Michael Fanning on Splunk’s CISO Report
Splunk’s CISO report highlights findings from a survey of CISOs and board members which reveals a disconnect between their priorities, and more particularly, the importance of fixing them. The report also emphasizes the need for better collaboration between CISOs and board members, especially in supporting AI and cybersecurity practices across organizations.
Transcript
This is Textron tv. Hi everyone. We're back here at techron tv and you know, I've got a gentleman, I, I never met him until today, so it was, you always like to meet new people.
I want to introduce you to Michael Fanning. Michael is the CSO Chief Information Security Officer at Splunk. And I, I guess we need to say Splunk, a Cisco company.
Um, Michael, welcome to Tech Drunk tv. How are you Doing Great, Alan. How are you?
Appreciate you having me on. It's Great to meet you. I appreciate you being on.
I, as I said, I don't understand why I didn't meet you before, but hey, we'll make up for that. Michael, how long have you been CISO over at Splunk? Pretty recent.
Uh, I, I, I took over this role in, in February, or I'm sorry, uh, this past, uh, September I took over the role. So about about five, six months now. Five, Six months.
Yeah. Very cool. Well, I guess that begs the question, what were you doing before that?
Give us a sense of your, your journey. Yeah, so I've been at Splunk for, for four years. Uh, I was, uh, I joined in to lead our global security operations organizations.
So that's your traditional threat detection and response teams. Um, you know, I was super excited about coming into the role, given my background in detection and response. And so there's no better company to work for in detection and response than a company like Splunk.
So I, I'd used the product in the past and was just very excited to come in and, and be a part of this great company and become a little bit more familiar with the product and the product organization. Um, so it's been a great, great opportunity for me. Um, so I spent some time in, in detection and response here at Splunk.
Um, became deputy CISO for about three years, led our product security organization, uh, and now I'm in the CISO role. Very cool. But what you're telling me, I'm reading between the lines, but it sounds like you always weren't a vendor.
You were actually a, a real life security person using products like Splunk and out in the real world, huh? Yeah, I've used you've Splunk, uh, quite a bit, uh, prior to my, my time joining the company. So we've had, we've had a lot of fun with it.
Very cool. Um, you know, Michael, I, I, little tongue in cheek, I said, Splunk a Cisco company. 'cause that's what I always see now come across in my emails or, or, you know, uh, stuff online.
Um, but Splunk is a Cisco company and the integration is ongoing and good stuff coming out of it. A as we were talking sort of off camera, you know, there's a lot to Splunk, there's a lot of Splunk in Splunk, right? There's a lot in there.
There's, as you said, there's threat detection and, and you know, that like really sophisticated security. Uh, there's OB observability, right? A lot of people use Splunk 'cause of the observability capabilities, even, you know, for security.
And outside of security are, you know, superb world class, uh, people use Splunk for data collection without even sometimes performing analysis. They'll use other third party tools for the, for data analysis or what have you. It, it, Splunk means a lot of different things to a lot of different people and, you know, and now joining into a company like Cisco.
Right. And so much more, give us your view from where you sit, Michael, and in terms what's Splunk today? It's a great, it's a great question.
So, you know, the way that I try to explain, you know, Splunk to, to those that I know is, is, um, it helps you to answer very complicated questions about data. Uh, no matter what that question may be. Uh, with a tool like Splunk, you can answer these very complex questions.
I like to say it helps you to discover, uh, needles and needle stacks. And from a security standpoint, you know, that's incredibly valuable, especially when you think about marrying together the value of observa observability data with security data. It can be a very powerful experience for, you know, those in a security operation center and those in a security role.
So with our, with our journey into Cisco, it's, it's really about understanding, you know, how can we kind of extend those investigation and response capabilities across, you know, other Cisco products. Uh, we have a great suite of, of, uh, automation tools with our SOAR platform. And, um, you know, really cool to think about how we can maybe make changes to an infrastructure based on a detection that's fired and you know, that that really helps you kind of ingrain yourselves a little bit more into the Cisco product areas.
Sure, it does. And, and you know, we think Splunk has a lot to it. Cisco obviously has a lot to it as well.
Um, we could do a whole interview on that, Michael, but that's not really why we've got you on here today. Recently, uh, Splunk released their CSO report and, and wanted to dig in today specifically in, in the findings around kind of how CSOs are interacting with board members and where there's agreement disagreement, they see eye to eye interest are aligned or, or maybe not aligned. So I wanted to talk to you about that and get kinda your thoughts and tell us about it.
Yeah. Uh, some really cool insights, uh, from the CISO report. Uh, what I, what I love is that I talk, this is that they talk about kind of the, the perception of the CISO's role of how they interact with the board and what the board is interested in, and then kind of contrast that with actually what the boards, you know, are interested in.
And it, and it's, uh, you know, it's just an interesting people dynamic and helping you understand the way that, you know, everyone's thinking about these problems. But my, I think my favorite takeaways are, um, the boards wanting CISOs to project themselves as business enablers, kind of rather than, you know, throwing these, these tactical metrics such as meantime to detect at a board. I don't think that those are things that the board, you know, really, it's not that they don't care about it, but in that, you know, it's Not their languages, That 45 minute window, you know, that's not, yeah, that's not something that's important to them.
They wanna understand how is security enabling this company to continue to sell more products and continue to gain more revenue. Uh, and this is something that I think that we've been very successful at at Splunk. Um, attaching revenue to some of our security goals as an example, uh, we do SOC tours.
We're a, we're a SOC company. We sell SOC software. Our customers are interested in understanding how we run our SOC internally with using Splunk products.
So every time we give a SOC tour, we, we attach, you know, a revenue goal, uh, the amount of revenue for that customer, the a RR for that customer, we report on it. And, and it's a great way to showcase to, um, the board like, Hey, you know, this isn't just a soc. We've actually enabled the sale of a, of products to, you know, this group of customers over here.
Um, so I think it's a, it's really interesting and I think each company needs to, and each CSO needs to understand what aligning security into a business enabling, um, initiatives looks like and how to present that up. Obviously, you know, not every company sells sells SOC software. So what are those other, you know, areas of opportunity?
Is it compliance and new emerging markets? And what is the revenue that is generated because you're a security in helped enable the business to go into a market with data sovereignty requirements. And so I think that's what they care about.
That's what the CISO report shines a light on. So I think it's super interesting. Absolutely.
You know, I mean, I always wasn't on this side of the camera. I was in security for 25 plus years and security vendor, co-founder of a company. Um, I think the biggest thing is, you, you, you spoke about it right in the beginning, right?
You said the board doesn't care about mean time to remediate. Not only that, they don't even know what the heck meantime re to remediate is, nor do they wanna know, right? And, and that, and that was always one of the big disconnects that I think led to the rise of the CISO role, which is we need someone who translates that, and I'm gonna call it low level, but I don't mean it in a derogatory way, but that low level data, that low level stuff, right?
What the, how, how fast am I remediating? How many vulnerabilities do I have? How many detections did we detect?
How many did we block? They don't give a hoot. What's their risk, right?
At some level, the CISO's job is to translate that low level stuff into some sort of risk discussion. That is something they know and understand in a business way. It's to talk business to the board.
It's a, it's not a security board, it's a business board, right? They're there for the business. And I think one of the big problems, Earl, especially early on, was that CISOs weren't talking business.
They were trying to jam down the meantime to remediate down these guys' throats. It just didn't work. Um, we've come a long way.
CISOs now are business people who talk business to the board. The good CISOs also still talk low level to their security teams under them, right? They don't need a translator there.
But of course, everything is different with AI now. Things are changing and, and the potential for it to be very different is AI and budgets, because why does this so go to the board? Well, hopefully it's not to get called on the car because you had a breach though.
It happens. Um, but you know, we, we need budget, we need alignment on priorities. AI is putting all of that stuff in flux.
Did that kinda show itself in the report? Yeah. Yeah.
I think that it did. Um, and, and you know, the way that we think about AI is there's, there's security for AI and there's AI for security. And, and you know, Cisco announced, uh, you know, last week this AI defense product that's AI for security.
And, and you know, that's something that can really help to, you know, enable a, enable a company to kind of harness the power of artificial intelligence or harness the power of and protect yourself from, um, um, the risks that may be associated with with ai. Yep. And then of course, the, the flip side is the bad guys using AI and we've gotta secure against it.
That's right. Right. And, and, and you need, you need, uh, you need product and, and services around that as well.
Um, but you know, when it comes to budget, Michael, I, you know, one of the things I, I heard it more last year. It wasn't actually last year. It was after RSA last year, I started getting, you know, from where I sit, I talked to a lot of different people, right?
I, so I started getting sort of information kind of transmissions that a lot of CISOs were hearing from their board. Hey, look, we've been giving you more budget every year for the last eight years, right? And you've been buying every new shiny trinket that comes down the pike, and yet our security is not measurably better, however you wanna measure it.
We're not, you know, measurably better than we were before you spent all this money. So before you come to me for, with the next shiny trinket, which happens to be named AI this year, tell me how you're using what we bought the last three, four years and how's that working for me? Right.
And I, I get it as a business person, I as a business person, you get it too. But this is what, this is where the CISOs have to step up and, and make their case, if you will. How does that, does that play out in the report?
What's your experience? Yeah, you know, my experience is is, uh, you know, I'll kind of bash on us a little bit and security is, we're notorious for finding solutions that look for problems. And that's what, I think that's what happens with, uh, you know, the new shiny object that, that you had, that you had mentioned.
Um, there is, you know, one of the things that we talk about is that those tooling sprawl that, that those in the SOC use, and there are statistics around the number of distinct vendors and tools that are being used in a, in a SOC and, you know, up to 30 and how many different dashboards does an analyst have to touch in order to do an investigation. And so, you know, there's really, I think, a lot of rationalization that's happening in the industry to really scrutinize, you know, what are the, what are the third party solutions that we're bringing in and what are the actual problems that we're trying to solve, um, with these solutions that we, that we bring in. And so completely agree, you know, with your assertion of, of, hey, we've, we've procured all of the software.
We have a great amount of software spend, but how is that actually reducing the risk, uh, and the organization? And I think that's just a great opportunity that we call out of where Cisco's have a, have an opportunity to improve the way they communicate up to the board. But also, you know, to your point earlier, having these conversations with the, with the leaders and the individual contributors in your organization to really scrutinize the procurement decisions that you make of what you're gonna bring into your organization, what you're gonna spend money on.
Absolutely. I got a hard question for you. So you've got the data from the report, specifically the ai, because that is the poster child, right?
Agent AI is gonna be huge in 2025. That's what everyone says, right? Are you seeing, and is the, the, does the data in the report show that wards are actually, I don't know if you wanna say increasing budget or allocating budget to AI security solutions?
In other words, security that utilizes AI to be, you know, leverages AI to be better? Are we seeing a, a, a budget line for that in a meaningful way? Yeah, you know, I think what the report is calling out is, is, um, I think neither the boards think that security is, is funded enough, but the CISOs think even less that it's actually funded enough.
So there's a, there's a greater percentage of, you know, board members that say, Hey, we are providing, you know, an adequate budget, not, not a great percentage, but CISOs aren't necessarily, are really in the area of thinking, our budget, you know, is not necessarily adequate for, for security. Um, you know, not necessarily with specific kind of ai, you know, line items. I think it's just collectively for the overall security budget and then making strategic decisions on how you're gonna protect yourself, you know, against, against ai.
I think conceptually, you know, the attacks that we face are, are still the same. The attacks are just getting better and faster. And so your ability to detect and respond, you know, really needs to continue to improve and keep up with the pace of what, um, those AI generated attacks, uh, like a phishing campaign, a more complex phishing campaign, better grammar, um, more like, you know, lifelike reproduction of a real phishing, like the concepts behind detecting that are still the same.
It's just the adversary is using AI to attack you quicker, uh, and better, more realistic than before. I, I agree that there, there is that, um, Michael, I, I wonder if this shines itself in the report or if you have any other knowledge on it. Are the boards going sort of like line item, veto line by line saying, spend this much on ai, this much on intrusion, this much on threat protection, this much on intelligence, or they saying, Hey Mr ciso, you're looking for a budget of X amount of dollars, how you're gonna allocate and you're gonna cover these areas.
How you allocate in these areas is kinda your call, because we are not, we don't pretend to know enough to, to make that decision. Yeah, yeah. Haven't seen, you know, where they're being very specific about their, where they want to call out for different functional areas.
I think you're, you're offered a, you know, a dollar amount budget and discretionary, you know, that had, the way that you choose to spend that budget, I think is kind of up to the ciso. But, but, um, it, it's, again, you know, we talked about the way that we communicate to the board. It's that the way that we're actually articulating that spend is what is what really matters.
Very cool. Hey, you, you know what I, shame on me. This report is available to the public.
Yes. How, how, how can someone get their hands on it? Yeah, it's hanging off of our, our Splunk website.
Uh, we'll send out the URL that for anyone to, to grab. And, um, it's a super interesting report. It, it pulls, I think up to 500 CISOs and a hundred board members and kind of really some super interesting insights for everyone to take a look at.
And is, is this the, the Splunk CSTORE report, is it annual that you're doing this now or It's In fact, I believe the, the new report is just released today. Really? Yep.
Fantastic. Great timing. Um, go check it out then.
Nick, you can just get it. com. It's probably front and center.
Um, you could get it right there and we'll try to put it in the notes as well. Hey Michael, thank you for making your first appearance as, as EL at Splunk here on Text Drunk tv. I'm, I'm hoping it won't be the last, we'll, we'll hear more about it.
And I assume you'll be at RSA in just a few months, right? Uh, we'll be there live all week doing, uh, you know, what do they call it? Broadcast Alley is, and you know, usually Moscone West over there.
We'll be there live as well as at our DevSecOps event. So maybe we'll meet up in person. Yeah.
Appreciate it, Alan. It was great to meet you and thanks again for having me on. Alrighty.
Michael Fanning, chief Information Security Officer at Splunk here on Tech Drunk tv, talking about Splunk's new CSO report, which just came, it just came out. com. Um, we'll be gonna take a break here on Tech Drunk tv.
We'll be back in a moment.