The New Insider Risk: When Creativity Goes Bad episode artwork

EPISODE · Mar 6, 2020

The New Insider Risk: When Creativity Goes Bad

from Info Risk Today Podcast · host InfoRiskToday.com

The latest edition of the ISMG Security Report discusses the developing definition of "Insider Risk." Plus, Former DHS Secretary Michael Chertoff on U.S. 5G rollout plans; Cloud Security Alliance on containers and microservices.

Episode metadata supplied by the publisher feed · Published Mar 6, 2020

Embed this episode

NOW PLAYING

The New Insider Risk: When Creativity Goes Bad

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Evolving challenge of insider risk. Secretary Chertoff discusses 5G in the U.S. and where microservices and containers are falling short. These stories and more in this week's ISMG Security Report.

Hello, I'm Nick Holland. Well, we're all back from RSA and in our respective editorial offices around the globe and digesting the phenomenal conversations and insights that we captured last week. I've been spoiled for choice in terms of what I should bring to this week's podcast, but I think I've picked some pretty interesting content from the smorgasbord available. Coming up, we have Michael Chertoff, Executive Chairman of the Chertoff Group and former Secretary of the Department of Homeland Security, discussing 5G in the supply chain and the inevitable Huawei.

We also have some insights on containers and microservices with John Yeo, Global Vice President of Research at the Cloud Security Alliance. But first, one of the more common themes that we came across at RSA was insider risk. And Tom Field, ISMG's SVP of Editorial, hosted a stellar CISO panel discussion on the topic, including Dawn Capelli, Vice President of Global Security and CISO of Rockwell Automation, Sujit Bambaale, CISO of 7-Eleven, Solomon Adote, Chief Security Officer at the State of Delaware, and Tony Pepper, CEO and Co-founder of Egress Software Technologies. Sujit came up with a great term for one of the most prevalent problems with insider risk and what he called creative gone bad.

And in this part of the conversation, the panel discusses how insider risk has evolved from something malicious to something more accidental. We'll start off with Solomon Adote. I think I can start that. It's not always just the ability to really provide a better service.

You know, you have a health and social services individual trying to work better with somebody in the Department of Motor Vehicles to provide transportation to somebody who needs state services. They just go to send an email and then that risk happens. Or they try to work from home because they have to get to their kids and they put some information on a USB stick. That's that risk happens.

So it's all intended and just looking for an opportunity to add value and it creates this opportunity. When I started in this area in 2001, my big hope was that someday there would be a technology out there that would pull all these diverse data sources together and enable you to detect these things right away. And we've gotten to that point. So that's very exciting to me.

It used to be much more manual. And thank you to the vendor community for actually making our jobs much easier than they used to be. But Don, also when you started, you were focused on that malicious insider. I think it was you when you were at Carnegie Mellon that coined the phrase accidental insider.

So the risk has evolved. Right, right. And the thing is, it may be accidental, but it's still putting your IP at risk or it's putting your network at risk. If the accidental insider is downloading some kind of tool that is going to put your network at risk or might have ransomware in it.

So, yeah, it's still dangerous. You know, I'd like to put some structure around the why, because I want to understand the mind of my adversary, whether it's internal or external. And I tend to break it down to four buckets, competition, compensation, attribution and affirmation. And I think that all four of those can apply to an insider as much as it applies to an external person.

So for me, for those reasons, insider risk, accidental or not, is something that we have to pay very close attention to. And certainly you are. Yeah, you know, I think Don makes a great point. I think 10 years ago, the technology just wasn't available to do this because it's a really complex problem.

Right. You know, ultimately, you've got to look at human behavior and you have to predict in real time when someone's about to make an error of judgment. But I think, you know, the cybersecurity community often focuses on those malicious issues, which actually represent one or two percent of the challenges that every business face. The overwhelming majority of cases is just accidental.

But I think to capture that is a much, much more difficult problem. And therefore, technology does need to catch up. And that's where there's been a whole state of machine learning that comes in. But I think if you now blend machine learning with the kind of context of the word DLP to ultimately give people the ability to understand where they're making mistakes or not, I think that's where you get something really meaningful.

But I think one of the things that we see, which is more concerning, is actually the accidental breach of security is the most unreported breach globally because and it sounds pretty obvious when you think about it. If I email Tom and Tom replied back to me and said, hey, was this meant for me? I think I wasn't. I'm not too sure if I've raised my hand to kind of tell security because there's a kind of blame culture globally.

But I think the second is probably more relevant to us all, which is if you send something accidentally to the wrong person and you don't know how do you even know to report that? So I think one of the areas technology has also fallen short with the enterprises actually CISOs don't have the data to actually tell how big the problem is. And one caution I always say anytime I talk to you, Tom, about insider threat or insider risk is people tend to think of insider threat as theft of IP and insider cyber sabotage is still happening out there. And that's one you really need to be on top of.

And it's harder. It's much harder, but it's a really important threat to be aware of. You're listening to the ISMG Security Report on ISMG Radio. ISMG, your number one source for information security news.

If there's a nexus for many of the conversations at the RSA conference this year, it was China, not just with concerns relating to COVID-19, but conversations related to election interference, state sponsored cyberattacks such as Equifax and Marriott and the evolution of telecommunications backbone and 5G networks with the inevitable roads leading to Huawei. ISMG's executive editor, Data Switch and Europe, Matthew Schwartz, had the opportunity to speak with Michael Chertoff, executive chairman of the Chertoff Group and former secretary of the Department of Homeland Security. They discussed a number of items pertaining to the 5G rollout in the U.S. And in this section of the interview, Matt asked the secretary what three things should the U.S.

be doing now to accelerate 5G deployment? Well, first thing, we need to begin to allow the companies that are operating in this space to scale and to become price competitive. Now, right now, there's no American company that does it end to end. Ericsson and Nokia, which are obviously European and Samsung in Korea, do have a competitive suite of products, but they're probably a little bit pricey.

What we need to do is collaborate with our allies in Europe and in Asia and to work together to help reduce those prices, whether it be through assistance, through creating a better market and also by pointing out the dangers of bringing Huawei in so that they can become real competitors. Now, Congress is enacting legislation that would help promote this sort of a process. Attorney General Barr recently suggested that U.S. firms invest in Nokia and Ericsson in particular.

You're talking about also the potential for collaboration. All of these measures seem like they would free the supply chain or free U.S. organizations to tap a more trusted supply chain. But they're going to take time.

How long do you think we're looking at? Well, there's no question we are late to this competition. And so we need to look in the short term at ways to mitigate the risk of having Huawei be the sole supplier. And that risk is twofold.

First of all, any sole supplier creates a risk to the supply chain. And if you have any doubt about that, look what's going on now with coronavirus and the effect on the global economy as people worry China won't be able to fulfill its obligations. But beyond that, because of the nature of the Huawei relationship with the Chinese government, there's a national security risk, which I think is uppermost in the concern of U.S. minds.

So here are some things we can do to mitigate. We can build a capability using software to at least shield or mitigate the risk to data that flows, even if part of the infrastructure is on Huawei. We can also reduce the extent of infrastructure that Huawei is operating in so that we can then ultimately, on the more important elements of the network, bring competitors in. And finally, we can work with other government agencies to help free up spectrum that can again jumpstart the marketplace for a certain kind of infrastructure.

Now, let's talk about that spectrum a little bit. What do you propose and what would it achieve? Well, there are elements of the spectrum that are particularly useful if you're using routers that are at the core of your operating system, as opposed to antennas or base stations that may be relatively minor in terms of the overall ecosystem. The problem has been up to now, much of that spectrum is dominated by DOD, which means if you're in the civilian business, you don't really have an incentive to build infrastructure that operates with that type of spectrum.

If we can at least have sharing, as I think the defense secretary said yesterday or today, then there'll be an incentive to start to build or increase investment in the kinds of infrastructure that would apply at that level of spectrum. And again, that helps reduce the advantage that Huawei now has. Finally, RSA isn't the only thing going on with RSA. Being the largest cybersecurity conference in the world, the event creates its own gravity, pulling other events into its orbit.

One of these was the Cloud Security Alliance Summit. And Scott Ferguson, ISMG's managing editor of news desk and our roving reporter of the event, caught up with John Yeoh, global vice president of

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on March 6, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!