Beatrice Sirchis on Managing Attack Surfaces in Banking | Qualys QSC23
Beatrice Sirchis, VP of application security at IDBNY, provides insights into the challenges and proactive strategies associated with attack surface management in the banking sector. Beatrice emphasizes the daily threat of attacks, the importance of maintaining awareness of the bank’s internet posture, and the need for continuous visibility over connected assets.
Transcript
This is Textron tv. Hello. And we're back at the Quala Security Conference Americas, and we're with Beatriz Circus, who's vice president of application security for I-D-V-N-Y.
And we're talking about attack surface management and how to maybe contain that attack surface a little bit so it becomes more manageable. Beatrice, welcome the shop. Yeah.
So, uh, being a bank, um, attacks are, um, uh, a daily issue. Um, it's not new, so we need to be able to know, uh, that our attack surface is maintained under a limit that we defined. Uh, and that would begin with knowing what is our internet posture, uh, what are the assets that are connected to the internet, and what is their security posture?
For this, we are using, uh, quality system, uh, that is continuously monitoring all the assets that are, uh, connected or somehow connecting to the internet. Uh, that is the basis. Uh, after that, those assets are automatically scanned for vulnerabilities, and we prioritize those assets that are related to the critical business applications.
Uh, besides that, anything that is related to external assets, we prioritize the patching, uh, into a very effective manner in order to ensure that those assets are patched or remediated somehow else, uh, before an attacker gets access to them. Well, let me ask an obvious question because I've heard this attack surface management issue for some time, but how does something get connected in the first place that cybersecurity folks don't know about? Is, are they all different business units doing their own thing?
Uh, 'cause it seems like a lot of times you guys are operating in the dark. Uh, it seems like this, um, not until we are using, uh, quality scanners. So we are using actually the internet, uh, quality scanner that is scanning anything that is related to IDB into the internet, and it will, uh, automatically notify us anything that is new.
On top of that, anything that would, is new would be automatically, uh, scanned for vulnerabilities, and we would get, uh, a, a note if there is any critical vulnerability that might be exploited. So we are not in dark. We have, uh, we have the scanners that are notifying us.
Um, if anything is happening, A lot of these systems are regularly updated. Is this essentially a continuous process? Because if I update my application, it's got all different components and I need to find out whether they're vulnerable or not, right?
Yeah, applications are one of the most challenging, uh, eh topics. Uh, and the reason for that is that some of those applications are business, uh, application that were developed way, uh, way ago. So they might be outdated from a perspective of third party software, for example, Java or T net, and they only support some outdated versions.
So we have to know that, uh, eh, that if we have to know to identify the, the application, um, and to know what are the vulnerabilities related to the application, and be able to coordinate, uh, in a, in a timely manner, uh, with the vendors and see what versions we are able to, uh, upgrade if they're supported by the application and if not, uh, to provide other defense layers, uh, you know, like the defense in depth, uh, in order to, uh, defend those applications. Are the attacks you're seeing increasing, I mean, I know they're increasing in volume, but are they becoming more sophisticated? They do, uh, they are more sophisticated in a, in a manner that, uh, uh, old vulnerabilities that we thought they were forgotten and they all of the sudden are used or, uh, are exploited.
Uh, besides that, we are, we are seeing that, um, many of the attacks are going on the basics. They are used, they are leveraging basic security features that might have not been, uh, eh, defended or, uh, correctly configured, and those are exploited. So our approach is first of all, to ensure that the basic base baseline is covered, and then that we have a continuous, uh, visibility and dynamic visibility over the assets that are externally accessible and over the vulnerabilities that are continuously happening.
We are at a Qualys conference, and you're clearly a Quass customer. Why did you choose Qualys? What was it that attracted you to the core capabilities?
Oh, that's a very good question. So there are, there are a few, uh, top vulnerability management platforms. Uh, we defined a few, uh, mandatory requirements, uh, for the platform that we select.
Uh, these requirements start with the dynamic visibility, go over the internet facing, um, uh, management, uh, from the perspective of vulnerability, go over the, uh, ability to identify automatically end of life, end of support, or anything that is related to software, uh, based on the assets, uh, and also an integration with a platform that we can manage the tickets for remediation in, in an effective manner. So having those requirements, we made a comparison between the, uh, best of breed, uh, vulnerability platforms, uh, and we selected, uh, qualities and actually we did that almost five years ago, and we are very happy with that. There's a lot of talk here today about risk management, and a lot of that conversation comes back to how do we communicate risks to the business and how do we communicate with the rest of it?
What is your sense of the maturity of risk management these days and what, you know, what issues do you guys run into? Uh, this is, this is really a very challenging topic, uh, and we are continuously dealing and thinking how to better, uh, communicate the risk, uh, to, uh, the different stakeholders. Um, we are using the QUAS dashboards, uh, in order to communicate the, the risk, um, to senior management, which prefer to see summarized numbers and make sure that we are staying into the thresholds that are defined, for example, for the key risk indicators.
Uh, but we are using dashboards that are more detailed for our colleagues in risk management or for our colleagues in the internal audit, or even the it, um, using the very same platform that is automatically updated and continuously updated, ensures that the risk indicators that we defined, they are up to date, uh, and they are up to date to the current environment and the current infrastructure. Um, so this is how we ensure that these indicators are, uh, showcasing an updated, uh, status for, for the bank. And also, um, the language that we are, um, using is slightly different between the tasks, different stakeholders, uh, but they are all based on the same data.
So there will be no, um, discrepancy between what we are reporting to one stakeholder, uh, as opposed to what we are reporting to another. And as opposed to what we are dealing in order to make sure, uh, we defend the bank properly, There is a chronic shortage of cybersecurity talent. The job is inherently stressful.
What's your best advice to folks about how to cope with all that? Um, my best advice is to love the job, uh, and to continuously learn. Um, I think, um, anything, it's easier if you love what you do and, uh, continuously learning, um, eh, which in cybersecurity is, uh, mandatory requirement, uh, whatever was appropriate a year ago, it's completely different today.
So continuously learning, uh, it's, uh, it's a must. Speaking of continuously learning, and different than a year ago, everybody's talking about ai, what's your take on how AI might be applied to cybersecurity? Will the machine save us from ourselves?
Uh, well, ai, it's a very interesting idea, and it's quite not new. I mean, we heard about AI systems in so many, um, in so many fields. Um, I think today it's much more mature than in the past.
Um, I still feel like for taking lifesaving, uh, uh, decisions, I would prefer reviewing, uh, the ai, uh, suggestions before letting this happen. Mm-Hmm. Um, for example, there are, uh, a idea of in intrusion detection or intrusion prevention systems that might be based on ai.
Uh, and they might automatically shut down some system because of, uh, uh, finding, uh, I would still feel more sure to review this before it's happening. It seems like everybody wants to review it too. 'cause the, it and the developer folks are a little, shall we say, antsy about somebody automatically applying a patch.
So how do we kind of create a workflow that works for everybody, that doesn't result in everybody kind of waiting for weeks to go by, but you know, we can get something done in maybe days and hours. Yeah, that, that's, that's a very valid question. So, um, it's, it's really a really, um, a fundamental difference between applying a patch automatically or not, uh, and shutting down systems.
Um, and I know that applying patches, uh, we, we did consider where for which system we can define an automatic patching and for which systems we will need to review, not because we don't trust the patch, but because they must impact, uh, some applications that might just not work after that. So it's, um, it's a risk management, uh, decision. Mm-Hmm.
Um, automatic procedures can be done and are, are done, uh, on environments that we know, uh, it's safe to be done and they will not cause more damage than benefits. I don't know how long you've been at the bank, but let me ask you this. What do you know now that you wish you knew when you first started doing this job?
Um, first of all, no, that is a very, very, uh, important question. Uh, first of all, knowing all the assets that we have to defend, uh, nobody can defend anything if it doesn't know what is the scope. So having an updated asset management that is, um, a mandatory requirement in order to be able to even say we are, uh, defending, um, and that is an ongoing effort.
Uh, and we are now in a, in a position that we can say, we did this. We know what is happening. Anything that would happen without even our knowledge, our systems will notify us.
So we are today in that position that we can be sure that any initiative from someone to connect anything to the network will be a, a setting an alert that we, you are going to, to get, uh, right away. There was once a great German emperor who said, he who defends everything, defends nothing. So how do you prioritize what to defend?
That is very true. We cannot defend everything. So first step to prioritize is to know what are the crown jewels, uh, and the crown jewels that we defined, uh, are the business critical systems and also the it and the cybersecurity systems that are mandatory.
Those, those being defined. We know that this is what we have to do. Anything else, it's step two.
So of course we cannot, we don't even try to patch everything. Uh, but we have to know what is the status, what are the assets, uh, to have the prioritization and to focus on the crown jewels. All right, folks.
You heard it here. If you don't know where the crown jewels are, you're in a lot of trouble. So start there and work your way out, Beatrice.
Thanks from stopping by. Thank you.





