SaaS for Building Forms – Johannes Wiklund, Jotform
Johannes Wiklund, head of information security for Jotform, a provider of a software-as-a-service (SaaS) application for building forms, explains what challenges fellow cybersecurity professionals should expect to encounter in 2023.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Johannes Wickland who's head of information security for jotform and we're going to be talking about what he and other Security Professionals expect in 2023. Johannes. Welcome the show.
Thanks for having me. I'm having me here Mike. I would say last year was kind of a bit of a rock and roll up and down roller coaster with lots of drama and stress.
So we're gonna see more of the same in 2023 or things gonna get better. I think we're gonna see more of the same unless companies Implement full weight of security controls in order to stay ahead of the attackers. One of my predictions for the year is that we really have to layer up our security model and what I mean by that is take the various layers of security controls that we already have and examine each one for where we can level up each one of those controls to essentially mature our Security Programs and do what it takes to protect our customers data.
Everywhere you go people are talking about zero trust and that seems to mean identity. So do the controls need to be tuned all the way down to individual identities or not just end users but the software and the machines themselves. Yeah, identity is certainly a big part of it Mike.
I think there are many other layers. I like to think of a layered security model in terms of Technology layers process layers and people layers and you know while identity as far as Network and server controls are concerned. They're also a number of other process related layers where companies can focus in terms of getting their incident response procedures tuned up their detection tune up and essentially, you know, as make sure that you respond to rapidly to evolving situations, you know, no level no level of Technology control is ever going to be fool approve.
So if and when something bad happens you have to know how to deal with it and you also have to have strong and well trained the people to be able to deal with it. How much of what we need to do is about new platforms versus what you're describing which is re-engineering or processes and kind of getting the people that think differently about how they go about securing the environment seems maybe it's a mix of both but everywhere you turn it seems like there's more focus on platforms and process. So I think if you go to any of the security shows, of course a lot of the sponsors have a vested interest in selling platforms and there's some truth in platforms being able to help you.
But I've also seen big platform implementations fail because companies just haven't been able to operationalize what those tools can do for them. So in my mind, it's really about you know, figuring out what do you need to get out of the tool tuning it in the right way to get those alerts and then creating process of around those alerts so that you can actually take the right level of action. I've heard horror stories of tools that are you know, alerting companies to an attack you're actually being in your network and then you see the incident Response Team kind of just sitting there watching.
Oh we wanted to see what the attacker will do next. So unless you have good incident response procedures and well trained Personnel just having a nice technology stack isn't going to help you. What is your sense of the how chronic is this shortage of cybersecurity people?
We keep hearing about all these jobs and yet I talked to a lot of cybersecurity teams and they generally feel competent to deal with what's in front of them. So some days. I feel like we're saying my God, we don't have enough people, but the people are actually doing it are kind of like pretty confident.
They've got any under control. So what's thinking in the Yang of the Staffing shortage? Well, one of my predictions for 2023 is actually the rise of departmental security Champions.
And this is really a way for organizations to leverage hidden talent that they may already have. So without increasing headcount. So that's something that I'm focusing on here at jotform.
Actually when I came to Josh Farm, I inherited a pretty solid team of full-time security Engineers, but I also quickly realized we had 14 parallel product teams. They're working out on churning out new products and features for our customers. There was no way even in my wishful mind that I could staff, you know a security engineer on every single one of those teams.
So I went on a mission to create a program for security Champions and recruit folks that you know can wear a second hat who are already on those product teams and can do more for security. I can tell you more about how I did that and what the program entails but the bottom line is, you know, I thought I would get maybe a mild interest of six to eight folks volunteering for this and guess what I got 30 So how did you get them the volunteer that level because a lot of folks are trying to figure this out right now. We're here about shift left and shift right shift left is get developers more involved shift right is get the product then the it operations team more involved, but I don't know if a lot of folks are, you know want to be the volunteer?
So honey, you kind of get them excited about joining the team. So the step one I think is really to get the executive buy-in. So I met with the VP of product development and some other Executives to make sure that they are on board.
This is gonna actually Empower their teams to be better developers. We're not trying to take away too much of their time. And then the second thing I did is I went out and had some lunch and learns where we actually gave developers actionable skills and advice over pizza and just kind of shared knowledge and I finished a presentation with a pitch to join the security Champions team and you know, we're starting small.
So we're focusing only on product engineers and it's a six-month program where we meet by weekly to give training and have live discussions. Sometimes Lively discussions about security topics and everyone really feels that they're getting skills. That's gonna help them become a better engineer and you know, it's really through those lunch and learns and the pitch.
Their gaining skills upscaling themselves that we were able to get traction. How automated do you think security can get we've been preaching about automation forever in a day. It doesn't seem like we actually get that far and a lot of people have high expectations for AI in general.
But what's your sense of what's really achievable? I really don't think we're there yet. Definitely not in 2023.
I think you know many companies are still trying to identify, you know, what patterns or use cases really represent a threat versus what's normal behavior? Even if you buy off this off the shelf tool whether it be a dynamic application security testing tool or or a security incident event management that's looking at your logs the biggest problem. I've seen Mike with those tools is really the rate of false positives.
The tools tend to be architect in it in such a way that they are, you know, they would rather report on something then ignore it and you know, so everyone ends up just getting alert fatigue. So plugging an AI into that pattern without fixing the root cause of the false positives and not not sure it's gonna do much right because I'm not sure how we can trust the AI to sort through and determine what's a false positive versus something. We actually have to do something about Once your sense of the bad guys, are they getting smarter or is it just that we have?
So much more of an attack surface to defend that, you know, there's just more places for them to take advantage of holes in the security, but they themselves are just running the same old game. I think it's a combination now when it comes to AI certainly the AI unfortunately can help empower the bad guys, right? So if you take, you know, kind of the the lower level attacker the AI can actually help them create scripts that you know that are attack vectors.
However, you know for us as Defenders. I think it's really the cloud sprawl over the last few years that that have caused problems and Security Department is really need to get control over their Cloud sprawl, you know a few years ago. I was very excited about AWS and and later Google cloud and the fact that you know armed with nothing more than a corporate credit card.
I can stand up my own infrastructure in minutes. But guess what Engineers were doing that also and they were doing it for proof of constant concept and prototyping and many times. They were not trained Security Professionals.
They were not thinking about things like default admin credentials or ports being open on the network. So in a lot of compromises early on in the cloud history really came from Simple mistakes with the cloud infrastructure and that's you know what you're saying about the attack surface really growing. Many of the Departments security departments have kind of honed that in right now and and have a better understanding of their Cloud security posture.
But as long as there is developers out there with a corporate credit card and access to any sort of sensitive data or even sensitive code, you know, we still have that problem. All right, we have met the enemy in the enemy as us as it were. What is your sense of?
There's more regulations coming down the pike unless here in the US for sure where the SEC and these other things. Some people say compliance is the enemy of security some people think that it wasn't for compliance. We wouldn't have any security at all.
What's your sense of the value of these regulations as we go forward and what do you expecting? So I actually think that compliance aligns with security. So here a jotform.
We're a worldwide company serving almost 19 million users across 140 countries. My responsibility really is to secure the customer's data and the meeting their expectations in terms of compliance, whether it be things like PCI for payment cards HIPAA for healthcare data gdpr in Europe or something else. So I have a compliance function under my team and I believe that As part of a larger risk-based security program, you know achieving this compliance and aligning that with security as a really important part of the mission.
As you look in the 2023 is there anything that we're not paying enough attention to the folks should be looking at and saying hey this is gonna be a much bigger dealing I think. It would probably be data privacy. So data privacy is the one issue that risk, I guess that keeps me out, but night the most.
We hear so much about data breaches, especially among public companies companies that hold data on millions of consumers. Those consumers are trusting companies with sense of information and I believe that companies such as us have to earn that trust. And what do we do?
We have to monitor the platform really on a 24 by 7 basis and you know, you say extensive log files to check for suspicious Behavior. And I think the customers are going to be more sensitive to if their data is exposed. You know, there might be more legal action taken class action losses and so forth if companies don't you know actually implement the right levels of protection.
So I think that's where you know, I'm predicting that in 2023. We're gonna either have to layer up our security controls or we're gonna have to lower your app. Okay.
To your point about implementing more layers of security and controls. How do we do that in a way that doesn't disrupt the process that we're trying to secure because there seems to be a lot of pushback from people on the other end when they go well we want more security, but I don't want to be inconvenient. So how do we kind of take a digital process and make it as frictionless as possible without Yeah, that's a good point.
And I think that some companies are not there yet. I'm lucky enough to work for a company that feels I'm quality first is really a key component of our mission. So we're we're you know, very defensive when it comes to implementing security measures and I feel that I am able to have a strong voice in terms of recommending both, you know network security data security process-based layers and you know finally training our people You know continuing to training people is definitely something that you know, I think is is going to be in focus.
You know rather than making Engineers suffers through the same old training about clean desk policy and strong passwords that they've all heard before. What I decided to do is train our Engineers on web application vulnerabilities and really give them actionable skills for architecting secure applications. And I think it's being well received, you know, I also think that fishing awareness is a skill set that's needed and trainable throughout any organization.
And you know, I'm not sure how hackers are getting new employees personal cell phone numbers might be through a data breach at another company, but we are facing as I'm sure many others are too texting scams targeting our specially new employees pretending to be your company CEO. And typically it ends with asking for the new employee to God and buy some gift cards and then emailing or texting them the codes so, you know fishing training is something that we really need to give to employees within the first five days of their life in the organization because we don't want them to fall for any of this. All right, of course the trouble is the fishing attacks are getting more sophisticated and harder to detect even by the human eye.
Can we really train those end users to see that or are we going to need a different approach at some point? Well, so the yes, so training is certainly only one portion. Another portion is preventive controls that you can put in in the process layer.
So one of the things that we've done for example is a fishing Vector is often to change wire transfer instructions on invoices and say, you know, we've changed Banks. Please send the payment, you know to this new bank account. So we have a process which I'm sure many other companies share where our accounting department has to manually verify any changed payment instructions with a known contact at that company and the same thing when we set up a new vendor is we don't just take the invoice that if at face value, we reach out to the company's accounting department and establish.
What the payment methods should be so we avoid, you know the fishing by shutting down kind of the attack Vector which in this case is fraudulent invoices and you know, putting layers of process controls on top of it to ensure that it just faking a single invoice isn't going to be sufficient to receive a fraudulent wire payment. All right. So what's that one thing you wish the it security vendor Community would do on behalf of you guys and and there's is there some pet peeve that you're looking at in 2023 guys and saying can you just fix this?
Well rather than naming one single pet peeve. I would say, you know security vendors as well as SAS companies like us really need to be industry leaders and security overall, you know, we have a million of users that you know, we feel it's really important to constantly improve the security program so that we can give these users the confidence they need to trust the data. So it's really about you know, having a road map where you constantly innovate and you know, there's always new attackers.
If something comes to my attention that races concerns my job is to really implement the solutions and ensure that we have those coverage. I don't believe there's single Magic Bullet, but if all vendors can be equally attentive to new attack vectors and continue to innovate their products, I think that would put the Cyber defenders in a much better place. Alright folks.
Well, you heard it here trust is one of those things that is hard to gain and easily lost. So pay some extra attention. And what's going on in 2023 you how does thanks for being on the show?
It's been a pleasure Mike. Thanks. All right back to you guys in the studio.