Catch Lightning in a Bottle – CISO Talk Ep 24
CISO Talk Master Class Pt. 1: While innovation is essential for businesses to survive and thrive, the rapid acceleration of digital transformation has increased the volume and complexity of new cybersecurity risks. It is not a matter of “if” but “when” a breach will occur. Although prevention plays a role in data protection, it’s simply not enough. CSIOs preventing cyberattacks can be compared to that of catching lightning in a bottle, meaning it is nearly impossible to accomplish. Organizations must put in place an effective response plan so when an attack happens, they will be able to identify and contain the security breach and minimize risk to avoid as much damage as possible. Join this panel of cybersecurity experts to discuss the evolving threat landscape, the role of CSIOs in risk management, how to minimize risk exposure by building a defensible position that allows for effective detection and containment of a breach and how to test the readiness of your organization if a breach occurs.
Check out parts 1 through 6 of our CISO Talk Master Class:
Transcript
com panel brought to you by Textron. My name is Cody J Brown. I'm the host of text strong learning.
We have a invigorating panel ahead. But first I have a few housekeeping notes to cover first. Today's session is being recorded So if you miss any of our discussion, or you'd like to rewatch The on-demand will be made available shortly after we conclude today's panel.
If you have any questions, we want you to go ahead and submit those to the Q&A tab, which can be found on the right side of your screen and for any additional comments or you just want to let us know from where you're tuning in. We want you to use the chat tab, we plan to keep an eye on that and be active in that chat tab today. So we hope to see you there.
And finally at the conclusion of our webinar, we will have a drawing for 425 Amazon gift card. So stick around. So our topic today is a cisotalk masterclass about catching lightning in a bottle and at this point in time, it's my pleasure to turn the floor over to Mitch to introduce the rest of our expert panel.
Thank you all for being here with me today. Wonderful. Thank you so much, Cody.
Appreciate having this great panel with us today and along with my co-host Matt Newfield. Matt. Good to see you again as always a pleasure match.
So let's let's say we'll do some introductions here and then we're going to jump into our topic. So I'd like to start out with JJ. Minnella.
Would you introduce yourself, please? Absolutely. Hi guys, Jennifer Manila JJ.
I am founder and principal advisor with vision security. So most of my role involves Enterprise security architecture, which is working with cisos and working with the technology operations teams to help kind of bridge the gap between security and operations. Excellent, Julie.
How about you? Hi, Julie, cullivan former CIO with responsibility for security. Also, Chief people officers Chief technology officer and have worked for several security technology providers.
So this is a topic that's near and dear and thank you for having me. Thank you for joining Chuck. Everybody.
I'm Chuck Kessler. io. Pindo makes software that helps.
Our customers make better software digital adoption and product experience Solutions. So very happy to be here and looking forward to the conversation today. Excellent and our originator creator of the series is joined us today Alan shiml my Cove founder partner for many years 20 plus years could be on a panel with UL.
Thanks for joining. So about yourself you I think you said enough it is it is It interesting different to be on the other side here. com Security Boulevard container Journal text Trump TV.
See so talk take strong research, which Mitchell's principle and I've been in you know in the security space. for a long time 20 plus years 25 years maybe and happy to be here today. Very good and I'm Mitch Ashley CTO of tech strong as well as principal with Textron research.
This is a special series and Matt. Have you introduce yourself in just a moment. This is a special thing.
We're doing here. She's so Talk's been going on for quite a while. I mean over a year.
Um, and Matt has has a talk as a topic of he's really passionate about helping other cisos, whether you're entering into the field you're in the midst of it. You know, how do we share and learn and help each other succeed bring up kind of the Next Generation all those things and Matt had this idea for a master class series. And so we have actually six episodes.
This is the first one we're kicking off via this webinar format life format. And we also have some recorded versions that will come out on Tech strong TV, by the way, Alan is start deck strong TV. So check that out too.
And then we'll conclude with another webinar live format in a few months down the road probably in juneish time frame. So I'd love for Matt for you. Of course introduce yourself.
Tell us a little bit about what the purpose of the series is and then we can kick off the conversation. So thank you so much Mitch and hello everybody. Again.
My name is Matt Newfield. I am the csio for Unisys Corporation and the title is really a combination on both the CIO and the siso and the joke. We always say is because neither is a full-time job, right?
So we we tried to combine them here and you know, what what really talking about. I spent a lot of time out on the road working with Cisco's working with cios, and I I got to see a lot of the issues that I used to deal with still deal with and all of the issues that you know, my peers in Industry were dealing with And as it was looking through all of my notes quite a while ago. I because I'm weird and don't sleep that much started to pull things together to see if I could find similarities and it was very interesting how similar everybody's problems were because we're all trying to boil this massive ocean of cybersecurity.
We're all trying to do these massive things and we were forgetting about some Basics. So as Mitch said, we have a six-part series and we are opening it up today and I'll talk a little about how we're going to handle today, but the other parts of the series we're gonna focus on security Frameworks and some of the importance of those Frameworks as well as dispelling some of the you know misnomers and some of the issues that people may have around Frameworks. We're gonna talk about implementing active response strategies.
How do you do that? How do you practice what does good look like if you're practicing an active response Strate? We're going to talk about the evolution of security incidents and one of the things you'll notice about this series and most of cisotalks.
We will talk about incidents and not breaches incidents happen. All the time breaches are the thing that happen after an incident and hopefully don't ever happen to you, but we're gonna talk about incident. And we're gonna talk about crisis avoidance and the importance of proper communication.
You know, we have a tendency in our field and I I used to be awful about this speaking the World of Fun. We are uncertainty and doubt and how we have to stop doing that jewelry. Remember that it's from a conversation.
We had a while ago and and how to actually speak to the business so that you were looked at as an advisor and a partner instead of what a lot of us are looked at is the the no person or the scary person or the the person who asked for a lot of money and as a hard time proving why that money was well spent So what are we doing today? Well, we have a panel of just massive experts here and we had some conversations prior to this and I'm really excited about their viewpoints. And what we wanted to do today was really focused our discussion around the evolving threat landscape things that we are seeing in the world things that we saw coming out of 2021 into 2022.
We want to talk about the role the CEO or head of security plays in Risk Management because that's a big one that a lot of people never thought of Cisco's playing a role in we're not in Risk Management. We're in security prevention or security implementation. So we want to talk about that and we're gonna get some advice from Julie and JJ Allen and Chuck on strategies.
They believe in on how do effectively detect how to effectively contain cyber incidents within their infrastructure. So with that said I think we should jump in and the way we always do this is I pose a big question to start and we're just gonna start having a conversation is you heard before if anybody that's joined. This webinar has questions.
There's a chat feature ask questions. We'll be keeping an eye on that most likely we will not do a ton of typing because it takes the focus off, but we'll bring those questions into the conversation. So I'm really excited about that.
So first question most of us speak to an executive team or to a board. I do five times a year for board and I speak to the executive team on average every single day and we talk about those big things that we need to keep our eyes on and it can't be everything. So every year we focus on a couple of big things that I want our executive team and our board really pay attention to when they're reading the news when they're reading whatever clogs to really hone in on.
So my question to our panel today is what's your big thing or big things for 2022 and I want to open it up to General who would like to go first. know what I'll go first. If no one wants to go.
Love it. so here's the big thing for 2022. The big thing is that it's a big thing.
And quite frankly. It's too big a thing for one person. I think a successful when I look at cisos today versus cisos 10 years ago who were glorified security Architects brought in to set up a security program and then they would demoted to like being a security admin with a seat.
So title or shown the door. Versus today see shows that are really integrated into the into the executive team and you know board level type of access is that this is such a big domain. whether we're talking about Application security which is a world unto itself encompassing deaf-secops and Dev and and all of these cool Technologies and SRE and all of that stuff.
Oh, we're talking about Cloud security or you know, it's kind of block and tackle and points and and policies response it this this domain has outgrown one person being able to truly have his hips or her fingers just in every pie a good seesaw today. They're big thing is to have a staff. That's going to allow them to really manage the domain.
To really accomplish the mission. It's more than a one person job. It's almost like you have to have the an office of the sea cell when you have one guy or one guy, who is the one person who is the sea so perhaps but they need trusted lieutenant.
Who can help them at the various? places the various domains the various You know different side. I don't want to use the word silos.
It's a bad word but the various different what's called battlefronts or you know, where where it's one hand on that Alan real quick. I'm sorry you've Pros for me for just a sec. It's not only internal but we'll throw it out there and it's part of some of the series we'll talk about later, you know, a lot of people that are in these roles focus on just the staff they have in their employee and forget about the Partnerships the Partnerships to me are absolutely 100% key we can only do so much because you get caught up in the day today, but we spend a lot of time talking about is building up trusted partners and I think a lot of people mistake the fact that Trusted Partners don't have to just be intelligence companies a trusted partner.
For example for me could be Julie. Spending time getting to know Julie so that we have a way to share information across organizations because one of the things we talk about on ciso talks all the time is we're almost same side of this. We're all friends, right?
I'm not in competition with anybody here. We we all have the same goals the same Mission we're all together so that to me is a is really important. So and I agree on here, but there's got to be a couple things Chuck.
What do you got? Oh, JJ was gonna I think jump into it. Yeah, Jennifer.
All right. I was actually trying to jump it. Oh, sorry.
No, I think. Matt I think you kind of want to get back to the to the To the original question, but there's definitely some threads in what Alan's brought up. So it's partnership outside your organization right now.
I will say that my experience is the ciso community in particular is one of the most giving communities that you have out there into your point right? There is no I'm not going to tell you what we're doing for this it is it is amazing how helpful and supportive and you just look at log4j and all these things how people come together to help each other and that doesn't always happen across other functions. I think that's important, but I also think the partnership internally Is so critical because the world has changed in terms of product is now the company like there the ciso doesn't have anything carved out.
They literally touched everything and making sure that those Partnerships are solid and strong and strategic but also more and more like Matt you've picked up some of those where it used to be about partnership and now it's like hey, why don't we actually have these organizationally aligned right so that we can really Drive change so I know that's not what your question was, but I wanted to pull those threads. Yeah, I wanted to pull those threads a little bit as well 100% agree from in terms of external Partnerships. I know we've had ice acts and things like that for years, but in the last few years, I've really got a tremendous amount of value out of I think I've got three different slack networks of cisos now that I interact with some of them are local some of them are national International but those communities are tremendous, you know, just sharing the, you know, the things that we're dealing with on a daily basis, you know, sometimes some inside information and things that we need to be able to keep an eye out for but just the camaraderie if nothing else is very helpful, even in some cases, you know relationships with cisos that are you know, our companies are competitors, but you know, we still work together.
We still collaborate so that that's wonderful. It's very empowering and it you know, I think it keeps me going some days the other side of it that I wanted to make mention in terms of internal Partnerships the concept of security Champions, I think is really key here as well. Yeah.
We have a team, you know, we want to have more security head. We're never gonna have enough security head count to sit in every single conversation that we need to be a part of so it's trying to build those Partnerships internally with whether it be an engineering or people team our sales team, you know, those folks that are advocates for security that want to learn more about security. I want to give them information.
Let them become our eyes and ears and some of those conversations that we can't be part of let them understand what the guardrails are if you're operating inside of these cartrails. This is fine. If you see something that appears to be maybe not quite in there.
Let's talk about it. So, you know, we're trying to do that as well trying to extend our team through the security Champions concept. so priorities right and you you brought this up earlier, like look it depends on where you are from maturity perspective small company big company, you know, who do you sell to right?
Like there's all these other things that play into where folks are are going to try to prioritize. I I would say I see a lot of prioritization around the continued compliance, you know challenges that even the smallest of companies are now being held responsible to, you know, be compliant around and that's just going to continue to Get tougher I think because you know of what's going on in the world today. There's always something new that the federal government's going to come in and say or financial services.
Look we need to amp these things up. So I think that's one thing that ends up taking a lot of capacity and then I think the other is still around visibility, right? Because the the amount of new Services New devices Every day there's something new happening and how do you make sure that you really have visibility to all those things?
I'll just throw those out but I know that there's many more so and I think I want to clarify the statement and I agree with you. There's never only a thing if I finally had to focus on one thing in the year and that would just be I wouldn't know what to do with myself. Most likely I'd be like, I think I'm out of a job because I don't need teams and partners to focus on a thing.
But you know, generally there's a top priority that we're all focused on and you gave two big ones visibility that's been something we've been talking about for years. It's hard to protect that thing that you can't see right and you know, I think it's important to note out there. I've yet to see in my career.
Someone that has that can sit in a meeting with me or anybody else go. No. No, I have a 100% real-time visibility of every asset across my network unless that company is six people.
In the same building generally sharing the same space with the server room right there, right? I mean, it's just it's not Possible and if anybody invents a way to do that, I want to buy in really really early. So let me know.
JD I haven't heard you. Sorry, I was just gonna add really quickly on the visibility front and you know, the one thing actually we just recently went through our strategic planning process. We arrived at three strategic acres for our year.
So everything's gonna tie back to these three concepts. So the first one visibility second one is automation trying to take the Drury out of things to automate what we can the third one is assurance and that kind of gets into the compliance side of things. We have a fedramp program ongoing right now that is you know, getting through that first audit is, you know, probably my number one priority.
I hate that compliance is the driver there because I like security to drive compliance not the other way around but yeah, this those are my strategic anchor seems to align exactly what this conversation. Sorry JJ. Yeah, we're good.
I was laughing because Matt I'm you know having Helped and coming out of a relatively small environment. It's I think even even with the handful of people there's a small space. It's still not it's still not possible.
You know, one of them the latest phone system has a USB port on it the ecamp. It's impossible. But now I was trying to think of some clever way to disagree with Alan, but the problem is is that his statement is the entire basis of of what I what I do and what my company offers and that's that You know somewhere along the way so obviously, you know several of you guys have known me for a very long time.
You know, I came out of the network architecture and network, you know, like sis admin kind of side for forever ago 30 something, you know, 20 something 30 years ago and then started doing more security and then, you know Consulting and working with organizations and what I realized through all of that when we were doing these complex projects that were crossing between networking and security functions and compliance was that Most of the problems we had weren't technology problems. They were kind of people problems or more importantly relationship and Trust problems. And so, you know shifting and taking the technical knowledge and then sitting between these teams.
now watching, you know, all of the trends I'm gonna just call them trends like zero trust to me zero trust is a very real tangible thing. It's you know, coming out of network access control Solutions. I know, you know, Julie what is really familiar with that?
You know, this is just kind of the next iteration of an advanced Access Control Solution. That's a little bit a little bit more complex and granular but all of this. You know, you said you can't have one person doing it yourself.
And in fact, I just wrote a book with Wiley and although it's a wireless security architecture book. It goes through an Enterprise security architect standpoint of network security risk and compliance the role of what we do with with the ciso and with analyst mapping controls over and make it you know, how to teach a technologist to make some of these decisions because what I realize is that a lot of a lot of organizations there's you know, I don't want to use the word Silo either Alan but you know that there's a knowledge Silo if nothing else where you know, their nose down with the Blinky lights and the challenges is that we have a suite of products that are unbelievably complex, you know, just writing the the wireless book. So this is one One piece of one network component out of the the broad, you know rainbow spectrum of Technology.
The manufacturer's books for for one piece of their solution set is two 3,000 pages and and any any enterprise system a network system is going to have dozens of these and so you start to you know, you have these people that are just so spending so much time and effort figuring out where the knobs are in these products. They can't possibly do everything else and vice versa. And so this kind of idea of you know, building cross-functional teams in a meaningful way getting these people that have the Hands-On knowledge because there's really nobody better to defend the systems.
Then your senior CIS admins and our network network Architects for those type of systems same thing with application security, right the people that understand the nuts and bolts know how to lock it down. So I think you know kind of kicking down these doors and saying you've got to stop having these different. And build trust between these groups and people so that we can come up with Solutions ourselves.
As a group and move forward. Well, I love it tag on this a little bit because what you just said JJ and something Chuck said earlier. I think it's really important.
We have a concept that a lot of us talk about in Chuck. You said Champions, you know, you're talking about building relationships. JJ Julie is have this conversation Mitch and I talk about it all the time this for us in the size company I work for to be so How do I build out these relationships it's a business information security officer that we can start building out generally or looking to become cisos be part of that c-suite one day and that's how they're working their way up.
But those relationships are key. And you know when I first got here one of my big things and you know, I love the power of three. I'm weird like that as well, but Was building the relationships I could not be successful in my job if I didn't build the relationships and that was one of my key things.
I talked to our board about because the in my opinion and we can Discuss this the number one reason for shadow it inside of organizations is lack of trust and lack of relationships, you know, if Chuck you're viewed inside of your company as the person of no and hard to work with. Why would I go through you if I need something? I'll build it myself.
And I've made it even harder for myself because I'm not only the security guy to say. No. I'm the IT guy that needs to do what you need securely and if we don't have relationships.
That will really destroy a company and you know for those that are joining you feel free to put something in the comment. If you've got questions or you have a big thing. The big Point here is it's not a one-size-fits all you see some commonality and what we're talking about compliance will always be a big thing for us we go through more audits.
Then I care to talk about and Chuck if I can ever help you with fedramp. Just let me know, you know, we we would miss all the time. And now we have cmmc coming out where you're not able to do self audits anymore.
You know, you have the cmmc accreditation board that is working through that with the different variants there automated Discovery and response. It's a huge thing. Zero trust JJ we've been talking about for a long time and it's wrapping people's heads around it is a big thing that they have to do.
And for me one of our big things is third party risk, you know, we all talk about stuff but you know something that happened really recently is that long for day situation? You know and and I have to throw it out there even for us. I also have channels like you do Chuck where I talk to a lot of people we were able to do such a rapid response to that threat because of my relationships.
We we would find log4j sitting in someone's Appliance and I didn't hold that to ourselves. I literally know in case you have this Appliance. They have no documentation on it.
They're using this. This is what you need to do as a workaround already notified. Here's my ticket number.
Right and being able to have those kinds of conversations. They were flooding back into us really sped up our response and we see that all the time with things like ttps and iocs. And I think you were trying to jump in earlier.
I'd love to hear. You know, it's several Point says gonna jump in and I forget them, but, you know, talk about to see word. You know.
To me compliance. That's to see word. is the ultimate tale wagging the dog issue in our industry.
Hmm. I thought we were behind this then put this behind us. There was a time maybe seven to ten years ago where I felt compliance over took security.
In terms of what was seesaw and security teams major focus and what a setback that was for the security industry because we adopted a least common denominator because let's face it most compliance regs. They are least common denominator security. They're what we say in Vegas a fine beginning but it's not the end.
It's not the big Bay off. It's not it's not the way. They're the minimum we should be doing and when we focus too much on compliance.
We detail Wags the dog we focus on what is the minimum we should do and then when when when when crap hits the family oh, but we were PCI difficult. Why are you with disco? We were yeah b******* zero tries.
Go to real security that makes us secure. I was always taught that compliance is a byproduct of security if you do you're security, right? your compliance will follow right for the most part.
There's a lot of compliance think it's dredged up today to our compliance regs and quite frankly have nothing to do with technology and very little to do with security. Right, but they're in there because some politician or not even some bureaucrats some administrators somewhere some dude on a board decided. Oh, we should throw that, you know onto the pile either table.
Thanks. You're you're 100% Right? And if you generally if you're doing things correctly in your organization, you have a good security program and we'll talk about Frameworks in an upcoming episode and how doing good security tie to a good framework will help in the compliance world.
That way you're not all over the plate. It is the right thing to do instead of saying to your point. There's nothing worse than speaking to Executives at a company going.
We don't need more security because to your point on I'm so certified or I've got PCI or we have a third party security. They can test us once a year. We're good to go.
And like wow you were as good as the second thing pen tested you and not a second after right and Counterpoint of that though is and so one of the challenges I see across, you know dealing with I'm not being gonna call them cisos people that are tasked with security in different organizations. Is that a lot of these panels? Everybody came from a large organization that was very mature the other 92% of organizations and businesses don't have that maturity.
They don't have the the reason the people resources. They don't have the tools resources. You've got people responsible for security whether they're called to see so or something else that were a Web Master two years before or a Linux system admin or a network admin that understand pieces of what it is to be a sea so but don't really understand and don't have any experience and building a risk management program and understanding what that Baseline security should be.
So from that perspective, I do believe there's some value in some of the compliance requirements and I think cmmc is Shines a huge light on this so moving from you know D far as a cmmc is you have all of these small businesses and manufacturers that have to meet these requirements that you know, when we look at it. They're they're bottom right there the minimum Baseline requirements but a lot of small businesses and and other smaller public sector like like schools that are meeting these requirements are struggling with it. So I I think there can be you but I I do agree that you know security does not equal compliance or compliance.
I agree with both points, right reality is nobody thinks this is the way it should be but for some cisos and Security Programs compliance is a way for them to gain traction, right? Because people understand that this now impacts our ability to do business with a large Market that's out there. So I don't think any of us want it to be this way, but because of cmmc This is this is now people are now like talking about the business impact of this as opposed to you know, oh you're asking me to do and again these programs like look they need to be driven by your sales organization and your other teams, right?
Not just the security team trying to make this happen. Um, so I think it's a it it's unfortunate, but there are plenty of companies out there that still have not really prioritized security and compliance the way it needs to be prioritized. That's anything, you know, I consider compliance or reporting problem most the time you're doing most of the things the regs require.
Just how do you document how you get into this whole morass of that? Yeah, one of the things I think also we talked about building relationships and Trust. We have to take an external to security view of that.
It's it's getting ourselves aligned with the business. Right the dev organizations are pushing to move faster and faster and get software out the door more quickly because that enables what the business wants to accomplish and we have to get out of the sort of tail tail end of the dog all the time. So we're forced to be the people say no and getting with software teams worrying about app security getting with other parts of the organizations design security into products as much as possible.
But I think that takes alignment, you know, Chuck you mentioned your three strategies that's kind of line with what the business what's important to the business this year because that's what they're going to drive to and if we're over here with our own parallel. You know stove pipe set of issue siled issues or strategies. We're going to be you know, looking for the next job and six to nine months.
I think yeah, I agree and ultimately you've got to tie it all back to the business you I would just pick on the compliance thing for a second. Yes, if you know, it's soft to compliance PCI compliance for whatever putting that in the context of look if we do this work yet opens up markets for us actually in some cases if your competitors aren't doing it. It might create a competitive Advantage for you.
So that's how I try to talk about those things that you know, most companies aren't even you know at that level. So, you know, we pendo is a very fast growing company when I joined a few years back to 250 people close to a thousand people, you know, one of those Tech unicorn types of companies, so we very much look at security as a strategic advantages and power that growth. I don't think we would have had that kind of Earth and in particularly, you know what to get a lot of Enterprise customers if we weren't investing security.
Appliance is part of how we demonstrate that we're investing in security. I try to make it make sure it's not the only thing that we're doing that we're not just trying to check the boxes that we're trying to do the right things that essentially have security Drive compliance and not the other way around but at the end of the day being able to have a third party come in and actually audit us and say look, you know, these were all the controls we looked at them. They were operating effectively, you know, not preferably not just a point in time.
But over a course of a long period of time like our socks you type to you on it, which covers you 12 months or they go back and look at evidence across that entire period I think that's helpful and you know back to the earlier conversations around third party risk management. I'm not going to say that every single customer or vendor of mine just because they have a soft too is going to be secure but it's a signal right? It's a signal that shows me.
Okay, they're investing. I still want to dig around and understand a little bit what they're on what they're actually doing and how we're actually gonna use that service. I have a lot of questions as many questions internally as I do for the vendor.
That regard because I want to understand what my internal users are gonna you know, send to that that third party how they're going to send it to and all that but you know, at least I have some signal if there's an audit or some sort of compliance. I can look at and say okay they're doing some work. That's a starting point.
So I'm such a big fan it. I don't think any of us are saying compliance is bad. I mean, I love to see them and see so much that I recently joined the board of the cmmc accreditation body.
I I I'm a big fan right? I want to drive the ability to comply with those minimum baselines, but I think that's the point. It's a lot of times.
It's a minimum Baseline. It's a framework. And again, we're gonna talk about Frameworks in an upcoming episode to in and hopefully everybody will join us and the importance of framework and being compliant with those Frameworks, but that doesn't mean you're it doesn't equate to your Perfectly secure I think is the the big point for everybody.
There was an interesting question posed in the chat that JJ's been answering and chat, but I thought we could just throw into the conversation do a little bit of a right shift because I like the question which is what is the role of the Cisco in the zero trust security process and how will it be effective in organizations? And I find that interesting because for me zero trust and we had another episode about this actually starts in non-technology. You know, it's funny when that first started coming out even in our own organization people were really offended especially my colleagues that were dealing in the federal space because they're like, how do you have zero trust methodologies on a trusted Network?
You're this isn't a right way to go and it was psychology that we started with before. We got into technology. So I'd love and JJ's put some really good comments in the chat but to get the rest.
Of the team here to discuss this because I thought it was a really good question. I think it's important. It's a transition from we all kind of have some of our DNA still tied into the Bastion host.
If you go far enough back, right building a firewall building remotes, and we live in a world where everything is changing all the time. And you don't know what state it's gonna be. It's impossible for us to know what we're dealing with at all times.
So you have to have strategies or an approach that can adapt with what's happening not what is and I think that's part of why zero trust is gain some acceptance because people are the old way doesn't work. We have to have a better way of thinking about Building trust and not having trust on you know where we can't carry susceptible to something. I mean the foundation of the conversation we had a while ago is in the old days if the traffic originated from inside and office like the office I'm sitting in my company.
Therefore it must be good traffic and nowadays you sort of scratch your head and go what? You know you third party to it coming to go I baselined, you know, we came in at scantra and we baselined it and anything that deviates from this Baseline is going to be considered bad and you're like, so everything happening. Today is good.
and that's everybody's smiling because that's a bad assumption kind of a good Baseline. Yeah, that's right. So John Julie any other comments on zero trust methodologies for you?
I just I mean, I think Jennifer and Chuck probably can speak more. I guess my thought this goes back to what Jennifer was saying earlier about You know, look it all starts with an open dialogue right across the organization, right? Because these are things that have to be You know planned for and understood right and and really thought through before implementation right because of the risk of business disruption.
To the point you're making right. So again, you know, this trust word keeps coming up, but I also think this is where the risk conversation comes in as well because right it's one thing to have a trusting relationship with other parts of the organization, but it's something else for the seaso to be able to have those conversations in the context of look you feel strongly about this, you know, we as a security organization feel strongly about this, how do we turn this into a discussion about likelihood risk? What would the impact to the business be?
You know, what's at stake? That's where I think it it changes the conversation quite a bit. Yeah, and the thing I would add is that zero trust is powerful concept.
It applies differently in different organizations. Pendo is a you know, it's a cloud native company. We're what an eight year old company just moved into a brand new office wonderful location.
There's not and never in any of our offices have there been a rack of servers or anything resembling kind of corporate it we are fully everything that we do is in the cloud. Our product is in the cloud all of our corporate services or cloud-based. So for us zero trust is really more based around a little bit of control on the device and some identity management in the cloud a little bit of device trust around that but I don't worry about what's actually in our corporate Network because there's nothing here so it might as well be a coffee shop.
My last organization was the polar opposite. It was a very tradition on JJ is familiar with this organization because she did some Workforce there. You're very large infrastructure very complicated and infrastructure.
Many zero trust in that type of environment is a very different piece. So I have to say where I am right now. It's very empowering because there are a lot of things.
I just don't worry about because we took those things off the table based on how we designed our environment. We said, it's maybe That's right. Last thing.
I was going to say simplification. That might be my four strategic anchor anything. We can simplify helps.
Sorry JJ now, I sorry I got excited cuz you know, I get a little wound up and so one of the things that kind of Tweaks me is all of the you know, the marketing. Stuff. I'm just gonna you know, sorry to choose my words carefully here all of the marketing stuff.
All of the manufacturers are coming out and you know the same thing with mac. Oh we do that too. We do that too.
We do that too. It's like there's zero trust toaster ovens now. But the thing is is like your organization now is is very, you know, cloud cloud Centric and distributed like that.
But all of the rest of the or and zero trust products that we have right now if we can air quote zero trust products, but but products that are designed to to meet a lot of those objectives work really well. In a remote Workforce setting where the users are not co-located with each other and the users are not co-located with the resources are accessing. that entire model falls apart when we get onto any type of on-prem Campus environment and this has been the the challenge with zero trust is all of these products are pitched equally and there's a very thick dividing line between how you're trying to do that level of granularity with I'm just going to kind of call it on-prem versus not and to take that one step further and just to demonstrate how how weird and Technical and mid-gritty this can get even in your environment check.
I'm going to pick on you because so you guys moved into an office everything somewhere else. If you I'm assuming you guys are connected to things wirelessly over Wi-Fi. Even if you have Network segmentation and you have different vlans any SSID that's being broadcast is it's own broadcast domain from this the same as we would think of a network wired broadcast domain which immediately means there can be lateral movement and put those things at risk if they're connected to the same as this ID again, they can be on different vlans.
But over the year, they're in a broadcast domain and so, you know all of this conversation around segmentation and ransomware and zero trust Those models are are great when we don't have layer two and three adjacency and then they start to fall apart. With from a product Suite when we when we move to on-prem and so that's one of the things that just tweaks me because at the board level they're going we're going to zero trust. We've got this product this product and none of that is effective for 80% of environments.
Yeah, and today I agree. You know, the other thing we've tried to do is focus on the device. So yes, okay, you get on our Network, you're not gonna see anything.
I also looked at it from the standpoint when we pivoted to work from home and we still you know, we're basically hybrid company, even though we have an office here and we're gonna continue being a hybrid company or taking their laptops. Everybody has a corporate laptop that's hard and that they take home that device has to be able to work on that home network as well as well as it would in the office. So that's the mentality.
We've tried to approach things from it's just, you know, the reality is, you know, people work off their laptopsies. There's laptops are going to be in hostile environments whether it's the office or something else. I'm just gonna assume the offices just as hostile as a coffee shop or the home so that Yeah, or my house exactly.
Yeah. You know, one of the things we haven't brought up yet. Haven't heard.
I don't know if I've heard the word yet is talking about risk. Risk assessment management mitigation assessing risk, maybe we start there. That's been traditionally kind of where we think about.
Okay, what is our risk profile in different domains different aspects and that drives maybe where our focus is. Is that still irrelevant strategy? For us is that still one of the key you kind of arrows in our quiver or we evolve past that?
Someone's gotta have you point on this? Come on. I'm just laughing at the toaster comments.
Like I kind of miss the first part question. Can you ask so risk assessment as a way to prioritize where focus is are we still doing is that still an essential part of what we do or is there's we bypass that doing something different now. I mean, I think it has to be part of what we do.
The question is, you know back to JJ's earlier comment about most organizations only having a bare minimum number of people your risk assessment, you know itself is a full-blown practice and you know, you could have fds that do nothing but that so, you know math organization can probably afford enough people to do that. You know, my organization maybe is getting to that point but let me jump in here. Yeah in that story and that's come to me.
They have a separate. If I'm not mistaken Chief risk officer. Right who separate it apart from the sea so and that again when I said in the beginning that this thing's too big that is the big thing.
We're risk used to be Paramount right managing risk was security that's when security was part of the risk team today security is more part of it. It's more part of I of ideas. I said, it's own thing but risks still maintains its its pedigree.
Right from that CFO kind of line up and and managing risk as has become. And I don't know if it's a good thing to tell you the truth. I don't know but managing risk has become bifurcated.
from managing security Yeah, I mean, I don't disagree with that. I mean really where I was going with this is to say even in a company of 1,000 people right now. There's not a formalized risk management function, you know, we're not quite to that point of maturity or you know size where we'd have that so yeah, I mean to the extent that that we think about risk and we do by the way, I mean, we do have risk assessment processes and we we go through and we document things it's just not it's part.
It's a small sliver of what we do. We do use it to help prioritize where we focus efforts. I personally would love to have more investment in the area.
But you know, I've got to pick and choose where I'm investing and you know, I'm not putting more resources to do a more through our risk assessment at the moment, but I agree. I mean, you know more you know bigger company. There's going to be a full-long risk management function.
That's what keep in mind that that risk management function is, you know, depending on what industry they serve Etc. It's looking at risk Way Beyond technology risk security risk. Those are risk.
Um items as part of this bigger program. So I mean I actually as companies get large right? I I like looking at risk more broadly, right and that the topics we're talking about are big components of that and then there's alignment with the CSO or you know, whoever runs all of the production operations or whatever right that they're making sure that all those risks are being managed and raised up.
So if I think about it from a board perspective, right like that's how I want to be having conversations with the organization, right and we talk about cyber and Technology risk and all these other things scale risk everything as part of this bigger program, but they all have quite a voice and the responsibility goes back to those organizations that are fundamentally driving those things. So and all that was really say is that and one example, this is one data point right? But a company That Grew From five people to 1,000 people and eight years security.
He has driven that broader risk assessment process. And so yes, when I like convene our Executives and we go through those risk discussions. We're talking about not just the cybersecurity risk.
We're I'm actually encouraging everybody think about broad business risks, but quite frankly Security started that that ball rolling and we want it brings the business if you have a problem and your customers say we're not going to do business, right? I mean, so that makes perfect sense, right you we have an ERM Enterprise risk management program. I am a sliver of Enterprise risk management because it's risk management across the board and it could be everything from socioeconomic things going on in the world to product releases to sales pipeline to it's all of these kinds of things fit into a larger ERM.
So Alan to your point. It is something outside of I I manage the risk going my world through the ERM. I actually don't present ERM stuff to our board.
We have someone who does That had a risk, but I have to point out. A lot of people have said hey, you know Matt you work for this large company. Of course, there's a Cisco and a program.
I got to be honest. I talked to a lot of companies in the world bigger than mine. Sometimes by multiple folds that are looking to hire their first syso.
That don't have an ERM right it to me. It's cultural as well when you're thinking about security. It's a culture Chuck.
You're lucky to be in an organization where they obviously thought about it. The fact that you all are so small and have such rapid growth and they didn't wait until they got to we'll hire our first sysa when we get to the one or two or three thousand person. Mark is a real big deal.
Any I think that's why risk is so important and not all companies Chuck. You're not for example and JJ talks about it a lot of the work. She does.
It's not all companies are gonna have an ERM program let alone a mature ERM program. But again, this goes back to the conversation through slack channels those of us that are lucky enough privileged enough to be a part of a really good ERM. We want to help ask nothing is private.
It's not like we develop something in patented it and I can't tell you how we do ERM. We'll tell you how we do era, right we can have those kinds of conversations without it being a you know, at least with me toward you X number of dollars to be a part of our ERM that doesn't work that way. So we're talking about risk and we're really moving on and there's a lot of things that are popping up in the chat that I absolutely a agree with throughout this, you know, a lot of people are bringing up the fear component.
They you know, they fear failing an assessment more than they are willing to put stuff in and I have to throw this out. We are gonna talk about this in some of the later Series in pretty significant doubt, but that to me means that failing the assessment whatever it may be and let's let's just use it as a Fed ramp assessment. All would fall on Chuck shoulders and I think that is one of the core problems with a lot of the way compliance assessments are done it.
It's just his fault or just Julie's fault or Jay or my fault instead of it being in the problem and we have to elevate those conversations. So that for us part of our board. We have a security and risk committee if we fail some of the larger assessments, it's the problem for a larger group of people in our organization, which I'm just one of I may have a lion share of the getting yelled at but it's it's a larger group.
So there's a lot more involvement in our ability to pass those things and a lot more conversations elevated in the organization instead of I show up to meeting go. Hey, we passed everybody goes. Oh good and we move on or hey, I fail and they go.
Oh, that's great. You're fired and they move on without me. It's it's very very important as you're going.
As you're going through this and again it ties even to some of what JJ was talking about earlier with some of the zero trust mindsets tied into compliance. So Mitch, I didn't know if there are any specific questions we missed, you know, we only have a few minutes left in our conversation and I wanted to make sure we got Through them before I bring up one last topic and we only have a few minutes left but I think topic as we're closing this out. So we talk about risks we talk about threat Landscapes, but you know detection I think is an important thing, you know, Chuck you're in a interesting environment where you don't have a lot of Legacy, you're all cloud-based.
You know, Julie has a different environment. JJ's talking about, you know going from being at home, which I always told people we move people from generally secure environments to the most Hospital networks on the planet that's people's houses. I mean, I the stuff that started attacking our equipment when we put them in their homes, we would make phone calls to be like, you know, your television is attacking us right now and they're like it what like, yeah, you've got a problem.
Please unplug your television because I attack back there from a video. I'm gonna go mental. How how do you all We don't want to talk about tech and JJ.
I agree with yours. We're not here to say. Hey buy this VMS versus that VMS.
You're killing me with the zero trust toaster. I will say I Googled it a minute ago just to see if someone branded one. I'm gonna brand a zero trust.
I'm getting here across I'm sticking it on my toaster at home and I'm gonna send everybody a photo. It's gonna be great, but when it comes to detecting Problems. I'd love just to get some general thoughts in the last few minutes from each of our panelists on how you go about that concept not actual it.
I'm not looking for we have this this but detecting a problem is is very difficult. So, how how do you all approach that? I mean it certainly starts with visibility.
If you don't have visibility into all the corners of your your assets whether you know, it's on-prem or in the cloud or whatever. And again as we said earlier nobody does right we all that we have some gaps but it certainly starts with that and then yes, certainly as we also we're talking about earlier having some idea of what what Baseline is. Yeah start there almost like you read my mind to bring this full circle.
I would hoping someone would say visibility. I agree. I completely agree Julie JJ do you disagree?
Absolutely not. I mean, I think that's where it AB. solutely starts in two point.
It's starting. To identify when something is is off as opposed to hey now, I have all this visibility. But what are the signals?
I'm looking for to tell me. Hey, there's something there. Yeah, I guess I disagree a little bit and that I do believe it's a starting point.
It's the it's the cost of entry into even you know to play but I think a lot of again kind of small mid-sized organizations really don't understand the complexity of event correlation. Let's just let me just be direct with that and you know, they think okay and believe me this conversation has happened scores of times where it's okay, we're of the size. We're in a regulated industry.
We're gonna hire our first real security person like an analyst. and that person's The way they're basically writing the internal job description is they're going to look at firewall logs, and I'm not joking. And so this is when I say, you know, there's a there's a huge gap in the expertise and the maturity level between an organization of you know of certain sizes and and those that are just starting out.
It's it's a little bit troubling and and you know, they don't necessarily have the resources and understand what that looks like and so, you know sitting them down and saying look, Having somebody look at firewall logs is not. It's really not gonna solve anything. Frankly.
I mean the best you could do is, you know, maybe trigger an email alert if there's an expected change to a firewall but when you scrub through any single system log, it's just a bunch of stuff and nobody no human can sift through that. I don't care how well, you know the platform so, you know that next step of what do we do with all of that data. Once we have the visibility, I think that's key and I think that's where you know, a lot of value comes in, you know, the managed Solutions if there's a lot of I'm not naming names but there are a lot of solutions or Services out there that are not really valuable and but they're a handful that are exceptionally valuable basically, you know, give you an entire sock team and 24 by seven response and and human You know visibility and I these things that is an extension of an organization and and that's you know, inappropriate next step for a lot of these companies, but there is just so much confusion around what it means to have a security person and looking at logs and visibility and I think we can't stop there.
About 100% Allen you've been quiet on this and I know it's a passion of yours you the last comment. You want me to take the last time? I'm honored but you know what that I feel like this people who are a lot more.
Qualified than me here. I don't. I mean Julie Chuck anything Well, I mean, I agree with JJ I it's not but in order to get to the hey, how do you look for the anomalies?
How do you look for these things? You got to have it right to be able to start to assess so I couldn't agree more and getting help. Is is critical right?
Especially for small organizations? Right? You're not going to be able to do this all yourself, right?
So leverage the community and the offerings and services that are out there to at least get going. So we are we are almost at the top of the hour. He's to cut it off.
We're gonna need to hand it Overcoat to Cody before I do on behalf of Matt myself. Thanks to all of our panelists. And of course thanks to you the audience has been fantastic a lot of fun conversation Cody take it away.
Thank you Mitch. And I'd also like to thank Chuck Matt JJ Julie Allen and Mitch for taking the time to be here with us today and give us all their perspectives on this topic. I'd also like to remind our audience that today's session was recorded.
So following this panel, you'll receive an email with a link to access the recording on demand. com/webinars. So quickly we do have 425 Amazon gift cards to give away.
Our first winner is Ruth b, our second winner is Jessica T. Our third winner is Black Mirror s and our fourth winner is Eric W. So congratulations.
Keep an eye on your inbox to clean that gift card. And if you don't see an email just check your spam folder. My final thinks of course always goes to you our audience.
We really appreciate you being here with us today. Please take a moment to fill out our post webinar survey and we hope to see you at a future Tech strong learning webinar. Thank you all for being here today.



