“What’s Bugging You?” – CISO Talk EP 32
Dan Glass, vice president and CISO with NTT DATA (previously CISO at American Airlines), joins CISO Talk co-hosts Jennifer (JJ) Minella and Mitch Ashley to talk about what really grinds his gears lately. Glass discusses the latest LastPass breach disclosure, what security vendors need to do to keep pace with IT, pursuing zero-trust in small-to-medium-sized businesses and hiring strategies for entry-level security talent.
Transcript
Well everybody welcome to another edition of cisotalk. Now. This is a little bit different edition of ciso talk is actually our new format and also with new co-host.
Jennifer JJ Manila, how are you doing Jennifer? I'm great. Awesome.
So happy to be doing this with you. We've actually recorded one. This is our second edition.
Actually our first guess that we had on. So we're together with you and I but she's still Talk's been going on for a couple of years now. So we've got a real Great Library of content JJ anything you want to do to kind of kick us off here.
And then we need to introduce Dan too. If you want to take the next step. Yeah.
I'm all in for that so sure. So yeah. I've known Dan Mr.
Dan glass here for I don't know. 10 not as long as I've known you Mitch but close and I met Dan, you know back he was a ciso at America and won the Airlines at that point time and it's been Cisco's different places and the seaso and TT now and throughout that time. We've crossed paths and besides and conferences and just in the community and he's always had something interesting to say he's always just been Pure entertainment and a wealth of knowledge.
So I thought what a great first guest. Welcome then. Thanks.
Yeah, king king or Jester, but well tell us a little bit about your background. JJ did a great job of where you've intersected. And yeah, she's so experience.
So yeah, I've been I've been in chair for over 10 years now, so that's where the you know at one point. I was clean shaven and had no gray hair. But as as time passes, you know, I the rest of it is just for gray or Just For Men the great son anyway, so I've been in chair for 10 years American Airlines was was my probably my most famous dent.
I was out there more now, I'm one of several kajillion. I think csos that we have an entity. It's a huge company, you know hundreds of operating companies within the NTT family.
So for people in the US that may not know NTT. It's it's the Japanese AT&T if you you know for for want of Better analogy and and just like AT&T went to diversify its portfolio. NTT is doing the same and so on working one of the companies in that diversification, which is North America, you know and US specifically and services and my my role now is I'm mostly in corporate side of this ciso, but more and more like getting drawn in to the client side because as everybody knows the intersection between service providing and the things that provide that service that backend stuff they they've melded right so corporate systems become client facing systems in some cases, you know, our laptops and things like that.
So I'm constantly getting drawn in on the client side as well. So it's it's an interesting job and and as I tell people it's punishment for how I treated my service providers when I was in chair in American, so and I'm now I'm now suffering the good graces of that. Well, we're going to start off and there's something that both JJ and I want to get into with you but we're gonna start off with our what's bugging you topic or segment of a new idea.
We're trying out here so I could go first but I'm gonna offer it to one or both of you where everyone wants to jump in what's bugging you? I think Dan's especially ranty today. So I think we lives wine him up and let him go first.
you there's boy and the list is long. Um, so so I think today, you know, seeing the some of my frustration when I when I see like what's going on at last pass once again more details come out, you know, and and it was a devops engineer with a BYO, you know doing work from home and and you know within our company and I'm sure every season that listens to this podcast is going to probably not an agreement. If they have any sort of, you know, next gen devops Cloud type Engineers is that they demand a lot of freedom on their systems, but with that freedom comes a lot of responsibility because you know my stuff breaks, right if I have a sassy tool that gets in the way of you know, doing doctor and things like that, you know, then that I either have choice.
I tell them don't do doctor which obviously isn't gonna work in a service provider Arena or and pretty much any company now or I have to lower the Barrier, so somewhat to allow. That application and others like it to go unfettered. So that's that's top of mind and you know, and so now seeing LastPass sort of getting pantsed over and over again over, you know, what's going on there.
It's it's I feel for them because I know that they are great people but you know, honestly the security product it's critical infrastructure and we you know, we as a community security folks, you know, we need to be doing better by forcing the business to align to the you know, they say, you know don't get hacked but then they do everything in their power it seems to to get hacked. Victim of their own I'll leave it at one because my goodness we can go there's and I have a question about that because I saw the announcement from today. and full disclosure that has been a really fun part of my morning this morning because there's some some that's part of my life still.
So and I'm curious to ask you guys because because Dan obviously you've managed these these programs and projects admits. You work a lot on that side. So one of the fun things is I came from the networking side and security and Mitch came from from the other side with software and application development.
So, you know my question looking at this is somebody who you know, one of the things I do is volunteer with Cloud security Alliance on the zero trust stuff. I am not a I'm not we've talked about this. I'm not a cloud native person.
I'm learning. I don't do any type of software development because I stopped programming it you basic not my thing but looking at this and saying okay, we have the tools now to do things like container segmentation Secrets management brokered access. I assumed that companies of the size and certainly a company who was in charge of securing other people's stuff with that level of trust would have already moved to these models and had these things in place.
So for those of us that are sitting back here not educated on how this works behind the scenes where where did this get off the rails or was it started off the rails and nobody got it back on there. Nobody put it on the rails in time. I'm gonna interject because we're definitely hear what you have to say Dan.
I think one of the Wild Card factor is it's kind of like working in a university right the professors and the researchers and our teams in Queens. They kind of get what they want and the world of developers. They view their world that much that way pretty much too and they'd like to be able to download whatever open source or I'm not making just that that's kind of that the Mantra and and you know, just like I want to have my doctor I want to have this tool.
I want to have that Eric necessarily security. Savvy or fully fully up just being on things you're talking about. So we rent it went into this Calvinism of our security and software teams.
Showing the Gap in whatever way they work together or not to do that. And I think that's a lot of the a lot of changes happening out of the control of the security team, but it's going to happen anyway, and you have to figure out how you're going to work that and then you can tell yeah, you're full of crap mentioned. They shouldn't be doing all that.
Oh, you're full of crap. That's no. No, you're you're you're right.
But you know, so the I think the biggest struggle that we have, you know in this once again this goes back to you know, what the incentives are, right? This is always incentive management and then I'll get to the boat more boring part incentives are some what more interesting than the final point. I'll make the incentives for the business is to make money.
Right and if you have a developer saying that well for me to do it the way security is saying takes me six hours, but if I just do it on my own laptop, it takes me 30 minutes. That's an exaggeration. Of course in reality some most of the time it's already mentioned.
They can't even do it with Already stuff. So six hours is even out the window because it's broken. So that's that's part of the problem is the technology that that there's so the security technology stack is a little bit behind where it is, right?
And and I know that some people are probably shouting at their phones or however that you know in their cars right now saying yes, there's Solutions. Well this comes up to the my second point which is the stuff's expensive the apps that that protect ourselves Secrets management. I can't tell you the name of the vendor and I won't go into details but I was gobsmacked and floored when I got the quote back for you know, x amount of seats and you know, I ask about buying licensing and you know, do you know how big our entire company is and I have reach into the entire, you know to Japan and the entire, you know, 200 something, you know, 50,000 employees at NTT and and they didn't budge.
It was not even a penny, you know, and then and no future discounts and I'm like, okay. Well, I'm glad you're so proud of your product, but I I've To walk away at this point. I'm gonna go find somebody else that's doing it.
Maybe not as well. Right and that and that happens almost in every segment of cybersecurity, right? So if you're a smaller company a mom-and-pop shop or or a school or Even a mid-sized business, you know, if you're if your it department is making revenue of you know, let's say 10 million dollars, but you have you know, your security costs alone or two and once again 20% you know, you just ate up all the margin right and I'm not you know, once again, I I am the siso right?
I get it and I'm here the one I'm the one putting together that bill of materials and I'm the one that's presenting it to get approved. So I'm all in line with it. But I understand the struggles, especially when the business doesn't even know that that application may prove to be valuable and I'm sitting here going but gdpr and they'll see and and authentication and authorization and two factor and all this stuff that I have to layer on top of it before they even know it's gonna make money.
And and that becomes a problem and so that's why I mentioned before the security companies that Barrel forward. I also have sympathy for them because they have to make those decisions of well, we're not doing it right but we can't do it right until we make some more money and so let's go, right Do you think it's fair to say though that they're gonna you know a company that's had this type of breach repeatedly and then what happened today is gonna suffer more Revenue loss from that market share loss and it would have cost. They said I think only four people only four developers had the keys to the kingdom.
If nothing else would you not at least have identified that and the risk model and put paid the hundred dollars a year for the four people to have something. Absolutely. No, you're absolutely right, but you know, and I'm and I'm a large Enterprise kind of expert, you know specialist expert on.
I can tell you when I am an expert in but it ain't this. Um, but but yes actually Physicians it's mergers. Well, you know in a large company those four people it has to have to put them through procurement and we'd still have to and then they would get mad at that price and they want discounts and we'd still get stuck.
Like I said I can I can rant and Rave about any subject and I'm walking angry meter. But but honestly, yes, you're absolutely right for a smaller company that can that that can get past all of that. Right?
They don't have HR and and procurement departments and you know, there's just like, you know hundred people and they're all just you're in towards that hockey stick of growth. Yes. They absolutely should be buying for licenses into that product.
They should be trying to work with you know, a and you know a next gen AV vendor to get better protection for those folks maybe not for match that works the front desk, although I think you should too. But for the four people for the kings of the Kingdom the people that have you know, any kind of directory access whether you're using a cloud-based IDM system or on-premise, I can active directory. It doesn't matter.
You need to protect those people first, right? Not. Yes Executives need to be protected too kind of I guess right but marketing Secrets isn't really gonna put you out of business right now.
It's really going to be this kind of thing, you know, or at least it's gonna erase your Revenue lower trust and get your your owners in the form of venture capital fancy, right? You don't want the man see when you're going for your next round. So I hear so here's capital in that environment.
No doubt when you've had that much exposure. Sorry. Go ahead JJ.
Oh, that's okay. I was gonna say so I think this this is an interesting way to look at it. because one of the questions I we get asked a lot on the zero trust site is will this all looks complex because most of the guidance for zero trust is geared for federal agencies.
So obviously this is something that's doable for a large organization and it's not doable for a small SMB a startup. So is it fair to assume that a startup or smaller company is gonna have a better shot at securing? their assets Yeah, I think that I don't think it's fair to say that an SMB or smaller company could couldn't do zero trust.
I think they could it's because zero trust is an architecture. It's not a product right? It's not even a series of product.
It is pure architecture. And so really looking at how your designing your your architecture and some companies may not even know that they have an architecture. But you know, if you're if you have systems and they connect to each other you have an architecture right to tell you that so in order for for zero trust to be implemented of those places.
Once again, you really need to look at smart product. You need to try to utilize all of the features within certain products, right? Because there's a lot of people by the Ferrari for the front right hubcap, right?
And that may not be the best way to that's not that's not always the best use of your money right you or the little bad, right? Yeah. Exactly.
Right. I want the key chain that comes with the Ferrari it's solid individually. So I bought the Ferrari because I really like Keychain, but it happens all the time right there.
And and that's why some of the stuff is so expensive because it can be because a lot of companies pay that money and then don't use the feature. So then they go do business with another company to you know, Left hand doesn't talk to the right hand. So especially these smaller companies where you know, you have fewer people making these decisions.
It may be even easier. But once again, you need to be smart about it, you know, so using cloud-based off whether that's using, you know, a Microsoft Azure ad or excusing an OCTA, you know, they have those SMB packages. They're not I wouldn't say they're cheap, but they're not like at the Enterprise package either right you get less features, but you can do zero trust with it because you're not a lot of those features, right?
Yeah. Yeah, you don't need a lot of those features because anyway exactly right? So zero trust is really it starts with the identity the identity of the device the identity of the person using the device and that identity of the application or service or API or whatever you're trying to use right and it's just validating the trust over and over, you know, making sure things are the way they are and so or who they are supposed to be, you know, so certification is important, but but there's ways to do it and you and there are ways to do it you can be creative.
Like using IP address blocks, if you're going through a sassy product only trusting coming from your sassy product IP addresses. That's a great way to ensure and then making sure that your sassy product is locked down to the point where only people that you know, the or the only way it's deployed is on your devices right and having a way to certify that right so well now you just created a zero trust sort of envelope between you know, like let's say your email system that has that protection in place that it can only come from, you know, you're the block that you use from your sassy product. now all the way through your device, right and then you do the same thing with using MFA if you can afford MFA if you can't and 2fa because a lot of 2fa has now baked into the systems just for free, right and the apps to download the the codes are free, you know, if you want to get fancy get with push and that's better but you know start somewhere don't use text messaging nobody use text messaging use it you use use the otps or or push if you can afford it once again and a lot of those systems like, you know, Azure, you know if you buy that That product Suite you it comes with it.
So use it, right. You don't need another product to layer on top of it just utilize what you have and once again and that's and and we can iterate on that right you just iterate on that and you always you step through and say okay. So how are people getting access to this how again access to that and you just validate each step of the way.
And once again, you don't need to have you know, a huge security budget. You don't need a large security team in order to get this done. You just need to be thoughtful about how you design not just the security but I T, right.
That's the biggest. I think that's probably the biggest point I can make on that the partnership between security and it because if you're trying to bolt the stuff on after it is built it No way. The zero tries can't happen in that you know with with that going on.
Okay described that as you don't wait till the car rolls off the assembly line to say we'd really like to have some airbags on this now. Yeah, we do that. Well, this can be a damn ugly car.
I'll tell you that no Ferrari for sure little duct tape. Fire will be looking good. You said my car I see in the background there.
I'm curious too is so say some more about the security budget versus the it budget. I mean, how should we how should I teach security be working together planning together coordinating words, they kind of leave the table and kind of go do the respective stuff. What do you think that intersection?
Been diagram? Looks like yeah. It's a that's a good question.
And I think every company is a little different and unfortunately, I think a lot of the answer to that is in the form of human being because there's a lot of ego, right and there's a lot of Empire Building nation building, you know, whatever you want to call it and I'm not trying to call people out and security people can be just as bad as the IT people but but people get their domains and they they're very protective of them. So identity is a great example where HR, you know is in the room it is in the room and security and some companies still not in the room right and or they're knocking at the door and and sometimes it is I'm in sometimes they're not so I do think that it insecurity need to work very closely together to understand. You know, what makes sense for that company now, I'm I'm a more akin to the big so role versus the small Cisco role that's you know, and and when I mean by that and that's not to mean big and small is important or not important, but but the sisos sisos I don't know how people say it.
We in the people that have my job title. I we have governance right? So we do audits internal, you know, we create all of the administrative processes and all that good stuff right that you know the policies which I know everybody reads and you know, but we may not manage a lot of Technology, right?
You know, maybe we get involved with security operations and you know and monitoring and and response and Recovery. Um, but we're we're not really in the protective part, right if you're nicia CSF nor like me and and I think that you know looking at the nscsf, they're pretty clear in there what they think right. They think security should own identity.
They you know, because it's in there it's in several points, you know, they they're you know, we should own portions of desktop management, you know and network management not just because you can't you know and JJ. I hope you'll not with me but it's it's getting increasingly difficult to segment Network away from network security, right? Because it used to be that the network team had the routes and they have the switches and routers and they have their way in and then we would slap a firewall in front of it, you know, and you know how to solves in the back and and go get a beer now.
It's a lot harder right? Because the not just I mean we we can still do that but it's way more expensive and once again, you're buying the Ferrari when you're only wanting the keychain. Um because every product whether it's Palo whether it's Cisco, you know there a juniper they're all baking security into the core platforms now, which we've been begging for forever.
But now that they did that now the network team has all the security stuff on their systems and then we're demanding that we need to manage it. So once again, I don't know what makes sense for your company or somebody else's company, but in some cases it does belong with network and it should and in other cases where like maybe their Cloud heavy maybe security runs that maybe you know, if you're if you're mostly work from home and you're the majority of stuff is in the cloud. Well, then you're sassy product is handling probably the majority of your DNS.
It's handling the majority of your routing. It's handling, you know, 100% of your Access Control right and and and policies going out to the systems. So maybe that is a security decision, you know, the same can be said for security endpoint management where security owns an endpoint management tool that it can then use and you know, so security becomes a service provider to it and it can login to do the patching right?
We don't own the patching and personally, I do the same thing. I do it I do that with configuration management and Patch management as well as vulnerability management, so I own I own the budget I own the Infrastructure, so to speak whether it's cloud-based on-prem doesn't matter to me. Um for those products but I have but I had I've made every incentive out there for those individual application system infrastructure backend people data center to go in to the vulnerability management tool and see, you know, their systems make sure that their systems are there that we get from asset management and then make sure that those systems are patched and if they're not they know that they end up on a report that my team generates that goes in front of you know, the big weeks in the company and so they don't want to be on that list and so they they patch their own systems, right?
And there's a lot more in the background of my team's working with them and we schedule stuff and we you know, but but at the end of the day, it's self-service, but it's also accountable right and that's a I think that's a big part of it as well and I have no idea what the question was that you asked originally. So it was a self-service. That wasn't the question.
Yeah. Yeah. Got a latte with no, I'm sorry.
Go ahead. So we moved from tequila to lattes now. Yeah, okay, because I think that's an interesting.
Wait. I know what was the coffee? I hope it's not tequila because that not to kill you know, no no, no, he Irish whiskey it could be whiskey I would be okay with that.
Irish whiskey, I think there's some opportunity for dark rum with the right coffee. Interesting. All right.
Yeah, and yeah, but not gin and not tequila. Those are hard notes. Oh God.
No. Oh Jin, I can't anymore. It's a different.
That's a different podcast though guys recovery program for that. Yeah. What does that RSA after hours?
Yes more than one RSA trip. I'm sure but anyway, I was gonna say I don't remember I do remember I think that's an interesting way to look at it. And I do think it's a depends I could argue both sides of that.
So obviously, you know coming in more from the networking side but working and security heavily for I don't know if 15 issues at this point. Um, I think there are places where that might make sense for security has ownership over some of the operational systems traditional operational systems. And then I've seen places where that has been attempted and failed miserably probably because they don't have the communication and the trust between the teams which is probably why I have a job because a lot of what it is sit between the security group and in an operations group and help them, you know Kumbaya, but it's the challenging thing to me.
Is that like these systems keep getting more and more complex. And so, you know, I've worked in networking on that side or probably Close to 30 definitely over 20 years definitely over 20. Let's just not age myself anymore than that and it's been fun fun and and terrifying watching it because you know when I first started doing that type of training We we did everything right?
I I did switch route when infrastructure's firewalls VPN Wi-Fi when that came out it all of it anything that had an IP address and passed packets. We architected it secured it configured Etc. And I think that was the that was how we grew up and then Hiring people in the past several years.
It's been bizarre because everybody has these Specialties because all of these systems. I'm assuming the same thing has happened on the application development side have gotten so much more complex. And so whereas before you can learn, you know, basically three vendors equivalent of switching routing and a week or two now.
You know, I'm not I'm well shoot. I'm just gonna call it out. I don't know all of all of the different training programs from all of them.
But you know, one of the Wi-Fi controller vendors who also make switches and other things the training just for one of their controller operating systems of which there are three out right now. Is more than a two-week training and that is just for that that is not for any of the security and authentication stuff. It's not for like Anything rate related to radius?
It's not for anything related to what we need to do to segment on the wired environment. And or do you know when routing out of those things? So it's like what you could learn in in a couple of weeks and I would say get really good with Hands-On and a few months Now it takes you a few months just to learn how to configure this stuff.
And you know, I was having this conversation with the senior engineer recently. We always used to be able to troubleshoot and now we can't because there's a 50/50 chance. There's a product bug.
And and my question is if you start if you take a seasoned. Network engineer with 20 and 30 years experience. That can't figure things out because the product is too complex and there's bugs on top of it.
How do we and again same thing with any of the other systems right this operational? How do you then take something that complex and dump it into a team's lap? Who I mean frankly a lot of the people that I've talked to an interview with for security positions.
Don't know the OSI stack. They're really good some of the networking people. I've interviewed.
Don't either they're really good at what they're like I know where to log into this thing and wish buttons to click to make this thing happen in this product and they don't understand the technology and architecture. Yeah, yeah, that's why we drink JJ no good back to my tequila. It's this is this is just Ginger all I swear.
But anyway, okay. But so oh my God and changing the it is this is a CSO. You can't go there to see so size cup.
There you go. There you that's the entry level season, right? You know, I think you could pick at any place in the architecture was Cloud whether it's identity, whether it's on-prem whether it's in the app, whether it's in for the infrastructure the network or embedded throughout it.
The level of complexity is extremely high and I think that's one of the reasons why it's almost like a school of fish. It's like Yes, there's security throughout all of it. But there are holes in it.
There are product bugs in it there. There's always something because it's also all changing at the same time. Right?
None of it's really truly static. There's some pieces they say that state for a while, but they eventually changed too and I think that's one of the biggest challenges. I have getting my head around of around it is any one piece of it can change not without usually knowing especially in a cloud or assasser other kind of world.
I'm wondering how you how you think about solving or just keeping your head around that problem man. um Yeah. Sorry You're Gonna Save the easy question for you.
Well, can you can you rephrase it? I'm sorry. You were gonna have to cut so there's a lot of complexity throughout the stack vertically and across the environment that we're in whether you're thinking about it Network and security.
Yeah applications are yeah. No I now I got it. Yeah.
Sorry. I I was following you and then you ask me the question and I was like wait what apologize for that? No, these borrowing my blonde.
It's right in that. Um It's hard you because we're not only having to keep up with what's going on in it. We have as JJ said we have our own issues within that complexity, right?
So so it's this race and like I said, the the security vendors not haven't kept up with that the it Innovations, but they've had some amazing Innovations themselves. And sometimes they're Market a little late or we don't need it. You know, we we ask for it and ask for it ask for it by the time it shows up.
It has moved on, you know, and and I think what we need to to have happen, you know, I don't think it's anything cisos can do other than maybe through influence with some vendors is we we need the devops community and I love that. Maybe I used to speak at devops days and and participate but big fan of it. I do believe it can lead to better security outcomes.
But what we need is better not just Outreach to security, but we need for those to be also considered. Like what I mentioned before with like system management tools traditionally seen as an IT product. I view it as a security product that it can use.
I think we need to maybe take the same approach with some of the the stuff that's going on within devops. You know Jenkins as a is a configuration management and deployment type system, right? You know, why why couldn't security get their hands on that and use it, maybe not be once again not be the the people who are managing the system as far as you know, making sure that employment go out on time or and doing the scripting but maybe they're the sort of sponsors of that system and they manage the ecosystem around it and the ins and outs of it because once again now there's a different mindset around it's treated differently.
There's a little maybe a little bit more scrutiny on what's going on inside of that. Um, you know same thing with you know, sort of like I said before about Network right when you're have a company that's working remotely and then may have some small offices, you know with Wi-Fi that they have local located. It may not make sense to have a network and a security team that are separated from each other because you know, there's not enough Network to really carry now other companies that have traditional data centers and when and you know, and then office back, you know back office environments, obviously, they need a network team and the security team, you know, but that that complexity needs to be addressed with JJ's every company needs a JJ to sit between Network and not you know, and and you know security architect sandal or Engineers that are managing security product the network team and we got to get rid of the finger pointing and the the flame throwing because that you know, that's inevitable but And but avoidable, once again, if everybody sits down and goes through and creates maybe a R&R document Rose and responsibilities or you know through project manager or racy, right a the responsible accountable blah.
Um, and then everybody will know what they're supposed to be doing and a lot of that friction will just magically evaporate. I'm fetch almost anything. That's what I just gave away one of JJ's Secret Sauce, but I'm curious Dan like in your roles, you know, as you as you've been kind of leading in that in that way do you Reach that point through cross training internally do your do the security because I think for a lot of companies, you know their security.
And especially the mid Market mid-market to lower Enterprise their security people are security people who have no prior technology training rate. So are you bringing people in that had you know a background in Application development in networking in something in something else in the teaching them security or you how do you do that? How do you merge those?
You just gave away my biggest secret. So, you know this this is something that I've been talking about actually well to my dogs mostly because it's been you know since covid I really don't get out much so my dogs are actually experts now too I could get them to work but you see the secret is what you just said you we have a security shortage we have we have a few problems in security and I'm just gonna lay them out. If you don't mind one of them is that we don't have good entry level.
Uh, you know, we don't you as tier one for everybody, you know tier one for the song great place to bring people into the security organization. Guess what that's mostly being outsourced and or automated away with with sore product, right? So tier one's gone.
So now you're at tier two, well tier two you need, you know people that can do a little bit of thread hunting and and know the lay of the land right. So now you do need like the three to five years experience and I can't think of another area in security where you can take somebody off the street and just drop them in without any prior knowledge, you know, just maybe an education degree and just say okay be productive now. right Not saying that that can't be done and you know, honestly it is done every day.
A lot of companies have to do that because that's the only option they have but but we don't have a good entry level and we don't have a good pipeline for the entry level, right? You know, so getting kids in college. I always get asked about, you know, can can we do some sort of internship and I said absolutely but I don't know what to do with them.
Exactly. Right? And so um and and actually we did have some things and Reporting is a great place to get some of those people started right and training them on on what's important and how to pull reports together and then they from there they can learn the different parts of security and what a vulnerability is and why it's important to report it in a timely fashion, especially for the boards and fives things like that.
But once again, that's but that's a you know, that's taking a teaspoon and trying to fill the ocean right? That's that's not gonna solve the problem. So what I've done is I really don't I tell the recruiters that that I have to work with.
I don't want security person per se right if I can find somebody with that five to ten years experience that that has worked in other place insecurity, you know sure but if you're having trouble finding that and they always do at least in the last couple of years security is just this amazingly hot place then let's go look for some sis admins for if you're if you know for for infrastructure, right, let's go look for some Network admins that you know for for network security. They know where the body is buried. They know how the things are built, right?
So I can't think of better people to help break the things or protect the things that people who know how they run. Thank you because teaching security it it's intuitive to most folks, right the security doesn't happen because once again, there's a miss miss alignment of incentives, right they're incentive is to be productive to get the system working and to have the least obstacles or problems possible. Right and unfortunately security products cause problems cause blockages and outages and things like that.
So let's just not put that on there and just have a system work right and then you can put a firewall out in the internet and I don't care right? But they also know how to do the security they just chose not to because they didn't have the incentive to do the security. Yeah, right.
I feel like we should swing this the other way because I I, you know made the comment and I do feel that these systems have gotten more complex over time and maybe there's some value in, you know, getting getting the manufacturing community in the vendors to roll that back a little bit but then Given your background. I think we have to I'm curious on your thoughts of some of the issues with Legacy systems and we've seen you know, some Airlines and FAA and even Railway issues happening. What's what's your thought on the opposite end of this spectrum of complexity?
Well, I wish I'd filled that with vodka. So, yeah, it's I think it's an endemic problem that does not have an easy solution. And and so Legacy systems were very vertically aligned right?
So nowadays, we talk a lot about horizontal scaling and you know, we can scale up and down and And do things like that but where where we end up is we end up with these monolithic single purpose systems that we built that are really robust and they can stand the test of time but unfortunately time moves on and you know, so now you have this Mainframe with code that was written when you know, my grandfather was still, you know, working in active life and it makes you know, and it makes for a tough decision for a company because what's gonna happen is you go to the the project manager, you know, they say, oh we need to update the system. We need to go to devops. We need to be Cloud fast.
Whatever right just buzzword buzzword go and they're gonna come back with like eight million dollar 20 million dollar, you know project over five years that will be incredibly expensive disruptive and time-consuming and and soak up resources because you need the best people right? You need the sneeze to keep the system running to actually be on the project. So who's now running the system, right?
that they all have full-time jobs and we're doing their job anyway, right so so now you got this big problem of this huge bogey of a budget item and you've got this huge timeline and a ton of risk and disruption or Let's just pay, you know, IBM extra money every year to maintain zos that version of zos and let's just, you know, keep things moving right and we'll just keep it the way it was. Don't you know and and we can put us a layer in front of it. We'll put an abstract layer in front of it for the for the code stuff.
And so we'll have a ton of ETL where you know, the Mainframe will puke out some cobal output and then you know, we'll get a script and we'll turn that into into JavaScript and shoot that out to the API for the for the web for the website. Thank you my cobal cold. Yeah, I I still remember having to write a whole ball program for my final exam and one of my college courses by hand and it was like 18 Pages.
It was not a simple problem, you know, so we're probably gonna need to rap here. You know, there's so many things changing they can think of it we can back for I'd love to pursue kind of the devops angle and you know, that's also becoming the network if you will, you know expanding with these But new architectures and software and we can also talk about like how do you manage your startup vendors? Who?
Want just enough security to get by but really need a lot more and five other things so we have to have you back if you'll come if you'll have us Dan. Oh you this this was therapy man. I'm feeling better.
For all of us good for all of us and JJ kind of partying thought you think is we're up things up with them. I mean my takeaway from this is to answer the question of what's bugging you for Dan. I think it's every day.
Yeah, so there's there's so much more and I mean we've had you know, the last pass for each we had key pass has a major vulnerability, which is common a lot of Enterprises. We've got a lot of the federal agencies, you know, we're like all all of the different acronyms of federal agencies or experiencing challenges currently. So there's so much more to talk.
I think you have such great perspectives on these things that definitely like to hear more. Anytime let me know. Alrighty.
Well, thank you everybody for joining us on behalf of JJ and Dan Dan. Thank you also for being here with you. It's been a pleasure and we look forward to seeing everybody on the next episode of ciso talk.
com as well as find out find the video. There you go as well as find the video on Tech strong that TV still hold them up get it. There we go here NASA fans.
We found the point to in the show on. All right. Take care.
Everybody. We all see you. Thanks so much.



