Implementing the National Cybersecurity Strategy – John Rostern, NCC Group
John Rostern, senior vice president and global lead of cloud and infrastructure security services for NCC Group, explains why the devil will be in the details when it comes to implementing the recommendations made in the National Cybersecurity Strategy.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with John roster who's a senior vice president with NCC group. And we're talking about the national cybersecurity strategy rolled out by the United States government John. Welcome the show.
Thank you. Mike. Good to be here.
I think when you look at this document, it becomes quickly apparent that is a mix of carrots and sticks and the sticks are pretty aggressive in some instances where we are seeing more accountability for misuse of data. We are starting to talk a little bit about penalizing people for making software mistakes that are appear to be courageous. What's your sense of this document and are there enough sticks or maybe not enough carrots?
What's your feeling? Well, I mean there's a lot of things on in this document that are right on point. I mean the need for a risk-based approach the the need for some form of software product liability.
I mean as we've evolved over time, we're no longer were well past the point where we're using these applications casually, but even for the for the consumer much less for the business, they're part of your daily life. They're part of the critical infrastructure of the country. So to say that, you know, we can continue to be where you're dismissing liability in the form of end user licensing agreement really is that ship is sailed.
The question is going to be the carrots and the sticks, um, you know, trying to do this through the form of Regulation. Um, you're going to need lawmaking to a company that's in order to make it work. How is that regulation going to work?
Is it going to just become another check the box in which case it could very well just be another get out. Free card in the event of the next reach that one everybody happened or will we actually be able to make this workable and a lot of the devil in that is going to be in the details? A lot of folks at dubious about the ability to actually make this work because the processes we use to build software are not exactly the most secure in robust things we have in the planet today we a shifted devsecops and we're trying to make developers more responsible for things but this seems to be a long haul and it's gonna take some time.
So what's your sense of the feasibility of actually making software more secure than it is today. Well, the the challenges with the software supply chain are long and they're unending you've seen this manifested in several security instance. So the past few years that are you know, log4j and things like that where you've had manifestations of, you know, insecure libraries and things like that.
There is a need for General hygiene regulation could encourage a higher degree of General hygiene by setting a baseline standard. The problem will be though with enforcement it will be with examination and things like that. So if this becomes as I said just another check the box exercise with respect to oh did your developers have owoss training?
Sure they did. Um, that's going to fall short of actually having any positive impact on the situation. What's your sense of the current state of the relationship between the development community in the cybersecurity community?
Because it always felt like to me developers were trying to maybe avoid certain requirements and and never clear to me that the security folks actually understood what was going on the software in the first place. Well The Challenge and this is again, this is part of what the strategy is trying to address when they talk about that. It's long overdue that we were relying on Market forces to encourage developers to develop secure software.
There's never been an economic benefit to being secure. There's never been a market benefit to saying my suit my package is inherently more secure than the than the other person's package that's been a problem. Therefore the developers aren't encouraged as part of their ecosystem to develop secure software that just encouraged to develop stuff that is fit for a particular purpose get to the market do it is officially as effectively as possible there needs to be a sort of a positive tension or constructive tension between security and developing, you know, and that can be seen as being managed in.
Excuse me. Tested in devsecops, right? And that's why that area is sometimes a little bit turbulent Maybe.
Do you think that we have the wrong set of incentives in place? And we don't really reward the developer for building more secure applications. What we do is we you know applaud when they develop on time and when the performance is great with do we need to recalibrate what it is that we're doing for incentives for Developers?
Absolutely, and that would be those Market forces that the strategy talks about in terms of. Being on achieved so far, right? We we haven't seen that happen in the market that recalibration.
So the strategy in attempting to transfer this sort of product liability model onto software is attempt to fill that Gap. What is being attempted here in the US compared to what other countries are doing or may have already done are we ahead behind what's your sense of where we are in the globe? I don't think we're right necessarily ahead or behind.
I think it's hard to measure because I think we're all running different races. I think it's very very similar to the situation. You see with privacy here in the US privacy is not a guaranteed human, right as it is for example in the EU therefore the premise that gdpr proceeds from is very different than the state level privacy Lawless received from here in the US also the economics here in the US with the economy base around identities and and selling information things like that are very very different than they are in the EU so similarly here in the US the market for software.
Um how you can successfully enact that are going to be gated by different factors than you would see in APAC or in Europe. For example What's your best advice to organizations in terms of getting in front of this? A lot of folks may be tempted to wait for actual legislation, but others are going to be well, we're gonna be encountering this one way or another.
So do I just throw all the people who are concerned with this in a room and lock the door until Common Sense prevails or is there some other way to think about this? Well, I think it's fundamental in some of the points that are in the that are in the strategy, right? So they talk about taking a risk based approach, which is absolutely correct.
But we need to understand how you're measuring risk how you're measuring impact how you're measuring the things that you're going to do that would be in some kind of incentive based program or some kind of a marketer of program absent or preparation for such regulation. Look we've seen executive orders from the last three presidents to you know to include President Biden. They've been they talk largely about the same things that are in the strategy.
They've been largely ineffective because they don't have any regulatory vacuum to them. I think this is going to be a very tough Hill to climb to achieve any sort of legislation that's going to pass both houses at this point. So I think we're going to still being largely left up to Industry to do that and to establish a market Advantage for secure software is going to continue to be a challenge.
So as you say you need to as you need to flip the script you need to establish a premise by which we're rewarding behavior for delivering secure software in the marketplace that's going to take time. Are we making any advances in terms of technology that would make it easier to comply with some of these proposed regulations. We hear a lot about AI you can't walk down the street with somebody talking about their chat GPT type of product.
Do you think that will AI save us from ourselves someday? And the end actually I think well at least in the near term, I think it actually makes the problem more complex. I think that was we add new layers of complexity and new technologies to the mix.
I think it makes the regulatory landscape much more chaotic. Um take for example cryptography right? We're just beginning to wrestle with the impact of quantum resistant or the need for prompted Quantum resistant cryptography that's going to mature over a period of time the same thing with AI we're not even beginning to wrestle with the ethical issues surrounding the adoption of AI much less.
The implementation issues that we're going to start to see and at the same time you see in a rush to adopt right because nobody wants to behind the curve. So again, this is those Market forces again and what we choose to reward in the market versus what we choose to penalize the market. So it's it's going to be interesting.
Do you think the bad guys are looking all in this with somewhat sense of amusement because they're like, you know, you guys are talking about all this stuff, but kind of feels like to them not an imminent issue. Oh, I think I don't think they're looking with on with Amusement. I think they're looking their chops because this creates opportunities right every time that there's change that creates opportunities because just remember that crime is the same it's just It's just by the pursued by different means right so you don't have to walk into a bank with a gun anymore to commit Financial crimes.
Right? So crime remains a constant and the motivating factors around that romantic constant. So and again, this is all in that risk equation.
We've seen some interesting examples of where software Supply chains were compromised, but I think maybe it's been a few months maybe even almost a year since we saw a major one, but are we going to see more? Um, sometimes silence is scary because it means it means that things are going on and maybe they're going on underneath the radar. I think various geopolitical aspects the war in the Ukraine Etc.
I think have influenced perhaps some of the visibility for certain events. I You know you always worry about the compromise that is still dark just because it's too good of a vulnerability to waste on something trivial and where that ultimate vulnerability, you know could end up being, you know used in an exploit right in somebody's box of tricks for ttps and things like that. It seems like the bad guys are a lot more.
Well organized than we are. So is that part of the issue in that? Yeah these issues that we're talking about don't spend a single organization.
They are involved multiple organizations that have to collaborate ultimately, you know, are we capable? Well, the bad guys are clear on their motivations and their goals, right sometimes organizations aren't so clear on their motivations and their goals. The better that we can get aligned between the economic motivations of Private Industry and the the obligations of a government to protect its citizenry and things like that, then we'll begin to make progress until then.
Criminal Enterprises and other malicious actors can continue to kind of flow in the gaps. If you will, you know the joke right here say, which is that that they only have to get it right once we have to get it right every day. There you go.
One is the probability in your mind that I mean, maybe an organization will be fine. But do you think they might come a day where someone might be arrested and given jail time for the fact that there are software was inherently insecure. I mean, how far will this go?
Well, if you follow the history of product liability, look where that's gone since say the 19. 50s until now you are starting to see people being pursued criminally for product liability on a variety of Grounds, I mean it's it's happened. There was precedent this case law.
I'm not a lawyer but there are there is legal present out there if software follows that sort of model product liability. You could see that day. I think you'll see civil long before you'll see Criminal Just because criminal is going to be much higher bar to establish.
And again, you're going to need bipartisan legislation, which is going to be hard to come by incarn. Are we therefore having something that's equivalent to a Ralph Nader moment with cars that are unsafe at any speed but it's actually software now. Absolutely.
I think that that could very well happen. It's funny. It was actually thinking about that the whole the whole Corvair analogy to some of the software challenges that are out there.
You could very well see that and again some of that is going to be a question of published public perception, right? I mean the people who are practitioners in cybersecurity, we view this differently than the general public does just as Automotive. Safety was viewed differently by the General Public.
Then was viewed by the manufacturers and then Along Came Ralph Nader. So if you have a similar Ralph Nader moment and software security sure. That's definitely a possibility.
So does that mean we'll be seeing lawyers attached to our devops workflows? Because you know, we'll need to review this whole process both not just from a security perspective, but from illegal perspective. I think lawyers are a constant and inevitable constant and John.
You guys have a multiple clients in this space. What are they calling you about? What are they talking about?
And what advice are you giving them the other way? Um, it's interesting. I mean it well depends on the client depends on the industry, right because obviously some of them work in much more highly regulated spaces than in others.
it when you you know, when it's easier to speak to somebody who is in an industry where risk is a accepted component of the way that they manage their business in other industry sectors that are traditionally less highly regulated or where risk is A lot of differently or perhaps not a large consideration in their daily operations. It's a different question. Right?
So there's a degree of the the context but there's also a degree of the maturity of the individual organization and things like that. So our conversation is very with them. Right?
So in some cases, it's very very tactical. It's just a question of what's the solution won't very Point level Etc that of course misses the larger picture when it comes to well. What is the risk context?
What is an acceptable level of risk? What? You know, you can't mitigate risk to zero.
So what should I be doing? And you know to go back to your earlier point, you know when we talk about carrots and sticks. People sometimes view regulatory standards is just providing cover by saying.
Oh look I complied with that standard therefore. I'm okay, and I should be absolved of any liability. Organizations many times look at things like best practices and various baselines is saying well.
If we're breached, I can go to the public or I can go to my board and say well we were doing at least as well as our competitor or this other company over here that was doing the same thing. That's problematic because that doesn't help Advance the state of the art. So we need to move away from that and how successful we are in those conversation with our clients.
Really there isn't look we have clients that are wonderful. They have a great approach to this, you know, they view this as a holistic problem. They then they tackle it hard.
On the other hand, there are still clients that are you know far less mature in the way that they're looking at this. The question is does that make them more of a Target depends on the industry depends upon why someone might want to go after them? All right.
Well, it looks like folks that if you collect data or you build and deploy software you're now officially in a highly regulated industry. Hey John being on the ship. Thank you very much.
Mike. Appreciate it. All right back to you guys in the studio.