Cybersecurity in a Hybrid World: Dan Cole on Resilience, AI, and Sophos Workspace Protection
Dan Cole of Sophos shares insights emphasizing the shift from pure prevention to resilience. He discusses how AI is shaping threat detection, the importance of consistent security policies for hybrid work environments, and the role of managed detection and response in addressing evolving cyber risks.
Transcript
Hey, everyone. Welcome back here to Techstrong tv. You know, we recorded this on the Snow Apocalypse Day, and a lot of, a lot of people, well, we were late getting this done because we had some people not able, not this one, but previous interviews we had people without power, without heat, without internet.
But my next guest has no problem. He's out in beautiful Honolulu, Hawaii. That's right.
Living the Life. Let me introduce you to Dan Cole, SVP of Product Management at Sophos. Hey, Dan, welcome to Tech Drunk tv.
Uh, Little Hi, Allen. Yeah, I'm coming from Honolulu Live. Um, yeah, yeah, look, it's, it's really nice to be out here and the weather is 76.
Nice and cold for us here. I put on a sweater, but, um, you know, we do have some stuff in Monolo. Occasionally you can snowboard that Yes, you do as a beat.
But, uh, the, the, one of the parts of living on a, the sad part is I do get up earlier than the morning, three, four of them, or it's actually six 30 years. The sun's not out yet, but you get a lot done that way. But, um, yeah, it's, it's been great.
Um, you know, um, being in Hawaii a lot of times you get both sides of the spectrum. You get a lot of folks. Um, my, my India team and Germany team, by the time they're up and I get up already halfway through the year, the day.
So yeah, lot, lot to get used to there. You know what I, I'll I'll admit, I, as I was talking to you off camera, I've been to Hawaii many, many, many times and I have fantasized about moving to Maui, actually. And I, and I figured that's exactly what I do.
I'd have to get up at about two, three in the morning, put in a day, but by noon the day, the rest of the day's mine. Yeah, Yeah. Guess Speech and all that.
Yeah, Yeah. No, absolutely. Of course, as I said, it was a fantasy.
Um, though my wife, my wife lived it with me, she'd do it too in a heartbeat, but, you know, so we settle for Bo Herts on Florida, where it's also about 76 degrees. Hey, Not a bad spot. A readable location, Not a bad, yeah.
On the water. But anyway, we we're just of course, saying this to rub it in all you poor souls out there. We're, we're snow in.
Dan, how did you get to be SVP of product management at Sophos? Tell us a little bit about your journey. Yeah, I know my journey here.
So I've been here for about nine years. I've definitely seen a lot of changes even at Sophos, but in the security business in general. But I rewind back to 1998, that's kind of where I really packed my teeth into security.
I worked that at telecom here in San Francisco, in California when I lived there, um, during the dotcom era. So my first experience, I think it was like day week one, where the Melissa virus hit and we Oh yeah. For the, for the SOC and the NOx for the, the Sun Spark Systems that ran all the exchange systems, right?
So my first week was balancing servers and then kind of fast forwarded a couple months later, then I love You virus, hit again, another issue there. And I quickly realized that it, telco is probably, although it's a hot spot, you kind of kind of run up and move up the stack. And our first job after that was in security working for a company called Sonic Walt.
And, um, you know, they're still around. They're still around. Yeah.
Yeah, I definitely, I have my roots there, but, um, code Red hit around that time. So, you know, it's just my, my experience in cyber has always been the reaction of all these different types of events happening and me just kinda like drinking from a water hose and figure out what is causing all these issues and how do I get a customer's back on the right foot. Um, yeah, so, so Sowa was kind of my first area.
Then kinda moving up the rank, we, I, I worked at a couple startups in, in Silicon Valley where we did some embedded chips where, how do we make the chips power be fast enough to run on these next generation of appliances and systems in there. Um, and then you've kind of fast forward about a decade later, moving in from, uh, sales into more of a PM role where I figured kind of going upstream, let's go fix the root of the issue, build the product the way we wanna feel, build it. Um, and I worked out a couple other different competitors in that mar that space there.
And, um, you know, I think what I learned quickly is that as you kind of move up the stack and up the ranks from, you know, an SMD to the enterprise, it probably just gets even more difficult, more interesting to go south. So I went from just having network security becoming kind of my, my main, my main forte to kinda expanding that and talking about the solution as a whole. How does it integrate with that, that interactive system that's out there, whether it be Sims or Jason Layer Chief technology, or even going up to second to cloud.
You know, that's kind of been the last 25 years of my, my journey being at Sophos. Um, the reason I came over to Sophos was to build a firewall from scratch. And, you know, in 2015, there isn't a lot of firewall vendors that are building things from scratch if, you know, a lot of times you're just kind of taking over an existing business.
And so the exciting thing about Sophos is they acquired a p two companies called Starro and Cyber, and they were trying to get those two technologies and build something new out of that. And, um, you know, Joe's, our CEO where I worked for in previous roles, um, was like, Hey, why don't you come over and go, go build this the way we wanna go build it. And so my last eight years here, my journey has been rebuilding the data plane to the management plane, the control plane.
And so now we have this new product called XGS that now it's in our second generation of hardware. So I'm really happy about, about that. But through that whole process and that, that exploration, we realize that as you move up from just the UTM you mentioned to next generation firewall to a network security clients, that it's not just that system that has to work with endpoint and has to work with adjacent technology.
So the last two, three years from that next, that next generation of technology we built, how do we now hook that into the rest of the ecosystem that Simple has? Right? And so, uh, I'll tell you a quick story.
So during COVID when we got hit with a lot of the different threat actors that were hitting the different vendors, you know, we're one of 'em, we actually have a great research pay product called Pacific Gram where we documented how these, these, um, poor national threat actors actually invaded our, our products and, and, you know, got into it through, through, through some very complex attacks. And I think that w that's the point in time where we realized that, hey, we some service that capability that can react to that. You know, we had those, we had a 24 7 bridge going on for weeks as we were responding to that.
So the, the, the, the birth of MDR really came from that experience that we had. Uh, we called it MTR, the not solid MDR. Um, so yeah, it's just been a really great journey last 25 years.
Just the, the evolution of where, where, where, where it all started to where we're now, You know, Dan, my my my security, oh, sorry, my AirPod came out. My security experience is probably similar to yours in terms of times and what we went through. I also got into managed firewalls in 19 97, 98.
Of course, checkpoint was like the only ones you, you know, with the OPSEC and all that stuff. And you know, and I was also protecting Sun Ultras, spark machines, and Ultra Spark tens and twenties. And I remember the Melissa and the I love you and, and all of these other things.
You, you look back on those days, Dan and is as hectic and frantic as it was as yeah, almost baby stuff compared to what we deal with today. You, you didn't have Nation, well, maybe you did have Nation state stu as threat actors then, and we just didn't realize it. Right.
But, you know, I mean, it was, it was kitty scripts and it was, you know, I did it because I could Yeah, yeah. Script kitties and just Yeah, Right. That kind of stuff, not, not cyber warfare.
Yeah. Yeah. Which is stakes has definitely been leveled out since that time.
For sure. Yeah. Well, the stakes, right?
The stakes are higher, the attack surfaces are bigger, the threat actors are more sophisticated where they, either, the technology is, you know, they use it as good as we can. And, and that's also been I think a, a constant during my career in security is, you know, don't think we're smarter than the bad guys. 'cause they, they, they ain't dummies, right?
They're, they're well funded, they're well organized, they're well compensated. Mm-hmm. Right?
Yep. They're, they're a formidable, formidable opponent. And we, you know, and, and almost by the nature of the beast sometimes they're always one step behind just by design.
Yeah. You know, I think for me, the philosophy of preventing stopping threats all the time, you know, it, it, it, it was kind of the, the goal in 2010s, 2000, you know, you, you find 'em, you stop 'em, you build out your signature database, you find a way to just sort that attack. And I think what we're realizing now is that, well, it is gonna come in and then how do you medic, how do you mitigate that time to reaction?
How do you mitigate the actual amount of the out spread of the breach? How do you know something came in? And then how do you ensure that you can quantify that value and that cost so that way you're, you're building into your budget.
That's what our customers, our partners are most concerned about is like, I think we're kind of in that, that that inflection point of like, okay, yeah, an accident will happen just like in a car, right? Eventually you'll get an exit. So what's your insurance policy?
You know, what is your remediation step? How do you kind of react to that? I think a lot of, um, board level, um, meetings are kind of in that, that top discussion point.
So no longer like whether or not gonna be attacked, but when it happens, how do you do then react to it? I think that's why products like services like MDR have really popular nowadays because we, we realize that that's that extra layer that you need. It's really kind of that additional insurance policy you have.
Um, but just let the car knowledge in that Absolutely. Look, to me, this all falls under resilience. Yeah.
Right? Absolutely. Yeah.
We, We, we, we, we had a shift from prevention to resilience. Not that we abandoned prevention that that's not it, but really, if you didn't have your resilience kinda planning built in and layers, you're, you're in a bad place. Dan, you mentioned it a few times.
MVR, is that what it was? MDR, what does that stand for? Energy detection of response, which is exactly what we're just talking about, right?
It's really about Yep. Managing that process and, and you know, with, you mentioned AI earlier, and that's, that's really kind of what's changed us at inflection point there as well, where it's just, you know, how do you ensure that as you have your systems that are really complex and hierarchical or sending that information, that data in, and there is some type of an attack or a breach, you know, do you have the personnel, do you have the AI augmentation that you need to first find that incident? And then how do you go react on it?
Right? And so, um, you know, at Sophos where we quickly realized as we have these products and customers installing it and deploying 'em, that when you have these type of events, what is that extra layer of, of personnel that we can actually provide to you at a, at a scalable level? And then how do we then use AI to ensure that detect and find those things faster?
You mentioned that, that, you know, the attackers are getting, they're getting faster, they're using those tool sets, so how do we then, you know, respond in kind? So yeah, it's managed detection response. Absolutely.
Um, probably read the news. We, we recently bought a company called SecureWorks where we, you know, we were able to kind of scale up with that new platform that they brought in. And SecureWorks actually been around for a very long time servicing various US customers and government institutions and banks.
And so by getting that technology, that core capability and that human intelligence, we're able to snap that in into the Sophos ecosystem, into our product database. And, um, that just gives us that extension that we need, which been really great. You know, I, I, I so my own, again, back to my own personal journey in security, I, I was the co-founder of a company called Still Secure.
Yeah. We did, uh, intrusion prevention, vulnerability management, network access control around 2007 or oh eight. I came to the realization that security was just too hard for so many, most organizations.
Yeah. And that MSSP was, was the way to go. You had to have, you know who you gonna call, right?
It, it Ghostbusters isn't helping you. Right. And so you needed, you needed that managed security service provider, and we bought one down here in Florida, and we were, you know, plans were to do more.
And then, you know, the oh 8, 0 9 kind of economic downturn came and mm-hmm. Actually I left, still secure then I've been doing this ever since. But, um, I, you know, SecureWorks of course was probably in the US anyway, uh, probably the biggest of, of the MSPs, you know, that, that brought that in.
Dan, if you don't, if you're okay there, I'd like to pivot over on January 20th, Sophos announced something called Sophos Workspace Protection. Yeah, yeah. That, that's, That's WP Workspace.
Yeah. You know, you know, really pointed, uh, the naming convention there. It's like, well, what do you do with this product where it's, it's really to protect your workspace.
Um, actually, you know, good story. During, during COVID, um, my wife and I decided to, you know, kind of roam around the country a little bit. You know, things were, you know, being in, stuck in a house.
My son went off to college and we're like, Hey, let's go explore the country. We actually stayed in Florida a little bit as well. And, um, I was remote quite often.
And so the idea came to me where like, hey, we're, I'm always, we're, you know, remote and, you know, our, our technology has us, you know, either V VPNing our Z ting, and to the infrastructure to access all the different things. And, um, some locations didn't have good internet. So, you know, what happens in those circumstances?
Some things, uh, require a little bit more deeper investigation that maybe A VPN doesn't, just doesn't cut it for you. So, you know, this idea came up of how do we kind of embed technologies into, you know, what you're working on. And, and the, the core part of workspace protection is really, you know, using a, a kind of a, a bro, a browser, a browser extension, using our, our, our ZTNA platform using DNS extension, using email extensions, and kind of hooking in that all together and having that consistent user experience.
Um, for people who are looking for, you know, suffic for the, those hybrid workers, those folks who may be come into the office a little bit or maybe are remote a hundred percent of the time, how do we ensure that their security experience is consistent wherever they go? And so, you know, there's been other d different technology acronyms throughout the SASS ESSE that kind of came about the last, you know, this decade has been pretty popular, but you know, that, that has a lot of big up upfront infrastructure costs, requires you to tether certain infrastructure that's processing the data in the cloud. And you've been in the industry as long as I have.
So we, we've done variations of that back in the day. Cloud web security Yep. IES and stuff.
And they have your own set of limitations and caveats and stuff. So we didn't want to go down that route. We wanted to go down something that's gonna be a little bit more specific and pointed into the user experience.
And, you know, one of the power power pool play of Sophos is, you know, we, we were an endpoint company from 1980s back in the day when it's on Flocky Drive back in those days. So, um, we have a really big endpoint presence. So we have an advantage a lot of these other SASS CSSC vendors that they didn't have, which is we have footprint coverage, right?
And so like, well, why don't we use that as a leverage point? You know, we already have endpoint agents. What if we were to extend web control, web behavior function, which, you know, most of our activities done through web browsers we're most inside even the SaaS applications just all piped in through your web browser experience.
You know, very rarely are using thick clients anymore, right? So, um, so yeah, the workplace protection was like a, a, a elimination of all those different technologies presented to our customers using kind of our endpoint footprint. And then, um, and on top of that, we, we hooked that into So central, we just kind of a, the single source of truth that's sort of cloud management platform.
80% of our firewall customers use, use central management. So that's pretty powerful. It's, it's been adopted pretty worldwide and our endpoint's only managed on Central.
So by doing that, we're able to harmonize the policy configuration of endpoint firewall and now the workspace protection, uh, suite. So that way you get that universal experience, whether you're on network or off network. And so really beautiful.
We're elegant, we're super excited about it. Um, we went EAP last week. We have over a thousand people signed up in one week.
And so, and we're gonna go ga this thing in February 26th. It's been about a year and a half in the making. Um, we don't wanna just, um, it's actually powered by Island who's our partner for this.
And, um, island has been doing, uh, enterprise browsers for a very long time. They're well, well respected, renowned, um, in the enterprise space. And so we struck a deal with them where we wanted to kind of collaborate and we wanted to make sure that it's not just us providing the code and to our customer, because we and our customer is a little bit more sophisticated in the sense that we have to kind of scale up and down in organization sizes.
Um, they're used to using SOFO Central and they're also missing some other critical pieces like DNS Protection and ZTNA. And so we thought, hey, let's get that stack from Mylan, let's combine it with our stack and make it all presented to Central and make it a really easy to use experience. So that's kinda what we did the last past year and a half.
So super excited about the launch. Um, we're really looking forward to it. Yeah.
Very cool. So GA on, this is February 26th, about a month from the day you and I recorded this. Yeah, Yeah, yeah, that's, um, we've been about EAP for the last two, three months.
So we've been having a lot of early beta testers and the, the, so far the feedback has been awesome. Amazing. Um, a lot of folks are getting this feedback as to how they plan to deploy it, how they're trying to augment their, their cus users with it.
Um, a lot of the use cases are stemming around, uh, that, that hybrid workforce, right? We have a lot of, um, customers who have offices that are now back online and they're mandating two to three days a work week, or they're still keeping some of their, their hybrid workers remote. So they're trying to fi figure out, how do I go to address this now that we have customers coming, yeah.
Users coming in and out of the network, how do we ensure that we have our, our security policy consistent? So that's the use case that we're driving for, so that we think that's, that's gonna resonate real well. Very cool.
Hey Dan, we're about outta time. What would, you know for people out there who's saying, wow, Sophos, this ain't grandpa's Sophos, right? There's so much going on.
How do I stay on top of it? What would you tell 'em? What's the best way to stay in the know on Sophos?
Oh, you know, some of us like to use Chate or Gemini or whatever. You can always search that and see what's new, but, um, you know, the traditional way is just, uh, you know, we have a great LinkedIn site. com, check out workspace.
Um, you'll find all the details that you talked about there. And, um, yeah, uh, we're, we'll, we'll, we'll make sure we propagate this video and anything else on different social media platforms as well. Very cool.
Hey, Dan. Enjoy, enjoy Hawaii, right? So you up as well.
I won't be out there this year, maybe next year. I'm waiting for them to rebuild the haina, but it's gonna be a while. Um, anyway, though man, keep up the great work at Sophos, this Sophos workspace protection sound.
Sounds great. Uh, MDM also sounds great. There's so much going on.
It's, you know, look, this is an exciting time. It's always exciting insecurity, but the stakes have never been higher. So Yes, sir.
Thank you, Simon. Good stuff. Appreciate it.
All righty. Dan Cole, SVP product Management at Sophos here on Techstrong tv. We'll be right back.