Contextualizing Cybersecurity Events for Executives – Matthew Wolfe, Impero Software
Matthew Wolfe, director of cybersecurity operations for Impero Software, explains why putting cybersecurity events in context for business executives is one of the most critical aspects of the job.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Matthew Wolf, who's director of cybersecurity operations for Imperial Software.
And we're talking about, well, whether or not business folks are taking this whole cybersecurity issue seriously or not. 'cause we sure are talking about it, but every day we wake up and there's more and more incidents. So what's going on?
Matthew, welcome to the show. Thank you. Thank you for having me.
Uh, I'm huge fan of what you do and especially your thought provoking leadership that you're providing. It's, uh, really exciting to be here. So thank you for having me.
Well, thanks for coming on by. I sometimes feel like we blame cybersecurity people for these issues, and I scratch my head sometimes 'cause I'm like, well, we don't blame the fire department every time there's a fire, right? So we usually have somebody else come in and, you know, they hopefully put out the fire, but nobody stands around and goes, you know, boy, I wish those fire people would be, do a better job.
And yet, with cybersecurity, we blame the cybersecurity folks for these issues. But the question therefore comes back to, well, maybe the issue lies with the people who are running the businesses that, you know, create these issues in the same way that homeowners create these issues. So what's your sense of, where are we right now in terms of the savviness of business folks about cybersecurity and how proactive are they being?
Pretty good question. Pretty good, uh, metaphor that you, you brought forward. So I think with the fire department, we have gained awareness that it's not the firefighter's fault.
Uh, whereas in cybersecurity industry, we lack, um, this industry historical depth of conversations and, um, really an educational aspect of why do breaches happen, why do people get into ransomware? What happens? So they typically fall towards the easiest solution is the one that they're gonna go with, which is blaming the cybersecurity people or blaming the IT people for why things happen.
And that's where it's gonna take time in the industry for people to really be humble and start opening up conversations with the cybersecurity champions in order to really bolster their environment. And that's why we keep seeing different breaches happen, or ransomware situations happen. Um, even this morning I got an email saying that there was a school district in Las Vegas that just got hit with ransomware attack in, uh, on the 27th.
And so the, these things are just gonna keep on happening. And I think what's gonna really help it to stop is, is communication and foreign organization to acknowledge that there's been a long time coming for, for change, for a change that's needed. What does it take to get the business folks to wrap their heads around this?
I think think a lot of them nod their heads, but it's not clear to me. They understand what it is that they're nodding their head about. So what do we gotta do here to kind of have that deeper conversation?
Yeah, that's a good question. Again. So I think, and, and I can speak on what my organization, not my organization, organization I work for has done, uh, they really, um, provided me the time to, to reflect on what's going on in the industry.
What's, what should we do? How should we posture our own defense? And that's where, uh, last year I, I brought forward a briefing about reversing the cybersecurity kill chain.
So cyber security kill chain. It was first started being implemented by Lockheed Martin back in the past, and then it blew up into this huge, um, uh, every cybersecurity certification mentions the cybersecurity kill chain where there's seven steps in it, but no one talks about how to practically use that for your defense. And so that's where in my organization, I was able to provide this briefing to all of our executives about how we can do it and how we can posture that.
But my organization said we need someone like Wolf to be able to bring us this information to, to really start that communication process of, of what we're doing and be humble and receptive to hearing how to make a change. And so that's what I did. I I brought forward this presentation about how to reverse the cybersecurity kill chain one step at a time and how to start reducing our avenues of approach with these, you know, different issues that could happen.
And so that's how an organization can really make a difference. I think every cybersecurity professional has had this conversation with a business person where they're basically saying, yes, we could make this more secure. And the business person says, well, that sounds like it'll be too inconvenient, so we won't do that.
And then the next thing you know, we have an issue, um mm-Hmm. How do we kind of strike that balance because sometimes the business person is right and that we can't just lock everything down because then it becomes unusable. But at the other end of the extreme, we can't cater to maximum convenience.
'cause ultimately that just helps bad guys. So where's the middle? Yep.
I have this conversation, I think, on a daily basis. And I think, um, something that the, the team that I, I discuss these conversations with, whether it's our finance operations, is what is applicable now and what can be applicable in the future. So let's take, um, Palo Alto.
I love picking on them. I, I really like what their, their vision is, or even FortiGate or yeah, FortiGate, Fortinet, um, what they offer, well, they, they talk about how you can have this amazing huge, large internal firewall that's a billion dollars and a organization has 10 people. It's like, I want that.
Well, that's not really gonna fit the need for today. And I think where a lot of it people may struggle with is saying, I want to adequately size our security solution for our environment today with the scalability for tomorrow. And organizations don't know how to translate that.
Like, oh, so you, you're wanting a $10,000 firewall, but yet the infrastructure backbone that you need to be put in place, this 30,005 years from now, you're gonna be purchasing another $30,000, you know, firewall, internal firewall or intrusion prevention system. So your total capital improvement plan is, you know, 60, 70, 80,000 over the next three, five years. And so that's where being able to consolidate the information, put into a plan and deliver it, and to get the buy off, um, that honestly comes down to a, a personal thing inside of business.
And that kind of goes back to that first point is where people have to start being receptive. Business leaders have to be receptive to hearing information that just because it worked yesterday doesn't mean it's gonna work today and tomorrow. And we, we understand how to rightsize the security investment to the risk at hand.
It feels like sometimes we don't really have a conversation about risks. So everything gets treated equally. And yet, you know, the crown jewels are one thing and the, you know, email addresses that are already been stolen or another.
So Exactly. And I think that's where someone that is really trying to be the, the champion for an organization. So if it's big, you know, you got your ciso, if it's small, you just have someone with the additional duty to be the IT security individual.
But for the, the larger organizations, they need to be taking in information from various sources. The open source intelligence network is, is really good, especially when you get connected with reputable sources. Um, one of 'em being like the Idaho National Laboratory, um, or labs, they, um, they're phenomenal.
I went, uh, I used to be in the Army and then did the cybersecurity stuff in the army. And I first got to meet these individuals in 2015 and they were talking about this exact thing about like, you know, budgeting concerns and with, uh, with their customers and how all of that looked. Well, one of the, the easiest ways that, that they got through to them was showing them these matrix that they provided saying like, here's your impact, here's the likelihood, and here is what is going to happen.
You know, and, uh, and this is the damage that it's gonna cause. So being able to do that RTO calculation on, on your own is, is almost impossible. And that's where, where a lot of organizations are leaning towards using those MSPs.
And even CompTIA the other day said, this is gonna be the time for MSPs. Um, so, so I'm assuming now that MSPs are really gonna start taking off to be able to address this specific issue. Well what will drive that?
'cause I've been following that issue for a long time myself. And one of the things that always comes up is people go, well, security's too important to trust to somebody externally. Or they sit there and they go, well, all I get from those people is alerts with no context.
So what is gonna happen now that will change that dynamic? And I think that's where the growth in how many MSPs are out there is gonna create a competitive market for them. Um, here in Texas, there's a huge MSP market and they're very competitive, but also collaborative because there's different events that are hosted like the Texas Cybersecurity Summit where these MSPs get together and they have healthy conversations and collaborations with one another.
And that's where you have companies like signer where they not only do the whole contact method of saying, we were alerted on your IDS that this happened. They are calling every phone that you have on the list and getting someone on the line to be able to start addressing those issues. Now as a, as a matter of trust, um, yeah, the, the trust issue is a funny one to approach 'cause it's how do we trust a third party?
Well, to an organization, everyone working there is a third party. It's not a family business anymore. So everyone you bring on, like take a DuPont way back in the day, uh, my mom's a huge NASCAR fan.
She loved Jeff Gordon. So yeah, whenever DuPont got hit by that insider threat person and cost him an insane amount of money, um, that, that was big news to, to my community. But that was an insider threat.
So really it's that risk reward. If you can bring on an entire MSP for the same thing you can bring on a security auditor, you're, and that MSP is really worth its weight in gold. I mean, you're, you're adding so much value to your organization compared to not doing anything.
We hear about AI every day now almost, um, will AI save us from our cybersecurity cells? Is that a way to have the, a meaningful conversation with the business people? 'cause maybe they'll think, well, I don't understand cybersecurity, but hey, AI is magic and we will buy-in.
Yeah, AI is a good one to talk about. So, um, in our organization we get to use machine learning in a, in a lot of different aspects. And uh, I, I think even recently you, you talked with, um, I can't remember his name, but his company does AI in, um, the software code of, um, their products.
Anyways, AI can be a great tool, but a terrible master. And what I, and to really wrap around that, that concept I AI is not gonna save an organization. The people using the AI is what's really gonna help defend the organization.
Maybe not save 'em. 'cause it's hard to know a hundred percent of where the attack's coming from, but people can start leveraging AI to really help reduce those avenue of approaches to attack the cybersecurity kill chain at every level. Starting at, you know, reconnaissance the first step, work their way down.
AI can help you with that. Um, I was actually having a conversation with my wife about ai. 'cause whenever I was writing my masters paper final things, I was like, what should I write it on?
You know, using AI to defend against ai, you know, like I was trying to conceptualize that concept. And um, basically to do that machine learning of AI to be able to defend against your network, you have to teach it how to defend it. So you can teach it how to start detecting, you know, zero days.
You start looking, you know, first teach it signature, then teach it heuristics, then teach it anomalies. And you, you have to teach it one step at a time. Maybe in 10 years we're gonna have every form of heuristics documented.
And you know, whenever something is not to the normal of a signature, that's gonna be great. But that honestly goes back to what Palo Alto and Port Agate say where zero trust, like even for the meeting invites that I was, um, you know, getting in for this or reminders that this was coming, those were actually going into my, um, my security, my s and TP gateway, uh, spam folder because I did, I do not inherently trust the, uh, that anything unless I choose to trust it. And so that's where in ai, if you can teach it that method, then it could do something.
But we're talking five, 10 years from now, How do you have a conversation with the business folks who don't really, you know, understand terms like zero trust. I mean, they nod their heads again then certainly don't really understand what's going on with AI and don't understand why, uh, they're getting phished every minute of the day. But how do you kind of sit down with them and start this conversation?
'cause I think most cybersecurity people are struggling with that conversation because they themselves grew up in their own little nomenclature and the terms don't normally apply. Yep. I think one of the best things they can do is show them like scenarios.
Um, take the MGT or MTG um, cybersecurity event that just occurred. Well, um, a couple weeks before that happened, a different casino got, um, exploited and that's where it had, let's say the SEC cybersecurity individuals gone up to their executives and said, Hey, this other competitor casino just got breached. We, we need to be on our guard 'cause there's an APT out to get casinos or it may, may seem that way.
And so that's where presenting it to 'em of saying, this is a like scenario of something happening and we don't have a defense for it or we don't feel comfortable having a defense for it. And I think one of the, the biggest things in business is where the numbers, they can be cold, but people should not be cold. People should invite that conversation because even with an organization where their business leaders are nodding the head of saying, yes, zero trust, zero trust, sure, whatever that means.
But if you say, well, basically here's the data of if this gets exploited, we are going to lose a quarter of the city's grid, then that may, may open up eyes and like, well, how did you get that data? And then that's when you can show them of where it's actually happened. And yeah, I, I've talked to my wife in the past, I'd like talk to my wife about these fun things that happened.
But, uh, I, I tried even looking it up today to see if I could find that article. I think it was back in 2013 or 2015, uh, two different Russian hacker teams were having an argument with each other and they were different cities and they were like, oh, our team is better. No, our team is better.
Well, they put up a competition on this certain day at midnight. They would race to see who could shut down each other's city. I think it was within five minutes an entire city was shut down for days.
And that's where these things have happened and they have continually happened over the course of years, but we again, cover the, the blind eye to not receiving that open source intelligence to really strengthen our conversation to those business leaders. All right folks. Well, you heard it here.
We can bring in full circle. Just like you had fire drills when you were in school or for that matter in the office, you need to have cybersecurity drills to know what to do and figure out how to prevent Yes. Things from happening.
Hey Matthew, thanks for being on the show. Thanks for inviting me. Good to be here And back to you guys in the studio.