Prioritizing Resilience in Cybersecurity with Absolute Security’s Christy Wyatt at RSA Conference 2024
Christy Wyatt, CEO of Absolute Security, discusses the shift towards resilience in cybersecurity, emphasizing the importance of focusing on the unexpected and maintaining continuity of operations. Absolute’s unique approach involves embedding security solutions directly into the hardware of devices, enabling proactive monitoring and automated repair of security controls. Wyatt highlights the challenges posed by increasing complexity in IT environments and the need for organizations to prioritize resilience alongside traditional prevention and detection measures, especially in the face of talent shortages and evolving regulatory landscapes.
Transcript
This is Techron tv. Hi everybody. Mitch Ashley here at RSAC 2024 in San Francisco.
More conversations about security, cybersecurity. Um, we're gonna be talking about resilience, which is a great topic 'cause I had a chance to do some research in this area end of last year. Um, and I think it's, you know, something we're talking a lot more about.
Great pleasure being joined by Kristi W who is CEO of absolute software. Absolute security now. But thank you.
I'm sorry. Absolute security. No, that's a, that's it's a big name change for us.
That's My own. Yeah, that's, that's the old me kicking in there. Out outta hat habit.
Well, tell us a little bit if somebody doesn't know absolute Security. Absolutely. Um, so we're very unique.
We're an endpoint security vendor. Um, we're the only cybersecurity platform that's actually embedded in the hardware of over a half a billion devices. So, um, with that unique position, we actually have the opportunity to look at a device from within.
And so mm-hmm, we look at, you know, are your applications installed? Are they running, are they healthy? We have the ability to fix them and reinstall them, repair them.
So we focus on really building resilience into security solutions from visibility, control, connection. Um, we have some really cool os restore capabilities that we're, uh, demonstrating this week. So, so that's a little bit about absolute Amazing.
You know, you think about, we think about virtualizing everything. Well, at some point rubber meets the road, right? And you got security all the way down to the hardware to truly have kind of full spectrum of security.
I mean, I, I think for a long time we've been talking about why a lot of the value is up in the cloud and let's move the data to the cloud. And that's certainly true, but there is a lot that happens where the hands could touch the keyboard, and especially when we sent all of our employees to work from home. And so there's a lot of things that worked really well when you were sitting on a campus network or in a building that didn't work so well when people were remote.
And so we've always sort of viewed that that security has to start with the user. Um, and where there are spaces where software is either disconnected from the hardware, where we can improve the performance, improve the user experience, improve the overall security posture of that device, that's really sort of where we work. And I know at this show, everybody wants to talk about ai.
Um, you know, my view is, is that ai, you know, kind of shifts a lot more of the value back to the end point. In some ways. As you have more intelligent models running on these devices, there's going to be more, um, data created.
There's gonna be more values actually sitting on the device that may or may not have made it back to the cloud. And so there is a lot of value in there in making sure that we're protect that user, their identity and, and their user experience. I'm glad you mentioned that.
'cause there is a, you know, people thinking about AI at the edge, pushing that to the edge. Okay, now we're talking about a whole nother security concern, just like other kinds of processing. I mentioned resilience, talking about that.
Um, you know, so my, in my conceptualizing my definition is being able to handle the unexpected, not just recovering from the expected, right? And being able to have some continuity of providing whatever capability that is. How do you think about resilience from your standpoint?
So, So we think about resilience in almost every step, right? It sort of starts with, there is a lot of, a lot of the talk in our industry is focused around prevention and detection. Um, and that's where a lot of the sexy stuff is, right?
People wanna talk about bad actors and, uh, nation state. And so, you know, there is a lot of money being spent on controls. We, we publish research every year that actually measures how well of tho are those controls actually working.
So what I mean by that is if I'm a CISO and I said, I know there's a bad thing and I know what application I need to buy to prevent these bad things from happening. I've purchased it, I've handed it to it, we've installed it on a hundred percent of our devices, and it's working flawlessly. So that's what we call a hundred percent of, of sort of resilience score.
Our research shows that actually on average within an organization, it's about 24%, um, is not compliant with your security posture. So why is that? That is because you have probably at least a dozen security applications running on these devices.
It's MFA, it's Tanium in CrowdStrike and Microsoft and all of these things. As time has gone on, we've added more and more and more you have complexity where you have complexity, you start to get decay, something misses an update, something unencrypt, and then doesn't re-encrypt or something kind of gets tampered with by the user. So you slowly start to see your controls kind of degrade over time.
Um, and it's not incredibly visible inside the organization. You may or may not notice, you may or may have gotten an alert from something that says that thing stopped working. What the CISO needs to know is that, you know, a quarter of your devices are unprotected.
Yeah. And that's a big number, right? And we've measured it in our research on an app by app level.
We've measured it kind of on a device level. So what do we do, right? We, we've created kind of automation leveraging this component within the hardware where if we see that something has stopped working, we will repair it, we'll reconfigure it if we have to, we'll redownload it and reinstall it.
Um, we think about resilience of the network connection. So we like to talk about things like comply to connect, right? How do we determine compliance so that we know it's safe to connect from a remote location?
Um, how do we make that network connectivity or net network connection in a zero trust world, you know, even more resilient. So if you're in a place where you're losing lots of packets, how do we heal that connection? And then some of the more interesting stuff right now is, let's say you're in a breach.
5,000 people got hit, they're disconnected from the enterprise. Now how do you get those users back up online? And when I ask CISOs this question, they say, well, it's really easy.
We just move all the work over to these people over here, or to these systems over here, and the business carries on. And I'm like, okay, but what about the 5,000 people whose device stopped working? Um, what, what they usually say is, well, we tell them to unplug it, put it in a FedEx box, send it back to us, or bring it in.
Next time they come to the office and it will fix it. And that's why you see breaches take weeks, months, you know, quarters, years to, to actually get things back, to get users back up and running from within the hardware. We can make devices resilient.
We can, we can heal the device and actually get it back up and running to a safe state and back into production, um, remotely. Wh why do you think people live with that as a solution to say, just ship in 25% of our users' computers back into the office and hopefully nobody plugs 'em into the network? I, I think CISOs and CIOs today are fighting a losing battle.
I talked about the complexity and there's all sorts of, uh, passionate debate about whose faults it is. I think there's some folks that would say vendors need to write better software so that things don't break. Um, you know, I think that there's a, there's a reality.
If you've written software, you usually have a test matrix, right? You test the combinations of things that could go wrong. So if you're thinking about a device that's sitting in someone's living room, you probably have two, 300 different versions of Windows 10 with different patches and configurations.
You probably have about a hundred different applications running on that device, each with their own state of patching and configuration. You have your security controls, you have your network configuration, you have your routers, you have your, so the, the, the matrix that you would have to contemplate for flawless execution is inconceivable. It's a very problem for ai.
But, And, and even then, you still wouldn't catch everything And you wouldn't, I mean, folks like to say you could get to zero, but at what cost? I don't know that you could get to zero. I don't know that we, we could contemplate.
So then, so then what you have to assume that things will get through and how do you snap back and recover? And that's really sort of what we're focused on, um, because I think the odds are stacked against them. And now, if you're the ciso, I don't think that there's a, um, comfort so much as there's a lack of visibility.
It's difficult to get an accurate read on what's really working and what's not really working. That's why we do the research and the reporting that we do. Um, it's difficult to fix it because we have a talent shortage in our industry.
And so there's only so many people that can put their hands on a keyboard. There's a time lag, there's logistics issues. I mean, it is a, it is a really, really hard problem.
So when you talk at events like this, there's a lot of people that wanna say, you know, let's talk about the shiny objects and all the fun stuff that's going on. And then behind the curtain they'll say, but you know what? I really spend my time on compliance, making sure my controls are installed and working really well.
Um, and that's, it's, it's tough. It's interesting. One of the things you made me kinda think of is, you know, we've invested so much in defense, we now recognize the value of response when, 'cause things do and always will happen, right?
We know it's just a fact. But a better, or, or the next stage of response is resilience, right? So we don't have to take all the manual efforts that we've traditionally done, and some or most, or, you know, majority of things could actually be corrected in the field or at the point of where that occurred.
That's, that's another way to look at resilience, right? I, I think when, and I was having this discussion with an analyst this morning, when we ask people what is the cost of a breach? Or, you know, we, we don't take our tabletop exercises far enough.
You, when you think about the big breaches like Maersk or Clorox or you know, the ones that we've all read about in the newspaper, we, we estimate, you know, was there ransom? Was there data loss? Was there, how long was the system down?
But we don't actually line that out over the entire spectrum of time. Mm-Hmm. If you had to put in all of the cost of shipping and support and reconfiguration and putting things back in, and the amount of time that's done.
Somebody, when I was having this conversation a few days ago, somebody said to me, the casino two blocks down from their house has been out of, has been down for three weeks. And I'm thinking, I'm not in the casino business, but I, I know that's gotta hurt. Right?
And, and not making Get much money. So I I I think that, um, people try to think, see these as two sides of the coin. Um, cyber, uh, security and cyber resilience.
I actually think they're one and the same. I, I think that when you take a look at the complete picture of risk, it's not just the risk of data loss, it's the risk of the business not functioning. And so you hear stories about grocery stores that can't take orders or pay their employees or drug pharmacies that can't do prescriptions.
I mean, these are happening day in, day in day and day. And it's not, it's not just because the, there was a virus and then somebody got it out. It's because it just takes a really long time to get everything back up and running.
And I think that's the critical focus of resilience. Okay. Kind of going back to the hardware level of things, do you think the use increasing use of AI chips, whether they're, you know, an apple manufacturer or intel or they're invidia, you know, that's gonna continue to advance.
Does that change things for you onboard when there's onboard AI chips versus more Traditional? I do think it shifts some of the value equation more back to the end point balances a little bit more. I don't think it's a binary thing, but you can't assume that there is a hundred percent of the data on that device has made it back to the cloud.
Um, when we think about how we restore something, can you restore the model and everything it learned? Can you restore sort of the data? Can you, um, if somebody got a hold of your device and they got a hold of your digital twin, what would that look like?
I mean, so there's all sorts of things that we're just sort of starting to contemplate. If you imagine how many different, um, models you may have in an environment and how they communicate with one another, there's, there's all sorts of new, uh, risk planes that we haven't even thought about. And, and yeah, I think a lot of that, a lot of that's certainly gonna happen in the cloud, but I think a lot of that is also going to happen, um, on endpoint devices in people's homes.
And I also think it's going to happen in the consumer world. So it's one thing when you're in an IT managed environment, it's another thing when we're talking about the consumer in their home, and now we're talking about a whole other level of, of what happens when you click on that bad email. Right.
You know, it's, it's so interesting to think about where we are now, what we can or could do. Digital twins, you know, desktop or, you know, uh, red blue teaming. Yeah.
Using some of those technologies as well as AI and different hardware profiles may offer better protections or more value, which means the devices at greater risk. I, I, I hear about, you know, adding more AI functionality to our smartphone, like, okay, but at what cost? What am I now putting out there even greater than my current personal information that's on that device?
It is A very interesting process I see going on within a lot of different organizations where every, whether it's productivity or security or media or, I mean, literally every form of application is asking, what could I do differently with ai? It's very tempting and it's very exciting. Um, and as we're going through this learning process as an industry, right, we, there's a return on investment discussion about when is the, the tipping point in each one of these areas where the return or the value outweighs the risk.
And it's not just the, the digital risk, um, or the security risk, but there's also gonna be an economic impact if you think about it, if each one of these applications has their sidecar or copilot or whatever it is, um, and there's just a little bit more power required or a little bit more processing, or there's a smaller per unit license, or, you know, there's a, there's a little bit more economic impact. I think organizations sit back and go, wow. Like that's a, so if someone was, uh, sharing within our organization that one of our vendors said, uh, you know, oh, the vendor's really great, they're gonna give this to us for this first year with like this zero price or this very, very low cost.
And I thought, and, and, and then how many zeros do we add a year from now? Right? I, I think we have to be thinking down the road and go and saying, where do we wanna start?
Let's take a thoughtful approach in terms of how we work through this, make sure that we're evolving and maturing our risk models around it, and really planning the economic impact on organizations as well. Interesting. Well, you kind of set up my, my last question was when we come back next year to RSAC, if, if we don't get a chance to talk between now and then, what do you think the, what might we be talking about a year from now that either is a continuation, advancing or maybe a new conversation we're starting, Uh, across ai, you mean?
And so AI or security or both? Sure. I, I think that this year we're seeing a glimmer of what's possible.
Um, and I think some of the interesting intersections that I've seen over this past week are where different industries touch touch corners. So I'll give you an example. If you look at what's going on in film and media and the impact of, of producing a film using AI and, and generative AI specifically, and why that's exciting and powerful, and all the complexities around who owns what IP and who owns it's, you know, it's fascinating.
And then you flip it and you say, okay, so if I can do really, really high quality, maybe not real time production yet, but but really amazing quality digital fakes, what is that going to mean on the security side, right? And then who has the legal responsibility? I mean, we've already, we spent a lot of time during this, um, RSA talking about the personal responsibility and liability for the ciso.
We had actually William Barr come in, in on, on a Monday night and do an event with us. And, um, there's just so much shifting in the regulatory landscape and now add AI into that conversation, not just, you know, the different kinds of risk and who's, who owns, who owns the risk, who owns the responsibility, whose fault was it? I mean, there's all sorts of different interesting places where this could take a right hand turn.
And so we're just at the very, very early, as much as the conversation has been very loud this week, we're really just seeing a glimmer of what people think is possible. Um, it'll be interesting to see what the reality is as, as it unfolds. Good.
I'll be interested. Hopefully we get to have that conversation. Yeah, I'd love to see where it's happening.
Then, uh, Christy, well, uh, Wyatt, it's been a, a fascinating conversation with you. And, uh, thank you so much for advancing the conversation with us, uh, with, uh, you and the absolute security team, and we look forward to talking with you more. Thanks for having us.
Absolutely. Christy Wyatt from, uh, a CEO of absolute Security, another great conversation. I keep telling you, we have amazing people, amazing conversations here at RSAC.
It's, it happens in the sessions, in the talks, and it happens here on Textron tv. So we thank you for joining us. Got more great interviews coming up.
Uh, if you're hanging with us, great. You join us tomorrow on Thursday. We'll have some other interviews for you too.