Brian Penn, Aflac | Qualys QSC22
Brian Penn, manager of security posture at Aflac, joins Alan Shimel at Qualys Security Conference 2022 to discuss how he’s reducing cyber risk with BCI and VMDR
Transcript
This is texturong TV. Hey everyone. We're here.
We're live at Las Vegas. We're at the Venetian for the qualis security conference in 22, you know, I I personally I've been going to Quality Security conferences mostly in San Francisco because he's the Doom the same time as RSA conference probably for 12:15 years if not more right because I've been in the security World a long time. I want to introduce you to this channel in right here though.
His name is Brian Penn. Brian is with the folks at Aflac not gonna make them say it like the duck or the goose or whatever, but it's Brian from Aflac and Brian's a veteran of koala security conferences as well. He's actually spoken in a few qscs.
First of all, Brian welcome and thanks for coming and joining with us here on Tech strung TV. Well, thanks for having me. Yeah, we're fat Flack.
I've been with them about seven years. I'm older security posture program then with that about six years and before that I did risk assessments and Technology compliance. Yeah.
This is my fourth Wallace conference. I've made the ram this year with Atlanta Dallas San Francisco. And now of course Vegas.
I'll be speaking again today fantastic. Um, you know before we get into what you talking about, let's talk about your role as a security. Sister, you know risk person, you know, that's that's not the average title.
We hear from people let's talk about what you do there. So I mean when people do as best of my kids my family I say I protect the duck so, you know, I feel like you know, if we get breezed hack, you know, it could be my team, you know, and our name is the brand so everyone knows the brand but you know, my job is protect the duck. So we managed to vulnerabilities we manage pen test findings and we manage misconfigurations.
excellent and you know and you don't have to say the exact Wireless products you use but quite I mean, those are three things that koalas can really help with. Yeah. So we we actually use the almost the whole Suite we use BCI.
We use vmdr. We use the wise we use the policy compliant and so my team is more responsible for vmdr the PCI, but then we my kind of parts used application part of the West sure sure and that helps a lot with the when you start getting into pen testing and stuff. Like that would have been anything cloud-wise the total cloud or that's not really good.
Where's we're getting into the cloud now, like most companies are shifting to the cloud. We've got probably I think over the next few years. We're shipped in five to 600 applications to the cloud.
So it's a big push for us to make sure our cloud of our secure and we mature in the cloud. Well, the cloud has to mature then you can return the country that it's getting mature. When you say the cloud is you know, is it more like Cloud native kind of thing things with kubernetes and you may not even know this kubernetes and containers of this more traditional hypervisor.
We're doing a lot of stuff. We're I mean baseball shift in our applications from on-prem to the cloud, which is also challenging because on-prem, you know, you're there and then as we shift up you've gotta have a lot more security control because we're going AWS and you know, if you don't have the right controls they can shut you down. No, it's kind of good for me because I know as we shift up our teams are not step up and be more secure.
Well, it's also a good chance, you know, look there's some people who do the shift and lift thing right and they just take it from their Data Center. Shoot it up to the cloud. I think you know I've been talking to people doing these kinds of Transformations migrations for years and years.
It's also a good time to kind of take stock or what you got. Why why you have what you have and if there's a time where you want to you know, maybe start changing things from mono lift and microservices and stuff like that. Well, this represents the opportunity to do all that.
Let's talk a little bit about the what you're speaking about here. So what I'm speaking mainly day is our journey from going from a previous tool to where we went from kwallis about a year and a half and how much we've matured. So when we first went to koalas, you know, we thought we had a very secure environment as we started shifting into the tool we realized hey, we had a lot more vulnerabilities than we realized quality did a great job of picking up third party vendors software.
We didn't have knowledge of that. And so even though the risk were there we didn't have identified. Yeah.
So when we first launched, I would say our highs increased significantly, but over time we've able to reduce that about 55% due to the tool and knowledge the tools being able to provide us. Are you guys using the automated remediation yet or not yet. We would love to but you know with some of the Technologies and of course you got the business owners.
You got the application. Well, you got a highly regulate it and you like you can't break the environments. So one of my goals for 2023 and 2024 is getting that Automation and and more of a self-service.
So, you know instead of us providing the vulnerability. We just go ahead and remediate it. But you know, you can't break your environment.
Yeah, that's where that's a challenge we struggle with today. Well, not you alone that look. I I co-founded security company back in 2001 in 2003.
We had a vulnerability management solution. We were offering And we thought why wouldn't you want to just order me your remediation seems like a no-brainer, right? You got a patch patch it.
Well, it don't work like that, especially when you get into Financial or government or even Healthcare, you know as simple as it sounds things aren't always as simple as this now and for us we have DLI, which is Department of Insurance. We have to make sure you we meet their needs and so you have to be really cautious of that sure does sure does what about like xdr has that come up raised? It's not quite yet.
No, not yet not for us in our environment actually response kind of yeah not we're not well Wednesday. We're using Wallace. We have some of our own stuff.
We're doing within Splunk with some other tools, but we are kind of with some of the new true risks. They're doing with them. We are actually right for our left our sock team and our team we're actually in our great and true risks to do some of that so it's kind of work great with what they when they launch it back in April.
What is one of the first companies to demo it? And so and that's one of the things I'm speaking again today is true risk and how it's helped us great Identify some of those critical vulnerabilities that are maybe not so critical but also the ones that maybe medium and low to say hey we need to remediate this due to the risk, right but it's about it's about prioritization. Yes things, right?
I wanted to ask you. Like clearly, will you using Koalas in vulnerability management? Not just on your own network, but third parties.
You know, you've got this whole financial regulation because you're an you know, basically insurance company and sometimes they don't like to say insurance company, but you've got to answer to the insurance right departments. What a kind of what's on what's the new threats that it kind of got you got your attention. I mean, I would say almost any of them because as they change you've got to be prepared.
I mean, you know last month you had to change vulnerability that came out we were able to remediate in seven days and a lot of was due to Quality. I mean, you know definitely want to they had a dashboard come out we was able to monitor it we tracked it down. So I mean for us having the right threat feeds which Trista for us having the right tool to get the signatures and be able to identify the vulnerabilities is key and we've been able to do that last year really successful and then provide the metrics to leadership to say, hey, we are being you know, we're being reduced in the risk, but while also keeping the business running love it.
You mentioned that another part of your team does a lot of the kind of apps that stuff right? I'm wondering has anything like around the executive order out of the White House around software Supply chains and software building materials that's bombs and this kind of stuff kind of factored in to where what you got to do because I mean Aflac has I'm gonna guess hundreds if not thousands of applications. Yeah, we have a lot and then that's the thing is as you keep mature and you got to make sure you have the right tools, but you always got to have the right some of the right documentation procedures to make sure that you know, because you can have the tools or you can have the documentation but they kind of go both together because you know for us when The Regulators come in they first want to look at our documentation then they go look at the tools and the data to make sure we are actually doing what we said we'd be doing right so that's kind of key for us and then our last team they use Quality for that as well.
And I think right now we're doing 70 apps in it and we're keep growing that as well good, you know Brian one of the Frustrating things about security is you do your job with nothing happens, right? If nothing happened that means you're doing your job but a lot of times. You know at the board level at the sea level they don't understand that right?
They say Hey, you know, we don't hear anything. I don't know how good it is. I know we spent a lot of money on right.
On the other hand though security is really become a number one priority for so many organizations. What about an Aflac have you guys would you say in general they're increasing security budget or they I mean it they understand the job you doing. Well.
I want to take a step back first. Our our leadership has been very keen to this for years even up to the executive board. We provide metrics monthly to them, you know, and I talk to someone peers a lot of there's equivalents don't even have a really clue but they we monitor our metrics and we send it to them and they actually are holly engaged.
So I think that's the key when your leadership whether it's just to see so or CEO but when he goes above that to your board that's important because that, you know, you'll get the funding or you'll be able to get what you need to be able to reduce the risk because you can't have Buy in with them and think you're gonna be successful it starts from a very top and so they they really monitor our metrics and and we have to provide those and they ask questions. Not all we just look at it. They come back with questions and that's really key to me have a successful company.
No doubt about it. What about you know, look, hopefully we're here in person in Vegas this year. Right?
And we're coming back from this whole covid kind of everybody working in their house think how's that change things at Aflac if any for the most employees, especially the claims? I mean, of course they went. I think we shifted when they made them kind of mandatory go.
Almost 99% of our employees and our Columbus area went remote so, you know from a security system. We was actually ready we handled it. Well, we didn't see any drop off applications in you know, good thing with quality.
They had the agent. So on all the laptops and workstations. We never lost monitoring for it.
And I think that was really great for us because you know, a lot of companies as they started shifting home, they lost visibility to their equipment or you know, absolutely and you know, that's where quality really helped us because we already had the agents on the systems so they went home we were good to go. So we never lost traction good for you. last question for people out there who say look he's talking at the Quality event.
You know, he obviously likes quality or whatever you've had experience with other. Solutions out in the market, right? What do you think?
I mean you mentioned while it's found vulnerabilities the other dentist rushing your third party, but overall, what do you think is for someone who's considering? Koalas? What was the The go to like the real critical thing that put it over.
So for us, I mean, it's actually not a technical first was we have Japan which is a lot of people don't realize Japan is one of our largest revenue part of our company and so we big market and you know, we're almost in every household there. So for us with our Japan counterparts, the number one actually on our PLC was language, a lot of the tools don't have that support in Japan. They don't have Tams or even support staff.
So that was actually our number one driving force more than the tool. But then as we got into quality in our PSC, we had our checks just like air and other company should do your checks. We have three or four vendors, but the language really hit home.
And then one of the other issues we had with some of the other vendors is finding the remediation and when it was remediated because with our sock two artists some of the other ones PCI, you have to show when it was remediated within a tool you can do that where a lot of the other tools you had to add it into some kind of a system. So for us those are two keys that kind of Gap for us as a company. Actually, that's always been true in Japan man.
If you want to be successful in Japan, you need to be native. Right? And that's really and it helps us because as we partner with them we'd had to get on calls with a translator and you know that 10 minute conversation takes two hour, you know hour I've been and so, you know, you understand that and so with for us having that someone there it's reduced a lot of our time and and our money and you know from having to be on calls and translators so it's been great good for you man.
Hey, I know you got to go speak here. I want to let you out to get on get on the stage, but first of all, thanks for coming on texture. That's today.
That's the luck and and thanks for all the work you're doing man. I appreciate it. All right, right and Aflac here a flat IQ.
I didn't make them do that. I promise iqsc 2022. We are live at the where the heck are we we're at the Venetian that we'll be back in a minute with our next guest.





