Threat-Based, Risk-Focused Security – Jason Loomis, Freshworks
Jason was one of the people involved in taking down the man who tried to attack a flight attendant on the United flight from LA to Boston in March. He also believes that a threat based, risk focused approach to security is superior in today’s value economy, and that AI won’t impact cybersecurity as much as people think. Jason also chats about how companies should be hiring CISOs for their leadership talent, not their technical talent and how the #1 focus in security should be people and training.
Transcript
This is Techstrong tv. Hey everyone, welcome back here to Techstrong tv. I, I, my next guest and I, I are gonna have what I hope is gonna be an amazing conversation that's gonna be very illuminating to a lot of you folks out there who either work for, uh, a tech tools vendor or everyone else out here who buys tools from a tech tool vendor.
Because I think it, it's, it's, uh, it, it deals with both of, you know, both of those scenarios. Let me introduce you to Jason Lumis. Jason is the CISO C I S O at FreshWorks.
Hey Jason, welcome to Text Drum tv. Hey Alan, thanks for having me. It really is my pleasure.
So, Jason, um, well, before we jump into it, let, let's talk a little bit about Jason. You know, it's first time on our show here. Why don't you tell our audience kind of a little bit of your kind of journey.
Yeah. Um, yeah, I, I kind of fell into tech. Like, it wasn't something I ever thought I'd be doing.
Um, you know, in my twenties as I was floundering through junior college, I was on an eight year, two year plan, you know, and I think up until college, my, my hopes and dreams were of being a swashbuckling archeologist. They were kind of dashed when in my first anthropology class I got ended up brushing a rock. I'm like, maybe it's not the thing for me.
So I, I was bumming around, right? Working as a bartender, working restaurant, trying to figure out what I wanna do. And it was my mother that had this genius idea.
It's actually, it's not that genius cuz it's just, you'll be like, well, why didn't you think of this? But I was a big computer gamer, so I was building land parties, which were the old school before we had consoles that networked. You had to build your own dude.
I was there, yeah. I was doing the B N C with Duke Newcomb. Do you know, try putting these together.
And my mom was like, you're so much into computers, why didn't you just do this for a career? 0 track from Microsoft took off and now certifications sort of became an easy foot into the industry. So I went and got my certifications, got my foot in the industry, and it's just been a wild ride since I've been in for about 23 years now in tech, focused on security for the last 12, which was through a confluence of luck.
I absolutely like think you can have a whole conversation around, I think under people underplay the idea of luck and how much really affects your, um, trajectory. So through luck and we meet the right people at the right time and the right job, I pivoted in security and I've been a CISO for about the last eight or nine years. That's fantastic.
What a great, you know, my story's a little different. I didn't get to be a bartender for very long, but I I, I actually went to law school. I saw that.
That's impressive. Yeah, I hated it. You know what, law school, you know, what's impressive about law school, Jason, it's not that you gotta be the smartest guy or gal in the room.
You, you just have to persevere, right? You gotta, you gotta keep putting one foot in front of the next and go through the process. But, you know, when I, when I graduated, so lawyers back then didn't use Microsoft Word.
We were one of the few professions that wasn't a big Microsoft. Uh, we used the word perfect. Mm-hmm.
And on Noel networking. So before you had your Microsoft, I Knew Noel. I used to support Noel.
Yeah. So, and, and lawyers are incredibly technology dumb. So I, you know, when you are the one-eyed man, you are, you're the king and the land of the V blind, right?
And, and so I became the tech lawyer who knew Word perfect and knew a little bit about networking. And I, I did the same thing. I set up networks in my house and for my friends.
Then we started doing the same games, you know, when Doom came out and all of this stuff. And man, I was on all kinds of online stuff, PBS's and everything. And I realized I, if I kept being a lawyer, I was gonna die young, miserable.
But this was my hobby. And if there was a way to make a living doing what I really liked Yeah. Fun to do.
Wow. What a deal. And, and I did, when the internet went public in like 96, you know, Netscape browser came out, I embraced it and, and kind of never looked back.
And, um, again, like you sheer luck, fate, whatever. I, I, I found myself in security after I said sold my first business or whatever. And, um, again, stayed in, I was started, started a security company or co-founded a security company in 2001 called Still Secure out of Boulder, Colorado.
And, and have been basically in security ever since, though I left Social Secure and I started what became this company? Yeah. 2013.
So now I don't, I don't, I just sit here and let people like you do the security. I just observe and talk. Can I do what you do?
How soon can I do that? Yeah, no, You know what? You're Almost right for it.
Give it a, you gotta lose a little boy of hair. Um, Good. But I, if I stay in security, that'll, that'll happen fast.
It It does. No kidding man. No kidding.
But I actually, it's a great story though. And you wanna know the truth? I, I've spoken to dozens if not hundreds of CISOs.
It's actually not an uncommon story or or fact pattern from people of our generations, right? Today's people are coming outta school with, you know, cyber in their college curriculum or whatever. Yeah.
We didn't have anything like that. And let's hope they do better than us. That's all.
You know, I'm not, you know, I'm not, uh, one of these people who say, oh, you know, I walked five miles uphill in the snow both ways. Um, you know, hopefully they come out with, with better skills than they do a better job. Though.
We've tried everything. I hope so, man. I'm hopeful cuz so far from when I see security is still not a core curriculum in software development.
It's still considered, no, we'll get to it if we have time, but I'm like, you need to start teaching it now. It should be standard for if you're gonna teach code, you're gonna teach secure code. I'm All for it.
But it's not. No, I, I hear you. But the other thing that I see, cuz I get a lot of people call me and ask me, how do I get into security?
I graduated with a bunch of security stuff from school, right? They're actually not taking software development. They're taking cyber in in college, but it's so impractical that they don't have any experience.
And then they graduate now they got a four year degree, but no security experience and they don't even know where to begin to break into this and that. That's a whole nother, we'll do that in a different interview. Jason.
Uh, let, let's, let's shift over to, to FreshWorks, which is where you are the Chief Information Security Officer. A lot of people in our audience are familiar with FreshWorks, but there are gonna be some who aren't. Why don't you give 'em a little of that kind of FreshWorks background?
Yeah. So FreshWorks is a, is a staff solution provider. I mean, software's a service.
So we provide softwares that enable businesses to run their business. We focus on really three primary, and we have a couple other product lines too. We have three primary core products around what's called I T S M, which is information Technology service management.
So if you have a help desk mm-hmm. Or department, our solution allows you to run that based on a very famous, if you're old school, like me and Alan called it Tilt. It's been around forever.
And it's this great framework for managing it. Cause managing it, if you work for anything over a hundred people, company is a lot of work. So our software enables that.
We also have, um, software for, uh, like customer support. So if you're, let's say you're selling squirrels online and you have a website and you want to be able to interact with your customer and chat with them or pick up the phone or do all these different things and track customer service. Our software provides that as well.
We have a sales line for fresh sales called Fresh Sales, which allows us to, in a operate within our customers or a company to do, uh, C R M. So it's a really great, the, the key about FreshWorks is that it makes it, you know, the goal is to make it stupidly simple to use the software. If, if, I mean, I've used a competitor of ours, I dunno if I want to say it, but it rhymes with how that is so complex.
It, I mean, I've used it. I mean, I had to go hire like five or six developers just to be able to use this thing. And the whole point of our approach is, hey, out of the box, easy to use, simple.
So you can get up and running fast. And there's not a lot of overhead to support the solution. I think that's why, you know, we're, we had a really great quarter this last quarter.
Results were just, you know, this why we're really hitting it. And I think there's a real need for that, especially the more complex, if anybody's used security nerds out there, it's like Archer, right? You never used rsa, Archer.
It is a beast. Sure. It does some great stuff if you're, I don't know, Boeing, but for a small, yeah, no, there's, There's five companies that can use it kind of out of the box like that and not bring in an army of, of folks.
And, and, and quite frankly, it's kind of jobbed would amaze well again, fo for another day. But what always amazed me about Archer is how many companies actually paid for it only to realize what the heck I, we can't do that, you know, and then boom on the shelf and they start looking at other stuff. But that's the way of security.
Jason, I I want to talk today with, I think you'd be, you're a great person for this, right? The role of the chief information security officer is a hard one no matter where you are and what you're doing because it, it varies so much from company to company situation to situation, regime to regime. But at a tech vendor, it's really two jobs, right?
It's what I call the traditional ciso, which is, Hey, I'm responsible for the security of my company's network endpoints, end users, attack surfaces, threat management, compliance, grc, if you will. You know, all of the things that a CISO is responsible for at an organization, right? Securing the organization.
But then there's like a second job, which is, hey, I'm forward facing to my customers. Cuz my customers want to know that we are delivering a product that is secured, that's developed securely, that is managed securely, that is continually secured, right? Continuously secured and not introducing any, you know, bed, bed mojo into their businesses.
Yeah. And that's, that to me is a herculean task by itself. Doing both of these.
How can one person do this? But here you are. Well, Well, it's not me.
I have a team. It's, it's my team. Okay.
Yeah. You gotta like the true leader. Yeah.
It's my team that's definitely doing the work. I'm just trying to do my best to lead and organize and strategize and get them what they need to do their job. That's really the role of a CSO in my opinion.
Um, you brought up a great point, you know, cause we, you and I chatted just a couple minutes before this to get to know each other before we, we went on with this conversation. You brought up an interesting point about that. You know, so I call it enterprise security and product security, and it's just like car manufacturing, right?
Ford is responsible for both. Hey, the, they're plants, they're ip, their, you know, their personnel safety, but they're also responsible for the cars. They roll off the road to make sure that they're safe and secure for their customers.
Exactly. We're the same thing. You know, I have my enterprise security, I gotta worry about our own data and our, you know, our secrets and our employees people breaking into our network.
Then I gotta make sure that our product, that people are out there driving on the road is secure as well. And you had brought up something about like, hey, you know, people are asking for this. Um, this is my second software as a service company.
Um, my previous company was also a global SaaS business provider. They did business for health, beauty and wellness. But what's what's surprising to me is actually the low number of people of businesses that are requiring security in their products.
You know, you, it, it's surprising to me how many businesses don't have security as a baseline. Like, look, we expect your product to do these things for us as security, but the numbers just aren't there yet in the market. You know, it's, it's, so, it really falls on me and product, you know, my C P O is awesome.
So working with him to go, okay, let's, if our customers we know probably 90, 80, 70% of our customers aren't asking for this, but we know that they're gonna need it, right? Like, for example, um, supporting m ffa, you know, multi-factor authentication is a way that banks now, so when you log into your bank, you have to have a second mm-hmm. Form of authentication that I I would guarantee that wasn't user driven.
That users weren't like, Hey, I need M ffa, they want it to be easy. Just get me into my account. And then when they get breached, you go, oh my, well how did that happen?
So it's really responsible for me to ensure that cuz we're not, I'm not seeing it in the marketplace that the market isn't driving enough. They're asking for features. They want the thing to do with what the primary purpose of that software is.
You know, I'm reminded Jason about 10, maybe more now, I bet you 12, 14 years ago, I'm, I'm on a podcast with the, at the time he was the CEO of Mongo db and then, and then we had the CEO of Couchbase. So these were two big no sequel databases, right? Yeah.
When no sequel was like rocking the world. Everybody was moving to no sequel. And I, I had them on and the, the podcast episode was, there's no sequel Stanford, no security, because there had just been a bunch of breaches, you know?
Yeah. On, on the, on the platforms. And you know, both CEOs, they, they act, I couldn't believe in public.
They agreed to, and they said this and the other one agreed with them was that, you know, they would build security in when their customers demanded it. And so what you're saying doesn't surprise me that it's true, but I really thought by now customers would be demanding it. I would've bet you five years ago, and you're talking, this is, you said 10 to 12 years ago that you had, yeah.
At least I would've expected that too. Man, it makes me think that maybe it's, you know, and I I maybe it's regulation, you know, we can't regulate ourselves as a market in the marketplace that it's gonna have to come down to like something like GDPR here in the stem. We can't even do privacy here yet.
You know, an EU is way ahead of us and it may come to just the sort of basic laws of cybersecurity or some regulation to get companies on board with it. But this has been the boogeyman for so long, right? If you know physician healed thyself, right?
If you guys can't get your act together, we're gonna have to pass the regulations from Congress. And you don't want that cuz you know what great technologists they are, but Nevertheless, TikTok hearings. Yeah.
You know, we've listened to some of those. But that being said, I, I don't disagree with you man. I like, what is it going to take, you know, the, this whole like, like software supply chain s bombs.
We're hearing about all of these things. But I've come to a revelation recently cuz I, I'm like, you know, truth be told, the reason I gotten into DevOps was for security. I thought it was a great way for us to do security better than we've done up to this, you know, up to that point.
And, and then the rise of DevSecOps and it's, you know, we've made progress. But here's what I've learned, Jason, you know what developers want to do develop. They wanna write code.
They don't want to be the ciso, they don't want to be the security person. They want to be the developer. They don't want to, no one raises their hand and says, oh, I wanna write crappy, s****y code.
That's insecure, right? They all wanna write quality, but they're not interested in being the security person. And so as a ciso, what do you do there?
Right? You, I mean, you don't wanna slow 'em down. You want them to do their job.
You can't slow them down. That's even, that's a such a stronger statement. Like, you don't want to, you really can't, when you're a CISO and you're blocking development or you're slowing down development, you're Not there long.
No you're not, you're not long. So you, you have to figure out how to, and you're gonna, you know, so overused term shift left, you know, but that is, you know, it still, it still hasn't gone left. We're we're still right.
You know, we're getting better and better at it, you know, and there's, you know, that's a goal of mine is to make you, you want, I wanna make it easier for the developer to write secure code. That's one of the things, oh, I can't believe I'm gonna bring this up. I think you said whoever brings up chat g p t first.
But there's some benefits to that, that hey, if I can get as a developer, something to show me faster and easier to write this securely. And if AI is a way to do that, that to me is the best benefit I can get out of ai. And it's that further left in the developers cuz it's all development now.
Most the system administrators, all this stuff, it's all cloud. It's really just the code that you're writing is how you're gonna survive as a business and is your product. And it relies on the developer's writing better code, in my opinion.
You know what, just for the record, Not bad. I mean, you made it almost 10, 12 minutes here without mentioning it. So you're, you're at, you're at the back end.
Some people get it in three minutes, two minutes. So you're good. Um, but you're right.
And, and, and quite frankly, I don't know if it's chat g p T, but can we use AI that looks at code? You know, this is the whole thing. We have like this GI ops movement, right?
Where people are literally developing writing GI and, and we have tools that work in the IDs that work in GI that really could flag, you know, 85% of security kind of, uh, issues, bugs, whatever you want to call it, right? In real time. Yes.
As they're doing This, that's actually a solution that we are in progress for about maybe halfway, we're about halfway to almost full over the next few months of rolling out that type of solution here. And that's exactly how you have to, you gotta get it as they're writing the code. None of these gates that are further down the path when you're, you know, no, It's, You're doing a poll request.
No, you need to do it a lot sooner than that. So that is the right approach Your time as you can. I do think it's the right approach.
But so, but back to my point, Jason, as the ciso, how do you balance these two? Because to me they're almost like really two different missions. How do you, and you know, you're an experienced guy at this now, this is your second size company with it.
How do you balance, how much do I, you know, these two missions, how do you or, or is there an overlap where you can get, you know, one plus one equals three? No, to me it's just another function. So you mentioned it earlier, you know, and I, at here, at FreshWorks, I have three teams that report into me.
GRC is one of 'em, that's a function. I have gtm, which is go to market, which is our, you know, we're sales enablement where we interface with customers with their security questionnaires and promoting security across our customer base. And then I have my normal standards, security operations, application security, and product security.
So it's that product security function that I'm responsible for that is wholly dedicated to building a better secure product Yeah. Across the organization and building those things in place. So I I just dedicate a portion of my time to that among many other Things.
So it's really three different teams. That's, that's impressive, right? Yeah.
Um, because I mean, look, there's a lot of CISOs watching out there that have a hard enough time just securing their organization, right? And they can't even, it kind of blows their mind up to think about I gotta secure the product product Too. Yeah.
You know what it you, you gotta have a good product officer. So I've worked with some, I've worked with some no names mentioned previously and not at FreshWorks. Horrible product managers.
It didn't care about no security. No. So, so my list of like, I've got 90 things plus, you know, financially their motivation is tied to not security.
You know, security is a risk reduction activity, not revenue generation or cost reduction. And those are their two metrics that they're paid by. That's exactly how they live their life.
So luckily, you know, I got lucky here at FreshWorks. I have a, I have a great, uh, precaution. McCarthy is our, uh, chief product officer and you know, he like lives and breathes security.
So if I ever need something done in security, he is like, all right, just tell me what you need. So that's a blessing here at FreshWorks where a lot of times CISOs don't have that and have to, it's more of a fight for those resources to get that done in development and product. Got it.
Remember that whole luck thing? Yeah, that luck. Exactly.
Yeah. I got lucky Sometimes. You know what?
So I, I recently had like a life event and I had this revelation that, you know, we walk a path and, and you, you make, you go right or you go left at the time you make that right or the left, you don't even realize what the implications are. But it takes you down to that different path. And, and sometimes it's Branch Rickey said, right, 80 per luck is 80% inspiration and 20% preservation or something like that, right?
So you say you get lucky, but I think your past success helps you set up for these luck. That is true. You have to be able to take advantage when that opportunity comes.
And that's the, and you gotta hard work, dedication, education. I mean I read it furiously. I'm trained, I know my stuff, but I've also gotten the opportunity.
Sometimes some of us are this smart and we never got the opportunity. So Abso you know, someone of vc friend of mine once, Tommy, it's much better to be lucky than smart. It's great to be both.
Hey Jason, believe it or not we're almo we're past 15 minutes. But for people who want to get more information about FreshWorks, where can they go? com.
com. Either one of those will work, check it out. It's great if you're an a small to medium size business, we're making great gains in enterprise too.
But if you're looking for ITSM or customer service and you want something that's easy to use because your current Salesforce or ServiceNow, oops, I just mentioned the competition is Unwielding. FreshWorks is a great, is a great product. Love to, we're gonna have you back on Jason cause I want to continue this conversation.
We could peel more layers off. Oh, I'd love to. How much time do you got?
Do you do hour shows? Because I, yeah, We do. So actually no kidding.
So we have a, so these are our interviews, but we have full on series one's called CISO Talk, actually with Mitch Ashley, one of my, uh, my CTO here and Jennifer Manila, who is pretty well known in security. They're the host of that. You'd be a great, a great panel member.
They, I'd love to be on that. We discuss some pretty cool things. We'll get you on it.
Awesome. But we're gonna end this one, Jason Lumis, CISO at FreshWorks. We're gonna take a break here on Techstrong tv.
We'll be right back.