CISOs and Remote Software Development – CISO Talk EP 36
Today’s highly distributed workforce is introducing new challenges for CISOs who must carefully navigate the journey from traditional perimeter-based network security to, well, the exact opposite. Securing remote work and managing BYOD on top of the usual challenges of protecting the software development life cycle (SDLC) means CISOs need to strike a balance between strong security policies and developers’ preferences, work location(s) and work style(s). It’s enough to make anyone crazy! Gal Shpantzer, IANS faculty member, CISO advisor and security consultant joins CISO Talk hosts Jennifer (JJ) Minella and Mitch Ashley to discuss these issues and more, as well as how to avoid the “C-S-No” approach, overcome resistance to necessary security and how to implement alternative strategies.
Transcript
Hey everybody. Welcome. Welcome to another episode of CISO Talk.
My name is Ashley, I'm c t o with Tetron Group and also analyst with Tetron Research. And I'm joined by my co-host, or I'm here with my co-host, uh, Jennifer Menella. How are you doing?
Good to see you. I'm great as always, Mitch. I, I, I'll bet you are, you're always fantastic with lots of good things and ideas to talk about.
And, and guess we have a, a new guest today. Um, so I think we're gonna explore some of his background cuz he's done a lot of different things and I'm really curious to learn about. Uh, so I'll let you introduce Ga Yeah.
Uh, survey. We've got gal today and I've known gal not as, I'm gonna say this about everybody, probably not as long as I've known you, Mitch, but, um, I don't know, 10 or 15 years at this point. He's, uh, been in the security industry alongside all of us, um, and doing some great stuff.
Um, I think with a lot of log visibility and observability and I see a lot of questions answered. We've had some weird conversations, but golf's competency tends to kind of tentacle into a lot of different areas and he is done some pretty cool stuff. Uh, and I, and I was just saying that on my list of things to do is to find out exactly what Gaul does, because I kind of know what Gaul knows, but I don't know what he does and maybe he can't share that.
I don't know. So, Gaul, tell us about it. Well, there's nothing, uh, super, uh, secret.
I'm just a paranoid guy and I try to keep a bizarrely high profile about me being in the industry, but very low profile about who I work for and what I do for them. Uh, I've gotten better at that more recently. And so, uh, I I, I can do the sharing thing the Dr.
Evo we wanna share. So, uh, you know, I'm a consultant. I've literally never had a real job.
I've always done just 10 99, uh, generally allergic to bureaucracy. So I've always found a good friend who has a prime kind of vehicle to work through. And so I've done work for very large companies like affectionately call Mega Global Corp, including Fortune 10.
Um, or some people call 'em Global 100, where they're just, you know, they count revenues in the billions a day. And then all the way down to very small kind of initial seed, capital level, uh, innovative companies in tech. Um, highly targeted nonprofits and NGOs and really anything in the middle.
So, uh, originally I started in the physical security world and I did work as, uh, everything from bouncer to bodyguard to kind of community level, uh, work. And that's when, back when I used to be skinny, so I used to be 6 4 1 70 and now I'm about 6 4, 2 0 5. Pretty lean.
But, uh, I just, that people would come and challenge me, uh, when I was working all the time. It was just one of those things, uh, just be careful about the skinny guys cuz they, they have to know how to fight. So one day I was working at this nonprofit and helping them do things and uh, I called a friend of mine.
I, uh, I'll just say yes, had some boundary issues, but we knew how to do hacking and knew stuff about information security. And I told him, Hey, you know, the cable company came over and gave us a new piece of equipment. And he said, oh, okay.
Turn it over. Tell me what it is just before cell phones are a big thing. Just called him on my landline in late nineties.
And, um, he said, okay, great. And he hadn't heard from him for a while and then like maybe a couple months later he very obviously understood and knew things that he should not have known about, who I was going to be working with tarmac pickup, like times and dates and locations and activities. And it's like, what in the world is going on here?
And so I figured out that he knew things directly because he was probably reading my 15 minute line by line, uh, itineraries. And I thought that was both amazing and disturbing cuz I have responsibilities to people I'm bringing in. And also I wanna, you know, leave the gig with the c on the holes I came in with.
Um, it's, uh, it's seven per the Antman movie count. Uh, well, I mean seven for some people. So the, the idea was, uh, he said, okay, well go to your desk at the office and fire up, ie at the time, and I go to 92 8 1.
And that meant nothing to me. I just had no idea. And I said, Hey, there's no, I don't know what it, what this is.
It looks like some sort of password protected interface to some device. And you said, uh, yeah, I know. Just type in admin and then admin and then press enter.
And, and I quote, and this is what I said, that will never work because I was so naive and I was so in my mind already raging that if that did work, how negligent and ridiculously irresponsible would that be for a company that I pay money to as an organization would do that to us and to the people we serve in that tri-state community. And of course it did work because he looked it up in various underground forums. And that was the beginning of the end for my physical security career.
I was like, I need to understand what this is, this is the future. And that was in the late nineties, early two thousands kind of transition that I made. Took a bunch of Sands courses, uh, Stephen Northcott amazingly probably got sick of me replying to these news bys and telling them, oh, well if you look at this website and this website is doing public safety wireless network and stuff and blah, blah blah, he's like, you know what?
Shut up and just be on the news bikes. And that was kinda my first big break in the industry. And thank you again, Steven.
That was, um, in 2001. Um, and I was just so passionate and active and wanted to contribute. Uh, Bob Alberti was one of my, uh, mentors in information security.
Thank you, Bob. He was one of the original creators of the Gopher Protocol. Uh, so, you know, just find people that know a lot of things and wanna help you out, even if you don't know anything yet.
But they, they just need to see that you respect their time and ability and their skills and that you want to be a net contributor to the industry and, and get a good career out of it. So, you know, that's how I kind of got my big breaks. I volunteered or did really low pay jobs for kind of IT admin and security work for nonprofits and stuff like that.
Bob helped me, uh, spec out and build a, I think it was an open BSD firewall for the nonprofit out of a cannibalized old desktop, like super guerrilla warfare stuff. Like, yeah, nothing, nothing, um, uh, well funded or formal, but we made it happen. Um, so over time those things tend to snowball and if you're out there, um, looking for, for stuff, uh, you know, ideally, uh, people will open doors for, I had a lot of open doors for me that I thought were open, but ended up not being open.
Cuz when I moved to DC in 2002, I didn't have a one of those T S S E I clearances and everybody I talked to, because of all the stuff I had been consuming from the open source stuff, assumed that I was already in the community. I know I just wanted to be in the community, but I was not. And so they just said, oh yeah, send us your clearance paperwork and, and absolutely wanted, wanna talk to you and hire.
And so I ended up having to kind of forge a very different, um, wait, Is that the, is that the 362 page clearance document? Is that the same one? Well, I think that's the 86 is the generic one, and then they, you know, give you all kinds of polygraphs and, you know, talk to your dog walker's cousin or whatever.
Yeah. So, uh, I didn't have one of those. I, there was no issues barring me from getting one of those I asked around, but they said that by the time I would get one de novo from start, it would be almost two years.
And if I any reason got bounced, they would've just paid me for two years for to sit around. They're actually farms in DC virtual farms where they just give you a thing to do before you actually get your full clearance and they employ, this is just hilarious, kind of, uh, a thing. So I, I had some close calls with that and as at some point I was like, this is not gonna happen.
And so I just went in and did, uh, work in the, uh, UNCLEARED space when, and, and every once in a while someone from an org would, uh, reach out and say, Hey, we wanna understand what you think about this particular issue. I'd go to a building sign, an nda, they'd like, you know, ask some questions about generic things. I'd pretend to not understand what they're talking about and not mention, you know, names or countries and I'd say was X, Y, and Z.
And I'd say, here's some money. Go away, don't tell anyone. And, and I did.
So now that, Now that you're, now that you're sort of equipped or better skill that's sharing, but not sharing too much about what you're working on, I, I'd love to hear more about the kind of projects, the kind of work Sure. That you do because there's, you know, security is a mile wide And it's a big thing. Yeah.
Right. So many things we can do in that space. Yep.
So in the two thousands, I did a lot of work consulting to CISOs as a kind of a consulting slash integrator, uh, person where I spent a lot of time on the West coast looking at new tech companies in the security space and IT space, and kind of brought that more kind of east of the Mississippi to the old school Rust Belt and, and the other bigger tech companies that were operating in the East coast and, and kind of generic like Minneapolis East, if you will. And that was really productive because a lot of people needed that kind of technology, but they just didn't have that, uh, bridge, if you will, between, uh, the big commercial companies and the small innovative, uh, companies on the West coast. And I'll give you an example.
I started working with a small German company actually on the other side of the Atlantic. And, uh, they had absolutely the best, uh, full disen encryption. So in 2004, I, I met, uh, those folks are called Ude Mako It, the sofas bought them a while ago.
And I thought, you know, especially with, uh, SV 1386, there's just so many companies and organizations losing laptops. And when the VA hit in 2005 or six, the two years, I'd spent knocking on doors saying, Hey, you need to encrypt your laptops. You need encrypts and encrypt laptops and sometimes your, your desktops so they get stolen too.
Um, boom, all that work I I had done to kind of evangelize that space and, and do small POCs and, and little pockets of the environments all of a sudden became enterprise deployments. So George Washington University, uh, crazy tra was the CISO there, fun factI was the second CISO there. The first CISO there did not last very long cause they didn't understand the DO edu culture like she did.
And she called me up and said, Hey, you know, we need a briefing on this thing because the VA just hit, I'm like the board of the university. The regents told the C T o, who is my boss, how do we make this not happen here? Because the entire VA lap VA database was downloaded by a GS 14 database administer onto their laptop, and it was stolen from their home in Maryland and it was gone.
Um, so that precipitated a lot of work on the kind of encryption and USB control and other things like that in that space. I also did work with Quali, uh, back in the day when they were a very, very young company. Imagine a SaaS company almost 20 years ago and bringing them to a global 100 old school engineering and manufacturing company and know, walking them through like, oh, here's their SOC two and here's how they do control.
Here's how they do, uh, tenant encryption. And so they ended up replacing their home-built version of a scanner with a SaaS, uh, almost 20 years ago. This is back when Gerhard Esbe was cto.
It's that that far ago, remember? So those are the kinds of things that I was doing. And I also work with, uh, you know, Bruce, oh, you're Making all of the 20 year olds.
You're making me feel old. Well, the interest thing about that is that these things, were not, Let's pretend like we're young little Spring team. We're absolutely young.
Yes. My, my hairline is right about here. Not actually here.
Totally. I've never, you know what, I'm sitting here staring at you cuz I'm trying to remember how many times I've seen you without a hat and sunglasses. Well, perhaps we should talk about that at a sometime today.
Yeah, I can count it on one hand. So this is a, this is a new look. So this used to be the reverse disguise and, and we'll talk about in a bit about what that was about.
So performative privacy arts. Uh, but the idea was I could be a bridge between kind of the Silicon Valley or European tech innovators and bring that to the big companies that were really, uh, just not able to bridge that gap between the innovative smaller companies in the tech world and their processes and personnel and skillsets. So it was silly thing to bring, you know, Qualis and a man's service provider together and, uh, full description to a managed service company that was doing walk-in and takeover of server farms and desktop fleets at very large companies.
So we put together products and services for those massive enterprises that were their end clients to say, Hey, if your laptops or desktop gets stolen, no problem. You know, less reportable issues, we can pre-scan all of your servers before they go on the internet. You know, uh, with, with a workflow, again, this is almost 20 years ago, um, we can look at your firewall logs and your IDs logs and, and integrate them into your processes.
So that was some of the consulting that I did. But I always felt like I was 3, 4, 5 years ahead of the mainstream adoption curve. And that's generally been, uh, something that I've been able to bring to my clients is, uh, what's, what's coming in over at Horizon and where should we be, uh, kind of skating to where the puck is, if you will, for our Canadian friends.
Sorry about Gretzky though, too soon. Yeah. One of the things we talking about, jj, if this works for you.
So in that same timeframe when Quali was going through that, I was in another startup security startup and I know one of the toughest lessons for startups, then I'm curious, what you find now is going from putting your product security product or whatever it is, uh, in a medium fill or small size business is light years away from being able to support an enterprise, going into an enterprise. The requirements were so yeah. Of such a greater, the scale went from this big to that big, you Know?
Yeah. It's a it's a leap Yeah. In a single move.
And it sounds like that's a lot of what you were doing with Qualis and others and maybe you're still doing, is that, is that still do, do startups understand that gap and how to cross it quicker, more quickly and get there? Or it's still a learning curve and everybody sort of learns the hard way? Uh, to an extent it's still a learning curve.
I think definitely the supply chain and third party risk is much more now formalized. And, uh, a thing in a lot of procurement departments, you know, oh, the business buyer, whether it's the CISO C T O C I O group wants this widget or this processing power, big data, whatever in the cloud. And the procurement department, because of the CISO and the G G R C and the risk people and the, and the general council folks altogether said, Hey, we're getting owned upstream, need to understand what's going on here.
And also there's just, will these people still be financially available here in the next year or two? And I think this year after kind of the Patagonia vest recession, uh, some people are calling it a lot of smaller tech companies just won't survive the downturn. They may not get a bridge round and they'll have to do a lot of m and a, which is some other things that I've done has, has helped, uh, both on the buy side and sell side, figure out what are the matches and what are the risks that we're bringing in to the bigger organization, how to reduce those and what are the risks we're buying in and bringing to the organization.
So I wasn't consulting on this, uh, with Verizon and Yahoo, but an example that's out in the public is Horizon about Yahoo. And Yahoo for reasons, uh, unknown to me possibly didn't disclose if there was a breach. And so, you know, Verizon kind of clawed back, played a billion dollars as a, as a post deal haircut.
Um, so those are things that are real. Uh, when I was doing v CSO work at a very, very, very large law firm, the very, very large law firm was buying up smaller law firms. Cause a lot of times these cuts companies and the consulting integration, uh, grow, uh, organically through kind of conglomerating in the smaller companies.
And so the moment you announce that, you know, company X is acquiring company Y and company Y gets owned the cu your customers and the company wise customers would be calling the org, the the buying org CISO and yelling at 'em. And in some cases that's me. In some cases that's somebody else.
But you have to be really careful to understand what you're buying, both financially, obviously with CPAs and, and lawyers, but also, uh, some basic cyber due diligence. So given the formality and the rigor and the, uh, attention, the third party and supply chain stuff is, is undergoing today, and I, I don't think it's getting any better. It's gonna get worse and more intense.
Uh, startup people need to really understand what is it that is a minimum bar that is kind of a threshold of okness, where the buying org is going to approve your stuff. And there are some companies that do kind of passive telemetry around detecting whether you're, you know, malware or your network or ATP space, stuff like that. But I think, uh, it, it should go deeper in terms of really understanding what's in the product.
How's the s SDLC working now? Is this already leaked? Is there, um, you know, indicators that, uh, they're about to get ransomware, cyber insurance is also now a thing these days and, and this type of process is becoming industrialized.
Uh, and I think we're iterating on some good practices and some terrible practices that are gonna scale that are just a waste of everybody's time. Um, but that absolutely is a thing that anybody who's in the tech startup world needs to know. And that's part of what I do is vc.
So work for a lot of tech startups series A, uh, even before that, help them get to a SOC tier really quickly map security work to compliance points, not the other way around. And then b at the table. Cuz I've worn the hat on both sides where I'm on the acquiring org or the selling org and explain, here's where we are, here's where we're gonna be, what are your concerns?
I'm your security POC if you have any problems. What's amazing to me in um, almost universally now is authentication, strong authentication MFA SSO is becoming somewhat of a standard, sadly. It's, uh, you know, behind a paywall if you want to go and shame some orgs go to SSO tax.
Uh, and I'm, I'm building a SSO tax version of for the logging world. But, uh, cause there, there's a whole pay wall for, for logging, which shouldn't be there, but it is. But the auth authorization after the authentication.
So I know who you are, I know you're coming in from this machine that is ours or some B by D that's been examined some way, but I don't necessarily know how to build an app that is hierarchically administrator, where you have administer and power user and kind of regular user. So many application builders are doing authentication generally correctly through APIs and SDKs with the authentication folks. But the is like this bizarre, uh, black hole exotic skillset.
Uh, and there are a couple companies that I started to look at, uh, to help, uh, with that. Uh, but that is such an interesting kind of a blind spot that I think we're gonna see a lot of work in the next few years, uh, to catch up because a lot of people are building and selling flat, non-hierarchical apps and the buying orgs are starting to say no more. So go, I wanna rewind really quickly, uh, and, and pull some of the juiciness out.
You said something a second ago, a couple minutes ago that, um, kind of what you're doing, and I know you work a lot in integration and, and log management and you're talking about kind of going to the puck. Sorry. Uh, I I like Skating to where the puck is.
Yeah, that's, that's, uh, Yeah. So we're gonna skate to the puck. I'm kind of curious if you had to pick two things.
So if people are listening and they're kind of thinking, um, what are some of these forward thinking applications and, and some ways without, you know, without giving away your secret sauce, are there two things you would kind of share that people can take away of maybe a different way to think about that? Yeah, so before my hockey buddie, uh, get, get a all irate, it's, I believe the term is skating to where the puck will be. So understanding, yeah.
Uh, but the, uh, the idea of, um, the, the two biggest things I think that I'm in interested in right now is kind of the, the AppSec sdlc, uh, cloud migration version of security. And all those are to some extent related in terms of the post covid re architecture, zero trust, digital transformation, cloud migration. They're all related to, okay, we're not just gonna be in a land in a building or a set of buildings that we own.
We can point to a server rack over there, and there's a V P N and an active directory server and stuff like that. The world completely detonated and atomized especially, uh, after Covid in 20. And so we're now in year three of that re architecture and there's a lot of people still running old school kind of hybrid multi-cloud.
And, um, what that means is you have to manage a transition where you are adding net new to the land old school protocols, a lot of new skill sets, and kind of moving into detecting up the stack and what that means from a point of view of understanding, let's say, uh, logging and observability. Most people in the information security world are most familiar with and most comfortable with logging observability, if you will, telemetry generation from operating systems and network security. And, and you're an expert in, uh, the wireless and network stuff by your book, by the way.
It's excellent. Uh, and you, so, so I think we really need to make it less exotic and more obvious and more common to log up the stack, the databases, the web applications, and all the custom applications. And these things are available to us in freeware and in various services.
Uh, it's just a matter of, uh, will and skill. We need to log up the stack because most people right now have some good telemetry of their old school land, but they just had to throw all this technology over the transom to cloud and SaaS. And there's this lack of skill set and lack of understanding of what can be extracted from the visibility, uh, generation tools that are in the cloud.
tax. And you know, you have to go, let's say to GitHub Enterprise to get any logs out of the thing to understand who's in your SD L C. And so I always ask people, you know, have you heard of the code co breach?
So that's an example of something that happened in 2021 with kind of an SDLC oriented breach. org, hash Corp, and tens of thousands of other orgs and large enterprises, um, and kind of tech foundations. And, uh, they put a BA script out to say, Hey, we use this batch to upload the code to code code and then we'll tell you how much of it you got covered in the testing.
Problem is that that BA script was in a writeable Google bucket, and some of you are about to can already sense. So it's about to unfold here. So a bad guy figured out that they could not just download the script, but also modify and re-upload it for other people in the code code universe to download and upload their code.
So they did indeed modify that and they said, Hey, I'm gonna add some lines to this BA script to tick your code with your IP and your secrets, upload it to Code Cov as expected, but also to my droplet on, uh, digital Ocean. So, okay, that's not cool. So now someone is reading your code and the secrets they're in and is iterating into your sdlc.
Do you know even what that looks like? Right? Uh, EA games had a Slack token stolen from a client and replayed against them, and a month later there's a terabyte of source code on the internet.
So these are not necessarily new attacks, but they're so now embedded in the common architecture of post covid and, uh, you know, big companies adopting these tech technologies that it's really a huge hole around the threat modeling, pen testing, scoping and all that kind of stuff. So take a look at those things and understand. Yeah, I think that, I think it's really fascinating where we are is it, it ha hasn't necessarily been a big, uh, target vector or attack vector, but now developers with phishing, um, uh, workflow pipelines and tool chains, you know, whether DevOps or others like you're talking about, it can be as, as basic as scripts that, you know, manage and set up environments, maybe more fancy things like Terraform, but the people creating software are now the targets and the environments that they created in are as a bigger target than, I mean, that's the new vector, right?
Everybody goes after that. You can talk about the last pass situation. I don't, Heck yeah.
Yesterday we found out happened, been there, yeah. Fishing to, to developers. Yep.
And, uh, you know, we're, we're always in this conversation about developers writing secure applications and how much can they do their own own versus working with security people. But now it's the environment too that they're building all this in. And The SDLC itself is a target.
It's not just the web app with the vulnerabilities that are directly exploitable. Yeah. So I mean, yeah, that, that's, that's, uh, absolutely a thing.
And so the, when I do work for companies that are developing a product or integrating a product, and everybody's a tech company in a way, I look at, I call it the four pillars. So one is the corporate security pillar where you have, you know, I need to comply with regulations. I have legal stuff to do, I have hr, I have laptops, I have desktops, I have servers, I have cloud vendor contracts, uh, I have, uh, SaaS companies that I work with.
I have an office, stuff like that. I have employees that I need to do awareness training for, yada yada, lifecycle management for employees, levers, uh, movers, joiners. Second one is the SDLC itself.
What are the tools and processes and people that are building the product? And we saw with last pass we saw with, uh, code Cov and many others, something's going on there, possibly a Solar Winds as well. Third thing is the product security features.
It, the, the, the product itself that you're developing and shipping either through SAS or a CD with a license key, however, it's you're shipping that product is interacted with and used by your customers. And so they need to have their own understanding of, Hey, does this come with SQL injection across that scripting for free? And so we saw with fs, IAC doing, you know, B BCM and other things like that around procurement and legal verbiage and that's great.
But also there's some technical security features like authorization, authentication, integration with s SSO and mfa. Some basic logging like, Hey, do I know if an admin promoted another user to an admin? And then that person who became admin did some really stupid stuff.
So activity logging from the people who, who are doing things on the back end of the application from the provider side and the front end of the application from the user and admin side. So basic visibility around that. And ironically, that's a lot of times DDoSing, the help desk people, especially if you're a B2C company, someone calls and said, Hey, you know, I think, uh, we got hacked.
And if you have good logging and understanding what's going on, well it turns out that you shared your password for this product with your, a relative or your babysitter and you never removed it after that time and it's still there. And they actually used it to, you know, do stuff in your house or in your, uh, workplace. And so the ability to understand really and instrument what's going on on the backend from the support side, did we do this?
Did someone inside do this work? And in some cases the due diligences is prove to us that you didn't touch our tenant because there are logs and we have access directly to the logs for our tenant. So those are basic types of things that in theory are not an exotic skillset or exotic request, but in reality we're seeing the leading wave of that due diligence and requirements from the third pillar of, uh, product security features.
So when you're selling stuff, you not only have to prove that it's secure from an AppSec point of view, doesn't come with pre-ex exploitable bugs, but it has features that are directly usable by your team that is supporting that SaaS application on the cloud and by the users and buyers of your product. So go Yeah, go Ahead. Sorry.
No, finish your fourth cuz I, I have, uh, yeah, so the Pillars really just like so many questions like running, keeping the lights on, keeping the cloud up, sre uh, logging into monitoring observability, uh, DDoS ir, you know, uh, sock and sim, stuff like that. Okay. So there were a lot of acronyms.
I yes, I I I've followed most of them. All right. I don't work in, in software development.
I don't really, I'm not a DevOp, uh, dev ops. I start mashing words together sometimes, you know, I've been up since four, whatever. Um, so I'm not a DevOps person.
I'm not a developer. Um, I'm kind of curious, like, so you talked through a couple of examples with some of the, the Phish and the exploits, um, but the other SDLC attack. So, um, can you kind of just talk through like what are some other ways that that can work?
Maybe what are, what are three other things that organizations need to focus on and maybe if, if, um, so I know there's, there's stuff that the, the organization that they're a tech manufacturer that's creating the product has some things to do, and then maybe there's some stuff, um, as well that and, uh, somebody consuming that product, uh, could you could do to validate, so maybe cover three or four things to spread across those two areas. Sure. Uh, so I think the, the SDLC piece and the product security piece are obviously interact in iterative, right?
There's not like a linear kind of ratchet going from left to right, if you will, because the, you get market and sales and marketing feedback from your prospects and your buyers around what do they wanna see in the product. And that's really interesting that you then feed that back into the TLC with the product manager kinda interacting between those two. And so they're obviously things, you know, off top 10 and other kind of standards out there that are, uh, part of the due diligence from the buying process.
And the auditors in some case will ask, uh, whether you're getting a certification third party that you can show, uh, or the auditors from the buying org will force you to kind of put together a, a questionnaire, I call them phone books of, uh, all the things you do around AppSec and secure, uh, development. And, you know, there are a lot of things involved here. And one of them, as we saw with the, uh, the password manager, uh, breached the other day, they said that someone had a, uh, home laptop potentially with a media, uh, uh, uh, software that some people are authorizing, just go ahead And call it a plex server.
Yeah, it Might be a plex server, who knows, uh, who knows. Uh, but that, that was exploited. And they use that exploit to put a key logger on the home machine of the developer.
And so I know for a fact that a lot of organizations really want to not necessarily use B Y O D and home machines for really sensitive DevOps type of stuff, but there's so much friction between various orgs, the ciso, the CTO, and, and kind of the speed of development. So it's a natural thing to kind of try to split that baby and say, fine. And there's a lot of privacy and kind of labor active as an issue now that we're also seeing around, Hey, we're gonna roll out MFA because we're required to, and our customers demand it.
And also our employees want their HR data safe, so they don't get, uh, their stuff breached. But we're seeing interesting pushback from some employees or contractors saying, you can't even send me a text on my phone without paying for it or whatever. And, and I've never, in the last two years where I started seeing this stuff, seeing a general counsel, uh, not give up on that stuff.
So there's a lot of really, really interesting friction happening around B Y D versus corporate devices. And when you couple kind of the, uh, labor pushback, and I consider myself la you know, labor like wetwear, right? As opposed to hardware and software.
So the labor pushback and the, uh, privacy regulations out there between EU and California and you know, going east from there, it's gonna become really, really hard to say yes to B Y O D without intrusive privacy impacting, uh, tools. And some of that is, you know, mobile application management versus device management and so on, a little containers. But that starts getting into, well, what can you see?
What can you do? And there was a huge Twitter blow up, uh, a week or two ago around a university, uh, PhD student in computer science at an Ivy League school that said, how dare you put an E D R on my machine in my, uh, lab And, you know, what about the privacy implications and academic freedom? And so we're still having this debate, and I think it's gonna be around for a while around where's the balance between, this is a corporate laptop, you have no privacy, we can see practically everything, don't do any stupid stuff on here and don't do anything that you don't want us to know about.
And so I, I, I generally wanna tell people start thinking about entirely cleaving B Y O D from, uh, corporate devices except for like checking a calendar or something really, uh, benign from, uh, multiplication management, uh, container that that's something I'm absolutely seeing as a, a thing that people are not ready to deal with and they're stepping on that landmine over and over. Yeah. And it's interesting that we took a B Y O D turn here because this is something I, uh, I personally feel passionate about.
Um, I started speaking on B Y O D and, and helping clients, I don't know, 10, 15 years ago when we had the whole consumerization of it. Right, right. Um, you know, whole blow up then.
And I feel like we never really got out of that. We just sort of started ignoring it. Mm-hmm.
Um, and it's interesting. So since you, since you pitched my book there, I will tell you, and I think Mitch, we can probably maybe even give away a book if we wanna do that. Um, there is actually a whole section in the book, um, around B Y O D that addresses not just the technical controls, but the legal considerations and implications.
And there's actually a couple of case studies I call out in the book to kind of give an example to to that, because I think in a lot of organizations, nobody, the architects and the operational teams as well as the executive leadership really don't have their heads wrapped around what that means. Mm-hmm. And it is so, you know, what you can and can't do, and the legal ramifications of that are very geographic or regionally specific.
So, you know, within the US there's, there's kind of some big umbrellas we, you know, and some sweeping statements we can make outside the US say, you know, I'm, I'm learning because most of my work, um, is in the us uh, it's certainly in North America. Um, so, you know, learning kind of some of these rules and regulations in other countries and what Europe does and how they handle things, it's been really, really eye-opening. And actually since we're golf, cuz we're both ions faculty, one of the trainings I'm doing for s coming up is A B Y O D training, like planning excellent.
And securing B Y O D, which covers all of the legal stuff. Obviously I'm not a lawyer, but, um, yeah. But yeah, it's crazy because to to really tentacle into all of the different paths from a personal device that may not have direct access into a resource, but if you can hop through it and, you know, it's easy for me as not a software person to kind of balk it, you know, how how could you, how could a company of that size with only a handful of people with, with that level of, of access, how could they have not been paying better attention and better secured that?
Because I think there will be a lot of friction telling people you've gotta carry two phones around just to check your mail. But my God, if you have, you know, the entire, the entire d you know, decryption suite for a, a vault of, of your customer's information, certainly that warrant's a little, a little bit of extra attention. And I, again, I know I'm sitting back Yeah.
You know, back here in the, you know, I don't, the the glasshouse thing, I don't, I don't know enough about that, that world, but I just have to imagine they, we could, we could do better. Well let me interject this cause cuz I do come from that world too, if, you know, the, the, the clash, if you wanna call it a culture clash or whatever with the ri with the whole digital transformation, the rise of software and the importance going from backroom and back office, uh, activities to really a forefront strategic part of running almost every business. Yeah.
And I'm sure you see that goal is with that is we've also what we call the democratization of software, meaning developers drive a lot of technology decisions. It's an entree point for open source and products and all kinds of things that maybe in, in in large, some large enterprises, you know, more regulated are under more control. A lot of organizations, it's developer fed into the organization and then it kind of gets formalized and adopted at some point.
But it, it has been anyway for the last probably two, three years to hire developers. You know, they pick you based on the tools and the flexibility and the environment and the kind of work they're getting. And if you said, if you said you will have to use a corporate laptop that has this installed in it, they'd move on to the next job applicant.
Not even, It's, it's absolutely a, Uh, it's a conflict. I Mean, yeah, it's a big deal. Uh, and Jamil Farci, uh, I saw him give a talk in DC years ago now.
He talked about culture as a competitive weapon to recruiting and retaining, uh, security talent and other it, uh, important people that are driving your business. And that's absolutely a balancing act. And, uh, it's really tough between the CSO and C T O and in some cases the C I o kind of doing the, keeping the lights on, uh, organizations to do that.
Luckily there are a lot of better tools and better processes now. And visibility is where it really starts in terms of what, what can we see and understand, uh, in terms of, uh, kind of, uh, things that just don't look right. Uh, you don't know what that looks like unless you, uh, turn those logs on, if they're even turn on a ball.
And we talked about a little bit earlier on in terms of how do we get the telemetry out. Sometimes you have to buy it back, uh, from the SaaS company, uh, by going full kinda E five or you know, enterprise version. And sometimes you have to instrument your own applications.
Uh, and all those things are difficult to justify and to do. They cost a lot of money. You know, we just, just I'm sorry, go ahead, jj.
Oh, sorry. I was gonna say, you know, we, we talked to Dan Glass on an episode not not too long ago, and he kind of talked about, um, that, and he said this not me. So nobody, nobody, like nobody be hating on me for this.
Don't hate me, I'm wrong. Please. The, you know, the developers are kind of like divas sometimes.
And you know, like if you walk into a hospital, maybe the doctors have expectations. If you walk into a university, the professors have expectations, but at some point it's like, if the two year old is screaming for ice cream, sometimes you just say no and you send them to their room. Right?
No, That is, uh, that is how security gets in trouble and that is why Chrisie was the second CISO at uw. I, I feel your pain and I feel your frustration because we are instinctively protective. We wanna help, we wanna explain and understand, but a lot of times that comes across as condescending or being a security Nazi or A C E O and it's really just a layer eight political discussion around what is the best way to balance prevention, mitigation, and detection and response.
And there's a lot of compromising and kind of horse trading going on. And I, I have not cracked that code fully. I've been in a lot of those conversations.
Uh, and in some cases I've wanted to say in some cases did say I told you so in a politically correct way. Uh, but it it is, it is not, It's not, I can't, I'm sorry, I I can't imagine You Can't imagine. No, I try, I'm, I'm working on it.
Um, yeah, it, it, it's still a tough issue and I think it will be for a while. Although I do think the telemetry that is available out there and the processes and tools are starting to integrate some of these workflow and observability, uh, processes that allow us to mitigate the impact of a single change. Ideally a initial access on a single desktop, initial access on a single server on the perimeter.
Uh, those are the types of things we really wanna look at is understand mistakes will be made and, um, what does it mean to really, uh, do good risk management around that? And, and that at the end of the day is good. Layer eight, looking at case studies relevant to an org that is of similar size and scale and maybe the same sector as the, the org you're advocating for, uh, security and stuff like that.
So a lot of layer eight considerations. But you do need to understand, uh, some of the technical workflow, uh, and, and kind of the people in the trenches doing to keep the business alive. I mean, I did a, a thing in, in Hollywood, uh, in 2017, I went to Hollywood, literally a Hollywood and shadowed people in a kinda non-descript building for, uh, three days and just took a lot of notes and I saw people getting hand delivered with a secure courier, you know, unwatermarked, full HD versions of billion dollar pre-release movies.
And the people in that building would take that, put it in a server, and then physically allow people to watch the movie. And there was a guy there whose job was to watch the movie and then score the trailer to kind of hook you in emotionally with the right bass and the drums and the piano music to get you to keep watching that trailer after the first three to five seconds. That's an art and a science.
This person been doing this for decades. And I was blown away. This person needed YouTube and other internet-based services to kind of jog his memory.
And who am I to tell that person? No. So we have to find a technical workaround between the laptop that is consuming the billion dollar asset and the laptop that is jogging the memory.
So you, but you really have to understand what is this person doing and how are they doing it? Sometimes you're literally just watching over their shoulder, asking questions, documenting processes, stuff like that. So it's, it's again, layer eight and, and empathy and understanding of, of where they're coming from.
That's a, that's a very nice way to wrap up. I pretend You, I did not expect you to be nicer than I am golf, but maybe you are. Maybe you are.
I'm working on it. He's people, he's seen the rejection. Yeah.
Um, but you know, I even, I've got a few takeaways here. Um, not not working in this space, but I think this has, you know, been an interesting, I think the, the, what do they call it? The, the Monday morning quarterback, like looking back on things, we have opportunities to look at what those indicators are, do a better job with the, with the telemetry coming in, do a better job, you know, triggering and bubbling up those alerts, getting the data from enough places and correlating them in the right way to, to get that visibility.
Um, and I, this is one of those things where I'm, I think we'll all look back and see meaningful opportunity. Cuz I imagine a lot of companies are dealing with this versus I think a lot of times like these weird one-off things happen and then we spend a lot of energy trying to figure out, you know, how to prevent What was the, uh, the, the marathon bomber that used the uh, the pressure cooker? Oh, the, The pressure Cooker.
Yeah, right. Like, okay, that was a one time thing and you can't just stop selling pressure cookers. So, you know, I think this though is something meaningful we can look back on and, um, this is a great conversation.
So thanks for sharing your knowledge with us and the four pillars and I'll, um, hand it back over to Mitch. Thanks for having me and, uh, my thanks as well golf for joining us. How do you say your last name so we know?
Sponsor. Sponsor. Thank you very much.
And if you're interested in getting a copy of JJ J's book Oh yeah, I have One. We will do a drawing for one if you want to hold up a prom over the book. There you go.
It's, it's beefy. It's got some great stuff. Adrian Adrian Sabia called it aome a Tome.
But it, it's good, it's good juicy stuff. It's good stuff. com and we'll randomly select a winner to get a, uh, copy of the book.
So look forward to it. Hey gal, thank you so much jj. Always fun.
Uh, we could talk about this topic for five hours for me, but it's, it's, what's interesting to me is that we're now talking about it and that's, you know, it's, it's been a destiny we have been colliding towards and it's now occurring. So it's fascinating to, to be part of that. So thanks again.
We will see everybody. Thanks for, uh, joining us for today's Uhso Talk. We will see you on another episode.



