'Wartime' Security Mentality Revisited episode artwork

EPISODE · Jan 15, 2020

'Wartime' Security Mentality Revisited

from Info Risk Today Podcast · host InfoRiskToday.com

Five years ago, cybersecurity executive Dave Merkel called upon enterprises to shed their "peacetime" mindsets and adopt a "wartime" stance against persistent cybercriminals and nation-state actors. How have they risen to that challenge?

Episode metadata supplied by the publisher feed · Published Jan 15, 2020

Embed this episode

NOW PLAYING

'Wartime' Security Mentality Revisited

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Hi, I'm Tom field senior vice president editorial with information security media group I'm talking today about the wartime mentality and it's my pleasure to welcome to the studio Dave Merkle He's the CEO and co-founder of expel David's pleasure to talk with you again Yeah, I'm great to chat with you. Thanks for having me on David's been a while since we spoke and tell me a little bit about expel in the work That you're now doing with this company yeah, we started expel back in August of 2016 and the problem We saw was basically that the security talent shortage is really not going away anytime soon and when I think about that problem Problem right problem on bad guys okay problem to probably I would say the pace of the change of the attack surface you're protecting problem free Can't get anybody or can't keep them and the markets that grew up to address that You know the ancient legacy one was in the MSP market has been around for a while And there's been a variety of other managed security services that really aren't quite fully hitting the mark when it comes to helping See so's deal with the fact that you got a higher bunch of security operators. You want to be serious It's 24 seven and the quality level in that market is just a bit small I mean you know what there's there's an opportunity here to take a more technology-centric problem provide a comprehensive managed offering And really solve the problems he says one salt use the investment you've already made get you all the way to done all the way to Answers in remediation and provide high value at high scale And so that's why we started expel with it to take a swing at that and you know We're three plus years in and I have to say having quite a bit of success David we last spoke it was five years ago people with fire right at the time you would ring concerned about the vulnerability of Enterprises being mired in what you call the peacetime mindset. Have you seen positive changes in the five years since you know I have and actually Frankly expelled wouldn't exist if those changes really weren't occurring and what I mean by that is Increasingly customers do care about having more active mindset about protecting themselves And there's not anybody else's gonna just do it for them And I think there's a much broader acceptance and understanding that there are bad guys They are going to attack you they will be a widely varied specification But don't be surprised if it's an issue say and that's less of an argument these days There's so much broader awareness and so so that's a positive another positive I see is the level of dialogue particularly in enterprise businesses And I'm gonna go ahead and define that like if you say a thousand employees and larger starting to get some serious revenues I'm really counting that as some sides of enterprise some sides of long-term going concern that probably has or could have depending on vertical Security mindset the conversations that they're having are more senior in the organization or potentially in the boardroom Board members are sometimes proactively asking questions and when that starts happening It really does drive a change in mindset a change in attitude about whether or not the things you're doing are effective So Dave, what's the reason what we talked about five years ago?

What's the difference between a peacetime mindset and a wartime mindset? I guess I'll add to that What does it matter to the system or sure the thinking back to our conversation? Oh gosh five years ago Five plus years ago the analogy I used was with this I was comparing just from my own experiences peacetime military versus wartime military behaviors and in peacetime military It's not super efficient You are focused on readiness But it's governed by drill and training regulation and there's an opportunity for a lot of extra sort of kind of bloat and effectiveness Because there's not a true bottom line because the business you're in is making more and there's no work going on in a wartime military It's a very different mindset at least a wartime military where you've been given clear military objectives in that case You have a bottom line. You've been told what the orders are It's you know get up this hill by this date with these resources and that tends to drive a lot of Inefficiency out of the process and the very critical important things tend to happen in a much CRISPR fashion and what I was really referring to was the I'm having to see so it's sort of a peacetime and I'm not going to be attacked mindset around security where you may be doing something for a variety of reasons But they may be hard to articulate and they don't drive a very crisp bottom line versus what I think is the reality of a majority of organizations today We're no good guys There's a bad guy somewhere that much of stuff and the fact of the matter is they're going to actively try on a regular basis to take it And that has a very clear line to to a wartime military unit where no you're going to practice the things you've preached And you're going to need to operation and try to count for the bad guy on a regular basis And I think that tends to bring to focus your objectives in a much much CRISPR fashion It also means it easier to have clear business conversations with the rest of the organization So I'm thinking back to 2013 when the fire eye released its first big APT report and that was 60 minutes news The world has changed significantly since then How are these threats obviously the threats and the threat actors have all particularly on a nation state level Yeah, I'll give you a couple of thoughts first of I want to mention besides the threat actors themselves is public perception Where it is kind of becoming regular news to your point when we did the APT report back in the day I mean, it was it was all over the place.

It was all anybody was talking about from a very extended period of time Now, you know, it headlined our comment that nation state xyz may be hacking us like that is now the common expectations So any one event doesn't have nearly the level of notoriety It's sort of the steady steady drum beat when I look at the attackers themselves and kinds of things that that we see going on At first Not a ton has massively changed a lot of the same techniques and approaches that we saw in the past are affected today For example, business email compromise fishing, you know credential stuff That sort of thing hacking the human remains a very very inexpensive and highly effective way to begin the early stages of a breach We are seeing more aggressive use of quote malwareless techniques things involving various aspects of PowerShell what have you And that's because I think a lot of security technologies and programs have gotten more effective at finding some of the heavier attacks of yesterday Or that may be involved a lot more malware a lot more malicious software code deployed in your environment No, pretty good finding that stuff and so attackers are trying to incrementally find quieter and quieter ways of of maintaining a presence But it's not through some transformational approach that has totally turned the tables on the defenders And lastly, we are seeing attackers adapt to new compute paradigm So as companies put things that matter in various aspects of cloud infrastructure and cloud applications We are seeing attackers go that direction attackers do look different in those environments The technologies you're using are different The security signal that you have at hand to process and try to do your job and find those attackers is different and the response process itself can be It can be different not radically different It's not like you've got to learn an entirely new discipline But you have different kinds of tools and techniques at your disposal just as the attackers do And so we're seeing some kind of beginning throws of adaptation As the threats move towards where more and more assets are being placed which is in some form of cloud repository via this application or So in response to the attackers, how have you seen defenses and evolve and I guess I'll add to that How have you seen the mindset evolve? On a positive note, I've continued to see an evolution of frankly some pretty good security technology There is a lot of very interesting security product on the market The downside is in here I am a security vendor I've been a security vendor previously and we're trying to not be a part of the problem But I'm not going to sit on some more high ground and claim that we're not part of it The security marketplace itself remains really confusing And it can sometimes be very difficult to tell the good stuff from from the chat But there is a lot of very security product out there and a variety of domains to help with the problem The cloud world's got farther to go Let's just take simple examples like you know AWS for example So you run a bunch of stuff up there There's some positive developments Amazon themselves doing a really good job continuing to add to the security capabilities of the platform itself The product pictures a little bit more confusing and part of that is product vendors trying to understand What threats will look like and what kinds of things would be useful It's product buyers trying to figure out what use cases they want to solve for so that's in its early stages So there's some some more work to do there But that innovation cycle is happening and lastly I'd say around mindset the customers we would expect to care about having security that works We find by and large do I increase self-awareness and stuff, right? And you might go through a 15 minute conversation to get to the aha moment of oh, yeah, maybe we do I think that's very different today I might still have one of those conversations, but there may be one or two in 10 and eight of 10 are ones where The organization is always a little bit aware of the kinds of rest that might be interested in is trying to do something Maybe the right things maybe the wrong things, but something So let's talk about your space of it. What do MSSP and such as expel need to do to help organizations to one maintain That proper mindset and maintain appropriate defenses going forward Yeah, I think there's a few things that are really important If you're looking for a managed provider that managed provider really is to come to the table and get you all the way to done You know the managed service of yesterday where they would take 10,000 alerts and turn it into a thousand alerts and give it to you That's not really solving your problem So managed providers that are leaning all the way in to get you all the way to answers and here's an incident Who what when or why how and here's what you need to do to remediate Yeah, those are managed providers that I think are adding real value for the customers Second you've got to be transparent A variety of visibility and what that value is and frankly as accountable as just on frankly in real time customers already bought So if you roll into an organization and say hey, that's cute You've got this kind of firewall on this kind of endpoint But you need to re-buy all the security kit before we can help you like it's it's 2020 What do you manage to secure about cloud in a cloud native way if they don't understand it intimately if they can't bring a playbook And help you understand the problems that you should be looking to solve Then they actually aren't in the cloud and don't know what they're talking about and I think in 2020 that's table stakes Fair points Dave.

I appreciate your time and insight today. Let's not let another five years go by before we speak again That's great Tom. Thanks so much for having me again We've been talking about the wartime mentality that is speaking with Dave Merkel He's CEO and co-founder of expel for information security media group. I'm Tom Field.

Thank you very much

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on January 15, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!