Securing Data in 2025 with Chris Gibson
Chris talks with Alan about securing data in 2025, AI, legacy systems, and global collaboration.
Transcript
This is Textron tv. Hi everyone, it's Alan Shimmel here for another Textron TV interview. I want to introduce you all to Chris Gibson.
Chris is the CEO of first, the Forum of Incident Response and Security Teams. We'll go find out more about that in a minute. First, let's say hi and welcome Chris.
Hey, Chris. Welcome to Techstrong tv. Thank you.
Alan's it. Great to be here. Fantastic.
So, Chris, before we get into, first, let's hear more about Chris. How, how did you come to be the CEO here? So my first job, when I left my education, I went and dropped bits of explosives down holes in Saudi Arabia.
I, I worked in a seismic company, really. I got pretty boring pretty fast. And I moved into technology.
I worked in a bank for a number of years. I then moved into Citibank. I bounced around Eastern Europe, upgrading and installing banking systems, and then moved into Citi's information security proper under Steve Katz, who was the sort of the, the world's first CISO back in 99.
I think. That was, um, spent a number of years there. Then running their incident response and their forensics gang globally supporting investigations and actually running the incident response team for a portion of that time.
Uh, then I've moved into civil service in the UK cert. The government here decided to set up a national cert for the first time. They had the pieces in place already, but there was no single entity that was a national cert.
So I jumped across to them and spent three years building and running the, the UK's first formally chartered national cert, which was a joy, absolute joy. Uh, if you're gonna do incident response, do it for a country, because that's when it gets really interesting. Oh, I'm sure.
And then Been a little bit of private sector. And then this opportunity at first came up. Now I'd already known first Citi was a member of, first we were, I was their representative to the, to the organization.
I'd been on their board, I'd been their CFO, I'd been the chair for a couple of years. And then the opportunity came up to work for them. First had moved, was moving from a volunteer led organization, purely volunteers with, with a number of contracted services, but run by volunteers to a point where they wanted to professionalize and bring someone whose job it was to do this.
So I got paid to do what I used to volunteer to do, which is just the joy. Can't think of anything better. Been here about six years now, and it's about building first stuff into, you know, properly global meeting, the vision and mission statements that we have.
Excellent. Excellent. You know, it's funny, I, I, I used to, uh, have a, I co-founded a cyber firm and I remember Citi in those days.
You know, it wasn't Citi, it was Citi Group. Yep. I think it might have still been, I don't know if it was Citibank City, but I think it was Citi Group.
Citi Group Citi, yeah. No, I used to work with, um, I don't know if you have, they had three global CIOs back then kind of thing. Right.
And one of them was a fellow named Peter Fisher. Yeah. Uh, outta New York.
And I remember talking to Peter, we were trying to get our vulnerability management products tested there, you know, and this is in the days now. Microsoft's starting to do, uh, patch Tuesdays and all that. And you know, but Citi, it, it's, if you put out a patch on a Tuesday, it was 90 days or so or more absolutely.
Until they applied it. But interesting times, interesting times. So it sounds like first though, has been around since those times though.
Give us a little, Chris, give us a little first background. So, first started in 1990, after the very first worms. Um, cert CC was formed in 19 19 90, after the Maurice Worm.
A year or so later, there was another fairly destructive worm and people on the internet, you know, the internet, there's no control, no one's in charge of the internet. It's all little islands of systems that talk to each other and sort of know where to go. So nobody knew how to deal with these incidents.
There was no one place to central place to go to. So essentially an informal forum of teams. Group grew together, primarily US-based, and worked out, you know, if I have a problem, this is the guy I'm gonna talk to at that place, and this is the guy I'm gonna talk to.
And this is his strong point, and this is my strong point. Forced forward, move forward five years, we set up as a formal organization. So we've been a legally, you know, proper organization since 1995.
We've now grown to 760 odd teams in 111 countries. And our vision is that when there's a problem on the internet, you can go the formal route of, go to your law enforcement, go up the chain, go across to another country, come down the chain. It just takes too long.
We all know that when worms hit, when viruses hit, you know, they can bring the internet down in, in seconds, minutes, hours. There's not the time to go through that formal process. So we believe in bringing teams together, building that network of trust, such that if I have a problem in Country X, I know someone in that country, I've been there, or I've met them at a conference, or I've done training with them, I can talk to them and get stuff done while we go through the formal process.
We accept that's not a scalable option that works now, but we need to fix that. So we also get involved in standards, we get involved in, in building systems that talk to each other and so on. It's all about improving the art of incident response.
We know we're gonna get hacked at some point. Everybody will have a problem at some point. So let's prepare for that.
Let's be ready for that, and let's actually be able to deal with that fast. That's amazing. That's great stuff.
I've, I, I have to confess, I've been in security 25 years plus and probably close to 30, and I, I'm not, I was not familiar with first, so now I am. So you at least you converted one person. That's, that's great.
There You, I think the challenge Is The years we tried to defend our way out of this problem, you know, we build a better firewall, build a better system, build a better list. Now we've got to that, you know what, we're gonna have incidents and, and central banks. Yeah, no, that, that, so I saw that's starting to take place in maybe 2010 to 12.
Yes. The shift from prevention to, to response. Yes.
Right. It used to be 80, 85% prevention, 10, 15% response. I'm not saying it's 50 50 today, but it, it's certainly not 85 to 15, which is a big, big change.
Big change. And I, I wanna jump into our topic of discussion, but before I get there, what, what's the website for first, Chris? It's very simple.
org. That's it. Dot org.
F-I-R-S-D. Yeah. And like a footprint at industry shows or anything like that where people can So typically, yeah, typically not.
We've always, because we believe in building this network of trust and whatever, we don't go out and do advertising. We don't go out and do marketing drives. Essentially, we grow organically.
So someone meets someone from first we talk about it, they say, that sounds interesting. They come to a conference, they join. It's been very much based on that.
We grow about 10% a year. So we grew from the original 15 to now of 770 odd teams. As I say, 111 countries.
But we've never wanted to just, you know, it's not a pay to play. If you don't sign a check and join. You've gotta be, you've gotta be accepted in, you have to be sponsored in by an existing team.
But it's all about building that network of trust And the king's Kingsman. Just kidding. Um, but that, that, that's interesting.
You mentioned the conference though. It is their first conferences. So We Run an annual conference.
We take it around the world. Uh, last year was in f Yoka Japan. We had 997 people attending thou from 96 countries.
So it's getting big. It's a full week. This year is Copenhagen.
Next year will be Denver, Colorado. We'll see where we go after that. So yes, so that's the big one.
But then we also do local, more regional events with local, um, partners. We do training events with the ITU, we do training events to do capacity building. We have funding from the UK government to do stuff in Africa.
We're all, it's, it's about building communities around the world through those training, through those events, bringing people together so they can work together, talk together, and learn to trust again, we're back to that trust. Absolutely. Alright, Chris, if you don't mind, I want to kind of segue, turn to our topic of discussion, which today is all about securing data in 2025.
Right. You know, we'd all love to live in a world where everything's a green field, it's all shiny and new, and we get the latest and greatest. Of course, that 80 20 rule applies to that too.
80% of what we work on or more even is not greenfield. It's brown, muddy fields, and you've got legacies and, and obsolete stuff, and a good mixture of, you know, just a mishmash of everything securing data in 2025. Chris, where do we go there?
So I guess fundamentally the challenge is, the first step to any of this is identifying what you've got, where it is, and how much you value it. I mean, none of this is rocket science. None of this is new.
You and I would've talked about this with peers for many years about that base level cyber hygiene. What have you got? What do you care about?
Why are you securing it? That's always been the challenge. When I look back at my time at Set uk, you know, we ran, most of the cases, we ran, most of the incidents should just never have happened.
They were, they were bad passwords, they were bad kit, they were unpatched, they were the usual litany of stories that we've heard many, many times, which is my frustration, you know, if we could persuade people to do that really well, we would solve a lot of the problems we have. But it is, it's that not knowing what's there. So I can think of, you know, significant incidents where there was a server, it was somewhere over there, they forgot about it, it wasn't on the radar.
Someone found it and booked and they got, and all their high tech kit that they had, you know, really well secured, was just broken by this weak link. That's always been my prime tape, just identification. I, I, I say it and you know, how I always enunciate is you can't defend what you don't know you have.
Absolutely. Absolutely. Yep.
But you know, I tell you, Chris, and I'm glad you, you are today because I, I had a conversation this morning with a few people about the idea of who's responsible for securing data in stats applications, right? So many of us today, and not just as individuals, these even within organizations, you know, everything's in the cloud. We don't have data centers, we don't have, you know, we're using all SaaS apps.
Those SaaS apps store a heck of a lot of our data, a lot of it. Mm-hmm. But when you read the fine print, they're not really responsible for that data.
Re still responsible for it. Obviously it's our data, but yet we really don't have total control. So it's a, it's like this is the old taxation without representation.
I know. Can't say that. Well, I remember going to the tower one year on a, on a, on a, a, you know, a, a terrorist chef and, and the, uh, you know, the, the, the terrorist, I forget who works at the tower, you know, they're in the uniform and everything.
Vp Yep, yep. Yeah. The V feeders.
They said, you know, I had you yanks paid your taxes, you'd have a piece of this too. But, um, but anyway, you know, it, it's a funny thing. How can we be responsible for data that we don't necessarily have full control over?
And, and to me, I think this is going to be an issue. It has been an issue, but it's gonna be a bigger issue. Couldn't agree more.
It's a real challenge that we face. I believe, you know, when I look at most small, medium enterprises can't afford to have a fully functioning incident. You know, security team, let alone an incident response team.
You know, schools, small, medium enterprises, charities, nonprofits, they're lean and meaner. They don't have that time. So we would normally, I would say, move it into the cloud because then you are, you're part of a bigger thing that hopefully and normally has, you know, sophisticated people looking at it, making sure that it's all secure.
But you're right, when it all goes wrong, the blame will still come back to you, whether you like it or not. That's a challenge there, isn't it? There's that blame culture that we have that anyone who gets hacked, it's their fault.
Which, which is still, still ongoing and it's still many cases wrong. Um, but, but, but it's not the bad guy. You know, if someone breaks into your house and steals something, people don't tend to bring the homeowner.
They blame the bad guy who turned up and did it. But that's just the way we are today. It's the way we roll.
It's not a good thing. I, I think you're right. How do we, how do we secure that data?
We need to understand what we've got. But again, small, medium enterprise, the IT guys probably, you know, it's 50% of his job because he's doing other stuff. We roll into this, we want, you know, faster development, better applications.
We want faster to market. We want to be, you know, leading edge and all the rest of it. Every one of those things is an absolute challenge when you're trying to slowly make sure you understand what you've got, where it is, who owns it, what you care about, it's, it, I don't have an answer.
There is no answer. I don't believe. No.
I, I, I don't have an answer either. I, I also feel like, you know, the trains left the station. We're not gonna take our stuff off of the cloud or off of SaaS.
But I think that ability to have an incident response process that, or you know, at least a plan, at least you've thought about it, you've table topped it. Maybe with the senior management, they know what they're gonna do when it goes wrong. That's, that typically is what we see now is, you know, central banks and whatever are not saying it.
You can't have an incident. It's how well you recover from that incident. And it's your ability to take your, you know, your public, your customers, your staff with you to make sure that you are not looking, you know, like an idiot.
Because we've all seen incidents where they've not gone well. They've been a train wreck. Sure.
So, Chris, let me pivot a little bit to related kinda thing. I, I, I, uh, I did a, a YouTube, short LinkedIn live thing a couple weeks ago on what I call it sovereignty, right? For a long time in the cloud, we've had this concept of data sovereignty, right?
I want my data stored within, in a data center within the borders of my country, or these, what I consider friendly or secure countries, or well understood countries or what have you. And, and cloud providers have spun up all kinds of, you know, data sovereign type of clouds where, where people can do that. It seems unfortunately that we're entering into an age where this is gonna extend maybe even beyond data to it in general, right?
I only want to use it that was born and read and, and you know, made here. 'cause I don't trust it or I just, political reasons, whatever. I don't want to use non-native meaning, you know, native to my sovereign, listen to me, this is gonna be a huge, it's just a cluster to tell you the truth, right?
How do we, how do we, how do we plan for that in terms of incident responses and everything else? It always feels as though we're going back to the days of data. If, of our own data sectors, you know, we want it closer and closer to home.
We want to understand everything that's in there. We want it to be only, you know, maybe poten, potentially, you know, our data on that bit of kit, no one else is. Yeah.
So no one else has access to those drives and so on. That feels like we're going back to the days of, you know, big data centers and IBM and, and all the other things, which, you know, maybe that's the way forward. Um, again, we're back to that identification, aren't we?
What is it? Where is it? Who's got ac, who's got access to it?
If you're on a, you know, multi hosted system with multiple people coming in and accessing bits of that data, well, if someone hacks, breaks into their systems, does that give them access to yours? So just understanding that, that's hugely complex for any organization, let alone a small, you know, back to the small medium enterprises, the charities, the nonprofits, most of the people who are, you know, generating the wealth throughout countries, they don't have those people. That's, again, it's a huge, huge challenge.
Again, I would say back to the incident response, yeah, you may not understand that, but at least have a plan, have a table talk, think about who you're gonna talk to, how it's gonna work, so that you can have a response to that. You're not caught flatfooted. Yep.
I I, I do agree and I think, you know, it, it sounds so simple, but it's been so true for all the years I'm in security stuff is gonna happen. Yep. Right?
Yep. Stuff happens. It's having a plan for when stuff happens that separates success from failure.
Right? A lot of us, for too long, you know, we used to say, if nothing happens, you did your job in security, right? How often have you heard that, Chris?
Over the years, right? When security's good, nothing happens. But we now know you could have good security and still stuff happens, but it's how you respond.
That kind of is really at the end of the day, the, the, the line of, of whether you're successful or not. And, you know, I guess that's what first is all about at that level, right? That is absolutely what we do.
We bring people together to talk to each other, to learn from each other, to give presentations, to do training, to run exercises to help each other get better at what we do. Our mission statement talks about, you know, making the internet a safer place. And we do that by try.
It's like we, we consider ourselves firefighters. We're there to put out the fires. We're not there to solve the problems, although clearly there's a feedback loop just in the way that firefighters do.
But we consider, we are there to just keep the internet up running stable so that you and I can do all the things we want to do. We can bank, we can shop, we can talk to our friends, we can chat. We can do all those things online.
Confident that the internet is a reasonably safe place to do that. Agreed. Chris, one last question 'cause we're over time.
Um, you, you basically have to get sponsored in, but for people watching this who may want to, you know, have their organization, their team mm-hmm. Become affiliated or learn more about first what, what's your best advice to them? The best, best, best advice Come to the conference, come to an event, see what we do, see how well, how well I think we do it.
You know, really do that. Alternatively, drop, drop a line as there are contact pages on the, on the website. You know, we will work with people with more than happy to have conversations and introduce them to folks.
But coming to the conference, meeting people, building those relationships such that there will be teams to sponsor you, that's, that's the best way of doing it. I love it. Chris, keep up the great work.
Thanks for you coming on here, evangelizing, telling us about first Appreciate it and, and best of luck. Okay. No, thank you very much.
It's been a pleasure. I enjoyed it greatly Love to have you back on Chris Gibson, CEO of first forum for incident response and security teams here on Tech Drunk tv. We're gonna take a break.
We'll be back in a moment.