A CISO’s Journey From On-Prem, Cloud to Software Delivery – CISO Talk EP 34
Whether on-premises, cloud-based or cloud-native, the basics of securing digital systems are similar. In this episode of CISO Talk, Chuck Kesler, CISO at Pendo.io, shares his journey from a sysadmin, IT leader and CISO at Duke University Health System and his CISO role today with Pendo.io. Chuck works with software leaders and developers to secure software pipelines, remote development, infrastructure-as-software, adopt new development technologies and practices and more. Chuck discusses what he’s learned from bringing traditional security skills such as identity, device security and zero-trust (just to name a few) into a business which natively began in the cloud and never had a private data center.
Transcript
Hey, welcome everybody and welcome back to another episode of siso talk which Ashley CTO with Textron group and principal was text wrong research and Jennifer JJ Manila and my co-host with the show Jennifer JJ, whatever. I'm calling you today welcome. That's again.
How are you doing? I'm great. I think I decided earlier today that I'm gonna be Diana through Diana through this day.
Yes at least till 8:00 8:00 at night. Nothing like mixing it up. Okay.
All right, Diana and I just hey we this this is you know, every episode is special. This one I think is even a little extra special because of our guest and someone that you've known for a long time Chuck Kessler. I'll let you introduce Chuck and then he can tell us a little bit more about himself.
You want to just start out JJ with your connection with Chuck. I've known. shot before we have the On so I can tell you exactly how long we've known each other but I'm gonna start now and Rewind and then Chuck ask you to kind of feel a little bit here.
So right now you're the sea so at pendo before that and I think when we met through Issa you were busy so it Duke health system and then I know before that we've had some conversations about some of the security work you're doing is a consultant with saman tech and some of the prior things there. So do you want to kind of move us back forward through that progression talk about how you ended up where you are now? Yeah.
Thanks JJ and thanks Mitch really appreciate the invitation to be here today. Hopefully I can do this podcast Justice. I haven't done many of these so I apologize for you know, I'm gonna try to be interesting.
I don't know if I can be. Well, I'll do you already are you're good. Great.
Yeah, so JJ. Yeah, I mean, I don't know exactly how long we've known each other. It's more than 10 years.
I'm just gonna leave it at that. So, you know, that's that's a reasonable amount of time. Yeah.
I joined kindo about four four and a half years ago prior to pindos to see so for Duke University Health System for I think it was seven years and prior to that. I spent about six years working with semantics advisory Services Consulting practice and I go back further than that. I actually started my career more in the technical side as a systems administrator moving up into it management and eventually security.
So okay, you know 30 plus years actually doing things in Tech in general and it's been you know, an interesting journey. I like to point out oftentimes that I've been around connected to the internet since the mid 80s before most people even have to clue what the internet was. I think they're very first time I connected to the internet was probably about 1986 from a little Unix mini computer sitting in a university office.
Um, you know just connecting with other folks at other universities. That was a lot of fun back then but to see it all, you know, see all this technology grow connect the entire world and then, you know security becoming a theme that we had to worry about, you know in the early days like yeah, you know, people are just playing around but you know this became a very serious thing obviously once the rest of the world was connected and and we started using this technology for taking care of patients. For example, when I was at Duke, you know, we have that entire Enterprise connected everything from the MR MRI machines to the ivy pumps to you know, all the things that are helping to diagnose, you know, the illnesses that our patients are, you know dealing with so, you know, obviously security was a huge huge concern for reason why they brought me in there, you know, it was an interesting transition going from that industry and Healthcare, you know, again taking care of millions of patients per year, you know, we regulated environment to a very fast growing software Services Company.
Nintendo when I joined pindo four and a half years ago again, we're about a 250 person company had already grown quite a bit pindo at that point I think was right at five years old. So we're hitting our 10 year anniversary this year, but we grew from you know, five people to 250 when I joined in that first five years and now we're close to 900 people now, so, you know, we're considered one of those Tech unicorns and it's a very different environment than working at a place like Duke Health where again very large organization taking care of patients a lot of you know, regulatory concerns a lot of traditional it infrastructure to a fully Cloud native company that was you know, never as had a rack of server sitting in a closet or anything like that everything. We've always done.
It's been sitting in the cloud and again a very software development oriented organization. We have to you know, move and adapt to the market very quickly. We're deploying new versions of our software multiple times per week.
If you know something very different again, from what I experienced you so that was definitely an interesting transition to have to you know, kind of do a mineshaft to you know, from a very slow. Yeah, very slow moving organization. The one that moves very quickly to adapt and take advantage of opportunities in the market and the word agile comes to mind.
Yeah, exactly. It's kind of a SAS cloud-based. Yeah software company, I would imagine to and this is something that JJ and I taught frequently talk about the intersection of security software and software development.
You have the added factor of kind of mobile, right your Maps, you know are about measuring mobile not to go too much independent. We don't have to do that. But you know, you're you yourself are dealing with customers in the mobile World which introduces I would imagine some unique considerations, especially given you came up through it and probably had BYOD in Delta with all those issues now you're creating that software coming into those Networks.
Yeah, you know so it's interesting window. Yeah, so our platform we started as a webcentric platform. So helping our customers instrument their web applications to understand user Journeys through those applications.
But over time we realized that hey yes mobile is part of that user user Journey as well. So pindo actually acquired a company that had a complimentary product at the time. This was roughly.
I think it was 2018 or so. So it was actually before I arrived at pindo or shortly before and you know, since we've actually kind of redeveloped that entire platform but you know, essentially it's an SDK that gets embedded into our customers applications. It helps instrument those applications.
So, you know, the interesting aspect of that is, you know, you kind of think about web applications and mobile applications and how they're different. Yeah. I mean with the web application it is a very Dynamic thing, you know again, we can deploy multiple versions of that in a day with a Application on the other hand, it is an app that gets built and deployed into an app store.
And so the customers then, you know update from the App Store, you know, maybe they update as new of new versions that application become available. But in many cases they don't right, you know, they turned a lot of people actually don't turn on auto updates, right? So that application might live on their device many many, you know weeks months years without ever actually being updated.
So our software is going into those customer applications. So, you know, if you think about our web application our agent because of the web application again, we can update that multiple times for week in the mobile world. We have an SDK that is going to get embedded into that customer application and we don't know when it's gonna get updated.
So, you know, we do have to think about you know, hey, we while we have a lot of processes to try to prevent security vulnerabilities in our own product, you know, if we do identify one in our agent in very quickly, correct it because all we have to do is deploy a new version with those mobile sdks. Like yeah, that's a little bit more of a difficult challenge because those those applications with that embedded SDK can live on a user device for a much longer period of time so it definitely introduces some different sets of challenges where there's updates are a lot more out of your control in the you know in the hands of a consumer that may or may not actually care about updating that application. I have a couple questions because you you know, you did come from a highly on-prem.
Heavy on-prem environment with a lot of biomedical devices and it's not a small help system. So it was a large volume of stuff you were dealing with there. I think we made a joke about A wireless or Internet connected wheelchair at some point and I think Chuck said no we actually have but I'm kind of curious mood, you know, moving from that to some place like pindo.
That's or any environment. That's you know, Cloud native and you don't have the on-prem infrastructure as a c. So what has been your transition what's changed for you and your process in terms of like how you create or update policies the Cadence with which that might happen and maybe Who's involved in that?
As you what what all have you seen shift or stay the same? Yeah, it's a very interesting question. I mean, I actually think in many ways it simplifies the world for me because there are a lot of things that I had to worry about from an infrastructure perspective.
Now that are just taking care of for me, you know, all of our services live out in the cloud. So actually I don't care where my end users are at. They could be sitting here at the office.
They could be sitting at home. They could be sitting in a coffee shop or a hotel. You know, I have to design with the assumption that my you know, my my developers could be anywhere in the world versus you know, that more infrastructure-centric view of the world where okay.
Yes. We're going to assume everybody is on-prem in their working and you know in an office or you know hospital room or operating room or something of that nature. So again, it's kind of heading down the zero trust world around here a little bit, I guess with this part of the discussion, but you know from an architectural perspective just to say look I'm not going to trust that, you know this network that the device is connected to just because it comes from this particular.
Working when to trust any of it. I'm going to base that trust more on the identity the authorization and authentication process of the user connecting to the application. This is out in the cloud and I might look at the device that is coming from and say okay is this a managed device?
Yes, that's that's part of the equation as well. But again in that that yeah that more traditional Network infrastructure World it definitely, you know, we have the part on the outside soft and chewy on the inside even though we had done a lot of work in terms of segmenting that Network as JJ. I know you work on a couple of projects with us.
So, you know how complicated that network was and how difficult was to you know, Adam and the network of that scale to actually manage segmentation in a meaningful way. Yeah versus just again assuming that look, you know, I have applications deployed in a public Cloud that are going to be connected to you know, basically through you know. That's that internet connection that the person is connected to so I'm not going to trust just because you're coming from a particular IP address.
I'm going to trust more on the authentication, you know, again the mf8 obviously for everything and then in certain cases again looking at device trust is this a managed device that the connections coming from so for me, it's made that that zero trust aspect of things which is just more of a natural motion for us. I mean, it's kind of how we build, you know built the Enterprise and when I look at a company again, like pendo that Russia quickly we were able to do that because we didn't have to invest heavily in building all this infrastructure up front again. We were consuming Cloud resources as we scale.
So we didn't have to go get again Capital to build big Network for structure, you know racks the servers and things like that. We were just paying as our customer base career and we gave everybody a laptop and we gave him a good Network to connect to you. So, you know, it allowed us again to grow a company much more quickly.
That way so yeah, I mean, I think that if you're building a new company today this sort of a natural motion to to go down that Row versus you know, the more traditional way of having to build all that infrastructure like you would have in the past. And check you mentioned. You know developers could be working from anywhere you mentioned, you know, the managed devices and possibly unmanaged being the other kind of BYOD model.
Not not talking about, you know, your your current environment, but just your feelings is a seeso and throughout your history and working with organizations. How do you kind of way the pros and cons of BYOD models and whether you're going to let people access things from a personal device and what to what degree and what things where what's your kind of like Risk risk assessment for that look like You know, it really depends on the organization and the mission the data Etc. I don't think there's a one size fits-all answer to that.
I do think you have to you know have to evaluate in the continent context. But ultimately yes. I mean, I think you you have to look at it from the perspective of if you're going to allow BYOD and there may be some cases where that's perfectly fine, you know being able to do some sort of posture assessment of the device to say, okay.
Yes this you know, this device is at least patched reasonably. Well, you know, it's it's, you know, not compromised. It's running, you know, some sort of, you know antivirus or Ed our agent or something of that nature.
It meets our minimum security requirements to be connected to this application or to this network. I mean, I think that's that's sort of the the basis for getting comfortable with the BYOD type approach. The reality is that you know, you can't I don't think I think it's very difficult for any organization.
These are most organizations these days at least to completely rule out things like connecting to email services from a like a personal phone. So, you know, there's some things like that that you might be a little bit more open to allowing versus connecting to a production database again from that that personal advice. So again, it's part of the risk assessment looking at the data, you know looking at what might be appropriate on certain types of devices.
But you know again if you're going to do BYOD, I think you know doing an MDM on a BYOD device. I mean that was actually something that we did at Duke but it was an opt-in and if you didn't opt into doing it we limited you to what applications you could get access to. Yes, we allowed access to email but we did not allow access to the clinical systems, you know without having the Indian application or the device enrolled in MDM so that we could again do that deeper posture assessment.
Yeah, that makes sense. I remember doing some work for the University of Colorado Hospital System and the security team in working with doctors. Doctors can have the ultimate power right in their organization and some didn't like security and didn't want to do things the security way in a way.
It's not the same but a bit of an analogy to developers right developers like their own environment. They like control they want to use the tools they want to use they don't want your stuff getting in the way. So it seems like both of those maybe the same maybe some unique challenges talk about that as a user part of your user Community people who really you need you need security, but they don't necessarily want or maybe even can't force them to do some of those things.
Yeah, you know it's an interesting analogy it certainly doctors and nurses and people that are taking care of patients. You you do want to enable them to do their work in a way that is comfortable for them and allows them to be effective at that because ultimately what they're doing is is you know, saving lives and oftentimes I would try to put my when I was thinking about a request from, you know from a healthcare provider for you know, hey, we want to do this we want to install this application. We want to use something in a slightly different way.
I would try to look at it from the perspective. Okay, you know is this you think about that, you know the patient that they're taking care of what that patient is me. What if it's a family member one if it's a friend like okay.
Yeah, you know if this is going to help them be more effective in delivering care to that patient, you have to wait, you know, the security concerns against that as well. Obviously, we have compliance and you know regulatory issues that we have to Was so there's a lot that goes into that mix in a healthcare environment to to making a determination, but you definitely have to listen to the people who are actually using the technology and understanding, you know, look is this going to affect them in a significantly negative way that is going to interrupt their workflows or make it more difficult for them to get their work done. I think a great analogy I can use for that is when we implemented multifactor authentication at Duke health and we did this fairly, you know early and actually in the grand scheme of things.
We have literate it back and I think it was 2015. You know, we thought very heavily about okay, you know, what is this look like in the clinical environment do we you know, do we want to be in a situation where doctors and nurses are having to pull out, you know phone to do MFA every time they do something on the on the clinical workstation that they're connecting to, you know, we probably don't because even if you know that only takes 15 seconds. Yeah, those 15 seconds can make a difference a big difference and actually a patient particularly in a you know, a life critical situation.
So, you know we looked at okay, what what you know in that particular case, we're going to be a little bit less restrictive or a little bit more open to not doing MFA in internal applications when you're connected to the internal Network versus your remote access and we're always going to do MFA. Right? So those are the sorts of decisions that we we went through there now, you know flipping that over to to the developers.
Yeah, I mean developers are creators in many ways the doctors and nurses or creators as well. Right, you know, you're doing creative work to some degree. Yeah, you think like to think about it the science or engineering but you know, there's a lot of you know a lot of thought that has to go into the next step that you're going to take and you know the right tool to get you to that next step is not necessarily always a you know, the tool that you currently have sometimes like okay, there's something new coming that I want to take advantage of Out.
Yeah, go ahead and bring in the you know, the AI part of the conversation now so, you know, one of the hot things at the moment is using things like GitHub co-pilot or chat GPT to help you write code. So okay, you know, this can help you this can you know make you more effective developer, right and maybe eventually put you out of a job, you know, there's that too but you know, there's no denying the fact that it can help help someone create code more quickly. Now, theoretically, you know, you're not just taking that code and tossing it in usually, you know, the developers actually doing some work, but we want to be able to find a way to make it so that they can do those things in a safe manner.
So we do want to put some guard rails up and help them understand. What are the safe ways to use these these new tools. So but we you know, so we want to know about them.
We want to be able to have a conversation about them. We don't just kind of run off and you know do something without us knowing about it, but one of the the reasons People run off and do something without telling you about it is that you've told them no too many times. Right?
So you want to build relationships with them and I think that's a very key in development in working with the developers anywhere certainly here Kendo if invested a lot in building those relationships, so they understand what we're not here just to tell you no, we're here to help you find a way to get something done. So let's talk about what you're trying to accomplish. Let's talk about the risk that might be associated with that.
We'll see if those risks or reasonable for the you know, the business value that we're gonna get out of this and you know, what we can do to mitigate this risks. So yeah, I always found that if we we try to go into the conversations and have constructive fashion versus just, you know, taking these stance up front that we're gonna tell, you know, we're gonna tell you know, you know, you know five times until you know, you go away but instead say, okay, you know, we hear you we want to talk about You know some risks and some ways that we can we can do the safely. I usually find that people are a little bit more engaged in those conversations at that point.
If you know don't have that history of being the department or no. So Chuck Mitch and I always like to ask the what's bugging you question. And I I especially think it's funny with you because you're always such a upbeat you always have such an upbeat happy demeanor.
Like I never have heard you complain about anything and I've never heard you really rant on anything. So I'm interested to let Mitch wind you up on developers using Ai and just see what happens here. Yeah, maybe dinner if that's what's bugging you or you know, you have privacy issues just like, you know different but you a lot of them that you have the medical field.
Yeah, you're Tracking helping people track customer Journeys talk about Privacy Information. What kind of things keep you up now? What's bugging you?
Yeah, I mean again, yes. I try to take a you know, optimistic view of the world. That's just who I am but you know, yes things move very quickly and it is you know, yeah, there's there's a lot of rare Scout there and we may not fully understand all the risks sometimes.
I think that's that's an aspect of being a security leader that you know, you have to find your your personal Comfort level with you know, hey, there's you know, always gonna be a certain number of things that are just gonna be running out ahead of us and it can be very Discerning at times and I think you know certainly looking at how quickly the world has, you know, kind of grabbed a hold of AI stuff over the last few months. I mean like everybody I've personally played around with a little bit and I've seen how powerful it is. So yeah, I mean on the other hand I also get how it could be misused and how it could present issues for us.
If we if we're not again building good guardrails around that so yeah, I Know I would be lying. If I said I wasn't worried about that. You know again, I'm trying to purchase from the standpoint of finding a way to enable the business to get value out of that way that we're also, you know kind of managing the risks.
I have had to tell people some people to slow down a little bit on some things because we were getting a little bit out. Yeah ahead of ourselves on that. But you know again, that's that's my job is to try to navigate this Waters.
Yeah, the the other one is certainly been a challenge for us is you know, we are working on a federal program right now and as a very complicated And certainly I know anybody that's senior done at you work with people that are doing CMC and things of that nature. Wow. I just you know to to figure out exactly what the federal government is looking for is just you know, it is a yeah, never ending battle the goal post and seem to be moving a lot on that.
So yeah, that's that's definitely something that has been keeping me up at night making me yeah, you know pull here out I guess portray yourself reasonably full head here there. But yeah, that's definitely has been, you know getting me a little worked up here lately. Government and and pulling hair out.
I think going the same sentence quite often and it's one of those things where you would think because yeah, I'm responsible for for CMC compliance. With the client and it's one of those things where you would think with all of the jokes we have about how slow the government moves on things. That they wouldn't get halfway into something and then pivot and change it.
90 degrees and then get another 20% the way into it and completely redo the whole thing. And so we're like basically the third revision of something before there's even an audit committee the certify you against it, but that's that's the that's been the life. We're living recently hasn't been fun.
Check I'm curious when you having never managed, you know developers and development team when you say that. You know, one of the key points which makes sense to me is being building relationships. There's so that you have some trust and you're not always that department of no and you can work together for Solutions.
Is that something that you do as a formalized strategy or is it just an ad hoc, you know gut feeling we're gonna listen to you and Open Door come talk. Well, I mean, I think it's a little of both. I mean I think part of it is yes how you approach the organization and it's not just the developers by the way.
It's also our product organization because they're the ones that ultimately set the agenda for our developers and determining what we're going to be voting. And so for example, we may determine or maybe hey we just have a dependabot skin and run and we've got like all these dependencies need to be updated and some of them are easy. Some of them are hard.
The hard ones are like, okay, you know that's gonna have to go into the backlog and then we're gonna have negotiate around, you know product features that are being built and ensure that we don't lose track of those things. So it's not just again working with the developers but also with our products managers to understand. Hello.
Yes. We're all about building new features in the product. But yeah to make sure this Tech that is addressed as well.
So yeah part of it is just being accessible, you know being connected whether it's well, I'm actually in the office here right now, but you know also we're very Slack Organizations so lots of lots of conversations happen there. And I have kind of a love-hate relationship with that because I think it's amazing how quickly we can connect and discuss something on the other hand that can also mean it's very distracting and very hard to get anything done and be focused on something but you know generally speaking just trying to make sure that we are being responsive where we can or you know, if we're hey look we've just got along, you know, even the security team me and we get a question from the product organization or from the developer about something and like might not be able to get to it right away. But at least trying to set expectations as to when we are going to be able to get back to them.
So just trying to be responsive trying to be transparent about what we're working on and you're sharing both ways, right? You know that we understand what their constraints are and they understand what our constraints are. Are we always perfect at that absolutely not I mean 20 times we can have done a better job communicating or building particular relationship.
But you know, it's just something you have to be intentional about and Recombination of sort of formal structures, you know, I think every organization sort of develops that you know that governance model if you will or how you're going to you know, perform your business in this case our business is building software. And so trying to make sure that we are plugged in at the reasonable places in those processes. So that security has a voice there, but at the same time also building Advocates so that people recognize.
Hey, maybe we need to have our security team, you know here for this part of the conversation. We have played around with security Champions programs as a way to to do that and we actually I mean we had that formalized a little while back we actually had to put it on pause because we felt like we were not investing the right resources in that but the general idea there is to find those people that in the organization that have an interest in security and want to help us, you know in their particular role helping and advocate for security by giving them some additional tools and Information that they can use so we we have that little bit formalized in the past how to pull a little bit back but we still informally use that method as well to make sure that we're again, you know, just taking advantage of Grassroots efforts that we can in the organization. And you curious about I'm sorry, JJ, go ahead.
Oh, no good. I was just gonna throw out there that I saw a stat on the news this morning that said, post-covid 50% of people are returning or are being forced to return in office full-time and then there was some Percentage that was in the 20s. I think high 20s it was working remotely.
And then only it was less. It was like 12% that was hybrid. Meaning they go into an office sometimes and I just thought that was a weird.
How do you ask me to make up numbers? Those are not the numbers I would have that's that's drastically off from what I would have guessed is going on right now. So I just thought that was interesting year in an office Mitch is actually feigning working from home today.
I'm green screening working from home. And you know, yeah on that note. I mean we're very much a hybrid company and we do have a very nice office space here and but people choose to come here we go on an average day.
We probably have about 50% of our Workforce that comes to the office. So the nice place because they like being here they like, you know, I like to say I come here because I like being around the other people the organization but also just a very nice space, you know, it's it's comfortable being lots of great. You can't see it from this room, but lots of nice views of downtown Raleigh.
We have a Terrace up on the 19th floor that's open, you know, and it's changing knows we have a pizza oven all those those nice amenities here as well and room And that the hidden room that's right the speaking easy. So at any rate, yeah, it's just a nice place to be and I think I think that's where companies that. Is my my personal opinion, you know compelling people or telling people that to be in the office is one thing but you're making making a place where people want to be that's that's really we're success in common giving people the flexibility to decide, you know, when is it?
Okay to be at home versus, you know, when you need me office, I think flexibility as well. A lot of people really ultimately looking for including obviously security people, you know that we all appreciate that our lives. No, check it stitching and none that you've been doing.
It kind of working in. The software world is security person a lot of organizations. A lot of ciso security teams are sort of faced with that.
Dev stick-offs supply chain software supply chain security all these kind of software things securing the devops platforms and tools and how much to get involved in that. We're not secured software Architects, but we are security people. What have you learned making that transition to yourself about the kind of team that you hire when when you get directly involved when you do kind of be involved in touch points in the process, how do you what have you learned doing the job you're doing right now as a C cell?
Yeah, I mean I came in here not as a software developer. I mean I've started my career as a systems administrator. So I had written my share of you know, shell scripts and pearl scripts.
Now that's a very different thing than developing. You know, the type of application that pindo is and you know, when I was doing that I used to think I was really great at it and make files. So, you know for those in the audience that are old unicious admins remember that in a while.
Yes, but yes, you know this whole get world. I do not understand all the you know, the mechanics. I mean I get the conceptually I understand it but you know the how people we actually use some of those tools.
I personally don't understand or you know can't fully appreciate right? I don't have the muscle memory in my fingertips for it. Versus I still have the muscle memory for Vi right handy, right?
That's exactly yeah. Oh wow and hjk now but you know, I think learning learning what they do learning how they work and you know again kind of but from the same side, you know, our Cloud operations team learning how they work. You know, one thing that's really interesting is watching how that SRE skill set as is kind of evolved in the operations side of it.
So our infrastructure is also code right? That's how we we build our infrastructure. It's all code based it goes through the same sort of change management and build processes that are actual code does which is great from a security perspective because it's not you're not counting on somebody there.
That's sort of manually clicking boxes to build this Cloud environment. It's all code so you can scan it you can you make sure it's gone through change management. We have all the Logs test Etc to do that that same sort of build process.
So, you know as a security person understanding those things has been important but also hiring people that if they don't necessarily have those skill sets of spells, they want to learn those things and I think that's actually one thing as Security Professionals as we always have to be learning and that you know, those that want to go learn these new things. They absolutely can and that's a great. You know, one of the great things about being in place like pendo is that yes, there's lots of opportunity to learn, you know, these these Cutting Edge and you should be ways of doing things.
So that's actually one of the things I'm seeing this different in the security operations team for example and security operations. I have three teams, by the way. I have security operations a product security team and a compliance team so security operations in the past which you know in would have been very focused on more traditional, you know, just looking at you know, Sam and kind of Reacting to alerts and things like that a lot more.
So we're we're now actually developing our own code. We're actually building tools, you know, we're automating things. You know, that's this.
So it's a slightly different approach and you know more like that that SRE in the Ops World. So yeah, I think that's where our skill sets and security are evolving in that exact same direction and that's all actually just today Microsoft released a chat GPT tool. That's for security, right?
Yes, that's all coming as well. So, you know this bottom line is all this technology all the way we're working Security Professionals has evolving. That's one of the exciting things about being in a place, you know, that is trying to keep up with all these the new technology is that we have to a Security Professionals.
We're after the same sort of thing sorts of things which means that we're gonna have job security. We're gonna know we're actually using all those technologies that the developers are using at the operations people are using so it makes us more effective as security people as well. So for a security person who might not be fully up on what SRE is.
How would you describe? Oh, yeah, great point so that that term I think started with Google site reliability Engineers. So again, really a heavy focus on on automation again, automatically going environment building environments through code not you know Hands-On right not racking and stacking servers and installing operating systems, but writing code that defines how that you know, that text back is gonna be built in the cloud.
So but also automating a lot of that so that you know, hey, if for example You've Got Loaded issues and you need to scale the environment up like you automate that scale up process or you know, we need to go back down. So, you know, there's things scale up and scale down automatically that skill set from the SRE is is what kind of makes all that happen the same token, you know, just autom all that ha type of work, right? You know that that's that's the sort of stuff that the SRE is a responsible for.
Yeah, that makes sense. Mm-hmm. very good pretty much so So when it comes to tools like chat GPT.
one of the things through the various Consulting engagements and clients that keeps getting asked is should we block access to these things? Well, you know while you're on the corporate Network on a corporate device and I mean, I think Chuck knows me. We'll have to know might you know, my answer to that is.
No, because they're always going to find another way to get to it. Then you just won't see it when they do but I'm curious what you guys are doing for Education around your user population with those types of tools. Is that part of your security awareness training?
Is it something you're dealing with just with the product management developers or How are you tackling that currently? Yeah, I mean I would actually say is become part of our future not necessarily part of our formal security awareness training at the moment but more so just part of you know various Outreach efforts that are going on. So, you know, we have a biweekly town hall and actually next one of those is tomorrow and that it's actually gonna be one of the topics is covered in the town hall.
We've we've covered as a topic in some of our engineering Town Halls as well in the past just to help people understand, you know, look there's a process that we have to go through that these tools from a security privacy and legal perspective and we understand that people are going to be interested in using those tools and they have some You know safe use cases for them that don't involve sending proprietary information or customer data, like, you know, there's some great area here but you know, but please just wait, you know, let us let us finish our duties before you start using this for any sort of corporate purposes. But you know, a lot of it is just reminding people that what we do have established processes for vetting in onboarding any sort of new tool. So it's not a you know, not something different than we would be doing for anything else.
It just happens to, you know, be very, you know, very newsworthy right now because everybody's talking about it. So we're using I'm gonna dig a little further into that just plain Devil's Advocate. So when you have something that's that accessible and is basically a browser.
interaction and experience How do you train what kind of education are you doing to explain people? That is a tool? Yeah.
Yeah, I mean again what we do is we try to remind people how these things could go wrong for the company. Hey, you think this is you know, I'm just going to take this code that happens to be a proprietary code and put it in here but in doing so you might be creating a legal liability for the company because you know, you taking something that is proprietary information given it to a unvetted. Vendor, we're not sure exactly, you know from a legal perspective.
If we own the code that it gives back to us after you've done or you know, if you've asked it to write code for something do we actually own that code? So it's reminding people those sorts of complications exist. Yeah.
I mean do people hear those things hopefully, but you know, we also are realistic enough to know that not everybody is going to fully appreciate those things. But you know, we just do what we can in trying to, you know, continuously to talk about that and ensure that people know that we are you know understand that there is an important business value to be achieved with these tools and that we are working on finding ways to use them in an appropriate fashion for the company. And in the meantime, just asking, you know Please slow down just a little bit while we work through this.
I have something that I've learned that's just in a couple last couple of days to help people understand some of the the some of the risks is just vast chat GPT to write your own bio. So right a bio for Mitchell Ashley and you'll see that yes, some of it's right. Some of it is I was see so at whatever I'm like kind of I never worked at that company.
So you realize that you know, there are some things that it's good at but it also well it all sounds truthful. It isn't necessarily accurate or true. That's it.
So it's still early to be to have a high level of trust and in some of the output right? I wrote it chat. I write a monthly post with packet pushers like and ask me anything calm and one of the questions was They told me my book was too long.
Can they just learn wireless security from chat GPT. So I said that I don't know. So I went on to chat GPT and typed a few basic questions and the answers were so then I scored them like with one to five stars and there were they were it wasn't great.
Like if it was a lot of information was old didn't know how to parse together new information with the old information and and what superseded what and then it left out whole chunks of things sometimes. So yeah, I mean even just the basic, you know, ask it the normal basic stuff. You'll start to see where some of the the gaps are if I can because this is we're gonna be coming right up on RSA and check we talked to Britta and Casey recently and got the dish on some of the stuff happening.
So I'm curious because I think you're you are gonna make it there this year. That's my plan. Yeah, is there anything specific you're looking forward to?
Wow, you know actually I yeah outside of the amazing technology and operations track which I'm lucky enough to be part of the program could be before and I think we have great sessions. I mean, I think the main thing I'm looking for excited about is just the opportunity to see people Network in person again, see some some folks haven't seen in a few years last time. It was RSA was February of 2020.
So obviously right before the pandemic and not a lot of you know in person contact with a lot of you know calling someone local areas team might, you know colleagues here in the wrong area a lot more frequently than that. But yeah, just looking forward to reconnecting with the larger community and seeing what new things are out there these days. But as you say Mitch 40,000 of our closest friends, oh, yeah all together in one conference.
Yeah, but me being a huge introvert like that's just fracking but also, okay, you know, it's kind of cool you do miss it to some degree as well. All right, we all insecure. Yeah, it's yeah most of us are introverts I guess, right.
Just we just pretend to be extroverts when we have to yeah. Well, that's the thing is we can be social. We just choose not to exactly that's to our own devices will not be but that's right.
Well check it's been fascinating and we appreciate your time fortunately run out of time here. We can go on for another hour and a half. It's been very cool that that you've had this journey from kind of it operations to segment through being a leader into a Cecil role and to a Cisco and a software company and I think a lot of people can learn from what you shared with this today.
So as oh, yeah, so he's JJ brings that perspective too of understanding. You know, what we know today and what we're gonna have to learn for tomorrow as a security professional and it's it's interesting to hear both of you talk about it as well. So thank you for joining us JJ.
Thank you for being a fantastic. Partner in crime here and see so talk and it's been fun. And we look forward to having you back.
We need John some more panels Chuck happy to do it anytime. Thank you. Okay, you heard it.
I just heard a commitment there. So we're good. Alright, JJ any parting thoughts.
No, I'm just excited about this reboot and excited. At the seed track and all of our future guests and thanks everybody for watching or listening. Fantastic.
tv. That's where we show up in video form. com as well as on your favorite podcasting platforms.
Lots of great ways to listen and why so we thank you everybody for joining us today and thanks to check for being with this on behalf of JJ and myself. We'll see you on our next episode.



