Aligning Security Efficacy and Business Outcomes – Brett Galloway, AttackIQ
Mike talks with Brett Galloway, CEO of AttackIQ, about the disconnect between the effectiveness of security controls and the funding of the security program. They also discuss how ransomware has changed the economic calculus of security funding and touch on the parallels between quantifying marketing and security controls effectiveness.
Transcript
This is Textron TV. Hi everybody. This is Mike Rothman.
We are here with another tech strong TV interview. I am joined by Brett Galloway who is CEO of attack IQ cool company doing a lot of research and and kind of providing some some insight into how organizations are being attacked out there. We do want to focus a little bit on budgeting today and really helping to understand how we're gonna align our security budgets with the reality of business outcomes since the end of the day, we all have to contribute to the business in some way shape or form so Brett welcome to the show and you know, as we get started want to just give us a little sense of who you are in your extensive background in the space and then a little bit about what attack IQ is doing Thank you.
Mike. Very very happy to be here and delighted to talk about attack IQ and to talk more importantly about the How companies can protect themselves in an era of constrained resources? So my background is technology companies.
I went to Stanford moved here for college and never left. So I live in Los Altos, California and I've been been very lucky to work with a number of great teams on interesting Technologies around networking and security and so on. And I'm particularly excited to be at attack IQ because the problem we solve.
You know, we sell a software solution that helps our customers validate their weather security controls are working. If you think very broadly about an Enterprise, there are three things going on from a security perspective Enterprise has a much of assets at risk. They have much of adversaries trying to get to those assets, you know, still Social Security numbers disrupt operations, whatever.
And then in general then companies put in place a series of controls in the middle to protect them and in principle, this is no different than the lock on your front door. You put the lock on your front door to keep potential adversaries from getting your stuff. The same is true of Enterprises.
What we find is that very frequently. The locks are unlocked. And this is where the metaphor breaks down because lock is a pretty simple thing and the technical controls that companies deploy in order to detector block adversaries are actually very complicated.
They're subject error. And so we have we have a software solution that basically proactively tests those controls to make sure that they're working. Great all in an automated fashion.
So it's not like some dude has to be on a console. No absolutely banging away get things like like the old the old pen test tools that we used to use to do that exactly. You know, you penetration testing is a well well understood and defined process.
The problem is it's very very limited in terms of how much testing you can actually do. And in fact, we find the companies in general don't test near enough now, we have one customer. It's a very large customer one of the richest companies in the world.
Their estimate is they tested less than 5% of their State per year. With with their red team, which is sort of the generalization that's generation testing. So it's a it's a huge problem and in candidly was that problem that Drew me to the company, you know, when I was when I was approached by the company, I was actually working on a startup germinator.
So I didn't have a full-time operating role was very happy not to be doing it, but I think but I think our mission is very worthwhile. We have a We live in a world. where we as individual members of society are increasingly dependent on a bunch of software-based platforms.
Frequently without even knowing it. You know, I'm not thinking like Google and Amazon. I'm thinking like Colonial pipeline or an attack.
I'm in 2021. You know the disruptive fuel delivery for a bunch of people for about a week and that was a ransom. I live in Atlanta.
That's right. I painfully remember that and you know, and and you probably never even heard of colonial pipeline. So I have no right in the area.
But yeah well in general but you know, you didn't know you were dependent on these incredibly fragile computer systems that were actually disrupted by accident yesterday adversary, right? They didn't even mean to disrupt fuel the liberty. So imagine what would happen, you know, and how dependent we are on these software systems if somebody really meant to cause disruption you know that this is sort of this is sort of threat to you know, Society level threat like on the level of covid or even worse so, you know knowing what I know that you know better this is defenses are so poor.
I felt compelled to help solve that problem. Now, that's great. And that's a great segue into you know, kind of really linking up security and business outcomes because I mean listen I've been doing this for a long time.
I've been advising cisos for you know, the better part of the last 25 years and they all have a problem sitting in the boardroom convincing the folks who are responsible for the business, right? You know what I should I invest in security Now 20 years ago. It was a much harder case to me because nobody even knew what security was and the attackers were obviously not as prevalent or as high profile as they are now, but nowadays you still because you mentioned right, you know kind of where entering and a year right as we as we kind of come into into or 2023 right where we need to expect budgets to go down, right?
We need to expect some level of you know Financial, you know, kind of cognizance that you know, we do have to type our belts in a lot of different areas. So all of these Investments are going To be scrutinized right? So how do you kind of go about working with with customers and Advising them relative to the and how to make a direct linkage between the stuff you're doing in security and what is actually happening in the business without resorting to the old chicken little thing of oh, it's gonna be bad and you're gonna be on the front page of the Wall Street Journal, right?
Nobody wants to you know, hear that that doesn't help them make business decisions anymore. Exactly, you know and what I see is actually two. core problems the first problem is that The is the one you allude to which is, you know, if I find the Chief Information Security Officer.
Right. What do I want? Well, I want more budget certainly because that's in any or any large organization budget is a currency for impact results.
And you know Prestige Etc, you know and certainly is a sea so I can incredibly say, you know, we're under attack and we need the resources in place in order to defend ourselves. That's a csos perspective. You know, the CEO's perspective, of course is you know, you only get so much budget, dude.
So you got it. You got to choose you have to make good choices, you know how you deploy that budget? You know whom you hire the kind of skills you hire the kind of tools you put in place gonna controls you to play Etc.
and frequently csos are not in a position to be able to answer very simple questions. like is a good you know, how is how are we doing? Right.
I mean the seaso can tell what they've done this. ISO can tell what what attacks have happened. They can't tell how susceptible they are to the next attack and that of course racio's perspective is the prime question, right?
Are we good? How much do I need to be how much do I need to spend in order to be good? And so not you given that they're not able to answer that question that obviously brings a huge amount of skepticism about the effectiveness of the spend that is done.
Right, you know, because the CEOs used to having functional leaders, they can answer those questions. You give me this much resource here so much business out there to deliver, you know, and so the see so fundamentally has given resources to to deliver a certain amount of protection to the business in the csos today can't measure how much protection they're delivering. So so that's sort of problem one.
Problem two is that very frequently when you actually examine the program the security programs that that get put in place. They map only weekly to the real risk profile the business. And a lot of this is actually driven by compliance concerns, right?
So, you know companies will end up with lots of sort of, you know influences to say you got to do this you got to do this you got to do this you got to do this, you know, and and so much of the budget is actually spent on compliance as opposed to protecting. The risk profile of business and every business has a set of things which have attacked would cause enormous impact of the business. Right.
Imagine you're a Semiconductor Company and somebody steals your mass designs or shuts down the fat. That's kind of a bad. CEO gets fired kind of impacted right as opposed to you know, somebody even mounts a ransomware attack, right and if you have good backups, maybe you know, that's sort of risk that although it's significant.
It's not it's not it's not lethal. And far too often the security programs that people put in place are very much in us the very vanilla and they're spread their Investments across risks of enormous impact and risks are fairly modest impact. And so this is the second problem that we see which is that the defensive program to put in place does not really reflect the risk profile of business.
You know what, you know what what we believe helps good can help people thread the needle there is fundamentally, you know and what what actually might or Corporation calls a threat informed defense miter Corporation, we work with closely a minor Corporation manages the two core databases that cybersecurity teams use the CV database of vulnerabilities and minor attack database of adversary behaviors. And and so this notion of threat informed defense says that you should start with what threat actors matter the most to you. You should then add to that what risks matter the most to you in an issued close with what controls you put in place in order to defend which to mitigate those risks against those those primary adversaries.
I mean, it sounds pretty simple. But in practice I think is represents. If if in fact people did that would be a huge step forward in the sophistication effectiveness of the industry.
Yeah, I agree, you know and back to you know, kind of the first point that you made breadth that we just don't have you know, I'll phrase a little bit differently, right but we don't have the dashboard. Right? We don't have the pie charts that folks want and a lot of cases.
We don't know how to talk the language of risk, you know, you use the colonial pipeline example. Well, you know again, they didn't necessarily understand the risk of you know, kind of that system going down and really the Ripple effects of how that impacted both the business as well. As you know, kind of the ecosystem within the southeast of the US.
I don't know that any set of dashboards or tools is gonna really go out that long but they didn't have they didn't know what they didn't know what right and I think that historically okay, you know exactly, you know, and I think You know, but you know, I think that's true, but I think there's a there's a subtle Nuance here. That's worth noting. I think there was probably somebody inside of Colonial Park by new about that risk.
Right what we typically see it's not a failure to know the risk. It's a failure to operationalize. the mitigation of those risks and so, you know from a ciso perspective the real Gap we see is, you know, very frequently people know what the big risks are.
Yeah, right. I mean that that's not a mystery. Right.
The hard part is turning that into a real operational program where the Investments are optimized to mitigate that risk given that resources are constrained, you know, and obviously, you know, we're entering a tighter economic period but resources are always constrained. Right. There's no see-so in the world gets an unlimited budget.
so every every siso is constantly having to make choices, you know, and For certainly from Attack. I keep perspective. You know, we're not we don't solve that entire problem.
But you know, the piece of the problem that we focus on is delivering evidence of effectiveness. And mapping that in the context of miter attack. So at least the company now, you know, at least the csuna has data.
To be able to evaluate, you know, either current Investments or perspective Investments against you know, particular threat actors. Yeah. Now you add and add to that in the context of then the company's risk environment and that's ultimately how I believe companies can both improve their cyber defenses.
And also make sure their Investments are being spent wisely, right? So let's dig in a little bit because you know, you mentioned kind of the operationalization word and I am quite sensitive to you know, kind of tools that ultimately can't be used to generate some kind of outcome, right? How do you get to risk within these organizations?
That's something that the security folks can do and and start to help, you know, the the organization understand, you know, what they need to protect and what controls with it. Is this a partnership that has to happen between you know, a lot of the business leadership and security to really understand what systems what you know infrastructure is presents the the biggest, you know, kind of potential loss on that front and then You can start to Overlay it I mean just like folks have a hard times like hey I get this tool on the security person what then right? Who do I have to work with?
What kind of you know, is it a task force is it, you know, some type of group that gets together really determine, you know what the real risk of the organization is. It's a great question, you know, and the the simplest answer is this is the csos job. You know again, you know, I'm a CEO and so, you know, I it's natural for me to sort of think about this if I have a business problem.
Right. I don't very few business problems. I can solve as a CEO because I only have so many hours a day five is significant business problem.
It's you know, sort of top level significance. My my out. My my solution is find a person that I can assign that problem to that person's job then is to make the case for resource Investments.
um Perform those Investments, you know monitor the operations. The result is Investments and make sure the business outcome that I pay for is delivered. And if that person can do that, then I need to find somebody you can and so in this context, you know, the CEO is basically delivering budget to the CSO to make sure that organizations will defend it.
So it is absolutely on the ciso to make sure those Investments are effective. And that effective is across two Dimensions again one dimension is are they working? And the other is are the optimally aligned with the business with the business outcomes that I need.
Yeah, you know you obviously you can't do any of that without information without evidence and data. You know and certainly you know, we see we see a number of you know, rally senior Executives and security organizations is still conceived of their job as you know buying and Building Systems kind of an IT view of security. And and very frequently folks with that with that mindset have a difficult time communicating with the business because the CEO doesn't want to hear about tools or Technologies.
They don't even want to hear about, you know, minor attack ttps or vulnerabilities. They want to understand. You know our week are we good?
Very very similar by the way to the CO's perspective the CFO, right? They may not want to understand the details of general ledger. They want to just know her books clean.
Right? And if I'm talking to my investors and my am I telling the truth and my forecast based, you know, based in reality Etc so much as it's the cfo's job demanders the numbers see those job to manage the risk profile the business to Cyber attack. And you know and it is certainly the case, you know that the you know, when we look at surveys, for example, I mean business people do not have that confidence.
Right, I mean was looking recently to surveys from Price Waterhouse, you know over over half of the business people survey did not have confidence that they're spend was appropriate, you know, and and that's in the context of relevant, you know, relatively benign economic conditions, right? So my guess right it's 12 months is that you know that that number is gonna Spike, right? Yeah, I could make the case that we don't know if the marketing expenses are being spent in the right way as well.
No exactly. But but what's interesting, you know, there was an old joke right that you know in marketing that you know, I know half of my spend isn't working. I just don't know what which half exactly you know, the Innovation and marketing though is actually parallels.
What we're trying on security is that's actually not so true anymore things like Google and you know, marketing analytics tools right companies have a much better ability to measure the effectiveness their marketing spend. In fact marketing the practice of marketing is actually been revolutionized over the last 25 years by technology. Now as well as my digital marketing right any on a TV commercial right and a whole bunch of online business, you know kind of transactions that can happen in a way that's that's much easier to track than they used to be so exactly which makes it much easier for the business to make investments and marketing.
because you can draw you and draw a line between the investment and a business outcome, you know, and that that ultimately is what Season can do as well, you know and so back back to your question. The Cisco has to understand the risk profile the business again. That's usually pretty pretty clear.
But but more importantly see so then is translate that risk profile into an effective defense program. That's right, and you know and the the You know and you know the solution of this is a combination of evolution of practice. As well as evolution of sort of tools and data collections much as in marketing.
Yeah, you know better visibility, right, you know kind of better mechanisms to you know, kind of understand the impact that your controls have on the attacks that are happening out there and obviously kind of a business centricity on the part of the security folks to understand that they're not there to just you know, kind of fight the bad guys, right? It's it's really about trying to help the business, you know operate in a much more efficient and effective manner can't do that go find something else to do. So totally agree with you on that front right any parting thoughts, you know, as we kind of start to wrap up in terms of what folks need to be thinking about, you know as we head into 2023.
Yeah, I mean I think you know again you using that you using the marketing analogy what what ultimately transform marketing was two things. It was the ability to measure. Well, it was the ability to sort of portfolio manage investments in well-defined marketing processes who's Effectiveness.
You can measure right and so, you know, if I think about where we're attacking you as a value where we had value is in both those pieces we had value in terms the ability to you know, help people sort of Be clear about what adversary behaviors matter what adversaries matter and then mapping that to the real-time Effectiveness the controls you put in place. You know and so, you know, I guess if there's any call to action for listeners, you know with sort of see so kind of titles or people and Senior security positions, you know, it's two things one is, you know start to think about not just the process of building all of the Tooling in place, but think about building the the the evidence and the data collection and the program that helps you map that to to the real outcomes. That's ultimately how you manage in a period of time budgets.
Yeah now I agree. That's great. Thank you Brad.
How do we get in touch with you? So if anybody wants to find out about attack IQ, what are your coordinates? Where do they find you?
com. com. And certainly if you go on our website, you know, there are lots of places for calls to action to get in touch with us.
You know, we have three demonstration we have The ability to do free trials, you know for sort of qualified opportunities, you know, we're certainly willing to do proof of concept with customers to demonstrate how we can help them specifically with our software Solutions. We're also founding research partners that miter Center for threat informed defense. So to call out our partners there you can find that in the miter Corporation website Mitre.
Where there's a bunch of great research that we contribute to in the public good that is highly relevant to making the miter attack Matrix more useful and actually realizing this broader vision of a threatform defense. That's great. I'm a big fan of miter go do that.
Thank you Brad for your time today. Appreciate it. Thank you.
I've enjoyed it. Yeah you bet and with that. Let's head back to the studio for our next interview.