But then you might lose some of the focus around cyber security, that makes Sysa serves Sysa well at the moment.

Yeah. Yeah, you're right. I mean, I'm not proposing. First, and I'm not trying to draw you into the controversy here, but I'm also not proposing that it's a simple solution, but it's just, I'm bewildered at the way we approach things sometimes.

And if you, you know, I pay attention to Jen Easterly and kind of what she's up to. And I saw a speech that you may or may not have to, that she made to Vanderbilt University back in May. I think that was the only time a sport team that had been happening. You know, I guess the only time I ever saw her be really, really serious about what we're facing.

And I was actually shocked. So I'm used to the, you know, the Jen Easterly who, you know, whatever you want to call it, plays a cute and her role and all of that, and when she obviously feels she can't or can't do, but the boy was that impactful. And they should, you know, bottle that up and resell it. If you've not seen that, I would encourage you to watch it.

You yourself were part of this thing. Why, could I ask why that only lasted a year? Well, this is going back, you know, not only a couple of decades, but a couple of generations of, you know, iterations of a U.S. Serd and cyber and critical infrastructure efforts, you know, at the time, I came in to help establish U.S.

Serd and put some programs in place, predominantly for the government to better understand and protect its own assets, but also to better engage with private sector. And so, you know, we pulled together a handful of programs, things like first couple of iterations of Einstein, which were, which were helping government agencies, you know, look across helping DHS rather, look across government agencies that critical civilian networks to identify common attack patterns and techniques and incidents. One together, it's a response government form of incident responders to get together to collaborate on incident sharing. And then also a number of engagements with private industry around both the ISACs and kind of the various iterations of those and some of the programs, you know, I feel went off and found their legs and, you know, added a lot of value to what folks were doing and others, and others didn't, and that's fine too.

But, you know, really my objective was to come in and help kind of establish the startup of this U.S. Serd program and initiative, and then, you know, decided that it was a good break, a good time to move on, as, you know, the end of one administration was wrapping up, and so found myself back back in private industries. In the letter, you say that, and this most, yeah, I know this is, as a West Point graduate, I'm sure this is close to your heart. Historically, Congress has always prioritized investments in our military and in protecting the physical security of our nation, our cybersecurity readiness deserves the same commitment.

Do you think that Congress understands the level of kinetic, actual threat from the world we're facing and trying to work through every day? Well, there are no doubt members of Congress, which invested the time and the energy and effort and understand, you know, these cyber issues at a very deep level, and, you know, you've got the Slaring Commission, you've got, like, all sorts of folks that have put forth the, you know, the sweat equity to understand this and make themselves informed. And I think that, you know, there are others that are, who us about technology and don't understand cyber from Adam, and it isn't centered on their agenda or at the top or even, you know, first of all, the fault of their to-do list. You know, that's okay, too.

Congress isn't a monolithic organization to say the least. You know, I think, again, in the past, those that have really decided to throw themselves in into the cyber issue have really come up with a truly bipartisan, you know, nonpartisan approach to the matter and worked very well across the aisle. And that's where I think, you know, that is the level of attention and focus and gravity that this issue mandates, demands. And so where we seem to have taken a step away from that, you know, we want to make sure that we keep it on track before, you know, before some of the partisanship, or before, you know, other factors send it down a path that is counterproductive to the momentum that systems been building.

Yeah, yeah, sure. So I'm conscious of the time, I'm that I want to, I have one final question if you don't mind. Yeah, then I want to come back and spar with you on the SEC topic. I can't let you get away with that one without saying.

Okay. Good. That's great. I for one view, you know, the actions that the SEC's taken while while it may be unpopular with CISOs for seemingly obvious reasons.

I think the, the, and by the way, I'm appreciative of the letter that you and others have written on the Joe Sullivan sentencing. And I think it did have a positive impact. I'd say the flip side is the cases which DOJ has undertaken and the cases which SEC has undertaken for enforcement, for the most part, we can argue about the nuances are pretty egregious cases. And, and I think they've selected those, those outlier cases for a reason, trying to, you know, nudge the market, you know, just a little bit in the direction of greater transparency and accountability.

And so I, if we get it to the, do they choose wisely and did they execute properly? But I think that's the intent and, and, and I think it's the right direction. Well, look, I don't disagree with you. As I said, I would try to say, you know, I think it was all very well intentioned.

But I'm not sure the result was entirely the result that we, you know, that all of us hope for if you will. Because transparency, you know, is, yeah, I mean, it's like huge. And we don't, we don't mandate it. We don't require it enough of public companies or certainly private companies.

And you see where that gets us, which is not a good place. So I, I don't disagree with you at all on it. So my final question was going to be, do you think it's, you know, it's kind of like if I were running, I don't know, 4-H or Girl Scouts or something, you know, it would like be, Hey, how come everybody doesn't care about 4-H? I mean, it's like, obviously the most important thing in the world or girl same thing.

Yeah, it only affects, you know, million people or whatever. It's right. But I mean, this stuff is, is different. And I'm in it every day.

And so I, I don't think I have, it's hard for me to imagine is what I'm trying to say. That my view is any more parochial, you know, than, than it sort of should be under the circumstances. And the only difference I can see here is that if you compare it to, if I may say global or climate, climate issues are global warming, you know, there's a visceral effect in the global warming business. And there is no visceral effect in the cyber security business.

You know, you look at it from a threat point of view, right? Or you can measure CO2, you can measure the stuff in the area. You can see the polar bears in the ice fields. You can see the height of the water.

You can measure ocean temperatures. None of that's possible with cyber security. We have no idea where the next stress is going to come from. We see it all the time.

We got move IT that can just continue into effect, you know, 20, 30, 40, whatever it's going to be, when it gets done, 1,000 companies. But there's no visceral, you know, the closest we got were gas lines from colonial pipe that, you know, lasted about three weeks or something. And people pouring gas into black plastic bags. Do you think that's a big piece of this?

It's interesting because, you know, as you describe the climate change piece, yeah, you've got, you know, very heated and passionate, you know, there are data points, of course, but there's very heated and passionate, polarized, partisan, you know, belief systems, you know, there's climate change, real and how much of it is man-made and blah, blah, blah, blah. You know, we can laugh, argue, or throw our hands up in the air, but it's, you know, that's kind of the reality. But it's something that people feel very passionately about. And on the cyber side, like, there's no demand.

You have real impact. You have loss. You have people's privacy impact that you have economic impact. You have, you know, crypto exchanges being put out of business.

You have, you know, colonial pipeline, other outages. There's like, you know, there's no denying. There's no doubt that these things actually happen and are happening, but nobody, you know, for the most part, you don't have a general awareness or appreciation or call to action around the public the way you do around some of these other really, you know, other issues, which may be just more emotionally intense for people. Or the benefiting from or enjoying really great marketing campaigns, one of the two, right?

Because, you know, because you're right, you know, those are real outcomes. But every day, I see real outcomes, you know, pick one, right? And, you know, a lot of the many hundreds here that are in the hundreds of millions of dollars in people listening to jobs and all the rest of that are going to jail. But there doesn't seem to be that connector, you know, between, it's like, no one cares.

You know, it's like, yeah, yeah, I see that, but it doesn't bother me. So whereas global warming is going to bother me and it's going to bother my kids as if cybersecurity threats aren't going to bother your kids. So I don't, I think it's like many other things that if you light a marketing fire underneath it and it's well designed, you can probably, you can probably get there from here, you know? No doubt.

Steven, it's been great chatting with you. I appreciate it. I look forward to talking again when time permits. It's been awesome.

Yeah, no, I appreciate your time. I mean, thank you. And we'll do everything we can to get the word out here. And thanks for spending that time.

Thanks to our audience for listening and hopefully it was as enjoyable to you as it was to me. Until next time, I'm your host, Steve King, signing out. Thank you for joining us for another episode of Cybersecurity Insights. You can connect with us on LinkedIn or Facebook or send us an email at social at cybered.io.

For more information about the podcast, visit cybered.io forward slash podcast. Until next week, stay safe and secure and we'll see you on the next episode of Cybersecurity Insights.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on December 6, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!