Insights on Cybersecurity with CYE’s Reuven Rubi Aronashvili
Reuven “Rubi” Aronashvili, CEO of CYE, shares his journey from Israel to founding his company. He discusses his military background in cybersecurity and the significance of visibility and customer feedback. Key findings from the 2025 Global Cybersecurity Maturity Report reveal that basic security hygiene is essential, and higher budgets do not guarantee improved security. The diverse roles of CISOs are also explored, highlighting the balance needed between technology, people, and processes.
Transcript
Hey everyone, it's Alan Shimmel for another Tech Storm TV interview. I have a first time guest on my show on, on our show today. He's actually the CEO of a company called Cy, that's spelled CYE.
His name is Ruben Arone. If I mispronounce, I apologize. We're gonna call him Ruby.
Anyway, Ruby, welcome, welcome to Tech Drunk tv. It's great to have you on here. Well, Thank you for having me.
My pleasure. So, as I mentioned, you are the, the CEO, uh, founder of, of, uh, p Si. You know, I've interviewed, I've been a founder four or five times, co-founder, and, um, it's been a long career, but, you know, and I've interviewed hundreds, if not thousands, everyone I've ever interviewed who's a founder, is passionate about what they're doing, why, why they found it.
No one wakes up in the morning and says, eh, I feel like finding founding a company today. Right. You're driven.
Talk to us about kinda your journey and where your passion came from to, to found Sai. That, that's a very good question. So, you know, I grew up in a small city in Israel, uh, called aco.
If you ever been in Israel, then that's the, you know, Aco Sure, The best place to eat humus in, in Israel. So, uh, definitely to visit. Um, they're coming from a, let's say, a very tough neighborhood.
You know, you, you need to use your capabilities, dedication, um, discipline, and, uh, let's say the will to succeed in order to move out from there and take yourself to, let's say, a success journey that changes something. In order to do that. I was drafted, uh, to one of the technology units in the, of the IDFA cybersecurity unit.
Um, and I was in an academic journey, a specific journey that, uh, is actually for excellent, uh, let's say students in the high school. They take you for the university first. I've done my b science and m science, the game, computer science and math joined the cybersecurity unit.
And there I got really, uh, the mission that, uh, I was privileged to get and that to build the Israeli red team. That was the first time that the Israeli army decided we are going to consolidate capabilities and going to do that as a strategic capability to use offensive defense, meaning offensive capabilities to defend ourselves by actually testing as adversaries our own systems, infrastructures and so on. So, I actually developed red team capabilities and build this specific team at the, at the time, uh, the name was Section 21, actually, it's still the name, section 21 in the Israeli Army, the Israeli Red Team.
The passion that I started to build from there was really based on how impactful you can be by just providing visibility to the organization or to the, the relevant unit by understanding where the weaknesses are. That's sounds like a basic step, but that's a very important step in the process. Spending seven years of, uh, of my time in the Army, that was an amazing journey, right?
I really, I've done things there that, you know, you couldn't even imagine to do in an environment that is outside of Army or playing with toys, let's call it this way, that are so expensive, you know, F 35, for example, right? That's a very expensive toy to play with, but absolutely. Yeah, you still need to test that.
This, uh, this toy, as I mentioned before, is, is cybersecurity resilient, right? How, how do you know that, uh, that that's something that, uh, uh, that can be, uh, let's say resilient in case of, um, of a need like we recently had, uh, in the Iranian situation that we had in Israel. So that's, that's of course important.
Now, from there, in 2012, um, I left the army. I, after finalizing my duty and a little bit more than that, um, and I decided to continue to a more private route from my point of view. And, um, this visibility concept came back over and over again.
If I thought that in the Army, that was a big problem in the commercial world, that was a huge problem, right? Because everything in the commercial world was really lagging behind. I'm talking the year is 2012.
So I founded Sai, started as a professional services company. At the beginning, started to learn the industry, and here's the point, hearing the feedback from customers on a continuous basis, and they managed to work with the, the largest and greatest companies worldwide, and you hear continuous feedback first. Great.
Now we know, we understand where is our risk? Then you're starting to get questions that you don't really have answers for. How do we know what to prioritize?
So it's great now that we, we know what's, what's wrong, what is more important to mitigate? Is it our application? Is it our network is our cloud?
That's a good question. In those specific environments, what is more important there? How do we know that our money that we invest is really going to the right places?
By the way, one of the things that you, you'll see in the report that, uh, we just, uh, uh, um, share the, the, the maturity report. You see there very clearly that more budget doesn't necessarily mean more security. How can it be?
It's very, I mean, it sounds simple, but we found that, uh, that that's something that really requires real understanding of the situation and contextualized understanding of the organization. From there, we built a platform. That was the first time that we decided to build a platform.
That was the year that I'm talking about 2019 already, right? Seven years of, we've decided to build our platform. So here's the thing.
The platform was built from mainly customer feedback. So we had a lot of feedback being a professional services company, and we started to build a platform that will serve our customers with their needs. We started to think about the concept of visibility translated to business impact communicated to management and different stakeholders, because I think that's key in what we do.
And above all, we wanted to put a lot of emphasis on how you do that, not only in qualitative, uh, manner, but also to do that in quantitative ways. So at the moment, this is the side promise. What we do at the moment, we provide you with a platform that gives you the option to understand where your risk lies, what is the threat profile of your organization, meaning what types of attackers are relevant to your organization, what do you need to protect and how those are connected with your own vulnerabilities, weaknesses, gaps, and so on.
That creates a very clear map for your organization. This map is then being quantified, meaning we put dollar value around each and every one of your risks. Meaning if you are going to have a ransomware attack, it's going to cost you X.
If you are going to have SQL injection, your environment is going to steal data from your databases, it's going to cost you y. Now, when you understand it and you are able to articulate that in this way, you are able to communicate it to your management, and you are able, the most important thing, you are able to make smart decisions based on the data. So our platform today allows you, as I mentioned before, to get organizational visibility around risk and threat, then quantify that to business, uh, uh, to business risk in dollar value terms and likelihood analysis of course.
And on top of that, we are optimizing, and that's maybe the most important thing. We are optimizing the mitigation plan based on a mathematical algorithm that we've developed to really get the highest return on investment on every dollar that you invest. And this is the concept of either platform today, we call it continuous exposure management platform.
Uh, that's, uh, the new buzzword, buzzword out there, but that's exactly what we did. Excellent. You know what, we didn't mention the website name.
Yes. com, this is our website. They are more than welcome, uh, to visit there, and you are always able, uh, to, uh, uh, reach out directly from the website or to us in any other way, LinkedIn or anything.
Anything works. Excellent. Very good.
And, and Ruby, you know, congratulations. Uh, what a, what a, a career, a background. Of course, we look, I, I've been in security myself now, we call it cybersecurity.
I've been in cyber 25, 30 years myself, right? And met a lot of people from 8,200 and, you know, the other Israeli, uh, cyber commands, uh, you know, they do great work. But really, you, you took what you learned there.
You applied it here to the commercial and to the commercial space. And, uh, as you said, the, if it was bad in the military, I, I, I sold to the US DOD for a very long time. One of the companies I started, I know what goes into what we call military grade.
Yes, right. Or information assurance. So, good for you.
Um, you guys recently came out with a maturity report for 2025, and look, cybersecurity, maturity, resilience, you know, the, the world is such a different place from when you first went into the army from when you first left in 2012. We didn't have ai, you know, staring us in the face at the time the way it is now. Maybe we had ML kind of stuff.
Yeah. Mm-hmm. You know, with everything with AgTech and, and you know, it's a double-edged sword, good and bad.
Yeah. Fibers come a long way. Talk to us about this year's report and maybe some key trends or findings that our audience should be aware of.
So, first of all, I think that, uh, this is a must read read, right? Because it really encapsulates a lot of the information that we've collected from different parts of the industry. Uh, you have it, uh, per vertical, you have it per country, your location, and a lot of insights.
But here are the key takeaways. Number one, from my point of view, and that's maybe if there is one thing to remember from this interview is that the basic hygiene of the organization is still the most important thing. Account management, passwords, multifactor authentication, uh, uh, patch management, um, access control in the, in the basic environment to the internet.
Those are basics item, the basic items that you expect most organizations to already have in place. And it's still not there. Most of the items, most of the weaknesses or actual incidents that we've see, we've seen out there either started or leveraged one of those items as part of the process.
And that's something that is extremely important. Second thing that I will say, and this is extremely important, higher budget doesn't necessarily mean more security. It sounds maybe logical or it sounds clear when you, when you hear that, you say, oh, okay, that makes sense.
But we say that the correlation between smart decision making or let's say data-driven decision making to more security is much more, it's, it's much higher than the budget itself. And then you find situations like the US where there is no doubt that the US invest maybe the most worldwide in cybersecurity. It's the most developed economy and most mature market from cybersecurity tooling perspective.
However, it's very clear to see that the investment there is not always that effective. So a lot of investment not necessarily effective. Of course, we need to, I, I would Go one further, Ruby.
Yeah. I think, I think throwing money at it Yeah. Is the solution, right?
And it, and, and quite frankly, this has been this way in cyber for as long as I've been in cyber, I wanna buy it. There's a new magic bullet out. Yeah.
This year's magic bullet is only a hundred thousand. Next year's magic bullet is 200. But at some point, the board gets tired of paying for the magic bullets because these magic bullets don't work, because there is no magic bullet.
And, and I would, and this is based on my own experience, I would say forcing people to do with less, to be more creative, to be more innovative, to be more, have more dirt under your fingernails of, of the cyber, because you don't have money to just buy magic bullets might be a better, a better solution, a better method, a better way of looking at it. That's spot on. Because from my point of view, you know, one of the, the things that you see in the report as well is that we've seen that the number of tools in the organization increased significantly in the last years.
And today the average number for a mid-size organization is 76 cybersecurity tools in the organization here, the number 76, it's crazy. I know Now, as you mentioned, tool is not a capability. So the fact that you have another tool doesn't mean that the capabilities of the tools are really fully, let's say, leveraged or utilized.
And that's something extremely important to mention. So yeah, I, I'm totally with you there. And that's something that we see as a trend in the industry.
And you know, the point is that sometimes it's the easy solution to buy another tool, but it's not always the smart solution. So definitely what you just said, understanding, and it all starts with, again, I'm going back to visibility. If you understand where the risk is, you are able to understand what the solution should be, right?
And the solution is not always a tool. Sometimes it's capabilities, sometimes it's a skill, sometimes it's a process or utilizing an existing, an existing tool already. You don't need a new one, you just need to change configuration in the existing one.
That's something that happens quite a lot. Yeah. You get a lot of shelfware, they buy stuff, and then three months later, I look in my time, I've seen they, they spent significant money and then decided not to use it before they even used it.
It never, you know, it never got unwrapped. Yeah. It's Crazy.
That's something, something that we see. And by the way, you know, our statistics shows this is our, uh, our investigation that we've done. More than 70% of organizations are actually reporting themselves that they are very incon uncomfortable with the level of visibility that they have into the organizational risk and third profile, and how they are actually covering for that.
There are other statistics out there, uh, uh, the Vanta, for example, is saying 75%, but that's more or less aligned to what we are doing. Another thing that I would say, and uh, that's also something that we found very concerning, uh, and that's going, that's going a little bit more to the resilience part. Let's assume that something already happened in your organization, which, you know, statistically, world Economic Forum just published 29%, uh, likelihood for every organization worldwide to be attacked.
That means every three and a half years, more or less, you should expect some kind of cybersecurity incident in your organization. What do you do about it? That's a good question.
But we've seen that more than 50% of the organizations, they don't have, let's say, a strong or any business continuity plan in place. Not how to react to an incident. What is the playbook?
Who needs to do what, who is communicating the basic thing, the business continuity plan for recovery in case of a cybersecurity related incident? That's basic. It's much cheaper, by the way, than buying another tool.
And still it's not in place. And that's something that we see that the correlation between this capability to more resilient is really, really there. Um, there are other, um, interesting insights there.
For example, third party risk is still a big thing. We need a paradigm shift there because I think that the scoring concept that we have out there, Hey, we are evaluating all of our, uh, vendors in a way, uh, that is, uh, on some kind of scaling. Uh, okay, this is a 10, this is a nine.
That's not good enough. You need to understand how those vendors, what the risk from the vendor is, what is the risk that is relevant to you? What is the impact to the organization coming from the vendor?
Those are important. And we've seen also maybe less thing that I say, a very strong correlation between, um, CO in the organization, someone that is the owner, let's say. It's not the C CSO all by definition, but the ownership of, of cybersecurity that is now also going to the board level.
That's something that changes a lot. Um, those are the main insights, but the other things Very interesting. No, no, I get it.
I, and we're gonna mention, let me dig into those two. I wanna give the URL for this. Look, there is, as you know, there are Sues CISOs and there are CISOs.
Yep. Right? Um, some CISOs, some CISOs job is to translate security to business, right?
So that the board understands the risks, the impact and, and what all those bits and bytes means, right? Other CISOs, they're glorified security architect admins, right? Mm-hmm.
And they really, though, they may have a seat at the table, they're like a junior seat at the table, if you will. Right? Right.
And, and then there are some CISOs. I see it, especially in, in security vendors, it's almost a marketing position. Yep.
You are talking to customers about their security. And I, I, you know, it, it, it's a, it's a hard thing. I I do think, you know, it always comes down to people, process and technology, right?
And in security, we've spent a lot of time on technology at the, at the expense of people and processes. So I'm not, to me, these, these findings are, you know, what we see out in the real world out here, right? com/resources guides dash eba.
It's a long URL, we'll put it in the thing. But Ruby, I'm sure if someone Googles the 2025 Global Cybersecurity maturity report from cy, it'll come up. And there's probably Also in our homepage, you, you have a link Directly from the home, right off the homepage is the easiest way to do it.
com. Ruby, thank you for what you're doing. Keep up the great work.
Don't, don't wait till next year's report to come back on here. Keep us, keep us posted to come in and give a report, okay? Would Love to speak with you again.
Thank you so much for a little time. All right. S cy security, CYE here on text, drum tv.
We'll take a break. We'll be back.