Social Network For Security Executives: Network, Learn & Collaborate
In our recent CISO Platform Fireside chat in association with FireCompass, we had Matthew Rosenquist, CISO Eclipz, and Bikash Barai, Co-Founder, FireCompass, who discussed a bunch of things related to the cybersecurity practices that are gaining momentum and about what the future holds.
Matthew - What we are witnessing now is quite unprecedented. There is a tremendous dependence on technology. With the evolution of the Internet of things and AI, more and more people and businesses are getting dependent on the internet. By 2021, 20 billion devices will be online. Technology is not about information only, it manifests to control things in people’s lives. For example in the automotive industry, you can have connected cars, and if it’s not secure enough, a hacker can build ransomware and demand money when you are trying to get home. This takes us to the next trend that is absolutely related to this one, i.e, the nature of the threat.
Threats are coming from say nation-state actors hacking airplanes to cause life-threatening damage. The automotive industry, the airline industry is going through this tremendous time to get on making autonomous cars and planes. But we are not ready for it, considering anyone can hack into an airplane and put traveler’s safety at risk.
Bikash - We are also dealing with this other kind of threat which is much simpler in nature. This is happening because of misconfiguration or because organizations are easy targets. In general, hackers will look for easy targets, and any organization that has open RDP ports or say easy passwords will fall prey. This has been one of the burning issues this year.
Also, Organizations are mostly not aware of their assets, about the fact that teams work in silos. And this creates invisibility, which in turn is making organizations vulnerable to attacks. While many people think the cloud is insecure, the truth of the matter is that the cloud is scalable and scales on how securely you build it.
Matthew - Risk Management is another thing that is always business decisions when it comes to cybersecurity. Which means you are managing risk and not eliminating them. So presently what is necessary is to understand how to manage risk consistently. And to some level, this process is taking shape and organizations are becoming aware of the imminent need of managing risk.
Matthew - For an optimal level of security, one needs to find a balance between managing the risk, the cost, and the friction that security will bring. Organizations are about people. So having technology will not do the trick alone. People need to be in line with the technology. Whenever new security practice is put out in place, friction will emerge. There needs to be a proper balance so that the friction does not make the exercise fail. For example, if you make people keep complicated passwords and change them 4 times a week, it won’t work.
What one needs to do is - Find the goals then look for technology, look at your people, and finally build a process. This has to be teamwork. Moreover, the knowledge that security can never be a point in time. So whatever your process is, needs to be maintained.
Bikash - In terms of building organizational alignment, I always ask the organizations to have a cybersecurity drill and imagine a situation where you might face a breach of security.
In such a drill you make the CEO/COO and HODs talk about what will happen if they fall in this soup and that’s when things come out about how unprepared the teams are.
Mostly after such a thing, people come out with playbooks. And in most cases, they also become more serious about this scenario and invest in security.
Matthew - Well as I see it people are trying to constantly evaluate their security. The thing is you can’t look for vulnerable ones and close them, then you are an easy target. People now realize that Red teaming etc is a much better approach. So having a manual red team to constantly attack your systems to expose your vulnerabilities is not a scalable model.
That’s where these tools come into people like Continuous Automated Red Teaming. These platforms are scalable and have much better insights.
What do you think that concerns people about this in the industry?
Bikash - Well most organizations are very concerned about shadow IT and other DEVop security etc. I am a big believer in continuous security models, continuous testing, etc. I am a big believer in Purple teaming. And see a great future for cybersecurity in it.
Matthew and Bikash signed off with some predictions for the future in cybersecurity. One of them was that the cybercriminals will start going after digital currencies considering more and more countries are going towards digital currency, like the Bahamas and China. Breaches in medical facilities will increase considering the previous year has experienced one of the worst health crisis in a century.