State of Cybersecurity in 2023 – Luke Tenery, StoneTurn
Luke Tenery, a partner with StoneTurn, a global consulting firm, assesses the state of cybersecurity in 2023 as cyberattack patterns continue to shift and evolve
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Luke tenery who's a partner with stone turn and we're gonna be talking about the current state of cybersecurity Luke. Welcome the show. Thanks, Mike.
Great to be here again. It seems like every day I wake up and there's yet another attack against somebody somewhere in a vertical industry and doesn't seem to matter which one it is. Everybody's a Target isn't your perception that?
We are actually maybe seeing more breaches that are successful and maybe the bad guys are getting smarter or is it just that the volume has increased and there's so much to defend and we're actually talking more about it and things are just as bad as they were. I I think a little bit more the latter from what you mentioned Mike. I think overall just some recent data.
We've been looking at and would certainly be evident with our workflow with our client base, but ransoms are down at some level in terms of whatever one was talking about particularly and 2021 Russian crane obviously sort of old news in that sense, but ransomware is down in terms of overall ransoms paid, but there has been a shift. Um to where incidents look a little bit different this year coming off of 2022 definitely with some of the macroeconomic pressures. We're seeing Insider issues come back to the foray in that sometimes with layoffs organizations to your point.
The exposures just look different now than they would have a little over 10 years ago the global financial crisis. What used to be just You know insiders downloading information and just looks a little bit different disgruntlement happens people speak out on Twitter the the underbelly of the organization looks a lot different now, it's more much more technology-centric and the Damage that can be caused. And so we've seen The Insider issue grow further to that because of some of the the industry distress we've seen issues arise in the digital asset community that sort of stating the obvious with the recent turmoil there.
But other Dynamics are play there particularly around the the value of digital assets Etc are driving a fair amount of Nefarious activities, the digital assets theft and a whole host of considerations there in a candidly in an organ in an ecosystem that has a lot of stress doesn't have as much to invest at times. From a security and protection standpoint. So we're seeing issues arise there in that space.
So there's still a lot of activity threat actors have shifted their focus. I think in certain ways because of Russia Ukraine because of the economic pressures more broadly in industry has sort of surface issues resulting from Insider threat and or other Industries and the distress that they're experiencing. Is there something that we should be doing differently about all this or or cyber security teams?
Basically doing everything they can or is it a matter of funding or it just seems like we keep talking about this issue, but there's no cure insight. Yeah, I would say that there are a couple things that aren't currently working. I think some of that is because some of these organizations that had massive growth over the last 10 years or so.
their assets look different now than what they were even six years ago pre the more recent boom meaning organizations have their It in the cloud when it was pre-boom. It was in a data center that they might have managed and so some of those changes while they sound so basic didn't really evolve some of their defenses to with where their assets are or they didn't take the time to kind of protect them in the same way that they would have traditionally. So I think that's impairment of an example is I think it was the New York Post that had a former Insider because they were disgruntled part of a riff.
They went to took over the Twitter account and/or deface the website. And so some of these issues there's different Assets Now like organizations don't necessarily put a value on the security to their Twitter account, but those things unfortunately have a reputational impact when they go awry and so I think that there's that but I think on the more positive note I do think Organizations are making that shift. We're monitoring closely.
What cyber spend looks like so I'm sure you follow. I overall it spend metrics and the like we've actually seen a Slowdown in security spend I take that as a positive and that Some of the current defense measures have been up to the task. There's other sort of macroeconomic drivers behind that as well.
I think the main thing that we're seeing in terms of that change and spend you probably have seen the same numbers where I think it was over a nine percent increase between 2020 to 2021 in cyber spend 2021 to 2022 was only a 1% increase and that's I think that's notable. There's this shift and consolidation to where you know, organizations are are consolidating their their technology stack across both it and security meaning Microsoft is an example has a much more advanced endpoint that threat detection platform now called Defender and it operates much more competitively now that it used to then say some of the other EDR vendors and when a CIO and a CSO getting the room and they look at the the budget and they can almost scratch some of their EDR money from an outside vendor. And have it included with their Microsoft 365 bundle at a fraction of the costs.
They're gonna do that when it means kind of saving headcount and or you know responding to the different, you know, profitability pressures that organizations are thinking about right now. So I think that that is running a you know, He a pretty significant impact on what security is doing now, they're getting smarter Microsoft CEO even said in self this week that organizations have to figure out a way to do more with less. I was more in the context of AI but I think you know, we're we're in a phase of business.
Now where security practitioners are getting a little bit smaller with the tools that they have they're gonna find Opportunities to find efficiencies on those and so I I do think that they're up for the task though if they, you know have the right levels sophistication. Where as long as anybody remembers security was a bolt on is that changing in the year of digital transformation is more people are putting applications that drive their business online and maybe they're starting to realize there's a lot more at risk. I I do I think more NASA companies.
I still have that to learn that Mike may not have the the resources to view security is like an integrated competitive requirement but larger more mature organizations. Definitely view Securities of partnership in some ways, you know, there's the age-old debate. I'm sure you're aware of is, you know, should the the sea so report to the CIO?
A lot of you know sort of some regulatory issues other just to be more competitive understand the balance better in terms of the roles and duties there of the two functions But ultimately, yeah. I hope that sheds light on on your question like it seems like there's more regulation coming down the pike as well. The SEC is getting more proactive about things New York state is looking at things and so do you think that that will just force the issue where organizations will have to improve their overall cybersecurity game?
No matter what? Yeah, I think it will continue to be a driving issue. I think the only cautionary note to that for me being too bullish on that is big.
I think the some of the issues are so expansive right now particularly with this. the The Fallout with the digital asset Market, you know just in the last Year, we saw this consolidation by the SEC signaling bigger investment in cyber and digital assets combining those two units together. I think that's emblematic of a few things in terms of regulator focus and then further you mentioned New York state New York DFS part 500, especially around cyber that's continued to mature.
They're very much involved in kind of monitoring Wall Street from a cyber and broader compliance standpoint. So those issues are going to continue to rise. We're also working with clients right now dealing with a host of regulator inquiries.
We are somewhat Focused on that increasing in terms of regulator impact on organizations, but I think the only murky thing is because of this upheaval on the digital asset side. I think the question is are there enough resources? For Regulators to to Really, you know tackle how big of an issue some of the you know, kind of more regulatory or compliance-centric security issues.
Are are they really expansive enough in their resources to really do enough about it? I think that sort of remains to be seen. We hear a lot about all things AI these days.
Do you think that maybe AI will save us from ourselves or is it more bad guys are gonna be using AI to kind of Torment this even further. Um, I'm optimistic about AI I do think it is part of the next Frontier. 0 being part of the next wave of growth from a technology technology technological advancement standpoint.
AI machine learning and automation I think are gonna be a big part of that. We've sort of envisioned 2023 there there is a rush to Ai and automation organization organizations. Again, Microsoft is smart people are trying to do more with less and the next sort of wave of productivity that All all signs are as that's what it where it's coming from.
I think it'll be a little bit more baby steps though as organizations get their heads around that it was sort of the same. I equated to the same migration to cloud like everyone was talking about going to Cloud wanted to rush there. There's gonna be bumps along the way because organizations, you know as they try it out.
They may not fully understand the risks in particular. And so we've already seen an uptick in areas such as AI or automation risk and some of its, you know pitfalls but yet, you know opportunities as well. So we were cautioning firms on kind of adoption, but we know that that's definitely where it's heading to some degree.
Are we getting better and treating security more as a team sport? Because we have such a shortage of cybersecurity folks. It seems like we've been making an effort to bring in the it operations teams to handle more of the security operations.
We talk a lot about shift left to developers seems like you know, it's an all hands on deck kind of thing. Are we getting any good at that? Yeah, I think that's true Mike, you know, I mentioned kind of that tool consolidation opportunity.
I think that's kind of emblematic of course and and even symptomatic of that shift like it's cliche but security is everybody's job and I would say that's the true in the case in it. It's really hard to separate certain security components from the it operation at times and I think Again, there's this this greater focus on consolidation by the product vendors as well. And so I think you'll you'll see again really good it admins.
We're gonna have some security know how and very good security practitioners are going to have some really good it know how I mean, I think that is the two that speak the business on both sides are gonna be the the resources that you know, I think are most successful because of this consolidation from a tooling stack and platform standpoint. All right. So what's that one thing you see organizations do in today?
That just makes you shake your head and go I can't believe we're still engaged in this kind of behavior. And and what's that one thing you kind of wish that everybody would just wake up one morning and stop doing. Oh, I think what I wish or I think they should start doing is moving away from just purely getting the right tool or control but starting to think about the the measurables.
and what that means is like you may do vulnerability scanning, but if you're not Monitoring the the effectiveness of and and follow up to what vulnerability scanning is doing in your environment. Then you're still going to miss stuff or bad things will still happen. So really it's kind of advancing Security in a way where people are thinking about it around metrics and monitoring and those sorts of things in a way from just thinking about it as do we have the latest tool set.
It's got to be more than that and I think You know once organizations, you know, think about security that way a mini are and so I don't want to disparage the the community. It's more of the problems that we see or when organizations they may have like a controller tool, but they don't have the right hygiene and rigor around that tool to make sure you know, just like your monitoring profit or spend on a monthly basis you would want to you know, make sure you're tooling is giving you the right inputs and measurables to to managing govern effectively. All right, folks you heard it here first things that are measured or easily secured is kind of the message of the day.
It's a place to start and if you don't know what you're measuring then you probably not scaring much of anything Luke. Thanks for being on the show. It's all said Mike.
Thanks so much for having me enjoyed it. All right back to you guys in the studio.