Welcome to Cybersecurity Insights, the podcast for the CyberEd.io Learning Community. Our goal is to bring Cybersecurity practitioners the latest and most relevant education and training to upskill and dive deeper into topics that matter in today's modern Cybersecurity world. Good day, everyone. This is Steve King.
I'm the director at CyberEd.io. This podcast today is featuring Brad Brooks, the CEO of Senses, who is a market leader in the Attack Surface Management Space. Prior to this assignment, Brad was CEO of OneLogin for five years or so and then spent three years as a marketing head at DocuSign. And then prior to that, four years as the chief marketing officer at Juniper Networks.
All in all, Brad is over 25 years of experience and technology from consumer and business applications, which included nine years at Microsoft running both the Consumer and Commercial Windows product and business unit, and two years at Enron as the general manager. So, welcome, Brad. It's great to have you on the show. Well, thank you, Steve.
Yeah, I'm going to check this out. We're all getting old. Tell our audience, if you would, as we get going here, a bit about Senses and any parts of your background that I may have missed or butchered. Yeah.
Well, from starting with Senses is, you know, it's a company that's been around since 2017 time frame. Start out as a doctoral program, graduate program by five individuals at the University of Michigan, of which the founder was the writer of the ZMapper code set. So, if you know the ZMapper tool around the standing engines, he was the original author of that and created a baseball company and it's kind of done from there since that time frame. We do two things.
We do what you talk about, Attack Surface Management. We also do a set of data for, so allowing customers as well as government agencies to go out there and find threats on the worldwide internet. Well, that's great. You also published recently, I think recently, a 23 state of security leadership report.
What were the key takeaways from your point of view as part of your observations there? Yes, we did. We did publish that. And, you know, there's a couple of things.
Number one is, I think with all these types of services, a lot of times the most interesting stuff can be found at the edges of the numbers. And one that stands out immediately when you look at the data, the first thing, which is 93%, so let me back up a minute, is that this is companies that have employee sizes of 5,000 or more. So these are not necessarily small companies. And there was some 100, including in the survey from the United States, Western Europe, Australia, et cetera.
And getting back to the edges of the numbers is that 93% of their survey response responded and said that there was a successful attack on their infrastructure in the last year. 93%, I mean, just think about that first. Isn't that amazing? Yeah.
Yeah. And the key word here is successful attack, which means somebody got in and got some across all of these companies. Right. Not small companies.
These are the ones that have staff, have tools, et cetera. The other interesting thing about that is that you drill a little bit more into that number. 53% said that a successful attack had happened two or more times in the last year. So it just goes to the level, the pace, the sophistication of these attacks and what's happening to these customers right now.
That raises the question that I wake up every day thinking about, which is what are we going to do? I mean, I hate to put it that way, but I'm not a pessimist. But boy, the weight of the opposition, if you will, it feels like it increases every day. And if you look at move it and what is going on with Microsoft and as you're AD, and it's just slate of vulnerabilities and they keep coming out of the woodwork every day.
And, you know, we're talking about the most widely used software product on the planet. It feels to me like, you know, no one cares. This is like a, to me, this is like a whole of government, whole of global government kind of a problem that needs to be addressed and it just isn't happening. So what do we do?
Yeah. Well, I think you hit on several things there. Number one is, and let me bring it all background in the end to what we do. But first off is you talk about the consistency or the pace of these exploits.
We're working with our U.S. government customers about identifying the federal agencies that were impacted by that. We put out a report right after that happens of locating several thousand different instances of compromised movement installations across the globe and the specific companies that were having it. To your point is that when one of these happens, it happens on a big scale.
And yes, we've got a lot of legacy code out there that was written years and years and years ago that all code is written by human beings and therefore it's going to have mistakes and eventually somebody's going to find. And I think the first thing is to think about this is it is not going to be if this is a disease of the Internet. It is not a disease that is going to be cured. It's a disease that's going to be managed.
And the question is like all of these things is how well are you doing to manage it? And what's your mindset in terms of going out there and managing it? And that's what you see also in the response of this server that we did, which is whether the leadership feels like they're equipped with the tools, they're equipped with the budget, they're equipped with the right people that they're equipped with. The right mental mindset is when you think about it is when you're under siege, again, going to use the analogy of a disease is when you're trying to find a cure for it and get into a managed state, as the mental state is maybe the most important to that goes to these organizations that can't find the talents.
They're constantly under attack and it's really showing up in terms of their mental health as well. So getting to your question about how to solve it. First and foremost is that we've got to come up with some more common practices is only solved by a community and it only solved by us working together. And some of these enforcement actions that have happened where we're going after CISOs because of how they've reported certain things, I don't think it's actually helpful towards getting information out.
The first thing is you've got to share this information. The community needs to share with one another. An exploit is happening. There's something new is happening where you can see these things happening.
You've got to spread the word. And so anything that detracts from that, either from a regulatory standpoint, enforcement standpoint, I don't think it's helpful. The second thing is that you've got to have the right tools. And why we've placed a lot of emphasis in the last 10 years around putting access management controls thinking about zero trust.
That's really more, again, training the symptoms rather than going after some of the more underlying tasks. And that's where new tools, tools like what Census provides, which is giving more visibility. You can't fix. You can't go after.
You can't remediate. If you don't know that it exists. If you don't know that a certain thing is in your environment because of shadow IT's fall where you don't know that an old marketing server that was held for an event three years ago is still connecting back into your environment and giving an exposure point. If you don't know that a bit bucket that you just set up an Amazon is configured wrong and is now exposing a bunch of PI information, you can't do anything about it.
And so really this new wave of tools and investment that's coming in around the BC community around giving that visibility is absolutely critical for folks to be able to operate. I also think that AI is going to play both a benefit and a curse here. As AI tools will be used by bad guys to immediately label and find vulnerabilities quicker. They'll be able to go after this one of those faster.
But taking those same types of tools and automating responses at least at the basic levels around an exposure. Hey, I see a server has got this particular type of issue. Automated taking it offline or putting access controls around it immediately before anything else happens and can do that in an automated way. I think that these generative predictive models are going to be very helpful in terms of machine learning and helping assist these understand teams to go after these vulnerabilities.
So coming down to number one is don't think of it as a problem that could ever be completely solved. Think about it as something that needs to be managed. Think about it from a mindset that I can get on top of this with the right sets of tools. And then think about it is to do I have the visibility?
Do I see everything that's happening? Do I have a good perimeter set up so I can see the attacks as they occur? And then have I optimized my infrastructure using automation tools and machine learning others to automate the response as much as possible because things are just going to be coming at me so quickly. Yeah, all of that makes sense.
I guess that my view is that we have a CISO community that isn't as equipped as they might be to deal with the kind of changes that you just alluded to and we're talking about and generative ISC obvious one. So I've got 450 clients who are the top cybersecurity vendors in the space. And we're constantly doing survey work for them and we've got a huge network of CISOs that we communicate with all the time. Every time you talk to them, I always walk away thinking, well, why?
If you know about company X and you know that that solves this problem, why haven't you implemented that? You must have, well, you've been in this space a long time. That must drive you crazy. I mean, if you can't figure out that you need a tech service visibility, it's hard for me to even make an eye contact with somebody saying, I'm not really interested in that.
And why is that? How do you not be interested? You know what I mean? Yeah.
I completely get it. I guess part of the great here is that you either get frustrated with human condition or you understand it to what it means to be human and understand that sometimes you get overwhelmed and you can say, but hey, wait a second, you're supposed to be professional. You're supposed to be the person in charge. You're supposed to be doing these basic activities.
But I think again, it gets to, like I said, some of the data points on the survey around mental health is that well over 70% of respondents are very highly concerned about the mental state of their teams as well as them individually. People just do funky things on their stress, right? It's just back in addition. And there is no more stressful role out there right now than the CISO role.
They used to be a CMO and the CMO had the distinction of as part of the executive leadership team having the shortest tenure of any member of the executive leadership team. CISOs still, for the most part, don't rise to level executive leadership team in a lot of companies. But when they do, they're tenures even less than a CMO now. Again, it goes to the stress of the job and just almost the impossibility.
You don't have visibility. You don't know what you're trying to defend against. Yeah, shame on you. But at the same time as how do I get there?
How do I find these tools? That's the question that they're all asking. Yeah, of course. And then the Joe Sullivan verdict didn't, you alluded to that, right?
It did not only didn't help, but it hurt significantly, right? I mean, I hope he wins in the appeal, but it felt to me like a vindictive legal event that was staged by the FTC for some purpose. And I don't know what it is, but somebody up there doesn't understand the ramifications. Well, it's going to stop best practices sharing.
It's going to stop sharing with the officials. It's going to stop sharing with the enforcement agencies. It just does not help. Right.
Right. And then if I offer you half an hour for you, you know, half an hour for you to go to the CISO at X, Y, Z and told you that you have personal liability or fiduciary, you actually have a fiduciary like a board member. I'd be like, I mean, if I were the candidate, I'd be like, yeah, I don't think so, you know? Yeah.
I don't need that personal risk in my life. It's just not worth it based on the state of condition. I mean, going to jail for company X for doing what you thought was the right thing. And that's what I believe Joe did.
Maybe, yeah, it makes no sense to me at all. But yeah, and you're using the wrong incentives and the wrong motivations, obviously. But it is the reality, you know? So, you know, I know a lot of folks, and I was a CISO for six years.
One of the world's largest banks and back then, and that was like seven years ago. It was much easier than today because things didn't move as fast, right? So, you know, if a new technology sort of came over the horizon, it came very slowly, relatively speaking. And so today, you know, you've got, it changes every day.
The threat landscape changes, the profiles change the technology to both, you know, to defend and to discover and to get visibility, all of that changes and stuff. I don't know how you can possibly have time to do the job any longer. I mean, you know, we try, we're an education, I run the education division here. You know, we talk to companies all the time about, so like, why aren't you doing this?
I don't have time to manage it. Yeah, well, that's why we've got a managed services version. But nonetheless, that's the answer all of the time. You know, who has time to do this?
So, it makes it very, very tough. It makes it very tough. You know, we talked about the number of successful attacks in a data point a little bit earlier. And the point about those successful attacks is they are going to run into a monetary value and maybe rise to the level of materiality and therefore rise to the level of the board and for decision.
And the question is, well, is it material? The next thing is do I disclose it? If I disclose it, do I have to disclose it to the SEC as well as the FTC and others? Or do I have to, do I want to keep it buried?
Do I push it under that minimum threshold of what's a material disclosure? And the CSAs are involved in these conversations now and they're being pulled into your point and say, do I want that job at any price? Now, I'm basically dealing with some of these matters at this level that I haven't been trained for or the compensation system to overcome that risk is just not there. And therefore, I want to be hands-off.
There's only so much that I want to know. And that's part of this problem that you talk about, Steve, which is sometimes you get frustrated with, hey, the tools are out there and you're not even trying to engage with tools and put them in place. But there's also the, do I want to know what I don't know because if I find out about it, do I really have the capability to handle the response to it? And then if I don't, does that put me at personal risk?
And so it really is quite a conundrum. I feel for these CSAs, I really do. And the other thing, too, is let's face cyber security industry over the last one of yours does not also have the best track record. There's been a lot of snake oil that comes out through the years in terms of providing protections that really were not provable or didn't exist in the right way.
Or stuff that was sold to early that really wasn't providing the level of protections that customers thought. And they got better over time, certainly, but wasn't quite there. And I think for all of these reasons is that if you're a CSO, you're cynical, you're hyper-vigilant, you've got an IIQ, you've got an understand team. Budgets are coming your way.
That's the good thing. They continue to prove that out. The budget's not shrinking. But you also really have to have a mindset.
Again, I'll go back to that word, a mindset that you can have confidence that you can go do this. It's also one of those things where somebody really feels completely confident about doing this job these days, that you've got to question whether they're blowing the job because they're probably not talking about that. Which part of this note you understand? Exactly.
Right. As we're talking about, you've been in marketing a long time, particularly in cybersecurity. What's your take on the current state of cybersecurity messaging? And I mean from a vendor kind of point of view?
The question is kind of like, what do you think CSOs want to hear? And how do you get their attention from a positioning messaging point of view? Yeah. I think first off is that this is my comment right in general.
Certainly in cybersecurity is still too much of a focus on the features, speeds, and feeds conversation, like X, Y, Z, X, Y, Z. And the reality is that the CSO doesn't need X, Y, Z. What they need is they need it to do specifically what they're asking it. They need to do it in a way that's provable.
And they need to do it in a way that they can then share that outcome at the senior or board level. And still not enough products do that. There's a lot of products that focus on the practitioners, the daily users, which are fun. But then elevating the, hey, I stopped that attack or, hey, gave that visibility.
And actually being able to prove that with the products, you can prove that in the messaging and actually explain that at a value level, rather than doing it faster, cheaper, smarter, et cetera, is that faster, cheaper, smarter will happen the next day will happen the next day. It's kind of a table stakes, but the messaging really needs to elevate to you. Hey, how do I give you some relief of that anxiety around the role? How do I build some of that confidence or more importantly, how do I prove it to you?
And how do I allow you to prove it to your board, your CFO, et cetera, as you're going into those budget conversations and saying, this is why I need this product to do this. And that's where, again, I think a lot of our messaging, if you look across cybersecurity, it does not go to the value. It goes to the feature value proposition and maybe sometimes the economic value proposition, but it doesn't really go to the core value of what they're getting out of it. And at the end of the day is we just spent 25 minutes talking about emotions and the feelings that you get in these leadership positions.
You get a product that can actually give you a message to you that you are going to feel more confident. You're going to feel more qualified in your role because it is doing what it says it does and it proves it. You're going to have a willing product that CFO is going to keep calling up and asking more about. And this is also a tight community.
It's one thing to find a product that works. They're going to be sharing with all their friends and it's going to move very quickly. Yeah, exactly. And so I'm always amazed that why is it that so many marketing folks don't kind of get that.
Don't grok that. I mean, I don't know how it happens, but you look at what I mean is I don't know internally, you know, a company acts out of that manifests itself exactly. But you look at the messaging that comes out of 80, 90% of the vendors. You're right.
And then you're all featured space and space and get nothing to do with outcomes, you know. I don't know. You ran both consumer and commercial for a pretty decent side. My guess is a product that we all know.
Tell me, do you perceive there's a difference in marketing to one buyer versus another buyer in business versus as a consumer buyer? Yeah, Steve. I do. I don't see that there's a difference, but I see that there's a difference in the type of marketers that go to that methodology.
I'm very intentional in my marketing teams. And this has been ever since I got Microsoft, is running B2B marketing functions, I look to folks that have done consumer marketing. And the reason why is consumer marketers are much better at terms of defining their markets as around the individuals and talking to the people, which means you got to quickly get out of that speeds and feed conversation and talk more to the value of if they're going to get out of that product. They think about it that way, and they communicate it that way.
And therefore those that specifically have had some kind of background in consumer marketing, I find I'm much more effective when I come over and into these B2B marketing roles, particularly in these technical marketing roles. Too often, you get a lot of engineer crossover coming into marketing, which is fine. I'm not gonna go to what they know. I'm not gonna go to the speeds and feeds conversation.
Getting a lot of these things to the background, how do you differentiate between Cheerios and CrossFit flakes? You're not doing it based on the grains or the field that the week came from or the quality counts of X, Y, or Z, what you're doing is you're going to have more visceral, more value emotional-based conversation. And people that think that went very effective in the technical B2B marketing space, and you're not about them. Yeah, I mean, you're selling, it's kind of the D2H thing, right?
I mean, you're selling to humans in both of those equations, correct? As I keep reminding my organizations, entities don't buy products, people do, and you don't market them and talk to the people and make it work their while, make them understand the value to them how they are gonna get something out of it, and then the conversation changes. And the trust level changes too, is because now they believe you get them, that you understand actually what they're going through, which is speeds and feeds conversation is never gonna get you to do. But the amazing part to me is that, we don't seem to know that as an industry.
Do you remember the Apple Silhouette ad campaign that- Oh, I do. One of the most effective, I shouldn't say best, but most effective campaigns in history and jobs initial reaction was the one you just described. Hey, wait a minute, this doesn't say anything about the product, then of course, the giant day team said, you're right, Steve. It says everything about how it makes you feel.
Yeah, we got behind it. It was David Roman. I was working at Apple at the time. He was a good friend of mine.
It was right, yeah. Yeah, yeah. That was one of my all-time favorites. This is such a great illustration of what we're talking about.
And they finally capitulated through in the 10,000 songs in your pocket, which is also a fabulous tagline. And on they went to billions of dollars in sales over three months or six months period or something crazy like that. But the last question that I'm conscious of the time here, Brad, is the, I know you're a risk IQ is an old client of ours and we know a lot of those people pretty well. And they had this kind of, I'll call it, kind of an open source, free collective that I think you guys have something similar, whatever you want to call it, a crowdsourced attack, vulnerability forum or something.
And I know they had like, I thought they had a million members or something at one point in time. They use that as a free product for their client base, which seemed to me to make a lot of sense. Do you have a community program? Is that similarly constructed like that?
Or is that, that's the purpose, is it not? Yes, it is. And we do have a community. It's got several tens of thousands of members that are showing, we're not quite up to a million yet, but we're definitely growing very fast.
It's global in nature and two things around it. Number one is they get free access to our data. And then come in, they can search, they can use our search tools. We have a community forum where we can engage with those users out them.
We've got specifically engagement with universities around the world as well as in their research teams to engage on threat profiling, labeling of assets, identification of risk, et cetera. But we use those all as feeds as well as that, when the community sees something interesting. They see an anomaly, they see a command and control network that's under construction. They see some of these other things that are going on as they feed it back to us.
And then we can put that into our tooling and for the customers of our tax service management product, they immediately get the benefits of us recognizing issued within the environment. One of the areas where that popped up quickly was how fast we could respond to the VMware Hypervisor flaw that was at the beginning of this year, is that we started recognizing a lot of these issues within the community in our research before, it was actually highlighted as a zero day export. And we could get that information out to our festival users based on this research the community was finding about some activity that we saw. So yeah, we've got this base, we've got this user community, we put it together and it's a big part of both background and company starting out as a college research project.
But also our feeling of our engagement community is that we're getting some benefits of our data and we're turning it into a commercial business. But the only way that we collectively get stronger is by sharing information what we see it and holding it back when we see major exploits or having our community identify some of these exploits and share them. We really want to encourage that as part of our product development. It helps us, but it also helps the community at large and helps us share information much more quickly.
Yeah, sure. And you end up with tens of thousands of products management team for, you know. You're going to speak back all the time. Yeah.
You better data, better labeling, better understanding. It really does help tremendously in terms of improving quality of product. Yeah, and to be fair, you know, you build yours from scratch risk IQ bot there. So that company had years to put together a million subscribers or whatever.
No, we are building one user at a time based on reputation and quality product. So that's how we do it. There you go. There you go.
Hey, look, it was great meeting you and talking with you. We have mind share on a lot of stuff here. And I'd like to do it again sometime, maybe a few months from now. And if you'd like to join me on here again, that would be great.
Thanks, Brad. It was really enjoyable for me. Steve, I really enjoyed it as well. Look forward to it.
And happy to come back next time around as well. Thank you. Great, thank you. And thanks to our audience for hanging in with us for another episode of our podcast.
And until next time, I'm Steve King, your host, signing off. Thank you for joining us for another episode of Cybersecurity Insights. You can connect with us on LinkedIn or Facebook or send us an email at social at cybered.io. For more information about the podcast, visit cybered.io or slash podcast.
Until next week, stay safe and secure. And we'll see you on the next episode of Cybersecurity Insights.