The Storm Chaser – CISO Talk EP 28
CISO Master Class Pt. 4 – The Storm Chaser – Your Security Plan is Already Out-of-Date EP 28
As hackers become more sophisticated, we need to be able to keep up with new threats and reconsider our cybersecurity readiness. An effective strategy involves constant evolution and continuous learning. By practicing and failing repeatedly, we are able to test our security plans, learn more about potential vulnerabilities and be more prepared to effectively handle attacks. In this episode, our hosts Mitch Ashley and Mat Newfield are joined by Mike Rothman (Techstrong Research) and Miranda Ritchie (Orbia) to discuss how to test your cybersecurity readiness and what are the most effective methods of communication for organizations to collectively improve their security posture.
Transcript
Hey, welcome glad to have you back. Welcome to see so talk another episode of sisotalk matter of fact, this is episode 4 in our Master Series class lightning in a bottle trying to share experience and perspective information to up and coming CISO shared amongst ourselves and and kind of help the community grow and expand. So we have a great panel here today.
They're all season veterans been on the show before getting sort of the power panel back together here Matt. It was great to be with you. I have talked in a while.
You've been a busy man. I think we all have it's great to be back Mitch. I hope everybody is done really well over the last Month and a half or so, so it is definitely been a while.
And Mat Newfield meant you know, tell folks. I don't know if I ever give you much chance to really introduce yourself tell people about what you do. I I am what's known as the chief security and infrastructure officer at Unisys corporations.
So I'm the siso. I'm the CIO. I also Run Security Services and security engineering for the corporation.
Busy person busy guy well, so speaking of some other great folks. We haven't talked to in a while Miranda. Welcome glad to have you back tell folks about yourself.
Thanks Mitch. It's great to be back and it's great to see things kind of getting back into the swing of things after covid and everybody's travel schedules are really starting to pick up since we've last spoken. I think I think I have changed jobs since then, so I'm now the director of cyber threat operations at orbia where manufacturing company with plants in 41 different locations.
So it's it's a global operation. It's really cool to see Fantastic and certainly not least but but last on the list my good friend and now actually colleague in inside of tech strong. We've been colleagues for a long time Mike Mike Rothman.
You've I'm not sure if you left the dark side came to the dark side of you just always been on the darkness. It's all dark all the time. It's you know that so obviously very excited to be back on on sea.
So talk in my new role, right? So as with Miranda, I have a new job. I have joined Tech strong as Chief strategy officer as well as the head of text wrong research.
So we're gonna be doing some some really cool stuff. I mean and I'm just couldn't be more excited to work with my old dear friends Alan and Mitch and and really yeah, you know kind of continue to push the thinking forward in terms of what's possible as we start to intersect devops security and Cloud native infrastructure all of which seems Matt runs for basically. Company, so, you know, he's our guy that's our guy right there you're and I know we've got stuff.
So I as much as I would like to talk about me the whole time. We do have some stuff that we do need to get through. Yeah enough of me talking about me.
What do you think about me, you know the conversation? Okay. So here's our topic.
We're in episode four of our Master Series class, you know, Matt you we've talked about this whole often, you know the idea of planning and preparing and how important that is, but on the other hand recognizing that I like to say as soon as you hit save on any plan is already out of date, right? So because we live in this changing world and when it comes to preparedness for cyber attacks through response, you know strategies for for how we manage that ongoing basis and don't become complacent. Like I've got a plan practice good.
Let's move on to the next thing well wrong because you probably need to rethink the plan over and over. You have the Practical experience of doing that for very large organization. Yeah, look this is this to me of everything we talk about is is one of the topics that surprises me the most when I'm out in Market, you know the joke in the 90s and early 2000s that we all remember as the the book that would sit behind the head of security the head of infrastructure and their office and you would ask them if you were doing an assessment.
What do you do if whatever happens like hold on one second, they would turn around and they pull the book down and they flip through them like really is that how football games are played is that how a race car driver works when a surgeon is having an emergency they go. Hold on everybody. Let me get the book out and figure out what's going on and Google that let me well not back in the day.
This is all pretty Google but it still surprises me today that people don't realize we have to build muscle memory and we have to constantly fail in safe spaces and and nobody take that out of context. I mean in the task, right? You don't want to be failing in the real world.
We have Miranda here who is doing this for you know manufacturing and iot and Mike who's been in this field forever. And I do this across the world. It's really building out that muscle memory.
And what we want to do today is really talk about the Practical applications. You know, how do you do it? What is good look like and to dispel a theory a lot of people have which is when you practice and test your protocols for response that you have to pass.
Which I'm just gonna say it. I'm gonna give the answer away. If you pass you didn't actually do the test you failed already.
You cannot pass a pass is a fail stop it and I thought that would just be a really wonderful conversation because a lot of up and coming sisters don't know how to do this. They don't know how to talk about it. They don't actually know what we're talking about.
We're two aspects of that. Matt right one is managing up and the other is managing down, right? So when you kind of set up a test in your environment.
Intentionally to push on and really to find soft spots but I mean that's why we do those tests is to find soft spots to find holes in our policies to find operational, you know, kind of aspects that that aren't as tight as they need to be. So we're basically setting this up to really try to understand what we really have to work on that has to be communicated. You just said that right that has to be communicated to the team so that they're not deflated right and especially the younger and this is probably ages for me to say right but the younger your team right the more sensitive they seem to be to you know, kind of not being able to handle failure adversity Etc.
So us as Leaders right us to see those we need to kind of bring them through a process to help them understand that it is okay that if you're not failing you're not pushing far enough, right? I try to import that to my kids. I try to import that to folks that I work with and it still is just like oh my God, you know, I've never And then the helicopters come in and you know, I haven't got a call from any of these Mom lately, but I'm waiting right?
I'm just waiting for when that kind of thing happens. Matt's cracking up looking at me like you dang Millennials just can't take that criticism. I actually flip it around.
I've actually found in my experience that when we say younger and age they do handle it. Well where I actually find people handle it poorly is Mike. It's us Mmm, especially if we've been at that Organization for a long time, it's what do you mean you're calling my kid ugly?
I've done it this way my whole career, who are you to tell me Mr. And Mrs. 25 year old or 30 year old how to do things I was doing this in Mainframe days.
So it it is ages but on both sides, right? It's it is difficult and when Miranda and I worked together and we've worked together in other organizations, you know, if you would go in and do these tests some of the responses it wasn't the new person. It wasn't the older person that you know, the season person it was both.
They just couldn't get it and and you hit the nail on the head and Miranda. I'd love to know since she said you're new or in your organization how you're approaching this but it's it's that up and down and sideways Communications. Setting the expectations with a board your peers.
Your staff that we're going to fail this and it's okay as long as we stay in our our boundaries. So Miranda, you just started an organization recently. How do you handle that given?
Given your very stressful role. Well, I don't know if you also had this this sort of like moment of realization coming from a security company now into industry but one of the things that was super eye-opening for me was like, you know, Matt and I work together in a security company and an mssp. And so when we would practice things like Crisis management or cyber simulations, even when you're talking to other people in non-technical roles, they had a foundational understanding of what the heck you're talking about and why they're here when I ran a simulation with my new company in the manufacturing sector and you start pulling in PR and legal and HR and why am I here?
This is a cyber incident just go talk to the techies. And so it's not only just like do you have to bring them to the table and force them to test the plan because you have to kind of overcome that cultural challenge of like why why am I here? What's my role in a cyber crisis as well?
Because there is a role for everybody to play right if your company's name is in the news your PR person better know what they're talking about, right? That I couldn't agree. I'll give a fun story and and I may have said this in another episode but I'll keep it at a high level back when Mike and I were younger in the day.
One of the things we used to do in company was table tops and I'd been asked to go do a tabletop at a company. That was a multi-hour drive from my home office went in we did the table top. It went fine.
You know, we make phone calls to certain people and even on the voicemails we left we said things like as previously discussed. This is a tabletop exercise and then we would act like there was a breach went home afterwards. I got a call from the CEO that evening and after string of vulgarities.
He told me to get in my car and get my blanket blank blank blank back up there. And you know as a younger engineer at you sit there and you're driving and there are no cell phones and you're like, I wonder what I did. I it was a tabletop exercise.
Pull in a lot of cars at this building I go in lights are on their boardroom is filled with people and I walk in there like it's about time. He did a press release. On a breach because of your tabletop and I was like, whoa.
Who's he and that's the head of PR and he goes, yeah, you left me a voicemail. I'm like the one that said and I read out he goes. Well, I wasn't really listening.
I just heard the end and I did a press release and the CEO is like, well, what should we do? And I'm like well fire him because he broke not only did he not listen to the voicemail, but he broke the protocols we had developed. Because he had no muscle memory.
He had never done it before and then we had to figure out how to claw back a press release in the age of print. and he trying to avoid me so it goes far what course stories that I've heard but but these things happen and again we were able to do it and you know, they it all worked out but this is why practicing is so important because if otherwise people don't know what to do, I mean In the Heat of the Moment In the Heat of a crisis when Miranda hires a red team or a purple team exercise People think they know but you don't and it doesn't matter what analogy you use you could pull down, you know, a sports analogy. You could pull down a race car analogy.
You could pull down a chef analogy, you know, if you're sitting on the line in a restaurant trying to cook meals on a Friday night and you know, the beef stroganoff comes in you're like, hold on everybody and you got to pull your this is a problem. You have to practice and practice and practice and you have to fail and make nasty stroke and off many many times before you can move on to the next dish. So are you seeing that right?
Did you pass your first exercise? I mean for me, I don't know if there's ever really such a thing as a pass or fail. I think there's Lessons Learned every single time.
Right did we do amazingly no, but I think that helps to uncover, you know, some of the issues in advance personally. I'm a big Advocate too of not just relying on tests like testing because people know when it's a test the pressure even if you say act like it's a real world scenario the pressures off to an extent and so one of the things that I think we did really well and then I'm trying to instill in my new company is you know, use your crisis plan for watching warning scenarios as well. You know, so when log for Jay happened when the Russia Ukraine war broke out right were we directly impacted at the time?
No, but much like you would have a tornado warning if it's coming inbound, right? You need to you need to shore up right? You need to put out your sandbags and get ready or whatever you guys do when there's a tornado.
I live in Virginia, you know go to the basement. But yes, we start we I want to really want to instill The Habit. Of using this is a living document.
It is not a plan to me that sits on a shelf in my bookcase. It's something that we're going to be using multiple times a year. Even if it's a real real scenario, but it's not directly impacting us at the time, you know, or watch or warning situation.
It's funny that this series is called lightning in a bottle because I have a funny story and a prior role. We actually activated our crisis plan when lightning struck our data center. Which is not a cyber crisis, right?
Like that's not a cybersecurity event, but we were so in the habit. We had that muscle memory that we knew exactly who to call what Cadence to establish how to define what constitutes a crisis so it was muscle memory and that, you know, even if it's not directly a cyber impact. You can use the plan for multiple things, right?
So still getting back to the idea of plan and the plan. Let me kind of poke at something that that Matt had, you know kind of started off with which was how old school it felt to actually pull out the book and start coming through the book right and and doing that kind of stuff. But I want to highlight the importance of documentation of a lot of these things for a lot of reasons, right and and one is you're gonna have people that join the team they're gonna need to understand what the expectations are that needs to be documented.
The other thing is you can't you know, you have to learn you have to evolve in the best way I found to do that is actually the right stuff down and to actually make conscious changes as more brand a fan our right some of our stuff just didn't work. Right and if you just leave the old stuff on the Shelf, it doesn't get updated. So so that documentation even though you hope In the Heat of battle, right?
You're not pulling the book that you do have the muscle memory that you know what you're supposed to Be doing having and gone through what is an intentional process. Right? I use that term a lot right intentional process for how you want this motion to work document it teach people what it is practice it practice it practice it some more and then change it based upon what you learn but that documentation is absolutely critical.
Yeah and really quick my guy. I thank you for that by no means was I say don't write it down. You can't audit what you don't have documented and you can't audit that which is not written down you have to have it there.
But if the only time you look at it is when lightning strikes your data center. Try to have a problem, right that's really my point. You know, I think the mother's not one more thing Mitch before before we kind of go ahead right into that because I've been talking to just a lot of people right now and I'm sure like, the two of you have staff resource allocation problems, right, you know kind of not enough people all that other stuff and and what we're sitting here talking about is documenting and working and practicing and doing that and how do we find the time right?
How do we find the time when you know, somebody's work Q is overloaded with all the you know, kind of Active cases they have to deal with when you have you know, work that that happens in terms of upgrades and all these other things that we have to do to keep our controls, you know, most current, you know, again, we can talk about it here from our school library Tower right but in in the world right folks have to figure out how can I carve out this time in order to do what I know what I need to do, but it feels really hard to do when you know folks are working at the red line anyway. I was thinking the modern parlance for this would be run book. So what we would call, you know documentation.
This is very much a continuous improvement process because as you go through each time that you do it, right you're looking at what went. Well, what didn't go well, what do we need to improve and sometimes that means not just your skills and muscle memory. It's you know what this is kind of getting out of date this process of that.
We have we need to modernize this part of it or the organization change the structure whatever it might be we've changed systems. We need to plan for some obsolescence and some learning and Improvement. I think the hardest place to be in isn't writing the first one.
I had a situation where I took over at it organizations CIO and the the response plan was like eight years old and it was still talking about calling trees. I felt like I was on a Prayer Line, you know, and so this person calls this person. This guy was like, oh my God, we're playing telephone and in our response plan.
It was just start over we couldn't modernize they had there's some good stuff in there. But that I think that's the tough spot is like you're so far off. Let's just reset and get and get back.
Right? I think that encompasses also what Mike is saying right the problem. I think we run into and even with the current Staffing crisis that we hear about, you know, it's not really current we've been talking about the shortage of it and security staff for a very long time.
Right? I mean this isn't a new problem. It is a difficult thing.
So you go into a new organization Miranda realizes I've got to write all of this new material then I have to train all this new material or Have to in Mike has to you just started Mike. I'm assuming you're going to want to redo things as you come into that organization, you know it if we are pushing all of that work effort down to our staff without giving them relief of in some way. That's a problem.
And I think it ties to the question you started with which is being able to have the conversation up. And side first getting your CFO or whomever runs your financial party organization to truly understand the importance getting your if you have an operations executive who is constantly on you going. Hey, your people are not you know, 172% utilized.
You get on you know, you got to start building that in so they realize that. the time needed Is worth slowing other things down? Because we will never have enough staff, you know, my former boss here at Unisys used to say it all the time in budget season.
People would ask him. Do you have enough budget to get what you need done in the security space and he was my boss and he started every time he would laugh. He's like, it's impossible.
You can never give me enough money to do everything that me that I want to do for this Corporation. It's impossible. We would be out of business tomorrow because I could spend money upon money.
It's just not possible. So you have to start making those trade-offs and you have to be open and honest with your team have to be open and honest with your leadership of what it's going to cost and make them be involved. I mean your point Mike about kind of carving out time.
I think just one thing that that has worked well for us in terms of like a really simple practical application is and all kind of ties into max point about auditability. Right? We have our plan.
We know that it is never going to be finished. Right? There's no such thing as a completely finished plan.
And so one thing that we've started doing is as we find things that need to be changed. We just submit a simple blur right what needs to be changed where in the document is it who's submitting the change and when and then quarterly we go back through when we issue official an official revision, right? And that way we have auditability as far as what the plan said On Any Given date we have traceability as far as who's changing what and we don't have just a bunch of cooks in the kitchen trying to make edits to a document, you know that they need an uncontrolled fashion.
So I know it's a little thing but like it really does help you to carve out time when you have that scheduled quarterly update or monthly update whatever you choose to do. Yeah, you know so funny remember back. The day I mean this was a while ago, right when Google first started and already started hearing about their you know, 20% time that their engineers and employees could go and just work on, you know, kind of side projects and you think yourself God they must be in a really great business if they can have 20% of time just to work on, you know, folks side projects and and that kind of thing but when you think about, you know, kind of managing your work as a leader in this space, you have to think that way because whether it's a strategic project whether it's updating the policy documents, whether it's you know going to class to make sure that you're folks feel like they're being invested in them as practitioners and them as people I mean if you've got folks scheduled out for a hundred percent, if not more the numbers just don't work, right so and then it gets back to the managing of expectations.
And and I know we keep getting back to the same thing, but a lot of people show up and say, oh I want to be a sea so and then they realize oh my God, I'm not like security anymore, right? You know, I'm just talking to folks and I'm writing stuff down and I'm sitting in meetings and I'm I'm going to do site visits in some friggin manufacturing place in Eastern Europe and you know an idea that this was what I signed up for right and and that's the job right which was what was so interesting when I first introduced pragmatic CSO in 2007 because it was the first time somebody says wait there's a game and I'm supposed to be playing it. It's just like yeah, man, everybody every other functional manager in a large business understands.
There's a game except the security person, right? So it's one of those things that you know, kind of it. It's really an adaptation when folks get into this position that they may not be ready for it.
Honestly that they may not be wanting or like but that's what it is and resisting it will just get you into trouble. Look and it also you gotta step back and really think about how you are scheduling right? I mean if you if Miranda in her role has her team and she and I'm gonna make the joke and we don't need to go down the what what's a work week look like but 40 hours you were booked 40 hours and I need 40 hours on you know that typical job description stuff.
I agree with you. You've missed the point. You're never gonna get to these other things that need to happen and you have to make sure it's broken out hundred percent utilized in security may only be 85% Because you need the other time to do stuff.
But again that goes back to communication and being able to understand get it others to understand what our world is really like because it is not just ticket flows and ticket queue. There's something really. Oh, sorry guys.
Oh, no, go ahead. I wanted to bring introduce something else. So rest.
So wrap that up Miranda. I was just gonna say make the comment that it's one of the reasons why I love this field, right? You're building the plane as you're flying it, especially in an immature company where there isn't a soft necessarily.
You've got to handle those tickets. You've got to watch all the alerts, but you also need to develop a sock strategy and you need to do you have to do both right? So I think it's fun personally.
I like building stuff. It is a boy and it's perfect for what I wanted to introduce next. We haven't talked as much or much about the introduction of change into this, you know, the best suddenly we're all talking about soccer supply chain or supply chain Integrity as an issue Matt, you've talked previously about changing role to see so that you know, I'm not managing my Network anymore.
I'm managing, you know an outsourced or I mean a service or suppliers, you know more of a shared risk model which I still own all the risk for but by the way, so it's also in the case. It doesn't just repetition. It's you know repetition of change because we want to constantly introduce the new changes the new threats the new business our operating whatever those factors are that seems to me to be the the most disruptive of this because if it stayed the same we could get really good at it, right?
Well, it's that's also the hardest, you know, as we talk about practicing and testing. That's also what makes this so difficult because when you control your world and if you think of the old school four wall tests where bad thing happens in my infrastructure. I own it all I can go to the CIO I can go to the head of it.
I can go. You know, Miranda was saying I could pull in my PR person in my legal person and a lot of Corporations the pr persons the third party and the legal team is all outsourced. And your ISP is another company and most likely some of the server infrastructure you're talking about.
Well, that's a that's a third party is well and who we Outsource this piece and this piece in tying that all together that's key. And that's why having a documented plan is so important in practicing is so important, you know, we we've run into situations here where the failure of a test wasn't people not knowing what to do the failure in the test. Was that the person or organization that we relied on that is not a bad Unison employee was unresponsive.
We have an SLA we have requirements. They didn't respond. Well, they are no longer going to be in our critical chain.
It's just not going to happen. Especially if they were pre-notified. We're going to be doing this and it changed our whole tprm program, which is another episode that third-party risk management program where if if one of our main suppliers fails one of our tabletops, They can no longer be considered a tier one.
They're out. Right so you can start really building because you are right. It is so few people in one of our crisis tests are actually badged employees.
Are you all seeing that Mike? I mean you do a lot of research. Are you starting to see that as well?
You know. I mean, I think that we're we're in a situation where we are an independent an interdependent Society right? And and you know, we can talk about ecosystems about but you mentioned my server somewhere else right my servers in the cloud, right and all my data is in a variety of different sass players and and I've got to understand how this attack has proliferated.
Where are they coming and it may not even be within my stuff right? So we would normally just get we would see something because we would be able to track. You know, remember that old school, right?
We be able to attract Network Telemetry and traffic and we would know something bad. We don't get to see that stuff anymore. Right?
So we've got to get a lot better at you know, the detection side. I am but our response motions have to factor in the reality that I may have to shut down Office 365 for a certain amount of time until I figure out what the hell happened and that means my business stops and I have to be able to again communicate up to manage expectations that says by the way in the old If I had a problem with you know an email attack in Eastern Europe, I could shut down Eastern Europe. That's not an option anymore.
Right? We have everything in the same place or Salesforce or work day or whatever big SAS player you use the fact is this is so interdependent. We have to have plans for the fact that I've got to be able to remediate in these platforms that I don't control and that is just again what you talk about things getting more complicated right?
I miss today. I'm like, oh crap, not only, you know, we talk about supply chain, and you know, I'm getting all these libraries and I'm building all these things, but me now I've just got, you know, I'm depending on all these other, you know, kind of organizations in order for me just to figure out if I lost data right if I lost data. I miss the days of being able to call Josh and the data center going unplug this port real quick.
Thanks. I'll be I'll be over shortly. Just just Pull it out real quick.
And I know that segments offline now, you can't do it anymore. You're right. It's the the way VMS work the way the virtualized environment Works getting something off of a network is not easy.
I mean no Blinky buttons. No Blinky flashy lights to say that there isn't and that's kind of one of the that's why one of the things I kind of council folks to do is um, you know, I mean not literally right but for verbally burn up your plan every year and if you were to start from scratch, what would it look like because I'll tell you if you're 90% Cloud the plan you build six years ago, you know, when most of your stuff was on brand, I mean, you know, that's the case where you probably do have to burn it up because you're motions are just totally different and it's a good exercise right for the leader or the security team to go. If I could zero this thing out I didn't have, you know, kind of install base and constraints and budget.
What would this thing look like and then you can start to pick from those things and say, how can I start to get there and that starts to develop your strategic roadmap, but without you know kind of being able to do that. You just do more of what you've always done even though the underlying infrastructure has totally shifted under our feet and in a lot of cases. You're so busy.
You don't even see it so that to me that's a very, you know, productive exercise or whatever. It is, right September, whenever your fiscal year ends or whatever when you're budgeting process starts, I don't care right but at least once a year go back in there and zero it out and just say listen, what would we do if we could just start over again? We bring up a really good point like but in that same vein, I think people are starting, you know, the industry is coming around to accepting the fact that like your incident response plan needs to be updated.
Annually. You need to test it annually, but they often so focus on the response element, like are you also testing how capable you are of actually detecting something in the first place. This is one of the things that I would do, you know coming from an mssp any time a client told me that they had a pen test or they did a red team exercise.
I wanted to go back and see what percentage of the kill chain did my team actually detect and if there were things that were missing, you know, we only can alert on what we see. So if there's elements of the text stack that we don't have visibility into We're Not Gonna alert on it and I think that's often a thing that people Miss we actually run back and did an exercise recently mapping our text back to the miter attack framework, right and we went through each TTP and said, Could we detect this with the technology and the infrastructure that we have today? Yes, no, and we developed a heat map over time and said we could probably detect 60% of this or 20% of this and here's our weak spots that can help spur additional investment too.
In terms of you got to build out the tool set that you're using in order to start on this in the first place, right? I gotta tell you because I love what you're doing. I couldn't agree with it more and now you can focus so you go through instead of you running tests, because you said at the beginning Miranda and I loved it.
It's it's not always about the test. But so now instead of you running a test on an area, you know, you only see 10% on why bother, you know, you didn't need to be tested for that failure. If if your team goes we would see a hundred percent of the time or 96, but that's you can start focusing these things because now you can prove yourself.
Yes, everything is really working especially using third parties, but doing a map to to miter whatever framework you like. I I love doing that as long as you get that validation at least third party. I've tried that an organizations and like we see everything and you're like really And so what he and can we all just take a second and and be thankful for the fact that a couple years ago.
We got the miter attack framework, right? Because what that did is that allowed us to standardize our vernacular for what these ttps look like before you had to deal with some let's call them overly priced responds firm that you know kind of had a lot of this information and and they would help you map it but you know most organizations that was Out Of Reach for what they had to do unless they could pay a $250,000 year retainer which not a lot of organizations can do so what I found it and even better A lot of the monitoring tools that we're using now are mapping their findings to the framework. So you can start to really pinpoint not just you know what I have coverage and that's a tabletop Marina and that's fantastic.
Right? But in actuality you can start to see the Telemetry that's coming in and and identifying where you may have AppSec in your stack not based upon your tabletop based upon the data, right and and that just it really changes everything from the standpoint of helping folks understand how many different ways you can get hurt or before it was really only the, you know, the experts right, you know kind of the lean forward folks the folks that really understood Enterprise security and now this kind of tool is accessible for all and and that's really just the huge gift to our community and most of them all be it don't understand what that means and don't understand it use it but at least it's out there and it's something that you know, again, we can start evangelizing and the whole industry has been um, we're the fact that how powerful that is. Now, they've got one for containers.
It really is. I mean, it's it's just fantastic from the standpoint of you know, somebody that's been struggling to help organizations that don't know what they're doing to sort of know what they're doing for a long long time. I think a collective moment of thanks for miter.
One thing that I am like super appreciative to is that they not only you know are standardizing on a set of terminology and and codes that we can use to talk about ttps. But they also go out and rate the products, you know, you get hit with so much vendor marketing material and Gartner reports and market analysis, but I want to see how did it actually perform in a real test and might have publishes all that. I'm not gonna name any names but you can go out there and see which vendors are doing a better job detecting the entire attack framework than others.
That's first it's great. Yeah, and especially when you move to that automation, there are also able to say yeah it detected and it can do these things and these scenarios instead of it being. Well, that's what the salesperson told me.
It could do. No. So before the end of this episode you're watching you need everyone needs to go out on their Twitter account and thank miter.
So just tweeted get it over with just we really the government doesn't do anything for us, but you know, and there are Cases where that kind of funding has been extremely helpful. So make sure you spell miter correctly. Otherwise DeWalt or some tool manufacturers.
You'd be like, I'm not sure. All right, it's not my dream one you when you talk to Europeans they call it my truck. I'm like, what are you talking about my truck?
I don't know what you're saying. And then I'm like, oh lighter got it. You know, it's just I was I thought that was very funny because it wasn't just one.
It was all of them that I supposed. That's how they pronounce it because I want to introduce something that I think has the potential to kind of really up into all of our worlds and and here's what I mean by this not to be, you know, I'm not I'm not saying like, you know, something's gonna in the world they're honest, but What's happening in whether it's the infrastructure stack and the in the provider stack the software world, you know going to Cloud native and devops and all these processes. You know, I've come to this mindset of I have to stop thinking of things that are in a state and remain in a state and think of the entire environment.
The ecosystem is a fluid is constantly changing any point in time. You might even might dip into it even why you have while you're dipping into it. It's changing on you.
So it how do we create processes and responses to the apis that I might be using or might have created in our development team. So, you know half a dozen wherever they are all over the world that could have changed, you know in, you know, five minutes ago. I'm using a brand new API.
We just created in something that got pushed out in a couple of microservices and this app and this region it's not a static world that we live in that we can say. Okay. This is what it was like let's assess what happened or how do we respond to it?
How do we deal with the challenge like that or do you buy into that premise? Maybe that's just how I view it. I I mean look, I'll jump into it.
This is where having it looked. This is the core of the company that you all are a part of this is For what you're saying this is why sdlc is so important to me right that documented flow so that you can have a way to go back and figure out what's where I mean Miranda talk to the beginning of this about log for Jay. I mean that alone should have been a wake-up call for every single organization on the planet.
I can't tell you how many times when we were doing our analysis we would go through and we'd be on the phone with major vendors like we're not susceptible. We don't use that and my team was like really because we ran these tests and we got into the system. How are you not and they'd hang up they call us back.
They're like, yeah. Whoops. We do have that thing that's sitting here, but you don't need it.
So we're gonna remove it in the past that's gonna come out in four months and you know that that to me is about really having a software development life cycle having Books that come out of that sdlc that go into your IR plan because for us we've tied that all together. If we have an incident, we're able to go and look and see in our documentation before we start just running Mass scans against, you know, some piece of code and you know spending the money on a you know vendray or a vendor B to go look or use licenses. I can now look inside of these books that we get out of it.
It becomes very powerful but to your point it is important because you could launch something today think it's a greatest thing in the world and tomorrow some Minecraft game or breaks into it. I'm not trying you that's gonna happen. Of course.
I think you have to expect that's gonna happen. You know, we always in why the agility is so important and one of the things that's been cool about spending a lot more time with devops folks and continuing to spend more time with devops folks is that one from a management standpoint? They understand the idea of unplanned work right and and managing, you know kind of the fact that you're going to have issues and and you know kind of back to the you know thing we were talking about 20 minutes ago on this front but also from a building in a security testing mentality to every stage of the development are things that we insecurity need to learn right and some of the more advanced groups that I've worked with have a what they call now a detection engineering team, right?
It's a software group that is building detections that they ultimately put into their monitoring environment, but they run it through pipeline, right they burn stuff in they monitor, you know to see what happens. They they Unit they go back they you know in their constantly testing this stuff for how it works and it is a software discipline and again when you when you talk about talking to some folks that don't know what they stepped into. It's just like oh wait, so I'm not managing the firewalls anymore.
I actually have to spend all this time with these other people. Oh and I've got to manage software people too because I've got a bunch of folks that are scripting out things in my in my infrastructure and now I gotta understand all that stuff. So the skills constantly evolve for senior security folks and and it gets back to you know, we talked about the importance of investing in our people and and saying them off the training and carving out time and protecting time for that.
It applies to sing to us. Right if we're not starting to learn about some of these motions and we're not working with our you know, Dev teams and the CTO group because they're starting to you know, my great to you know, these types of agile, you know infrastructure environment. How are we going to protect it?
Right how we're going to protect it? You know, I think the thing I I get out of this that I think the audience needs to grasp is for a lot of organizations the thought of having your CTO your head of engineering is part of your corporate crisis as part of your incident response program is not even in the realm of what are you talking about? And I think Mitch what you've brought out and I think it's a really good point is they must be they must be because if you don't have the books if you don't have an SBOM a software bill of materials, if you don't have a program around that you're not that different from most organizations on the planet, I mean most organizations couldn't spell ass bomb let alone have an SBOM that's worth its weight in anything.
So you have to have the people who are responsible for that tied in so you could be working with them on a regular basis because I mean, let's be honest coding if you do a lot of your own coding and your organization for your own products and your own stuff Well, there's there's where most of your issues are gonna be. Well, we're coming up on that. 2 so it can continue this more.
I was just as wrap up with a parting thought. I know there's we've really emphasized the documentation in the process and building the muscle memory. It's a Mike you want to anything you'd like to also get out there that maybe hasn't been said yet.
I don't I mean, I think we covered a lot of really, you know, kind of good and important stuff. But but you know to me that the real pin point on this is as Leaders, we have to continue to evolve we have to lead our organizations in terms of you know, practicing and building a culture where you can experiment where you can fail where you can really push what we need to do because our world continues to change. I mean, it's just fundamentally different than when Matt and I work together what 20 years ago yikes, um, maybe longer, you know, and it's different than it was 15 10 5 and it'll be different two years from now based on how quickly things are working.
So if we don't have that mentality and we're not bringing that to the leadership of our security group. It's just not gonna work. I mean, it's just not gonna work.
Miranda how I think I think that's a very good point and I think the other thing that I would add to it is just when you're considering how to test your plan you need to think of off the wall scenarios, right? Not just tabletop sizes red team exercises where it's maybe unknown or unplanned or you know, those kind of watch and warning scenarios that the mimic real world or that are in fact real world scenarios. So I think you just have to hit the testing from multiple different angles.
Otherwise, you know, I'm going back to our other comment about testing response and testing detection, right you're testing plan needs to be more than just an annual exercise that you go to. It's not a fire drill. It's it's something that you yeah, like you said you have to develop the muscle memory.
Okay, Matt, bring it home and I'll wrap it up for us. No problem. So one of the things we say a lot in Cesar talks and and I say a lot out there is is you're hearing this.
You may be thinking to yourself. Well, I don't have that plan. I I've never done a tabletop.
I've never thought to map something to I have no clue how to do all that and what I would say to those that are listening to this that that may not have really an understanding where to begin. You don't start with the blank piece of paper. There is enough material on the internet and there are enough of us in Industry that want to help right.
It is not rocket science and it's not something you should do as an individual sport. Let us help you even if you don't have budget to hire a big consulting firm, you don't have the money to go out and and buy all of this stuff. There are plenty of groups within your region within your industry that you can utilize to help you get going because again, This is a team sport and no matter what company you work for.
We're all on the same side of this right. We are protecting ourselves from an adversary or group of adversaries. So, you know reach out to us, you know, we can be found all over the place, you know on social media reach out to others in industry and and don't start from scratch.
Awesome. Thank you. Those are all fantastic points because sort of cherry on the top.
I'll add to this is this Dynamic nature of our environment. I think we need to start thinking about continuous response not incident response. It's much easier to to grab onto something that's in motion and execute the things that need to now happen in addition.
What's already happening as opposed to firing up the old generators, you know and kind of getting the flywheel going to to get this up because things are happening that quickly. So if we have this built into our processes, if we have the response built into the flow the workflows that are happening whether it's across the software organizations across the dynamic infrastructure. That's also software or processes themselves.
We can respond much more accurately and quickly frankly and adjust to what's happening in the moment. So I think that's the world we are already are in and we're figuring out how to adopt you so consider that as you're as you're updating your writing or starting your incident or you're continuous response, So, that's the great. Thanks, Matt co-hosting here today.
Of course. We're great to have you back again Miranda Ritchie, and hopefully we won't have quite as long a gap to get you back on the show. I know you've been busy with starting this new job, and we're very happy for you and Mr.
Rothman great to be working with you and talking devops and Cloud native and cyber security. You know, it's just mind expanding. So thank you to your audience.
We have another episode in our Master Class series coming up. So please tune in and thank you for watching. Take care everybody.
Bye.



