Welcome to Cybersecurity Insights, the podcast for the CyberEd.io learning community. Our goal is to bring Cybersecurity practitioners the latest and most relevant education and training to upskill and dive deeper into topics that matter in today's modern Cybersecurity world. Good day, everyone. This is Steve King.
I'm the managing director at CyberEd.io. And with me today is Lonnie Price. He's the vice president of Cyber and Information Warfare at Periton. They are one of the nation's leading national security companies headquartered in Reston, Virginia, and their focus in cyber digital cloud operations and engineering.
Lonnie's role is to lead the Periton's corporate strategy for cyber and information warfare. He drives the development of advanced cyber solutions across Periton's diverse portfolio of most spectrum cyber capabilities, both offensive and defensive. Ops and Information Ops has extensive experience in cyber and technical countermeasures and counterintelligence, counter-terrorism, threat analysis, cyber investigations and forensics and emerging technologies. Prior to Periton's line search and senior roles in the U.S.
State Department, including 17 years overseas, and more than 100 countries managing security risks at U.S. Embassy. So welcome Lonnie. I'm glad you could join us today.
Thank you very much, Steve. I really appreciate the opportunity to be part of this conversation. Yeah, sure. Great.
Why don't we dive right in? I wanted to start by asking you what you thought the impact of the war in Ukraine was having on the cyber security landscape, if any, and how you perceived that part of that war that had been called a non-kinetic part of that war to be going. Well, I'll tell you, Steve, while the Russian criminal invasion is egregious and has caused a lot of misery and destruction of lives and property, there are some technology lessons to be learned about what's happened over there. Starting with the Viasat hack on day one of the invasion, where the Viasat's modems were crippled by Russia's acid rain malware, keeping tens of thousands of folks from accessing the internet via the satellite infrastructure.
The intention was to disrupt operations in the Ukrainian government and interrupt their decision-making. Later on, we saw the synchronized cyber and kinetic attacks working together, right? The cyber attack of Ukrainian state power company combined with the shelling of the bombing of the nuclear power plant. Again, the combination of cyber and kinetic disrupting operations, disrupting decision-making and quick response and so forth.
But I'll tell you, the modernization is a positive, let's say, lesson and a positive outcome that we've seen from the conflict, when Western tech firms came in and really, really helped out the Ukrainian government, state operational, state resilient, they helped them modernize and move a lot of their information assets and their infrastructure to the cloud at scale and at speed. I mean, it was absolutely a technology modernization success story. It not only, again, gave the Ukrainian government resiliency in their operations, but it also enabled the hats off to Google, AWS, Microsoft, and others. I mean, it enabled them to offer the Ukrainians that cyber-defensive service of protecting those Ukrainian assets on those platforms.
They were vigilant, they were watching the service providers watching for anomalous behavior from Russians or sympathetic hacking community, watching for that behavior and showing it down when they observed another platform. So, if it's a lesson to be learned, Steve, it's that modernization is the key. Moving to the cloud, we'll help with resiliency and the cyber security, the cyber defenses of your protector assets and infrastructure. Yeah, and I guess to say nothing of Elon Musk's satellite system as well, which kind of took the place, I think, of that system they destroyed.
Is that true? Absolutely, on the power of technology, right? I mean, his, I think, 5,000 terminals that he loaned to the Ukrainian authorities, essentially provided uninterrupted comms through that satellite network. I mean, again, Western tech has offered him for coming to the aid of the Belieger Ukrainians.
That's unique in history, I think. As soon as I said that, I thought about him, about Henry Ford manufacturing trucks for the Nazis during World War II, perhaps that's similar, but with the wrong side, I have never seen that happen or anything sort of like that happen at crossover, at least that I was aware of. And I, you know, that usually these things are, as you well know, I mean, this is your daily weight, this is what you do for a living, and these things are always kept from those of us who just wander around the planet here. I'm wondering what's happening, but these things are usually not shared in the way that we now know that all of this occurred.
And that was a real crossover between private industry and public to help the war effort, essentially, on the Ukrainians behalf. One thing that I definitely learned in, you know, 38 years of government service is that we could not accomplish our missions without strong industry partnership. That's one of the things that's gratifying about my job now with Caraton is that I know what I used to need and require as a government executive, and I'm able to help the company tailor those solutions and provide what's needed. And this is not just, you know, the State Department, of course, and other civilian agencies, this is military, this is intelligence community, law enforcement and so forth.
Strong industry partnerships is absolutely key to mission success. Yeah, sure. We set aside national security as a mission for a moment. I think it's easily fair to say that we're not doing a good job winning the war that we're in right now as private industry.
I wrote a book called Losing the Cybersecurity War and what we can do to stop it a while ago and identify five different theaters of engagement where we are getting trounced and identified the reasons for that and things that I thought we needed to change that. But how are we going to do this differently going forward? I mean, you know, from my point of view, there was no magic bullet, but I would be curious as to your view of at least the direction, either technically or ideologically or philosophically or however you want to look at it leadership-wise. Steve, I think I like to get down to the basics and not make it so complicated, right?
I think part of awareness and education are huge components of cyber defense, right? I think the messaging coming out of the federal government specifically that says an infrastructure security agency, right? That's multi-factor authentication, right? And zero trust.
These are some very basic principles that need to be applied and two years ago this month, right? The executive order for cyber came out and, you know, mandated multi-factor authentication. This is multi-factor authentication. Many homeowners know that, you know, MFA on your banking account, your financial or health or anything that's important to you online, MFA is the way to go.
And once enabled, you know, prevents, I mean, as you're well aware, you know, 85, 90% of potential compromises. Yet, Steve, I'm chagrinned at so many, while it's relatively easy for the homeowner to implement MFA on their devices and tablets, right? It can be extremely difficult for large organizations to implement MFA, even if it is mandated by an executive order, right? I mean, large amounts of legacy applications, legacy hardware software is very difficult.
Sometimes they don't have the resources to move very quickly, to modernize with the new new infrastructures, perhaps moving more and more steadily to the cloud. The basic Steve, multi-factor authentication and implementing zero trust principles is so key. And, you know, fortunately, there's help, right? I mean, you know, my company, Apparathon, has been helping large organizations implement zero trust years before the executive order ever came out.
It is so fundamental because we no longer are watching for adversaries cross a perimeter to understand that we're being attacked. The perimeters are shifting. You have to nowadays trust no one at no time and at no place, which is essentially zero trust principles. And it's just so extremely important.
Yeah, well, I agree. And we've been, we've been flogging that here for the last two years as big zero trust fans. And the problem is that somehow we've managed to shoot ourselves into what, you know, if you look at the current, I was just looking today at some analyst observations from RSAC. And they all concluded that, you know, a lot of yada yada about zero trust with corporate level, but the facts appear to be that only 7% of companies that said they wanted to do it are actually doing it.
And then they point to all of the usual suspects in terms of the problems with implementing it. You're absolutely right. I mean, in my mind, there's no excuse. And you said resources at one point.
I'm sort of kind of sick of hearing that excuse. You know, you're either secure, you're not secure. You're not secure. You need to fix that.
Whatever resources are necessary, you need to spend money to do it. There is no alternative. So I don't actually get any of that. I do understand why if you misunderstand the objective strategy architecture framework, however you want to think about zero trust expression, if you misunderstand that, then you can, you can be overwhelming to you.
But the guys that we formed the cyber theory Institute with, which are, you know, kindergarten Cunningham were crystal clear about what what an incremental service implementation has since got nothing to do with everything that people are complaining about. So any of that, you know, if you want to do it, it's there to do. We know a lot of companies that have succeeded, but 7% are very depressing number after a couple of years of hard work with this. Yeah, big size, Steve, completely in agreement.
If you were to look for our biggest, the company CEO here, what would you say that it is in terms of, you know, from a, why can't we get to cybersecurity in the in the literal sense. I mean, when Achilles here, I would focus on that, you know, our cyber defenders need help, you know, the humans that are the analysts and the operators threat hunters, the incident responders, the humans need a lot more help. We've installed sensors and appliances and we're bringing back data from all corners of the, you know, the IT ecosystem logs from endpoint devices network appliances firewalls, you got telemetry coming in from multi cloud environments. You know, if it's real time streaming, some of its massive data dumps, it's an ocean of data that's coming back and an all for a good reason, right, to increase operational visibility on what's going on within your infrastructure.
Not only the security aspects of what's going on, but also, you know, the health of the network, which can certainly, you know, point to security issues. All of this information is coming back at great velocity in great volumes and in like widely varying formats, right? I'm not talking about just the information technology networks, there's the operational technology networks, right? And control systems talk about widely varying formats, right?
So all this stuff is coming in to these, you know, poor beleaguered and few too many cyber defenders, they can basically drown in all of this data. And so what we need is better data management, right? All of this stuff needs to be properly managed. And the tools, the cyber analytic tools that is used to analyze this data to query this data to extract from that data, actual information and intelligence about adversarial behavior, right?
Those tools need to be developed to go hand in love and match well with that data management platform. I mean, simply, the metaphor I like to go back to Steve is, you know, your garage, if the garage is very well laid out with drawers and shelves and a bench and a tool case, right? And you store things in your garage in an orderly manner, then you can later extract from that storage, right? And have the utility of whatever it is you need.
But you can't just throw all this cyber data into an ill-prepared, you know, data management structure and expect to get useful intelligence out of it. There's help in this regard, right? I mean, that's one of the things that, you know, Perathon does. Today, we operate the largest US government data management platform in existence, and we helped to architect and build that platform.
You need the professionals that know how all the bits and pieces fit together, how the data flows, how it needs to be structured and enriched and curated from collection and ingest all the way through analysis to ultimately data sharing, right? Because sharing is what it's all about, sharing your conclusions and about some data. Yeah, data is drowning our cyber defenders is, I think, our Achilles heel, and, you know, they're going to need help. They're going to need these tools to best be able to understand all the data that they're getting.
And I tell you, Steve, there's a very real fear by many organizations that we already have in our hands, in our data stores, evidence of adversarial behavior, and we haven't seen it yet. It's lost in the noise. It's essentially opaque until we have the right capabilities to fully understand it. Yeah, well, I mean, that shouldn't surprise anybody.
They've been in there for a long time. You know, SolarWinds is just one example, but I mean, we've had bad guys working in our networks for what seems like ever and collecting a lot of data, not for our benefit, but for their adversarial leadership benefit. And I guess that leads me to wonder, I have to ask the generative AI question too. If you do have this huge data model or do store, are you, I'm sure you're using, started to use generative AI to further enhance your large learning model around the stuff and parse it out by threat type or threat actor type and the rest of them?
Yes, Steve, we are absolutely venturing down this path, but I want to say, you know, it's got to be done with very due diligence, right? Because, you know, the PT for GPT is pre-training, so that means anything that is contributed in terms of queries or parameters or anything that anybody around the world is putting in to these generative AI applications becomes part of it, becomes part of the training, and is therefore accessible by anyone else on the planet conducting similar queries. So it's a really interesting time we're in with this generative AI, right? And I know for a fact that there are federal government organizations as well as industry are looking very seriously about the corporate and organizational policies that are needed to help govern employee use of generative AI, because you can put stuff into the system, the pre-training parameters that divulge sensitive things about your organization that is absolutely not copacetic, right?
So as much as this is an incredible tool, it can also lead to some unfortunate ramifications for some organizations. But very, I mean, extremely interesting. This is absolutely, as they say, one of the most impactful contributions to technology, you know, the smartphone and some even say, since the transistor. But clearly, there's a lot of research.
Well, yeah, sure. And I think that, you know, trying to do something about it at a regulatory or even statutory level seems hopeless to me at this point. You know, the genies out of the bottle, there's nothing that we can do about it beyond optimizing or leveraging that data that is already out there for our own proprietary purposes. So there are, I'm aware of several companies today that are already offering that capability as a service.
In other words, you know, I'm a commodity trader in Chicago or something. I want all of the, you know, I want the global data model, but I want to throw on top of that all of my data and I want that to be proprietary and closed. And yet I want to feed it every day with stuff from the outside. And that's the kind of service that they're offering, which gives that Chicago trader at least theoretically a significant advantage over his or her competitors.
And so I would imagine the same thing's going to be true, no matter what market you're looking at here, instead of trying to control it and failing or being worked around, because that's, you know, is far better than I do. That's how we do it. You know, why not go with the flow sort of and take advantage of what's out there. So that's just my view.
But these, you know, you say to me and sister, I'm not already, it feels like printing press to me, you know, and it's only been what four or five months and I've never seen product release cycles. A matter of minutes, you know, maybe this is the printing press, you know, we have this cyber ad IO platform that we've built. We're rolling out where it's part of our strategic initiative future. We're a lot of us are passionate about the fact that we actually don't believe that most of us understand anything about what it is we're doing or trying to do for a living.
And I don't mean that. That's not the fanatory, but it's the truth. You know, when you rush to satisfy business units needs for digital transformation, you've got to give up some knowledge about, you know, some leading edge technologies in order to get them in place in order to leverage that opportunity. And so, you know, hybrid cloud and Kubernetes and edge computing kind of, you're just not, you're just not going to know what the vulnerabilities and pitfalls are to configuration issues around that unless you spend some time studying it.
And what we've been trying to do here is build up a library of content that's very relevant, very current on demand that CSOs can use to upskill themselves around those topics since we're not expecting him to carry friendships and screwdrivers on their belt, but we are expecting to provide leadership around these configurations and the implementation of these technologies. And unless you, I mean, we saw, you know, Capital One is a classic. I mean, the fact that Capital One, which was such a simple breach from a mechanic's point of view, occurred in whatever was 2019, wasn't something, you know, relatively recently. It's just mind blowing.
That should never have happened. And you know, you'd say, well, you know, it's an idea problem. Well, it is, but it's also a knowledge problem, I think. And so what we're trying to do is make sure that we can provide the kind of training to folks that will actually prepare them to do the jobs that we expected to do in spite of the fact that, you know, there's more work than I think than any normal human being can do carrying that title around as CSO.
Oh, I completely agree. And a type of program is so very important. I couldn't agree more. And when I said, you know, our humans need help and spoke about cyber defenders equally.
So IT managers, my, you know, heart goes out to these folks because they're often understaffed, sometimes underskilled, and they're just running from job to job. They can barely get the green blinking light on the appliance they just installed going before they have to run to the next job. And they've got vendors selling them, you know, these appliances with, you know, sometimes all of the security features disabled so that they can, you know, integrate it much more quickly. All the while you got users clamoring for additional functionality and CSOs and CIOs under pressure to meet those demands.
So, yeah, your program, as described, is absolutely something that they need, our own configuration mistakes, you know, we're shooting ourselves in the foot. I see it time and time and time again. Our adversaries are gifted, heavily resourced, heavily motivated. They really don't need to be helped by us shooting ourselves in the foot.
So my hat's off to you. But you guys have appeared to me to put together some training and online education of your own that's kind of focused on the cyberwarrior skills development. Is that not correct? I mean, you've got tabletop exercises and, you know, taxims and hackathons and all that sort of thing.
That's absolutely right, Steve. I mean, there's great academic programs, you know, at the undergraduate level, across the, you know, the country and the better universities and those are fantastic. They're augmenting the students are augmenting their hands on skills with internships, with industry, like my company and government institutions, right? That hands on training is extremely beneficial.
When we can get these cyberwarrior candidates into our programs, we rely heavily on continuous learning, right? We get the folks together in communities of practice for cyber where the various skill sets come together, the offensive cyber operators, the defensive information, you know, warfare operators, right? They get together. They can cross pollinate your expertise lessons learned.
We bring inventors and researchers with the latest invasions. The tabletop exercises that you mentioned are absolutely fantastic. Steve, I've seen them. These are facilitated exercises, right?
A compromise. And then, you know, you walk through the incident response. I've seen it where a week was spent during for a tabletop exercise and within two weeks, there was a compromise by a nation state and the organization without skidding a beat, the incident response team, everyone absolutely knew their roles. They were all practiced up.
It was actually like phase two of the tabletop exercise, except it was for real, right? So they're very productive and helpful. You know, we do cyber attack simulations and get this product that our parrotton lab says has, it's called cyber van and it's a cyber range. And you can basically simulate any type of a hybrid network, whether civilian or military, wired or wireless, and you can, you know, conduct the simulations and also help prepare your folks.
The hackathon competitions are really neat. One most recently was actually called hack a SAT, right? In the fall, sponsored by the Air Force Research Lab and Space Force, where, you know, the hacking goal was to take over the ground station, right? And with that, command and control the digital twin of the satellite itself.
So, all these these kinds of activities are very helpful with the continuous learning that we, you know, we absolutely foster. We try to take this knowledge and give it back by partnerships with academia, right? I mean, we had a couple of Virginia schools, like Virginia Tech, George Mason, University of Texas, San Antonio, Dakota State, right? Great partnerships in academia where we actually have full time employees there working with faculty and students on active cyber programs to include Steve, classified facilities for government research and program work.
So we, it's very active and, I mean, that's the good news of the cyber workforce pipeline, right? It's very stimulated and very much active. The bad news is it's just not enough with skill set gaps in the triple digit thousands. I mean, we're going to have to be patient and until the workforce develops to fill some of the gaps.
And in the meantime, we're going to have to rely on technology to assist back to humans need help. Yeah. Humans need help indeed. Yeah.
So we should talk about that offline. If we figure out a way to partner there, we can certainly help expand your expand the presence of those capabilities. Threatboard is another product of yours that's similar to cyber and what is that purpose of the threat board? How does that work?
Oh, yeah. Threatboard is a single pane of glass for all of these data feeds that I mentioned earlier can be viewed again, trying to save the analyst, the human operator time, trying to give time back to that analyst. It is an ingestion of the data, right? And an enrichment of that data.
And it's weeding out duplicate data, erroneous data, and again, focusing on the important data that needs to be observed and adjudicated by an actual human. It uses artificial intelligence for that enrichment and national language processing, you know, for that absolute critical speed that's needed. And the idea with all of this data and the cyber analytics needs to understand that this is to not only identify that adversarial behavior, Steve, but it's the ability to predict it, right, to be able to predict it within the patterns. And that way I get ahead of the behavior, get ahead of the adversary and actually stop it.
Because as you mentioned Steve too often we're, we're finding out about the compromise weeks or months after the initial breach, after the lateral movement has happened, after the information has been exfiltrated or the operations disrupted. Yeah, threat board is one of our tools that we've developed. We've used Scaled Agile for our app development, or our DevSecOps, and threat board is one that's available now and is being demonstrated to our customers. Yeah, it's your customer based largely military right now, or are you keeping from him when I say military?
I mean, federal government, you know, level one contractor too. Steve, we have, you know, in our portfolio, basically, you know, seven areas that we focus in cyber space and intel, defense, health, citizen security and homeland security. So, pretty much you name it, right, the federal civilian executive branch, the dot gov agencies, law enforcement, intelligence community, and certainly military so we have an immense portfolio of customers and, and when I mentioned that cross pollination in our core cyber communities And that's a very gratifying part of my job is as a corporate VP for cyber, I can look across all of these customers and all of their their mission sets. And, you know, something that's working for the army, right?
Now we're on malware analysis or some sort of a cyber offensive tool, right? It might be very much fit the mission of another customer. I can help make those connections and foster the, again, the pollination of more customers finding use out of same tool. Yeah, sure.
Well, we should, well, let's make sure we talk about that sometime soon here. All right. Well, look, I know we're quite a few minutes after our, after our allotted 30 here, but it's been fascinating to me and I hope it's been equally fascinating to our audience. And so thank you, Lonnie, for taking the time out of your data, share your thoughts with us and your experience here on this podcast, Lonnie Price, the VP of Cyber and Information Warfare at Parrotown.
Steve, it's been a big pleasure. Thanks for the invitation to be part of the conversation. You will do it again, for sure. And thank you to our audience for spending 35, 40 minutes of your time with us.
Hopefully it was equally entertaining and engaging. And until next time, I'm Steve King, your host, signing off. Thank you. Thank you for joining us for another episode of Cybersecurity Insights.
You can connect with us on LinkedIn or Facebook, or send us an email at social at cyberf.io. For more information about the podcast, visit cybered.io or with slash podcast. Until next week, stay safe and secure, and we'll see you on the next episode of Cybersecurity Insights.