Cybersecurity Priorities and Embracing Zero-Trust – Jason Loomis, Freshworks
Jason Loomis is the chief information security officer at Freshworks, the company creating business software that anyone can use. In this interview, Jason and Alan discuss the importance of prioritizing people in cybersecurity, the shift to a zero-trust approach and the challenges faced by CISOs in today’s industry.
Transcript
Hey everyone. Welcome back here to Tech Drunk tv. You know, I, I had this next gentleman on with us a couple weeks ago, and I invited him back 'cause I, I felt like we barely scratched the surface and what I wanted to talk about and what he wanted to talk about.
So hopefully we'll get a little bit more into it today. And if we don't finish it today, we'll bring him back again. Um, he works cheap.
So let me introduce you to my friend Jason Lewis. Jason Loomis the Chief Information Security Officer over at FreshWorks. Jason, it's great to have you back on.
How's everything? Hey, Alan. Great to be on again.
Uh, everything's good to have you. Everything's hot. Yeah, we were talking about it off, off camera.
It is, uh, it's funny, I be the, the interview before you, I had some folks from Athens, Greece on, and it, it was 110 degrees there. Wow. So it, it's, it's not just us, it's, it's global climate change, I guess is real.
Giving Us something else to talk about besides AI and chat GPT. Well, we could talk about how AI and Chat GPT can help with global climate change, but let's not, and say we did. Jason, you know, for people who aren't familiar with FreshWorks, why don't you give 'em a quick little kind of just refresher?
Yeah. Uh, FreshWorks is a, we're a global SaaS solution provider. We provide I T SS M, so if you want software to run your IT business, uh, sales and marketing teams, um, we provide software that's just really stupid, easy to use.
I don't think that's a real sentence, but yeah, it's just, we made it really just make it simple and at ciso it's my job to make sure we're doing it securely and protecting our customer's data. Excellent, excellent, excellent. Um, so, you know, you mentioned ai.
Everyone's talking about AI and chat, GPT and I saw a survey today. What are the top three considerations around AI usage and, and security was number one, it's always number one for these kinds of surveys, right? That doesn't necessarily mean we're putting a lot of dollars to it.
It just means it's, it's a top consideration, unfortunately. But nevertheless, Jason, I I think it's, it's already having an impact on CISO and their jobs and what they've gotta do. And it, you know, we, we talk about how, how, how does CISO, what does CISO have to do to be effective today?
And I think a, you know, some AI awareness, if you will, has, has probably crept into that picture. But of course there's more than ai. So what, what do you think how, what, how, how, how to be an effective CISO today?
Yeah. Um, you know, it starts with figuring it out. You know, a this is so new, you know, this is like, came out.
It feels like it came out of nowhere. It feels like six months ago we were talking about how a covid rebound is happening. And then suddenly, wow, everybody's using chat.
GPT, everybody's using ai, everybody's trying to develop it into their products. So, to be honest, it's, it's just keeping my neck above water to figure out, you know, what's going on with it right now. And then, you know, that's typical, right?
New products come out, new solutions come out, and then security has to figure out how to adapt to it. Yep. Yeah.
So right now it's really in the adapt adapting phase, trying to figure out how we can do this. You know, it always starts, you know, this is a challenge for every company. My company too is, you know, we gotta start with administrative controls.
So this, you know, as a ciso, we love the word control part of what we do, but that's really comes down to what controls are we gonna implement to help protect security and privacy for the organization. And we're trying to figure out the controls. It always starts with, you know, the simple administrative controls, like telling what you should and should not do with it.
And that's where we're at right now. And then, you know, it's now the market's gonna start opening up to how can we put in technical controls, these technical ways of actually, you know, for example, first thing you wanna tell people, Hey, Alan, it'd be a good idea if you don't give chat GPT your social security number. You know?
Yeah. That's the administrative control. Hey, don't do that.
Yeah. The technical, I, uh, It'll be interesting. Let's build our system so it keeps you from entering or sends you a warning.
Oh, oops. Hey, I probably shouldn't do that. A little popup or something.
So that's like phase two of it. Right now we're starting at the administrative control level. The, so, you know what bums me out though, people will blame AI for, for taking someone's social security number and somehow making it available or something.
Well, I'm AI's not the idiot who gave it to it. Right? I mean, uh, it still goes back to an old adage in security that the weak, the weakest link is the, you know, in between someone's earphones.
Right. And, uh, you, you do stupid things, you know? And stupid happens.
It is, I know, we, we, we, we kind of chatted about things we're gonna talk about today. And I absolutely believe they're all connected, including AI is connected to, you know, how CISO work. We, it, it's, it's not technology, it's people, you know, really that's what a CISO's focus should be, is Yeah.
Beings communicating to human beings, talking to human beings and Absolutely. Yeah. Humans are the weakest link.
Yeah. It's, it's our weakest link in security And, and always has been. And I think probably, unfortunately always will be.
But you made an an interesting point there, Jason, that I think bears repeating an emphasis, which is, you know, so much so, so many people, when we think of the role of the CISO and what a CISO has to work about what we think of controls and technology and processes and, and regulations and governance and, and, and these things. And, but at the end of the day, it really is about people, right? How do you keep your people, both your, you know, employees of the organization as well as your customers who are people and, and, and, you know, and the people you interact with as secure as possible and what, and what, what kind of, I don't wanna use the word guardrails, but what do you put into to kind of make that happen?
Oh, how much time do we have for this? Yeah, I know. I that, well, that's always, this, this is what happened was the last time we talked.
We, we tackle big subjects, you know, in 15 minutes or less, you know, one of the, which is the world we live in. But God, I have a, I have a, a foundational mantra that I use for my teams one, and it's, it, I call it the three C's. Is it how I want our team to live and work how I live and work how I breathe?
Guess what the three C's are? It's communicate, communicate, communicate that it, 99 problems, I swear, come from a lack of communication. Mm-hmm.
So I over communicate to the, to the public, to my, to my stakeholders, to my team. I want to be CC'd on everything that means carbon copy for people for you millennia, gen Zs that don't understand what email is. That means copy me on everything I want that insight, I'm gonna copy you on everything.
So at least we have that visibility and that communication. So I think it starts with that open the doors of communication. A lot of CISO are very tight vested, right?
Like, oh, I can't share this because it's confidential or there might be a risk. And I think you actually cause more risks and more problems when you don't share information as a ciso. So I tend to over-communicate as a ciso.
You know what, that's an interesting, uh, so I, I'm all in on communicate, communicate, communicate. I think for a long time a lot of CISO played a lot of stuff very close to the vest. And, and, and it was interesting.
It was like, oh, when I talked to my board, I can't tell them everything. 'cause they don't understand security. I almost, I have to dumb it down for them, right?
I have to, I have to translate it to business speak. I gotta give it to them in, in ways they understand. I gotta spoonfeed them.
You know? And, and so what happens is the CSO becomes the, um, well it could become a bottleneck, right? But they also become the, the what, what should I pass through and what should I not pass through?
And it's not just communication, like up to a board or the rest of the C level, it's communication down as well sometimes to my people. And, and it's communication from security to, to it, for instance, or non-security, security to risk and compliance at the financial officer, the CISO in many organizations, that was one of their big jobs was figuring out who, what and when to tell about security related cyber related issues. And you are saying, you know, you're saying you, you're a successful ciso and you, you've had sort of an open border policy, if you will, right?
You're just, you're, you're brokering, you're sending the information everywhere it needs to go and you're not necessarily filtering it. I start with that. Yes.
You know what, what you just, uh, brought up is I think the storytelling aspect of what an important job a CISO has is you have to be able to talk to the lowest common denominator of the audience. If you can't explain it to a fifth grader, the concept of what you're trying to get across, well, you need to, you need to be able to do both. And you need to be able to go as tech as you can.
And you know, boards today are, there's a wide variance of expertise on boards. Tech companies like I work for tend to have more technically oriented board members. So technology, it is the language of the business.
So this old school idea, which you know, is still out there that, oh, well you gotta speak the language of the business. I'm like, I'm sorry, but it is a language of a business. You can't speak it as a board member.
You know, in today's world, it's, it's actually, I think that's a failure of the board member not to understand the basics of it, but to me it is a language. But I also have to be able to not, you know, there's a certain level of depth they're not gonna get to. And that's where the storytelling comes up.
You know, you break it down to analogy or tell an interesting story about it so that they do understand what that means from an IT perspective. So another good skillset and Being clear, you're, you're not equating board members with fifth graders? No, no.
You know, you're like the third person to call that out. No, not at All. Okay.
Alright. If you can tell a story to a fifth grader, anybody in your audience is gonna get it. Board member or you know, salesperson.
So, absolutely. And I'm not calling salespeople fifth graders either. No, I get it.
Well, Don't get me started. But, um, but, you know, but that being said, you know what, Jason? I, look, I've been talking to security people a long time.
We've been talking to CISO a long time. There were a lot of CISO who felt it was their, part of their job was to be the translator and the governor, if you will, of information flow up and down the stack, uh, around cyber. And, and I, I agree with you.
I, I think I trans, I trans I look, I'm a C E O right here, and I, I have, I try to be as transparent as I possibly can be to our whole organization so that everyone knows exactly what's happening and what's expected and what, what success looks like and what failure looks like. And you know, I, you can't have enough transparency in, in, in my opinion. But again, that's just my opinion.
Um, that being said though, let, let's move on a little bit and, and talk about look with so much on their plate today, right? What, back to this, what does it take to be effective? How, what should CISO be prioritizing today?
Today? You know, it goes to that how we opened the conversation about, you know, well there's the three pillars, people, process, and technology for any cybersecurity program. That was my big sigh because still in today's world, it seems to focus on technology and then process.
And then people, I think CISO absolutely need to prioritize people. They need to prioritize training their people, educating their people, making sure their people are happy, satisfied with their role. Especially with the shortcoming that we have in the security.
Like, what is it, 86 per or 86 million? Well, ah, I don't even know my statistics right now, but there's a shortage of finding talented and skilled and capable security people in the industry. So for me, my number one priority is people.
And it should be for every ciso. I, I don't disagree. I don't think it's 86 million.
I think it's like 6 million. There might be a million open jaws, something like that. Yeah.
There, I mean, the bottom line is we don't have enough people who have security skills. But, you know, to that point, just going off, I was, I was on LinkedIn early this morning as I often am, I, I look at my LinkedIn kind of feed and people ask me things or what have you. A guy, uh, a guy put out there, he was a guy who probably a little older, he sort of had a midlife career change and went and decided he wanted to be a cybersecurity guy.
And he's got CompTIA and a bunch of other certs. And he, you know, he's, he's trying to break into the cybersecurity space and he seems like he has plenty of, of, he, he went back to school as like a community college cybersecurity, uh, offering as well. And he can't find a job.
He's like, I don't know what else to do. I've sent out 1300 resumes or some crazy number like this. And I, these are the, you know, the certifications in education, but I don't have a, I'm short on heart, on real life experience as a security person.
There was a truck driver and a welder and some other things in the rest of his life. There's that disconnect. This is something I hear a lot.
Yeah. You took the word on my, there was a huge disconnect in the cybersecurity industry and the talent acquisition pipeline. And I, I, I can, I can blame a lot of different people for this, but, um, recruiters need to stop having, thinking that they need a one to two year experience for an entry level position.
It's entry level, right? It's entry level. And even then, I'd argue that some non-entry levels, if you have any kind of tech experience, if you were a computer gamer, if you built a computer, if you have the certifications, to me that counts as one to two years.
So this idea that, that, oh, they need to come in knowing what they're doing. No, you don't. You'll figure it out.
Take it, you know? Sure. Yeah.
How many times in is this being recorded? How many times in my career I faked it till I made it? You know that?
No, I don't. No, No. But you know what?
I wanna figure it out. I'm gonna figure it out. So you hire a talented individual that has that drive and that willingness and they want to learn.
I'll hire that any day over someone that's just, you know, doesn't really care, but has four or five years of experience. I, I agree with you a hundred percent. But it's something, and it's not necessarily that, well, CISO can help because, you know, they make these kinds of decisions, but it's something as an industry that quite frankly, we suck at.
Right. You know, and, but, and, and by the way, it's not just cyber. I remember in DevOps, right?
com, DevOps burst on the scene. It's 2013. And there are people, you know, whose job, uh, you know, they're posting jobs.
They need three to five years of DevOps experience. Well, DevOps has only been a thing for two years. Where, where, where's anyone?
You know, you could say I was doing something. It wasn't called DevOps. Okay.
But yeah, a lot of times, and, and this begs the question of this whole other thing is do you need to go to college for some of these technical positions? I'm a big believer in going to college. It makes you a well-rounded individual and it teaches you things beyond whatever, you know, kind of thing you may specialize in.
But we shouldn't impose that. You need a master's degree to, To be an analyst, to be an engineer, to be a contributor level for security. Absolutely not.
You do not need that. No. And I, you know, I think that's another big pet peeve of mine.
Let's talk R T O and how it's affecting CISO. Yeah, I I, I hear that question a lot. I think it depends on what type of environment is a ciso you're, you are currently in.
So if you were in a non r t o call it old school banking and finance, everybody came into the office and had their desktop computer underneath their desk, then yeah, you're, you're up for a lot of shift with this whole, you know, return to office or the work from home thing and now coming back into the office. Um, for me it's, it's, and for the shift in security is this whole, this idea of zero trust, where they're getting rid of this whole idea that we're gonna trust your laptop because you're in the office or trust that you're in the office. We're just gonna pretend that, that if you're, you could work from Starbucks and we're gonna have the same security profile.
And that's how I approach it. And that's how every CISO should approach it. Assume that laptop sitting in a Starbucks with open wifi, you need to protect their connectivity, their endpoint, everything with that.
So that if they're in the office, not in the office, they're at home, they're at Starbucks, they're in Russia, okay, maybe not Russia, but they're, you know, remote. That's where you wanna look at, you know, protecting that endpoint and protecting their access and making sure that you're doing continual checks. This idea about user behavior based risk assessment for, Hey, you know, Alan's really clicking really fast.
I mean, this is a way that you can do in security these days. He'd be like, you know what? Look like Alan, he doesn't click the mouse that fast.
There's tools and solutions that can help us detect that and that helps us that we don't care where you're working from in the office or outta the office. Absolutely. You know, I, I tell you, I had the, here I work in my office, right?
We have a nice office down here. And yesterday we had the annual fire extinguisher inspection guy come in and you know, I'm the C E O, we have about 10,000 square feet. So I usually walk them around 'cause the last thing I want is to get in trouble 'cause we don't have enough fire extinguishers or they're out of date or whatever.
So I always walk with the guy and it was funny, you know, he, we walked around, he, everything looks good. He says, look, I gotta go into your server closet, make sure you have an extinguisher in there. And we, the way our office is done, actually I have two what used to be server closets, right?
And I said, all right, come on, I'll show 'em to you. And we, we go in the server closet and they both do have fire. I forgot they were in there.
There's fire extinguishers in there. I said, well, let me ask you a question. Take a good look around here.
You, you see anything that remotely resembles a server in this closet? 'cause one of the closets I used to store the extra paper towels and toilet paper and cleaning supplies and the other closet. The only thing electronic in there is I have one wireless access point, one little wireless access point plugged in all the, there's racks, there's all the phone kind of things that you would, you know, that you would hook wires to just sitting there empty.
What do I need a fire extinguisher in here for? I mean, it, it's a waste. But, and, and I think for a lot of organizations that's true.
So whether they're working here in one of my offices or they're working at home, Jason, I gotta treat every device the same. They're logging on via wifi and once they're logging on via wifi, who really cares where they are from, from a security point of view. From what I'm doing.
Right. Exactly. Exactly.
Yeah. This idea, I, I don't trust anybody in the office or outta the office. I think the old method didn't, the old method was, hey, if you get through the front door, you got open access to everything.
No, it was the Eminem security model. Right? Hard on the outside.
Soft on the inside, right. Melting your mouth. Yeah.
But, um, I, I do, I I think that's absolutely the thing. And I'm not, look, I happen to believe teams work better in offices for certain things, for certain things. Team, you get more done in an office in that collaborative environment that I just can't, I can't duplicate remotely.
But Agree completely. Creativity based activities. When you're strategizing, when you're road roadmapping Yeah.
You're trying to create new ideas, you need that debate, that con The velocity. Yeah, the velocity and depth of communication. But from a security point of view, I don't really care where you are.
You, you, they're all logging in the same way. Anyway. Hey Jason, we're about outta time.
com. com. Yes, absolutely.
And if you wanna ask me anything, you can reach me on LinkedIn. Jason Loomis with FreshWorks. You gonna be out Maybe a black hat?
I will be a black cat. You're gonna be there too. Um, maybe I'm glad you asked that.
Yes. I will be in Las Vegas. I won't be at the Black Cat event because Informa has clamped down on giving out media passes to media unless you happen to be working for one of the informa owned, owned media outlets.
Wow. And so they, they actually refused me and everyone else here at Techron, our media passes. That's nuts.
I don't Know if they think we're a threat or what, but that being said, I actually do have a beautiful suite at Mandalay and I will be doing video interviews there and I'm sure I'll be out at night having drinks with my friends and enjoying the, you know, security summer camp. So I'll ask your people to get my people and maybe we could grab coffee or a drink or something. Tell me in See in person.
Absolutely. I look forward to it. Alright.
Jason Loomis. C e uh, c i s I almost made you c e o there, Jason, c i s o of FreshWorks here on Tech Drunk tv. We're gonna take a break.
We'll be back in a second.