Evolving Cybersecurity and Compliance: Bob Plankers on VMware Cloud Foundation 9.0
Bob Plankers, a product marketing engineer for Broadcom, dives into how the management of cybersecurity and compliance is evolving in the age of integrated platforms such as VMware Cloud Foundation (VCF) 9.0 that will be featured next week on a Tech Field Day event hosted on Techstrong.tv
Register to join our event on July 29th at 9:30am ET to learn more and chat LIVE with the speakers!
VMware Cloud Foundation 9.0 Showcase: Powering the Modern Private Cloud
Transcript
Hey guys. Thanks for the throw. We're here with Bob Planker, who's in charge of product marketing for security and compliance for the VMware Cloud Foundation.
Over at Broadcom. We're talking about how the whole relationship between IT and security and compliance is changing. Bob, welcome to show.
Oh, thanks for having me. Mike. Historically, security and compliance kind of sat off to the right and everybody in it did their thing.
And then, you know, we tried to bolt something on after the fact. I feel like that's fundamentally changing these days 'cause we're managing platforms in a more holistic fashion. Is that what's going on from your perspective?
Yeah, absolutely. And, uh, it's nice that security gets, gets some attention. I mean, some of the attention it gets is bad.
It's because of ransomware, it's because of high profile attacks and things like that. But more attention is being paid to that. And yeah, and to your point, we can manage it more holistically too.
You know, if we start thinking about it, build it into the products, bake it in, not just bolt it on. Hmm. So how does that manifest itself and how does the job function change for the IT team?
Well, uh, security is just, I like saying it's an inherent property of a system. It's just there. It's not, it's something you should be always doing, but, uh, you know, it doesn't move your organization forward.
It, uh, uh, it keeps it from going backwards really quickly sometimes. But the, uh, you wanna do security, you want to be secure and you wanna be secure fast, and you wanna stay that way, but you don't wanna spend a lot of time on it. And so that's, that's really the challenge when it comes to, uh, uh, you know, how this stuff manifests.
Can we make it such that IT professionals can get this stuff done, can make sure that they're secure, can do a continue, we can monitor continuously, you know, like, did something change? And then even be able to drive answers to questions like why did it change? What changed?
Things like that. And then, uh, and get them back to helping the organization faster. It also seems like maybe this is just an oversimplification, but don't we just wanna make it easier for folks to do the right thing?
I think part of the issue is that sometimes configuring things is just too complicated and it's easier to make a mistake. So in some ways, is this a security by design issue and how are we gonna go fix that? You're exactly right.
In fact, I really like that you said that. 'cause I say that a lot. Make it easy to do the right thing and people will do the right thing and they'll turn it on.
Or we can turn things on right away, uh, and, you know, have it secure out of the box. We do that where security's always a trade off though. And so, you know, sometimes there's business decisions to be made.
Sometimes there's performance decisions, uh, things, things like that. And so the things that need human interaction need it to deal with them, we make it, uh, we really try to make it easy to, to do, uh, eliminate trade-offs where we can, you know, we've got a, uh, the VMware classically now Broadcom VCF has got a small army of user experience designers that actually worry about how humans deal with these, these tools and these features and all of that stuff. And, and you can really tell, because we make a lot of the stuff really simple.
In fact, uh, some of the features that we've got when, um, uh, when I explain that it takes less than five minutes to turn it on, if you're brand new. People don't believe me, but it's true. You know, it's because we've thought about it.
Mm-hmm. Is the relationship between IT and security changing them because the security folks have always been understaffed in shorthanded. And I can't help but wonder if more of the security operations tasks are being, uh, now managed by the IT team to kind of augment the security folks who maybe can then spend more time looking for threats.
Yeah. That's actually kind of the dirty secret of all of this is that CIS men's, the practitioners, the virtual virtualization administrators, they've always been on the front lines of security and security. The security groups sometimes really just tend to be a policy group.
They set a policy and then a policy and auditing. They set a policy, Hey, the organization should have passwords that are 400 characters long or something, whatever. That's ridiculous.
But you get my point. And, you know, and then the s admins, the virtualization admins, all of the, the workload admins, app administrators, they're the ones that implement that. And then the InfoSec folks check to make sure that that's, that's happening.
And so that's, that's always been the relationship there. I mean, all organizations are different in, in ways, but you know, the, uh, helping where we can help check this stuff and help check it continuously. Uh, and that's the thing with security.
Security and compliance often get conflated with each other. Compliance, regulatory compliance is a business process. And these checks are for compliance, including the checks for the security controls are periodic, you know, like every year, every six months, something like that.
And that's too long, you know? And so can we speed that up? Can we, can we help administrators know that they're insecure faster than six months from now?
You know, if I change something right now, well, if it takes six months, that's six months of opportunity for an attacker and we can't have that. So, you know, doing continuous monitoring, things like VCF operations that do continuous monitoring of these controls on an hourly basis or less, you know, that's, that's really where it's at. And that's really what helps, you know, be on top of the stuff instead of running after it later.
Just be on top of it right now. Hmm. Of course, you can't walk down the street these days without somebody leaping out to tell you about their great new AI thing.
But I cannot help but wonder if AI and agents and all this other stuff will further streamline all these operations where I can converge more of the management of it and security. Um, I think you're right. Uh, ai, you're stumbling into an area where I've got, well, I've got opinions, you know, ai, we've kind of invented a child, you know, and, uh, the, uh, uh, there's a whole, there's all these security things within the, it's a very rich field of, of research as far as AI security and not, and there's a whole lot of different aspects to it.
You know, there's geopolitical things, there's, you know, but there's even people just doing jail, what they call jail, breaking prompt, jail breaking, all of that stuff. Can you get the AI to do something that it you, that the owners of it taught it not to do, but maybe you can convince it to do it. You know, that's why I call it a child, you know?
And you can convince children to do things that maybe they shouldn't do, that sort of thing. And, uh, the, uh, um, and so AI doing that, you know, that's, yes, I think AI is a future. We are definitely living in a William Gibson novel moving forward here, but the, uh, um, uh, you know, we need to be careful about how that works.
I, I think AI helping us explain things, uh, you know, hey, dear integrated ai, what's, you know, what's talking to TCP port, whatever on one of my systems? You know, I think that's a great thing. But AI making decisions for us, we need to still con continue to have some supervision there so that, uh, uh, a malicious person can't come along and convince AI to do something we don't want it to do.
Mm-hmm. When I look at BCF, it really is the convergence of compute, storage, networking, and security now who wakes up in the morning and has the aha moment that we can converge all this and manage it in a more holistic fashion, because we've been dealing with it silos now for decades. And I think there's a certain amount of inertia in the equation.
Yeah. Uh, inertia's a a thing, you know, but who wakes up? Well, I'd like to think VMware and, um, the VCF division of Broadcom, we wake up and think, Hey, we should do this.
But, you know, I, I think for most organizations, it's not just a, a realization necessarily, but it's a gradual working towards it. You know, like when you realize that you don't have to spend so much time babysitting a certain aspect of your environment, or, you know, you can integrate to your storage instead of worrying about the storage as a separate piece. It's just part of the virtual environment, and you patch it along with everything else, and the compliance audits are along with, uh, come along for the ride.
And it's, it's that stuff. It takes a little time, but you were, you start realizing that you've got more time to spend on, again, things that are productive that move your organization forward, helping an organization, an organization helping their actual customers, you know, building applications on top of these platforms to do that, whatever the organization does, you know, like, and I think it's just kind of a, a maybe a, a retrospective realization in a lot of cases that, Hey, we saved a lot of time with this. Mm-hmm.
Interestingly enough, you mentioned compliance and what is your sense of how much time are it folks spending on compliance? Uh, you know, it's a chore. Nobody enjoys doing it.
It's a necessary evil, I guess, but can that whole process be even much more automated than it has been historically? Yeah, absolutely. And so what they're spending a lot of time on it, and it's, um, it's related to security.
I said earlier that security and compliance are different things, but they're like cousins, you know, uh, compliance is checking to make sure to make sure that you're doing security, but it's checking so that you, in order to, to let you participate in an industry. So if you wanna run a hospital or a nuclear power plant or something, you know, like there's regulations, you wanna take credit cards, that's a great example. P-C-I-D-S-S, and you want to take, uh, credit cards, you want to get paid, who doesn't.
And, uh, the payment card industry, PCI, uh, says that you need to follow certain rules in order to participate in, in their industry. Okay? And so once a year, you get in a visit from an auditor that goes through all this stuff.
The challenge is with auditors, auditors, there's just like everyone else, they're, you know, they have a wide variety of knowledge. You know, do they know what they're looking at with a particular piece of technology or not? You know, and are you prepared for it?
Or, you know, what are they gonna find everyone dreads these things? Because they, they, uh, the term findings, you know, the things that, that auditors actually find that are wrong, you know, and that get bubbled up to management and make, uh, and people take it as a personal affront that they failed or whatever. It's just very stressful.
So if we can short circuit that, you know, VCF operations, for example, the security dashboards, checking the stuff constantly, you know, so when the auditor shows up, you know exactly what stage you're in, you know, and, uh, you know what the auditor's gonna look for. Because we, one of the things too that we are really trying to do is standardize what we're telling auditors for security guidance and all that stuff. Auditors use our tools just like our user guidance, just like it practitioners do, you know, just kind of from the other direction.
And so if we can get everyone to agree on that, and we can help people check it proactively, not only are they compliant, but they're also more, more secure as they go, Hmm. How automated can we get? Because it's one thing to prevent the compliance issue in the first place, but almost inevitably we'll encounter some sort of issue.
But can I auto remediate that issue in a way that just reduces the overall stress level that you described? Uh, so I'm gonna answer that with the motto of it. If it had a motto, which would be, it depends, you know, and the, uh, uh, it depends on what it's, you know, and so that's the other aspect of this.
No workload, no, I've joked in the past that, uh, no compliance effort, no security effort ever survives contact with a real workload. And, you know, they're all different. They're all one size does not fit all.
And so remaining flexible like that and being able to have certain security controls for one application, but not for, or have them be a little different in compliance. There's a, a term called compensating controls, where if you can't meet, uh, a requirement directly, maybe you can wrap it in other things. You achieve the same goal just more indirectly, you know, and being able to support that, that that's, you know, that's something that, uh, the VCF platform does really well, is being able to support that flexibility.
The not one size fits all, but if you want more granular stuff, maybe, maybe certain things need different considerations, that's fine. You know, and then you can pato principle too. You can get rid of, you know, 20% of your work, you get rid of 80% of the, the problems, and then you can focus on the other stuff, you know, and really drill into why stuff is special, whatever.
But, you know, having that flexibility, having the automation, to your point, you know, can we automate a lot of this stuff away? Yeah. Can we remediate it again, depends on what, um, what it was, you know, what it is.
And if it changed, eh, you know, there's still some discussions there, but if we can be more flexible, flexible about it, that the differences, the, the need to remediate or the need to be different, uh, isn't a big problem. That saves a lot of time and effort. All right.
Hey folks, you know, there's a whole virtual event coming up on this topic next week on Tuesday. By all means, check that out. Um, but in the meantime, if you keep doing the same thing the same way and expect a different result, well, you know what the saying says.
Hey, Bob, thanks for being on the show. Yeah, thanks for having me. It's been a pleasure.
All right. And back to you guys in the studio.