Cybersecurity Insights in Food Manufacturing with Andrew Morrisett and Larry Lawrence at QSC24
Andrew Morrisett and Larry Lawrence share insights from the QSC24 in San Diego, focusing on Midwestern Pet Foods and the pet food industry’s scale. They discuss the critical role of cybersecurity in food manufacturing, emphasizing compliance and the threats from bad actors. The conversation highlights the importance of endpoint security and effective patch management, along with Qualys’ solutions for managing vulnerabilities.
Transcript
This is Textron tv. Hey, everyone. We're back here live at, uh, QSD, uh, QSC, qua Security Conference in San Diego, continuing our day two coverage.
It's like two in the afternoon here, so moving along, but we still got about two, three hours worth of good, good interviews and guests coming on. Let me introduce you two of our next guest. My extreme right is Andrew Marset.
Andrew is with Qualys. He's senior product manager for Endpoint Security. Andrew, welcome.
Thank you. Thanks for being here, man. Yeah.
All right. And to my near right is Larry Lawrence. He's actually Larry Lawrence Jr.
Yep. But we do have a Larry Lawrence ii. You might be on an NFL game on a Sunday near you one day and the next, I don't know, 20 something years or something.
Right. Wink and Hope. Yeah.
You, you and me both. Uh, Larry and Andrew, welcome to Tech Drunk tv. So, uh, Andrew, I mentioned you work with Qualys, right?
You're the endpoint product. Mm-Hmm. Larry, you work with Midwestern Pet Foods.
Midwestern Pet Foods, and you guys are approaching your 100th. We started in business in 1926. Um, we're coming up on our 100 year, and we couldn't do that if we were still behind the times doing the books on pen and paper and, you know, moving forward.
So even though we are a pet food manufacturer, we still have to have today's latest and latest Cyber. Well, look, let me tell you something. The pet food in, so I, I'll tell you a little secret.
1993 mm-Hmm. I was into, I, I had gone to law school. I was a practicing attorney, and I was dabbling in computers, and I was, I knew I didn't wanna do Laura, I was looking for something to do.
A friend of mine wanted to open a pet food store. I said, I'll put some money into it. And we opened a pet food store, and it was in Valley Stream, long Island.
And, um, I'm trying to, it was the pet Gourmet was name, and I learned an awful lot about the pet food and the pet. Oh, yeah. Product, business, doing that, um, didn't make a lot of money, but Never do.
Yeah. Because you couldn't compete with the big box stores. Right.
It was, it was a different world too. But I forgot what the number is, but you probably know this. How big is the pet food and pet, you know, industry in the US it's billions and billions And billions.
It's Quite of billion dollars, Tens of billions. You know? And, and that not just in the us you go to Europe and, and other parts of the world.
It's the same thing. We spare no expense. Yeah.
Well, and you know, just to follow up on some of that, we ship to over 70 countries around the world, our product. So it's not just a US thing, US business. This is an international business that we deal with.
Sure. Is. So anybody who thinks it's some, you know, hazy, lazy kind of operations that has not, you know, especially now when you, it's people grade food and it's, it's all kinds of inspections.
And there's organics and there's, you know, as we were talking off camera sourcing Yes. Ingredients for the supply chain here, which is something we could relate to in security is, is it's a big time job. It is.
And you know, we all, we have to answer to some of the same entities as what your yogurt manufacturers. Absolutely. Or your milk manufacturers, your day dairy farmers.
You know, we have to deal with the FDA, we have to deal with, you know, the inspections and we follow the same line and same rules and regulations that every other food manufacturer out there does. Absolutely. And unfortunately, it also makes you a target.
Of course. I mean, you Know, this is why we can't have nice things in this world, right? Yeah.
It's a lot of bad people. For everyone that wants to sit there and help you along, you know, whether it's purchasing your product, helping work, get out, you always have those one or two people that want to tear you down. They want a piece of what you have.
You know, those are the bad actors out there. And in today's world, if business doesn't follow along those security mindsets, they don't think about those bad actors. They're dooming themselves to failure.
Oh, absolutely. It's only a matter of time, a matter of time. So you guys are presenting kind of on stage right after this.
Mm-Hmm. Unfortunately, most of the people watching this live are not gonna be there. Why don't you give a little preview about what you guys are presenting on?
Well, um, Andrew, since you're first in that session, session, I Wanna let let you go Far. Start, go ahead. Lay, lay, lay the foundation.
Thank you. Lay it down. You've heard from a lot of people you've interviewed so far from the qual side, we wanna obviously expose what we're doing to the world, but not just us talking about our product, but exemplifying it in action.
Right. So I will do the portion of that I am called to duty to do, which is explaining how we're doing things a little bit differently for endpoint security, where we're seeing gaps, how we can help customers, but then again, how does that all come together in reality? Because we spend a lot of time building products, and if we don't, you know, interconnect with where the rubber meets the road, we're just creating things in the background that don't actually help the customers.
And so the presentation is on what we've been working on, what our solution looks like. And then again, more importantly, we're doing a, uh, interview style like this where I'll ask Larry pretty much the same questions, which is good. It's powerful.
Right? And then everybody in the room is, is in Larry's position in terms of I have so much to manage, not enough time, not enough budget. Do I have everything covered?
You know, um, the things that keep you up At night. Yeah. Excuse me.
I'm going to follow up after that about telling some of Midwestern story and journey, and I don't wanna spoil that, even though your audience is getting a preview or sneak peek of Mm-Hmm. What I'm getting ready to talk about in that, uh, keynote session. But, you know, I want to tell our story.
I want to tell the story and the of the journey that we've taken with Qualys to move ourselves into a more secure digital footprint. You know, protecting ourselves, me protecting the company from the bad actors out there. Sure.
So, you know, even though, even though I don't want to give away too much of what I'm going to talk about in that meeting. Well, you can't, you can't be a tease, Larry. You gotta lay something out here for these people Can always watch because it's gonna be posted on the web on Qualys site.
I not all of 'em gets posted. Not At all. I have a, it's not on Texas on, It'll be on, it's not on text.
Strong TV though. You wanna be a star or don't you? Well, You know, let, let's, uh, move this direction.
Go ahead. Uh, because I don't wanna steal my thunder from what I'm No, no, go ahead. Prepared for with Qualys.
But you know, there's a plethora of options that Midwestern pet foods went through with Qualys. And I'm gonna say even with 2020 four's threat report that come out, one of the biggest things that everyone needs to worry about is still one of the same ones that's been out for the past five years is I'm Patched systems. You know, and that's, uh, that's what started, It's longer than five years.
Well, it's been in the top three on the threat report for the past five years. Mm-Hmm. Uh, so that's where our journey started with Qualys.
Um, you know, patching systems is something that becomes very daunting. The more systems you've got, the more geographic area that you have to cover with sales teams, with offices, the harder it becomes to touch each and every one of those systems to get 'em updated and patched. You know, that's something that Quas excels in.
You know, their patch management system is very easy, very simplistic, very quick to go through and implement from any IT manager's, uh, standpoint. You don't need a team of 20 to do an implementation in here. You need one person and a dedicated technical account manager to implement that system and secure yourself and best bang for the buck if you're starting out with securing your systems.
That is step one that I feel that most people need to get in there and do. So Larry, I haven't always been on this side of the camera, you know, I've got 30 years in security. Patching systems has been a problem for all 30 of those years.
As a matter of fact, it's, if you read the Verizon data breach reports and stuff like that, 85% plus of, of, of, uh, incidents are from known vulnerabilities, right. That people patch. Yeah.
Now, the real issue is though, are you just patching as soon as the patches come out? Are you testing those patches before you install them to make sure they don't break nothing? We have to go through a testing.
If not, we wind up in the same issue. CrowdStrike. CrowdStrike.
Yeah. Yeah. So we don't want a dry incident in our business.
So if, and I'm not going to ask you to say anything that'll get you in trouble and don't give up family recipes here. But when you, when you go through that testing phase, before you apply a patch, how many, like what's your average me time to apply that patch from the, when it becomes available? We have, uh, we have a basic, uh, sock plan.
Mm-Hmm. That says that when that patches come out, patch day plus one, it needs to be in our testing environment one Day. That's fantastic.
That's For our testing environment. And then Okay. Testing.
Got it. Then patch, Patch day plus five, all of those critical patches, everything that's deemed four or five need to be in our production environment. So we're patch day plus five for complete systematic rollout.
Hold on. It's really, I don't know if you had a chance to see the keynote this morning, uh, from Marsh McLennan. Did you see that guy?
Uh, I've been in a number of interviews today. I might've missed that one. So he was the keynote and, um, so Marsh McLennan is 150 year old company, a lot of insurance, reinsurance and stuff like that.
This guy was outta MIT if you get a chance and they do post it, check that one out. So they've run these numbers backwards, forwards, six ways from Sunday. Mm-Hmm.
And what he said is the, the threshold for, and you know, and this is for the cybersecurity insurance industries, now using that on what they should charge you for a policy, they say that the threshold is seven days for critical patch, seven days from the time that patch is released. If you are not getting it done within seven days, you're a risk. Yeah.
Or your risk is much higher, and subsequently your premium is gonna be higher. If you're doing it less than seven, you, you're in that green zone. Right.
So plus five is good for you. Right. You're, you're with less than, uh, the seven.
That's a great thing. Right. What are You saying You should check on his insurance premium?
Tell him, tell him you do a little rebate. Well, um, you know, insurance is not my purview. No.
That's Usually over on the c on the CFO side of the house. Right? Yeah.
Mine, Mine is going to be, uh, you know, ensuring that we have the most accurate, the most UpToDate and the most secure systems for our people to work On. Absolutely. Absolutely.
Now, of course, excuse me, not every vulnerability has a patch. Correct. Right.
There's other ways to, there's more than one way to skin the cat. Right? Right.
There's other ways to remediate. What do you guys do around that? 'cause the nice thing about Quas, for instance, is usually when they give you a vulnerability, they tell you, here are ways to mitigate, remediate.
Right. And not all of them are a patch. Maybe I gotta shut that port off at my router, or, you know, we used to call that virtual patching.
Yes. And, um, you know, or there's other things I can do. Yeah.
Communication, patching like that is, you know, something that can happen. It's usually a last ditch effort or a last resort. The Until, until something comes Out, until, until a hard line patch comes out.
Uh, but that's another beautiful thing about the Quala software, is I can run pre patch and post patch jobs as well. Uh, when I schedule out these jobs for deployment, if it is a registry change that needs to be made, or registry keys need to be added, you add those into the pre or the post patch job. And as it's going through and doing all of those patches that it does have a quote unquote patch for, you can add those registry keys or you can make those registry changes.
And that's a very good thing to have happen. Now, again, there's always that one or two off that's out there. Uh, one that I can think of is the Curl Overflow right now that's very predominant.
You know, that's a manual update within the system. That's something that you can't quite kick Off. Automate.
Yeah. So, you know, I'm not gonna say that Qua solution is going to be the end all be all for never having to touch individual systems. I would be lying at that point.
Well, No one would believe you. Yeah, exactly. Uh, quite honestly, right?
'cause nothing is like that. Nothing. 5% that's out there, it's a perfect solution and it's a good first step.
It's something that needs to be in your primary security stack. I think that's a good place to end this right there, man. Larry, thank you.
Where are you from, by the way? I'm from Evansville, Indiana, where we're heading With that Indiana. All right.
Very cool. I could tell from that New York accent. Nice to meet you, Andrew.
Pleasure having you, man. Good luck on there. Keep up the great work at Midwest Pet Food.
Right? I definitely will. All right, man, keep doing what you do.
We're live, we're in San Diego. We're gonna have another guest here in a minute. You're watching Techstrong TV.