Eran Livne, Qualys | Qualys QSC22
Eran Livne, senior director of endpoint remediation at Qualys, joins Alan Shimel at Qualys Security Conference 2022 to discuss how to operationalize cyber risk reduction with patch management.
Transcript
This is texturong TV. All right. Hey, we're back here in Vegas.
Welcome. We're at the koalas QSC show 2022 If you've never been to a quality qsci and you're into security and Remediation and risk management, I highly highly recommend it the great thing about this show is it actually qualis doesn't charge attendees where you're gonna get it for the meals alone. It's probably worth it.
But if you can't make it to Vegas for their QSC though, they usually do do a road show and around maybe you can tell me I know they were in San Francisco in Atlanta Dallas news. So New York and that's just in North America. So if you get a chance, I highly highly recommend checking out of college QSC.
Not only it's a great to learn about what Carlos is doing, but you're gonna learn about what the state of the industry is, and it's a great opportunity to peer to, you know meet with your peers and exchange ideas anyway, Let me introduce you to my next guest. He was actually with us at last year's College USC here in Vegas. And his name is Iran livne, right and Iran.
I'm I gave them your name, but tell them a little about yourself. So yes, so I'm I'm around I'm basically managing qualysis ability to respond to all the vulnerability to be fine part of what we're trying to do in qualities. Help you take all the large numbers of vulnerability that you can prioritize with us, but actually find a solution.
How do you how can you solve it? How can you remediate is it patch? Is it a configuration chance whatever you need to do and whatever process that you need to get them safe to you know to do the change safely.
So they're the vulnerability will not be there anymore, but nothing will break right. So right, you know, I as you know, I've been in security a long time one of my personal aggravations is that We have talked about. Prioritizing vulnerabilities most bang for the buck on on remediation.
We've talked a good game around remediation for 2015-20 years, but as you and I sit here today. A lot hasn't changed in terms of utilizing some of the great technology that's been developed, right? Automation automated patching is probably one of my and when I say patching I don't mean just applying a patch.
I mean maybe changing a bed a misconfiguration or a bad configuration. Yeah. It's not that doing it is hard.
But for whatever reason I used to think it was a security industry problem. It's not just the security Folk. The IT people too.
They're afraid to let something be done automatically and and that's something we see and I think I agree with that's the biggest challenge that we see so many vulnerability discovered and nothing is done with it. Right absolutely. And you know, they started to always I heard from customers.
They always tell me I had an accident five years ago that I patch Java and it doesn't work anymore my Chrome which always work there was one case with something didn't work. We cannot touch Chrome anymore, right the challenge there is that those eighty guys and they live in their own side of that of the organization and they use their own tools and they don't understand the impact the security the risk that this fear. That is a real.
It's a risk management exactly. So there's an open risk and because of something that happened long time ago, they're not they're not exposed to this. They're not exposed to basically this decision what it caused the organization from a risk perspective.
things on that point number one I always thought it was a little bit lunar lunacy, right? It was a lunatic kind of idea of saying, you know what I'm afraid that fixing this vulnerability, which is a probably a serious vulnerability with exploits in the wild and everything else. I'm afraid if I applied this patch without fixing it.
I'm gonna break something. So I don't want to break anything. So I'm just gonna leave this vulnerability there and hope for the best and then no one ever gets fired.
Right you were using an old open source, because you're using struts too instead of updating to the latest version. You didn't apply this patch that came out 30 days ago. And they said well because we we had a fully tested first, right?
He takes 45 days. But it's okay that that risk they're willing to live with. The one in I don't know how many chance that it breaks Chrome.
And then you have to undo it that they won't live with. Yeah, and and you're right. That's something that's repeated that that's the reason we're When I'm talking from a college perspective from what we are doing where we know how to discover those vulnerabilities and prioritize them sure, but that's one thing as I said, there is also this it guy that has this experience what we're trying to do.
We're trying to bridge this Gap. We're trying to show it. Here is what it means not to take this section here it what it means not to to deploy the Chrome patch or not to deploy this Java.
This is how much risk you're exposed to. So we're trying to bridge the gap and show those two different people what's going on in each one of you know, each one of their roles and and yes, there are cases where you may you don't want to patch a production environment immediately because if the production breaks you may lose more money a great example, I see you devices. Yeah those thing if they break somebody dies, right?
You cannot take the chances, but but because we can understand the risk and we can understand the operation risk what happened if it breaks but what what happen if I don't patch it and everything is in one location, you can much better communicate with each other and decide here is something I can do easily. Here's something I can do easily and I know how much risk I am exposed to because I'm not doing it easily here. I want to emphasize what you said though when it comes to medical life and death.
Critical infrastructure, I understand I think anyone could understand why you want to you know test them and not just maybe just automate back out of it. But then there's another element and you hit on it when you spoke not before and that is well, it broke Chrome once yes, you know the chances usually what happens is because it broke Chrome once that's the first thing people are gonna test in a patch. Let's make sure it doesn't break Chrome again, right?
So there's probably less of a chance of it breaking Chrome then something that we haven't seen before right and but they don't care the people who say no don't do it. They don't think of it that way it broke Chrome. Once it's gonna break it could break Chrome again, you know again, it defies logic exactly.
Exactly. And and we also talked a little bit before about the automation, right? Yeah.
There's Chrome is a great example, but I always you know, what? The reason I talk about Chrome because customer do have experience with chrome. The reason the problem is browsers is that some old web applications can break when you upgrade a browser itself?
So not the Chrome is broken. Basically the application that use Chrome is right. And and the thing is it happened a long ago because JavaScript and all those things are you know, five ten years old application may cause the problem but it's 99% is not the case actually another example iTunes VLC.
You won't believe how many customers we run. We have all those reports Anonymous report. But how many customer are using those what can happen if iTunes breaks how many company needs iTunes as a mission critical application?
Everybody's using it to stream. Yeah, of course that doesn't work. Somebody will not be able to stream music.
I bet the business Will Survive now when you look at the risk how much unless you're a music streaming business then I can I actually right but when you look at the risk that Chrome provides and we we have those reports you can see how much risk your specific Chrome and your specific environment. How much risk it in? Us you can see the risk is so high and the fact that you're not automating and making sure it's always up to date.
It's just extra work that you need to do when you know, you have to go through all this reports and you have to manually touch Chrome it doesn't make sense. So there's so many candidates to automate patching or when we don't call it patching anymore. We call it remediation because we don't care about the patch itself we care about let's fix the vulnerability.
Yeah, so so much automation. You can do there without breaking thing or very low risk of breaking things right? I I think In some organizations, just all remediation is equal right?
They don't they don't quantify how hard the remediation is or what the possible effects of the remediation is they don't even necessarily apply to The risk of not remediating right? Is it a major risk? Is it exposable and all of these things?
Iran, I want to talk to you a little bit. You know that look the economy. It's no secret.
Right? We've seen layoffs in Tech. We haven't seen layoffs in Tech and I don't know how long I am and everybody's budgets are shrinking though to be fair security is more important than it's ever been before and and it's a bit of a sacred cow right the security budget, but nevertheless.
We're going to have to make do with less less headcount less people. Let's hands. And you know my my theory and I spoke to you about it off camera is that this may in fact help?
Kind of not force. But encourage companies to use more automation for remediation. What do you think?
I actually agree with that because when you think about automation, it's not only will if somebody's get fire or we will fire somebody we got because we're automating thing. It's actually the thing that we see with automation. The most is you get more efficient.
So the same if our people you know, there's less people in the company. less people can achieve more With Automation and the key with automation always when I sell automation. I like to say smart Automation and not just call it automation because people are worried about automation is say we don't want to automate patching for ICU devices.
Right? But smart automation means let's understand where most of risk is let's understand the operational. So what can happen if this thing if iTunes break if Chrome break on the workstation compared to production one, right?
Those are different question that we need to ask once we understand operation risk. What can go wrong. And what is the the risk itself?
The security is that I'm exposed to because I'm not patching. Automation can play a huge role because there's so many places. You can apply Automation and we call it in quality zero touch automation.
You define it once and it takes care of itself. It basically takes care of making sure that there's no zero they Chrome just released two weeks ago over the weekend or before the weekend the release that critical zero day patch what most organization need to do. They need a person to go spend the time whatever we can test everything package everything and deploy everything if there have automation running.
They don't need this person. The person don't need to spend the weekend. Absolutely, you know you say that a lesson I learned early on in my security career as I was talking to a CIO and I think I was at a bank or a company.
And I made that argument. You know, what? If you would use vulnerability prioritization you do your scan, you know, which ones are the ones you must do first.
Your people wouldn't have to work on weekends. You know, he told me he said I pay them by the week. I don't care if they work weekends.
And and that would you know, that's a bad attitude. Let's face it, right? Yeah burn through your people like that.
I but I I hope You know if there's a silver lining in this economic malaise and stuff that we will see more automation smart automation like you're talking about because that's the key right and and it and the more people use it the more confidence the more they'll use it more exactly and I have actually great customer story that tells the story that they start with automation. They start to trust the system. They see that you know, the demon is not so bad.
It's not really as is frightened as it sounds and they try to trust it more and more. So there's less Change Change Control you just trust the system and there's one more important thing when we talk about the formation. There's what I call Proactive automation.
Those are the patching of chrome. So once you're automate the patching of those low hanging fruit this thing that you can automate easily you don't have to mess with all those large detection report because you're taking care of those before we even detective on ability. Yeah again save you time save your people the need to do those work on a regular basis.
Absolutely and I look I hope you have more stories like to tell us next year. Yeah, right because that'll be a key thing around. Thank you for coming in again.
I hope it won't be a whole year till we talk to you but you know, we do this three days a week. You can always come on and say hello. I will perform much.
All right, we're live in Las Vegas the quality QSC 2022 will be back in just a little bit with some more interesting guessing and insights into the state of security.





