Navigating the Future of Cybersecurity with Thales’ Todd Moore
Transcript
Hey everyone. Welcome back here to Tech Trunk tv. My next guest is Todd Moore.
Todd is the Global v VP of Data Security at Sales, sales Security. Um, he's going to be talking to us today, but let's welcome Todd. It's the first time he's on text on tv.
Todd, welcome. How are you? I, I'm doing great, Alan.
Thanks. Thanks for having me here today. I'm excited.
It's a pleasure, man. I appreciate you coming on. Um, Todd, before we jump into, we're gonna talk a little bit about last week's Black hat, and we're gonna talk about sales, but let's talk about you first give, you know, I mentioned your GVP, global Vice President for data security there.
Give us a sense of kinda your career arc, your, you know, your path. Sure. So, uh, I, I've been around the cybersecurity business for over 30 years, um, probably back in the day when cybersecurity wasn't so cool.
Right. We didn't know what it really was, and we Didn't call it Cybersecurity either. No, we did not.
No, I get it. And, um, I spent some time working with, uh, the US federal government, had some fun rules there for a while, and then moved into the, uh, into the commercial side, um, with SafeNet, uh, working really around data in motion Sure. And data at rest security.
And I, I've, I've followed that path, securing data, protecting data for the last 15 years with SafeNet Alto, now tlu. And, uh, we've really built out this beautiful, wonderful data security platform, which really, you know, can protect data when it's in motion, when it's at rest, when it's in use. And, you know, it's all about, uh, it's all about the data.
It's finding, it, it, it's putting the right controls around it, and it's watching it to make sure it's being used properly. So it's been a, it's been a great career taking a lot of what I learned back in the early days working with federal and the same problems there on the network protection all the way to the day, and protecting data for a whole bunch of different customers. Trying to think back to the day, was SafeNet, were they based like in Interlochen in Colorado or something like that?
Uh, I wish I, I live in Baltimore, Maryland. Alan, they, they were based in Baltimore, Maryland, so we were Oh, okay. We were, I mean, east Coast Us, I knew SafeNet back in the day.
Yeah. And I was doing a security company that was in, in near Boulder. Okay.
And, and so I remember, but it might have been a different company with the word safe in it. Who knows. Um, but yeah, I definitely remember SafeNet Todd for sure.
Um, you mentioned, you mentioned Tallis. Um, um, how long have you been over there as GVP of data security? So, I've, I've been at Tali, uh, for about 15 years now.
And, uh, we've expanded our, our data encryption, data security space. Um, we started out with something called HSM Hardware Security module, which, which Alan, you may have heard of from IT Security Stack. It's at the base.
And on top of that, we built an enterprise key management platform, uh, the core of a data security platform where we do encryption, tokenization, and files and applications in cloud. And, uh, we've moved to data in motion, and now we do, uh, we, we purchased a company a year and a half ago called Imperva. And a lot of people out there may know brand Inva I know.
Well, and so now Imperva is part of my, uh, yeah, they do, they do, they do the web application excuse firewall. Yep. And they also do, they do data activity monitoring for databases.
And now we've added unstructured data, and that's part of my, my team as well. But for Tallis as a whole, for those that don't know, I mean, we're based in Paris. So it's, it's a global company.
Um, it has two sides. Uh, one side is the defense side. Um, we, we build submarines and we build fighter jets and things like that.
But there's a huge cybersecurity piece of Tallis, and I'm part of that. And we've done nine acquisitions over the eight years, and I bet everyone on this, uh, watching this, uh, sort of podcast show w would know, would have something from Tallis that you didn't even know you had. Uh, we build, uh, passports, driver's license, credit cards.
Um, a lot of, uh, biometrics devices at airports are done by Tais. That's part of the cybersecurity identity that we do. And then when it comes to the data security, the piece that I'm involved with, any banking, um, any bank that you work with around the world, it's a good chance, uh, that, that you, you're using our technology to protect your transaction from a point of sale terminal all the way through using the ATM and just your, your bank account itself.
We're, we're, we're protecting that information. So, so we're big into the financials, but also other regulatory markets, healthcare governments around the world and, and really about protecting the data. Hope that helps.
You know, the high, the highly regulated industries are always, you know, a big, I mean, obviously they need great security, so security companies tend to focus. Um, Todd, what's the website for Tais? com.
com. And it, it, it's funny, whenever we talk about Tallis, it's spelled different than it looks. I should probably talk about that for a minute, Alan.
God, you Know what I'm thinking myself, and I just thought it was me. So what's the deal there? Well, what's, is it a French thing?
What's going On? No, it's a Greek philosopher. We we're based around from a Greek philosopher.
His name was Taes. It's T-H-A-L-E-S. And so a lot of folks would, you know, English speakers would say Thales, but it truly is Taes just like Dallas, the city and the us.
com. You could find us up there. But, uh, that's, that's the history.
And it, it makes it interesting when we do conversations, we, we get asked a lot, how do you say, how do you say your name? But, uh, absolutely. We like to keep, we like to keep it interesting for folks.
Make it hard. Very cool. No, you know what makes sense to me now?
So, Todd, let me, let me switch gears a little. Sure. Uh, I was out in Vegas last week for Black Hat, as were many of my friends in security.
I've been in, I've been in security way before. It was cyber, you know, same as you about 30 years. And, uh, the last 10 or so here is a, a media person, but before that, I co-founded and, you know, helped build a couple of companies in the security as we now call cyberspace.
Sure. Um, been going to Black Hat since 2003 when it was, it was over in Caesar's, and we had a booth on the hallway and some of the sessions back then and the speakers, they were giants. Um, but I, I was out in Vegas last week, you know, summer camp for Hackers, right.
Black hat, DEFCON b sides more. And there were definitely some themes this year. I know Tallis was, there.
Were, were you physically there, Todd, for this one, or, I was, I was, I, I, I wish I had the history of black hat that you have, but I was, this is probably my eighth. Eighth or ninth black hat. But I was, uh, Attendance.
So you've only been there since, you're only there since it's at Mandalay then? You weren't there at Caesar's. No, I don't have that history, unfortunately.
Yeah. No, Caesar's was much more smaller and intimate. Yeah.
It wasn't as big. Yeah. But it was, you know, it was there each in its own way, you know.
Very cool thing. You believe how hot the wind is in Las Vegas at night out there in August. Oh my God.
So being in a convection oven, man, It was, it was, uh, for the years, you know, first of all, it's, it's, it's a desert and it's August, so you know, it's gonna be hot. But, uh, yeah, it seemed like it was an exorbitantly hot this time and the wind was up. Yeah.
So In the wind at night, it was like, oh my God, though, I, I will tell you, last year I made the mistake, mistake. A friend of mine called me up. He said, Hey, we're throwing a party, a blackout.
We need another sponsor. Would you mind being a sponsor? It wasn't a lot of money.
I said, all right, what kind of party? He said, oh, we're making a pool party. I said, oh, that's great.
So I, this is last year, not this past year. So we go, first of all, walking out to the pool. By the time I got to the pool, I was medium.
Well, you know, I mean, it, it was, I felt like a piece of meat. No one was in the water because the water's as hot as it is outside, it seems. Yeah.
Everyone is congregating under these like misters, right. That, you know, that wrinkle out the cool water in a fan. Sure.
And I said to myself, what was I thinking? Sponsoring an outdoor pool party in August in Vegas. Never again.
Never ever again. But anyway, this year's Black Hat, of course, was, uh, it was a great show. You know, a lot of enthusiastic people.
There were definitely some themes, right. Ai, everything, everything was ai. But I've written my, uh, black hat recap.
Let's hear about your blackout recap. Uh, sure. I mean, it was, uh, I think it was a, a great event.
It was definitely a, a large group of folks there. I, I, I met with someone that kind of, of, uh, described Black hat to me in this way, which, which I thought was kind of fun, was, you know, if you have, if you remember, if you had kids or grandkids, you know, you go to the five-year-old soccer games, wherever the ball is, everyone kind of converges on the ball. Yeah.
And, and this year, and this year, the ball was the Agen ai of course, right? Yeah. So everybody was converging there.
Um, you look around the showroom floor, you talk to CISOs, everyone is racing to get to an AI story. And, and I think some of the key takeaways from the sessions and the CISOs I spoke to where we're just trying to balance all the hype, you know, we wanna keep up with, with the person next door, the company next door. We wanna make sure we have all the great technology, but at the same token, we're trying to balance, you know, keeping us out of jail and out of the papers and the press.
And so security was definitely a key element. I, I think one of the key messages was that, you know, AI can be used for good and bad. I mean, we all know that the, the, uh, the hackers, uh, what was one of the key phrases that AI takes amateur hackers and makes them look like professionals?
And, and you mentioned, uh, deep fakes and things, and I think that's pretty, pretty, um, relevant that, that folks are worried that the attacks are getting more and more sophisticated. But, you know, I think the messaging from Tallis, and, and what I also heard back on the defense side is there's no one silver bullet. It's, it's all the same things we've been doing for 30 years, right?
I mean, it's about the data, it's about defense in depth, having layers. It, it's making sure that you know, who's accessing your data, why they're accessing it, and what are they doing with it every time? It's not just, you know, a blanket approval.
It's every time someone's coming into your systems and trying to access your data, why are they doing it? And, and who are they? And are the machine, are they human?
And, you know, ask all the right questions. So a lot, a lot of, a lot of noise, a lot of excitement around that. Um, I would think that that hype's gonna continue for a little bit longer until we really do figure out how we're gonna control this beast, you know, of agen AI coming our way.
Yeah. Yeah. I, I agree with you.
Look, I, I, I think as you said, you know, I, I went to St. John's University undergrad, and we had a great coach there. His name was Luke, aka when I was there.
I don't know how old you are, if you remember, he was like five foot one Luke on sucker. Okay. Uh, but amazing basketball coach.
And, you know, St. John's was a small school, and they used to say that Lou could make a bad team good, but he could make a great team Good too. That was the knock, right?
Yeah. We, we never won the national championship. We made the final four.
Once AI can make a bad hacker good. Mm-hmm. But unlike Luke Acker, it can make a good hacker.
Great. Oh, yeah. Yeah.
Absolutely. Right. Absolutely.
And I think, you know, we're just, I think unfortunately cresting that wave, that peak of what we're going to see the bad guys, really AI powered. And, and the only way to fight it, I think is ai, right? You gotta fight AI with AI kind of thing.
Yeah. You, you got, you. You have to, to keep up.
I mean, it was, uh, you know, it was kind of a one, one thing in another conversation I had at, at the conference was around the use of ai and, and we were talking about discovery and classification. Um, how, how do you know what's good when it comes to data in your organization? What's important to you?
And, and we've been talking forever about classification of data, and there's a bunch of vendors that talk about how they do that. And you know, honestly, even though the tools have been out there from all these companies for decades, nobody classified a hundred percent their data. They just can't.
It's too much. And it's, it's too wide. And, and at the end of the day, the tools don't always work.
And so the question is, AI has been a leap forward in classification tools. I mean, in the last couple years using ai, we can actually classify tools our data much better than we ever had before. And so you say to yourself, do, do you wanna leverage ai?
And the answer is, of course I do. I wanna get better data posture, but I wanna do it to, to defend myself against some of the AI threats. So you have to just, what you're saying, Alan, you have to use AI to prepare yourself, to protect yourself against AI and, and data classification.
Understand what you had was just one use case that we were talking about at the show last week. So, yep. Hope that makes sense.
Agreed. Yeah. No, it makes total sense to me.
Yeah. Hey, I wanna switch gears a little bit. Sure.
Let's talk scattered spider. Yeah. So I actually, I forgot what briefing I was in.
It wasn't, it wasn't CrowdStrike though. I think they had a scattered spider kind of, uh, puppet or something, you know, life sized puppet at there, booth. Yeah.
But I was somewhere and we were, they were talking scattered spider and wondering your take on that, what you think, Um, you know what I'm interested, you know, just from, uh, a background, an engineer, an industry perspective, um, I, I think it's interesting to see how social engineering can be used to, um, you know, gather information. But it's no different than we've ever, ever found before about insider threats or outsider threats getting in. I mean, being, I talked earlier about what Tallis does from a credentialing perspective.
You know, we build IDs and, and we build all kinds of credentialing type system, physical and, and card systems and such. And those get stolen all the time. Digital identities, physical identities.
And, you know, when someone impersonates and gets out inside an organization, it's easy for them to move horizontally and to create all kinds of havoc. I mean, that's, that's kind of how a lot of these breaches that we've heard about occur. And so with Scattered Spider, I, I think it's really, you know, getting the ability to gather, um, information that's important to people get inside the organization and to wreck havoc now.
I mean, there's safeguards you can put in place. We, we can get into the, the next step of how you don't allow that to happen, you know, from a, you know, your identity management perspective. But yeah, I think, I think we're gonna see more scattered spider, um, attacks.
Man, I don't know about you Alan, but I get three phishing emails every morning when I wake up. I get five calls a day. I mean, we, we can go on and on.
It's just crazy. It's text messaging everything else. And, and, and, you know, it's gonna get, it's, it's getting harder and harder to differentiate about what's real and what's not real these days.
Well, they're Better, you know, So It, it's, the English is second language kind of problem, right? Yeah. The AI is, is is just blowing that out so they all look good and all look good.
And identity threats is another area, Todd. Yeah. Um, you know, for those of us in the security space, it's a scary time.
It's a scary time because as much as we have these new tools that, you know, allow us to do maybe more than we've ever done before Yeah. The bad guys have these new tools too, that allow them to do. Yep.
You know, it's what they wanna do. And so it's tough, man. It's disruptive.
Tough. It's tough. It's tough, tough fast, and it's, it, yeah, everything's accelerating.
Everything's getting faster for sure. It's crazy. I agree.
I agree. Um, I don't know if we've left out anything else on, on Black Hat before we move off that. Uh, I mean, if you had asked me what was one thing I thought was missing from Black Hat I was thinking about before we talked today, and, and one thing that I thought was missing was, um, we're, we're a little bit worried to tell us about, uh, a post quantum computer.
And, and, and that could, may be taking us off in the weeds. And, and you may say that's, that's fantasy. It never will impact us in a lifetime.
But, but honestly not buddy. Honestly, I, they're there today. They're getting more performant.
They're getting stable. We don't know when it's gonna show up. And I, a lot Sooner than most people think.
And I, and I agree, and I think a lot of folks aren't ready for it. And, um, quite frankly, I didn't see a lot of people talking in the sessions or in the, the, the vendor Sessions. Not in the sessions, but I, um, around that actually, I wrote an article about, Hey, you know, forget AI looking, your rear view mirror Quantum's coming up fast.
Yep. And I, I interviewed a guy from a company called Q Secure, Q-U-S-C-C-U-R-E-Q, secure. Okay.
Post, post, check them out, post Quantum, these people, you know, they, they come outta government, a lot of government stuff, Todd, they have Stanford. They have, they have an amazing advisory council. If you were in the government, you know how these things go.
They have amazing advisory council of ex generals, admir Roll, and Right. So forth. Yeah.
But they're, they're real. It's real. It's real.
What they're doing with Post Quantum and, um, you know, I-I-I-B-M has been on a war path lately too with their quantum announcements. They're committed Yep. To having quantum computers out here in 2029.
Absolutely. Yeah. I I I think Quantum's gonna be a new soccer ball in a couple years.
That would be my prediction. Oh, absolute. Absolutely.
But, but we haven't gotten there just yet. Yeah. No, but it's, it's coming.
You know, the guy from Q Secure, the way he explained it to me was fantastic. I, I have a video of his interview with me. You know, when we talk about, you know, we, regular computers take data in 64 bit chunks, and that data could be one or zero.
It's binary. Yep. So you could figure out how many permutations you have within 64 bits.
Yeah. In a quantum, in a real cu qubit, a clean qubit. Yeah.
It's actually two to the 64th power, which if you take all that data, it's about the amount of data, compute data that the world puts out in a year. It's crazy, isn't it? Blows your, it's, it's, It's like, wow, you know, my, my thumbnail is the universe.
But, um, yeah, I agree with you, man. I'm, I, I, I really think 20 28, 20 29 at the latest, we, we are going to see this and it's as, as bigger soccer ball as they are a bigger pitch as AI is. Yeah.
Quantum's gonna be just as big. And then when you put 'em together, luck out, look out. Yeah, exactly.
That togetherness is really scary. So let's get back together in a couple years and talk about blackhead. Hell, and, and maybe we'll see if our prediction are right or wrong.
I don't know. You got it. You got it.
com. Yes. Just wanna make sure we hit that.
Todd, thanks for being a guest here on Text Trunk tv. We appreciate you, man. You, I'm glad you enjoyed Black Hat.
Don't be a stranger. Don't wait till next black hat to talk to me about it. If you guys have any news, you'll come back on and keep us posted.
Will Do that. It's great meeting you, Alan. Take care.
Bye now. Nice meeting you, byebye. Todd Moore, global VP of Data Security at Thais Thais Group here on Textron tv.
We're gonna take a break. We'll be back.