Threat-Informed Defense with Tidal Cyber’s Rick Gordon
There are a lot of companies talking about threat-informed defense, but there’s a critical construct that requires companies to adopt it appropriately to best organize critical threat and defensive intelligence structured against MITRE ATT&CK. How can we improve threat profiling? How can we make better use of defensive stacks? How can teams more quickly implement coverage maps that show residual risk on a TTP-by-TTP basis. Alan and Rick Gordon, CEO of Tidal Cyber, will discuss.
Transcript
This is Textron tv. Hey everyone. Welcome back here to Techstrong tv.
I have another first time guest, another company to introduce you to here. Uh, let me say hello to Rick Gordon. Rick is the CEO of a company called Title Cyber, T-I-D-A-L, cyber.
And, uh, as I said, it's his first time on. Let's welcome him. Hey, Rick.
How are you Alan? Good to see you. Thanks for having me.
Our pleasure. So, Rick, well before we even get into Title Cyber, let's hear about Rick. I Sure.
Um, I'm the CEO Co-founder of Title Cyber. As you, you mentioned earlier, I've been in the cybersecurity industry since 1999. Uh, you know, started my career, uh, in the military actually, as a lot of us that are in the industry did, uh, I've, uh, mostly been in on the early stage side of, uh, cybersecurity, have been involved in a number of successful security startups.
Uh, this is the most recent one. Give us an idea, what are the, what, what kind of other startups or security companies were you with? Yeah, great question.
So, um, many, the, the first one, uh, that I did was an email security gateway back in 1999. So it'll give you a sense of just how early we were. We were Evolution.
I was there. That It's okay. I hear you.
Yeah, it's funny. It's, uh, cybersecurity wasn't even a thing back then. We called it information security Yep.
As they say back in the day. Yeah. Um, but I've been involved in, in, uh, in threat intelligence significantly had a senior operational role as the COO of looking glass.
Uh, sure. Even before, you know, a, a tip was a thing. Uh, we were really doing a lot of correlation of, of, you know, adversary indicators of compromise, uh, backend.
I mean, gosh, 2010, 2011. So it goes way back. Spent a lot of time actually helping birth a number of security companies like Huntress or Black Kite, if you know, ed Lumen.
Uh, all three successful companies that, uh, yeah, we, I helped stand up out of Mach 37 with this, a little accelerator in Virginia that I Familiar with it. Yeah. No, we, we've actually had, I think it's the two co-founders of Mach 37.
Well, one, one is the, a guy who co-founded, and then there's a gal who does a lot there. We found him on here. Yep.
Good, good people Also. It's a great program. Yeah.
Is title Cyber A a Mach 37 graduate, or No? No, No. I, although I tell you that we just implemented a lot of the, the discipline that Mach 37 was really instilling in in all of their portfolio companies, we really did apply it, uh, to our launch.
Uh, and we stood up our company two years ago. Very cool. Well, that's, you know, what, so I, I've also been in InfoSec as we called it back then, since the mid nineties, late nineties.
com days, then watch that crash and burn when the bubble burst. Yeah. A lot of them did, right?
Yep. Yep. And, uh, you know, then I stayed in cyber all the way through.
So similar, similar background, similar times. So tell us about Title Cyber. What, what, what's, what's the mission here?
Yeah, it's, so it's probably best to, if we talk about the origin of the company, it helps sort of explain, you know, why we're doing what we're doing. Sure. Uh, all three co-founders, myself, rich Stru, Frank Duff, uh, we were all working together at Mitre.
Uh, if you're unfamiliar with Mitre, MITRE is a federally funded research and development corporation. Actually, they operate multiple FFR dcs, all mission oriented principally, uh, in, in most cases national security oriented. Uh, the area within Mitre that Rich, Frank and I were focused on was in threat informed defense.
Basically, uh, applying the knowledge, uh, that's native to the Mitre attack knowledge base, uh, to different security use cases and building adjacent capabilities to make it easy for both vendors and consumers of security products, uh, to integrate the knowledge of adversary behaviors into multiple use cases. Um, and I think what we learned in that, uh, through that experience, one, that there was a significant, significant demand for sort of structured threat intelligence, uh, but also there was a demand for capabilities that allowed for the contextualization of that intelligence using attack, uh, at scale. Um, that that platform did not exist.
Uh, most of, a lot of our customers were very large enterprises, uh, and they basically asked us to build the platform. So we did, we left two years ago, stood up a platform that essentially allows for the automated, um, organization, uh, Synthes, uh, synthesizing and operationalization of threat intelligence into, uh, their security operations. Excellent.
Um, so as you had said earlier on, you know, threat informed defense, which is kind of what you guys are, you know, doing with title cyber threat, Intel itself was kind of a recent, in my world, a recent thing, right? Yeah. Maybe 10, 15 years ago now.
Yep. Of course. It's become very, uh, commonplace now.
Everyone, I mean, of course you have threat intel, right? And, and then actionable intel and then acting on it and, and all of these things, but free, you know, I, I get how now the genesis of this, right? And, and by the way, we have always have Trace Bannon from, from Mire on here and others, but putting this all together, um, what exactly, well let, let's start with this threat informed defense.
Here's threat intel, here's threat informed defense. Take me from one to how you get there to the other. Yeah, that's a great question.
So, uh, you know, to really understand the value of it, to have sort of tried to deal with right informed defense, really over the past decade, you know, 15 years, um, so much of not just CTI, but, um, a defensive or security architecture is really based on, um, you know, essentially chasing down indicators of compromise, right? Either, you know, hash values, domain names, IP addresses, and, you know, a lot of threat. Uh, CTI elastic, it was really about correlating those and trying to identify, you know, when something was su uh, suspected to be bad or known to be bad, and, and then when something was not, and then we would build and, you know, defenses based on those things, based on that knowledge, either at our, at the end points, uh, or in our networks to be able to identify, you know, when, when we see something that we recognize as being bad.
I think around 2013 when David Bianca wrote that Pyramid of Pain, a famous blog, I think we started to recognize, uh, throughout the industry that that was really a failed strategy because the adversary just quite frankly had as many of those, uh, unknown bads as they could ever possibly want to draw from. And so, you know, putting all our eggs in the basket of sort of looking deterministically for known bad IP addresses or, or hash values or domain names, was just a little bit foolish. And what David, I think, illuminated was that, you know, what we need to be able to do is detect, um, you know, uh, adversary behaviors or what we would call TTPs tactics, techniques and procedures that are indicative of malicious intent in ways that are less dependent on those brittle indicators of compromise.
Uh, and, uh, yet sophisticated enough to have high probabilities of detection and low fo low false alarm rates. And I think that did birth, uh, a huge, uh, industry around EDR, uh, managed detection and response where they are, they, the detections are more sophisticated. Um, but I also, uh, you know, think it has quite a long way to go, right?
It's, um, the, uh, you know, what, what we know, here's what we know. Um, security organizations at large have grown really custom sort of, you know, building security architectures that are essentially managing portfolios of capabilities that detect three, three types of IOCs. Now, what they're being asked to do is manage security portfolios that, uh, represent 600 behaviors.
And so that, that portfolio management process is significantly different than anyone was accustomed to, that anyone was prepared. Uh, for security organizations, security leaders, you know, they may be able to track certain adversary groups, but they don't know how that relates to which behaviors, which techniques and sub techniques matter to them today based on what's being used in the environment. And even more so they don't know with these often expensive and complex security stacks of tools and EDR, uh, a next gen firewall and in, um, a, uh, uh, email security gateway, for example, on and on and on, they don't know, uh, what those tools actually defend against on a technique by technique basis.
That's the problem. That's where people are trying to get to, is to get an understanding of how well do my defenses today work against the techniques that adversaries are using against me today. Where are there gaps and what can I do about those gaps?
That is what our problem, our product solves. Excellent. You know what, it took us a little while to zero in there, but we certainly zeroed in on there.
You know what Rick, I, I realized we jumped right into kind of the bag diving on the technology without laying foundation on title cyber for people who want to get information, what's the website? com. Title is T-I-D-A-L, Like a Tide, a rising Tide, and of course cyber.
Um, so Rick, how, how do people consume, you know, product? You, you guys are around two years. How do people consume this?
Is it like a subscription service SaaS kind of thing, or It's a SaaS based platform. It's really easy, uh, to, to implement. I think in general, uh, you know, proof of concepts for customers last 30 days, we don't always get through the 30 days.
I think, uh, within the first couple of days, I can show a customer what their coverage is, where they have gaps, what to do about it, uh, and, and, uh, you know, and the vast majority of cases, you know, it's easy, uh, for them to make a decision, you know, when you, so it's funny, um, when a security leader sees, uh, with specificity what they can defend against and what they can and what to do about it in a way that they've never been able to see before, they want it. Absolutely. You know, I'm reminded a hundred years ago, not a hundred, but 25 years ago, I helped found another company early on in the vulnerability management space, and then all of a sudden a guy named Giddy Cohen, I forget Giddy company right now, but they started coming out with the 3D attack graphs that would show you not just the vulnerability, but like the path a hacker can take or a bad guy can take.
Yeah, yep. You know, through your network and how he would, or how they would go no to, no to hit that vulnerability and what they'd have to do to exploit it. And that was kind of a whole different view of just a telephone book of, of vulnerabilities that we found scanning.
Right? Yeah. More than half of which probably weren't even relevant.
Um, right. So to me, this is kind of that same sort of paradigm, right? It is.
Um, there's a lot of thread intel out there, but go ahead. No, we've seen, uh, sort of vulnerability management, past prioritization. We've certainly seen it evolve.
Right? Um, it's a little bit, uh, akin to, um, you know, what, everybody's dealing with the vulnerability problem. They're 20, what, 25, 20 6,000 or more that were released last year alone.
Mm-Hmm. And so it's just not, it's not something, it's great, uh, that we can identify what the vulnerabilities are, but, um, uh, having an operation in place where you can scale to, to keep up with, uh, the rate at which the vulnerabilities are being created, it's just not reasonable. So you have to take a much more strategic approach to it.
Um, the way that we intersect with that problem, though, it's, it's, it's telling, I think, um, in, in many cases, for example, uh, we can relate adversary behaviors to vulnerabilities. Either it's, um, a behavior that's required to exploit a vulnerability or a behavior that's exacerbated by, uh, uh, vulnerability. In either case, it's useful to know, though, if there's a behavior that's related to a vulnerability and I have fully mitigated the ability of the adversary to engage in that behavior because of the defensive capabilities I've stacked between the asset that's vulnerable in the adversary, uh, themselves, then I've effectively reduced risk in a similar way.
And perhaps it's, uh, equally, uh, effective for me, uh, to do that at least initially. Uh, if I can't patch, let's say for operational reasons, I can't patch immediately, uh, understanding what's in your defensive stack and how it mitigates those specific behaviors that are related to the CBE is incredibly valuable. It's not only just on a cbe e by CBE e basis, but take for example, if I, if I take an action to actually mitigate a CB, uh, that I don't wanna patch for whatever reason, it is very likely that the action I took just impacted thousands of other CBEs in a, in a risk reducing way.
We've never had that visibility before. Now we do. Excellent.
Excellent. Hey, Rick, we're about outta time. 15 minutes goes really quick here.
I apologize. com is where they can get more information. Um, is there a trial or anything that they can, you know, get their hands on this right away?
Absolutely. Uh, I could have, uh, a company if, if they reach out to us, we're happy to, uh, set up a, a conversation. We'll get a POC in place, uh, within a week.
It's really, really light touch and easy to, easy to do. Perfect. Hey, man, best of luck with Title Cyber.
Do keep us, you know, up to date on what's happening. Come back and visit. Okay.
Thanks, Alan. All right. Rick Gordon, CEO Title Cyber here on Tech Drunk tv.
We're gonna take a break. We're back with a lot more today.