HR and Cybersecurity – Keith Neilson, CloudSphere
Keith Neilson, technical evangelist at CloudSphere, explains why HR needs to become more involved in cybersecurity.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Keith Neilson who's technology evangelist for cloud sphere and we're talking about the role HR plays in cybersecurity Keith. Welcome to the show. Yeah.
Thank you Mike. Thanks for having me. There is a perception that HR folks probably don't have a lot to do with cybersecurity and maybe that you know, they're very focused on say compliance issues, but do they have a role in cybersecurity?
And where does that manifest itself? I think I think the absolutely do I think really what we see and what needs to be in place is a sort of synergetic business process that's in alignment with HR as a department as a function of the business along with it departments. And that's really to ensure that you know, we've got smooth transistor processes from onboarding of new employees with the assets that they need to use for their for their day job and their role and with access to systems that they need to use to function to deliver that role that they've undertaken but equally, you know and arguably from a security perspective potentially more importantly is the off-boarding process.
So I think Human Resources as a department absolutely does have a critical piece to play in that role. And that our boarding gets overlooked. I'm pretty sure I have access to at least three or four systems that companies that I probably worked for in the last 10 years that are still there.
Wax. What makes off boarding so tough for organizations? I think what makes us a tough is the lack of visibility first and foremost over what assets and what data what systems and potentially even devices, you know, an employee or even a consultant which is a slightly different challenge actually actually has access to and you know, of course throughout our employment life cycle, you know, our device has changed access changes.
We perhaps inherit access through groups, you know in terms of our user management. All of which has this Dynamic nature in terms of what we have access to and the level of access that we are actually granted. And so I think that visibility is a key issue because when it comes to off-boarding, it's it's about not only having a really comprehensive and and considered strategy and process to actually off-board properly and check everything but that's only as good as you know, the visibility you have technically to ensure that we've got a handle on what what exactly they did have access to so that we can you know, go ahead and efficiently remove that when needed so, I think it's a number of things.
It's the visibility. It's the mechanism to actually, you know, carry out that offboarding and then it's it's the process that you know, those two departments that we've already talked to actually have making sure that's cohesive and aligned and actually a living thing because you know, our business is process the process of change all the time. Like I said Devices and the technologies that we're using change of the time so those things have to all be cohesive together.
And the longer that person is working before they leave the more systems they have access to because they're probably been promoted across multiple departments over the years and right we kept the access to all those things that they already have so short of off-boarding. Should I also be more aggressive about who has access to what systems when even while they're working because you do see people getting their credential stolen and maybe people have access to too many things as it is. Indeed and this is you know, kind of getting to the point of cyber Asset Management because fundamentally what that does is it combines Discovery and visibility with governance and policy and that's really about having, you know awareness and an inventory of what systems we actually all have within the business and you know, it will look at assets such as our identity management the data that we're using the devices that we're using the applications that we have access to all of that combined with context, you know fundamentally allows us to get a grip of what exactly we have in our state.
What's the posture of that of those individual assets? And what's the level of compliance and governance on those what's their configuration? All of these are must have questions that you know security teams in particular need to have the answers to and fundamentally as I say that's what cyber asset management is actually all about and one of the use cases, of course that we've talked to is obviously leverage toward off boarding and onboarding but absolutely it's also whilst someone's actually in place within a corporation.
A lot of security people tend to look down their nose at compliance issues because they're like, well, you know compliance is the bare minimum and we need to be a lot more secure than your fundamental compliance whether it's hip or whatever it might be. But does that kind of put us at odds with one another and maybe we need to figure out how compliance and cybersecurity needs to be a little more joint at the hip. Well, I think you know that's another thing that Cypress at management does in particular and what it does is it provides predefined compliance templates?
So you mentioned a couple before you know, sock HIPAA as an example PCI DSS and these are you know, predefined pre-governed compliance Frameworks that products within the Cyber Asset Management domain allow you to drop onto your existing assets. So, you know, very rapidly and quickly we can ensure that we're compliant in addition. Of course, we have corporate governance and corporate security that often, you know, will leverage those Frameworks as guidance and they'll have their own bespoke interpretations and most of which go in above and beyond those those Frameworks that we've mentioned and that's of course what allows so it combines that governance and compliance and Security in one place combined with you know, that entire Dynamic visibility.
Of the whole environment and it really just ensures that we're compliant not just from that framework perspective that you talk to but generally from a corporate perspective think the security policies that we must have as a business that we Define internally. Are we too isolated in our approach? Do we need to converge roles?
Because it sounds like the technology is enabling some level of convergence. So do we read we need to maybe rethink our organized to manage the whole process? Well, I mean like the reality is Mike that we're seeing that right.
We're seeing modernization take place in a number of different domains and monetization isn't just a technology focused effort it in order for modernization to be successful. It actually should comprise of you know processes too and often that requires a cultural change. We've seen that in devops, which is all about, you know, the delivery of our services and our applications combined with technology and architecture.
And of course what we've always seen is this SecOps strand away from that which is all about incorporating security at that earlier stage. And so I you know, I really believe that we Already seeing that Trend in Dara suggests would see more of that and perhaps some some different angles take place. But that's all about making sure that as technology moves forward as the threats evolve as you know, new cloud services in particular are generated and evolved.
You know, that opens up the space of misconfiguration Greater again, so it's being able to make sure that we keep up with those changes and I think that you know, those those team changes that we've talked to have absolutely taken place and will continue to do so. I think it's fair to say that maybe we're a little sloppy when it comes to managing all this stuff and we hear a lot about AI these days. So do you think that the machines maybe someday we'll save us from ourselves possibly.
I you know, I know that clearly I think when we look at the market around cyber set management and the next logical step in terms of efficiency would be to introduce, you know levels of automation. I think right now we're at that stage where it's all about data Gathering and interpretation of that data that really does help us and it supports all these use cases. We've talked to such as misconfiguration and awareness and you know things like You prioritization terms of threats, but clearly to optimize that and refine that even further as you put, you know to kind of prevent human error even more than clearly the use of automation would help and the reality is that some of these environments now are incredibly large and they're so Dynamic.
It is getting to the point where it's challenging to maintain a grip just through scale and the fact that a lot of the services are you know, so Dynamic so yeah, I I fully expect, you know levels of automation to start coming in and you know, let's hope that they're a lot more reliable than we are. I'm when you start thinking about all this. I talked to this security people all the time and we hear a lot about more sophisticated threats all the time.
But when you to ask them about it, they'll tell you that most of the attacks are not really increasing in sophistication because the issue is that the tax service is just too broad and right deal with all of it and the bad guys are like, why would I go to all that extra effort? When all these simple little attacks just work just fine. So is that become the core problem is just that we can't defend the attack surface as it is.
I think there's a couple of things. I mean, I I would say that one of the things that we've seen, you know in light of the recent pandemic is we have seen a flurry of activity take place. Obviously the world's in a bit of a funny place with some of the stuff that's going on.
We have seen an influx of cyber activity. I think in general. Yes there I would agree.
I do think that there have been some attacks that have lent on the fact that some organizations most organizations are now a little bit more dispersed geographically than they were before we've certainly seen some end user type attacks that specifically targeting the fact that we're at home. I don't think that necessarily in a smarter but they're just changed attack in terms of how they're going about attacking but but generally yeah, the issue is the fact that the the attack service is just so big and Broad and varied. As we mature our technology stacks and we're starting to leverage, you know iot devices for an instance.
We're seeing different attack Services emerge that we perhaps didn't have before so trying to maintain a grip of these Estates, you know, where they reside what we have, you know versions of what we have all the different firmware and software versions. It's an absolute mind field and that's why we're seeing our Market emerge and you know, so I press that management is an emerging market for that very reason because the the challenge of trying to maintain that visibility let alone control is certainly needs help and that's you know, hence us being here. This is really primarily what we're focused on.
So once your best advice to folks, I mean does the cybersecurity team need to pay each or a visit or do I throw everybody in a room and lock the door and hope something good happens. You know, how do we approach this? I think it is a couple of things I think.
The first things first is I would ensure that there's Unison between the HR department and the IT department security department and that's really to ensure that from a business process perspective. There's a lineman in terms of the end-to-end process. I think the next step would be you know, and some of this isn't necessarily technology driven.
It's just, you know, playing common sense, but it's incredible how often you know over time some of these processes stray away from where they needed to be. It's ensuring that you've got like a checklist, you know of allowing HR and IT cohesively to work through and to ensure that off-boarding is actually successfully delivered and then combined that with you know, the help of Technology such as Cypress that management to give you that visibility and governance in terms of policy. I think it's the only real way to ensure that you've got a scalable automated and govern process to off board employees.
Now obviously we see, you know, many different types of threats when an employee leaves, you know, the obvious I guess malicious activities that sometimes take place like, you know, stealing sensitive records or you know, intellectual property or deletion of files and you mentioned at the start about, you know, just accidentally having access to systems. Yeah. I've I've personally be in that position too.
I'm sure a lot of us have but it's not just the malicious activity. I think one of the biggest misconceptions and something to add on to that checklist is considering and the regulation and compliance of the company itself. They have a duty and a responsibility to protect the data that they keep about past employees.
It's not just malicious activity. It's also making sure that you know, any data that's left behind is stored correctly and handled properly just as it would do, you know through the terms of Women and so there's a lot of things to consider a good strategy and a plan I think is first and foremost and that strategy should incorporate the technology to make that that easier. All right.
Well, I think there's a lot of cybersecurity people that would rather go visit the dentist than actually go to the each other department. So I think I think there's gonna be a lot of pizza involves start handing out pizza people will show up for meetings and then maybe some good things will happen. We'll see what happens from there.
Normally for sure. Yeah Keith. Thanks for being on the show.
Thank you Mike. Cheers. Thank you.
Bye right back to you guys in the studio.