Alexandra Landegger, Collins Aerospace | DigiCert Trust Summit
Alexandra Landegger, the CISO at Collins Aerospace, reflects on her journey and the evolving role of CISOs. She highlights the changing landscape of cybersecurity, where CISOs are now responsible not only for IT security but also for the security of digital ecosystems, operational technology, and supply chain. The conversation delves into the importance of digital trust in the aerospace industry, acknowledging the critical role CISOs play in ensuring the safety of thousands of engineers and passengers. Alexandra discusses the challenges of preparing for the post-quantum cryptography world and emphasizes the need for crypto agility.
Transcript
This is Textron tv. All right, everyone. Hey, welcome back.
Thanks for staying with us all day today. If you have, it's been a great day here at the Las Vegas Resort world for DigiCert Trust Summit. We have our very last guest of the day, and I, you know, in many ways we might've saved the best for last.
Let me introduce you to Alexandra Landecker. Alexandra is the CSO at Collins Aerospace. Did I get that right?
You did. All right. And, you know, feeling the pressure after that setup.
Well, No. Well, I didn't mean to do that. I apologize.
All good, all good. I'm, I'm looking forward to it. So, Alexandra, look, I, you know, you're talking to someone who is here as the rise of CISOs came about, let's say around 2005, 2006.
We started seeing them, and it wasn't always easy. I had a lot of friends who were CISOs and got the heck out because it was, it was a thankless job. In many ways, it's Destined for burnout.
Yeah. Um, but I'm always thrilled to meet CISOs and, and talk with them. Let, let's hear a little bit about your own personal journey, if it's okay.
Sure. Would love to share. So I, um, went to Georgetown School of Foreign Service, and if you had asked me back then, there is no universe where I would've wound up in, in cyber.
Um, so really, you know, started with geopolitics, then was offered the, the chance to work as a consultant with Booz Allen and focused in on risk analytics. Mm-Hmm. For everyone's favorite government agency, the TSA Mm-Hmm.
And then all of a sudden left here, You all have a job to do, You know, we all have our first jobs. Right. And then from there, had a chance to work, um, across a number of different US government customers as technology matchmaker, what will Body Armor of the future look like for the Army war fighter?
Some really cool stuff. And then all of a sudden there was a chance to work with General Motors on their first vehicle cybersecurity program. Oh, wow.
And again, cyber, I didn't realize it felt like left turn, right turn, left turn. And all of a sudden, once I got into the role, I realized geopolitics, risk, analytics, technology, destined, all comes Together For the cyber physicians. Right.
So, helped stand up Booz Allen's automotive practice and aerospace practice, which is ultimately what landed me, my, my role here at, at Collins Aerospace. And How long have you been CSO at Collins now? Uh, A little bit over three years.
Wow. Wow. That's, that's, that's long in the tooth know cso.
Yeah. I, for the game of musical chairs That we play, I don't wanna give you any bad luck or Oh, You know, Justin, I know. I count my day.
That's, that's pretty darn good. So I don't know if a lot of our audience is familiar with Collins Aerospace. Why don't you give us a little background there?
Absolutely. We're one of those companies that you regularly benefit from our products, but don't always know exactly who we are. So we're part of the RTX or formerly Raytheon Technologies entity.
Um, and we are the largest business within that. We make everything on airplanes, nose to tail, except for the engines, which is our, our sister company, Pratt and Whitney. Mm-Hmm.
So whether it's the HVAC systems, the toilets, the coffee makers, the avionics, the air-to-ground network communications, truly everything on the plane, as well as a number of, of different, um, technologies into our, our sort of space industry as well. So you, you guys are the third party suppliers to the Boeings and so forth of The world, the Boeings, the Airbus especially. Yeah.
Yep. Uh, And, and I think, you know, that is, I think people get that in cars. Mm-Hmm.
Right. Mm-Hmm. That the car companies assemble cars.
Yeah. I don't know if they realize that the plane companies assemble planes. Mm-Hmm.
They may design. Yep, yep. Absolutely.
There's design and there's flow down, but really the assembly and, and frankly, sometimes even we are the assemblers of a, a system of systems. Systems. And then that becomes even, even a system of systems, of systems as it makes it up the chain.
It's crazy. That's, that's interesting to know. And where, where's Collins based?
So we are headquartered in, in North Carolina parent company in, in Virginia, DC area. Okay, got it. So still that government sort of roots Area.
Yep, yep. It's all coming full circle. Yeah, I see that.
So here, you know, if we want to talk about an industry where digital trust Mm-Hmm. Uh, plays such a role. And we were talking off camera, my friend Chris Roberts, that's his name.
Oh, that's, yep. Chris Roberts. Chris Chris was pretty well known for hacking into a plane from their infotainment system.
And you know, how much access he had is up for debate. I've spoken to Chris about it, but Chris is now the, uh, CSO at a company, I think it's called Boomer. Yeah.
Something Like that. Something, they're outta Colorado and they're making civilian supersonic passenger jets. Mm-Hmm.
Which is pretty cool. As I, I grew up right outside of Kennedy Airport as a kid. Oh, Neat.
And just watching planes land. Well, the Concords, we didn't watch them. We heard them.
Yeah. That's awesome. You heard them a lot sooner than you saw them.
I believe It. And they weren't, you know, at that point they weren't sonic booming. Mm-Hmm.
But they were so loud. Yeah. They were beautiful to come in though, because, you know, with the nose up like that, they, they were gorgeous.
So I, I can't wait for supersonic jets, but you got me it, it's that easy to get me, especially this time of day. Oh, this time of day, it's time to chit chat. Oh.
But anyway, you know, this is a, this is, this is an industry where we can't afford a mistake. Mm-Hmm. One mistake can be a fatality of hundreds of people.
Mm-Hmm. And, you know, digital trust here. And, and, and we live in a world of where there's bad people.
Yeah. So, as CSO at Collins, I mean, this is an awesome responsibility, right? This is a big kid job.
Yeah, that's absolutely right. And I mean, coming in and understanding the, there's so many layers and it's almost, we're, we're at this point where there's this convergence of cybersecurity across domains. Mm-Hmm.
Traditionally the CISO reported to the CIO, it was about protecting email and servers, networks, back office. It now all of a sudden, we're also responsible for protecting the digital ecosystem of our products. Yep.
The ot, the operational technology, factory environments, lab environments, even once things get shipped out the door, pretty much everything is digital right now. You look at Breaks, it's the avionics, it's about supply chain, all of it. All of it.
Yeah. No, it's, it's, it's a, it's truly the software supply chain. Mm-Hmm.
We talk about things like SBOs Mm-Hmm. And, and stuff like that. I mean, this is, this is now part of your job.
Yep, Yep. Really, at, at the end of the day, the, the CSO job is, is about customer trust. And, and so it's, it's absolutely crucial to understand what is the mission that, that we're serving.
How can we collectively between product ot it, um, really drive that all the different intersection points because our adversaries don't care if, if they're hitting this product or that IT system they want into the network. And then being able to traverse across, just find that entry point in and then get to where you're really trying to go. So how do you look at this as a full ecosystem and really drive down risk in a, in a systemic way?
And the, the key to all of it is, I can't do my job alone. It is not the job of the CISO to do all things cyber. IT is together with the rest of the business, building security into the DNA of how everyone in the business operates.
I get it. I get it. Um, what have you learned here today?
Who, What have I learned here today? Man, there have been so many fabulous hallway conversations. I, I think one of the, the really most interesting ones is, you know, over the last couple of years, we've all been limited differently around travel or, um, being able to get out to conferences.
And so how do we spark learning into our enterprises? How do we take what, you know, there's only a few of us here the next couple of days. How do we now take this back in, into our teams and, and really cascade that learning?
Mm-Hmm. Certainly. I, I think that those were some fabulously interesting conversations, but, um, really one of my big takeaways, um, and I know Jason was on the show earlier today.
Um, understanding crypto agility, i, I think is the other really hot topic of the moment. Mm-Hmm. Explain what you mean by crypto agility.
So the ability to, you know, the world is changing around us rapidly. We are getting rapidly to that. Rapidly, rapidly.
We are getting to that post quantum cryptography world. And so how do we create that foundation today so that we are ready for the changes that are, are coming in the next 3, 5, 10, 15 years, depending on who you talk to here. Right.
But it, it really, it, it's interesting because crypto agility, while it sounds really cool and exciting, it's about the basics. What's your asset inventory? What's your crypto inventory?
What do you have? Where as long as you've got that understanding now, and then you start thinking a little bit more strategically around how do we build things in a way that we're preparing for the future? You gotta start with that 1 0 1 though.
I, I, I don't disagree with you at all. I think one of the, and it's something I learned here today too, just sitting here talking to people is that it's one thing to say, Hey, don't sweat it. We got a new algorithm.
Mm-Hmm. Or three. Yeah.
And, and we're going to, we got, we, we got this post quantum stuff. Don't, you know, solve, we're just gonna say, we're just gonna change algorithms out in the hardware stuff. We're gonna convert it to software anyway.
Don't worry. Mm-Hmm. And then we find out, well, you know, these algorithms, uh, if we don't have a crypto, if we don't have a quantum computer to run 'em on, it's like a 10 x performance hit.
Mm-Hmm. And when you're talking aerospace systems where there is, you can't be Doing that. Limited.
Yeah. I mean, it's, you can't afford the, the Complete time. No, that's too big a it.
So how, you know, so, and I hate to be a glass half empty kind of person here, but my glass is almost empty. Um, that, that's a problem. We haven't, it's, it's not all, you know, it's rainbows, sunshine, rainbows, unicorns, right.
Rainbow. Yeah. But you know, your glass, technically there's water and the upper House, there is some water in it.
Air it was full at one time. Air. And it has, Air has, there is something everywhere.
There is. It's, yes, There is. And that's really the, the CISO's job right now is you've got thousands of engineers in my organization scratching their heads.
How do we stay compliant? How do we drive security? How do we maintain privacy but also deliver excellence?
Yes. Deliver next gen capabilities. And if you just approach it with that glass half full mentality, we're not gonna get where we need to Go.
No. I, I think, well, and I think that's been a problem. It's security for a long time.
Mm-Hmm. Is we tend to focus on our failures. Yeah.
We're a team of No, we're a team looking backwards that we react Well because one never says, Hey, great job. You didn't get breached today. Great job.
There wasn't any kind of incident today. Mm-Hmm. We don't know if there wasn't an incident because there was, if there wasn't an incident because there was something we did.
Right. Well, we were just the lucky zebra and the lion ate someone else happens today happens. Yep.
Right. And, um, that's the nature of our, it has been for a very, as long as I've been in it, you know, for 25 plus years. And so it's hard, it's hard to Yeah.
It, it, it's, don't get me started. Um, I'm gonna say one more word for you. I'm gonna get your take on that and we'll wrap.
Sure. Generator of ai, friend foe both keeps you up at night. Sleeps easier.
I think the key to success is we need to use AI for security, help ourselves out, but also we need to figure out how do you do Security against, For ai. ai it goes in both direction. And same thing, frankly, with compliance.
Yeah. Compliance for ai, ai for compliance. Both sides of the coin of, of our mission here.
Do you think we are? So you're, you're a glass half full kind of gal, right? Yes.
So we are making progress here then. Yeah. I, I really do believe it.
And, and I think there's some phenomenal programs out there. Like I, I sit on an advisory board with NYU and they've just launched a whole new program focused on AI security and partnership with a, a university in, um, South Korea, actually. Oh, really?
And seeing some of the, the research coming out of there, the student energy around the topic. I mean, this is truly shaping where we're gonna go tomorrow. I I, I don't disagree with you at all.
I can't wait to see it. Oh yeah. Absolutely.
And that's, that's really to me, I mean, and you know, the thing about this whole AI thing has just exploded so quickly. Yep, Yep. And there's so many risks.
I mean, whether it's, you know, where does your intellectual property wind up? Who owns the intellectual property of the outputs? I mean, there's so many moving pieces that we don't have answers to quite yet.
And so how do we as security professionals create the frameworks, make it easy for our users, our entire employee base, to access and use these tools as a way to help them innovate, think differently, see things differently, while also protecting our core ip, our core value that we bring as an organization. You know, like you, I, I didn't go to school for technology. I, I went, I wound up gonna law school.
Nice. And my con law teacher, who was, he was a pretty famous guy. He actually taught Con Law at Stanford before he came to my school.
And he, he was the con law professor for, uh, William Renquist at Sandra Day O'Connor. Wow. That's how old I am.
Wow. And, uh, well, it was at the end of his career by the time I got him. That's, I'm sure.
I'm sure. But, um, It's a good resume though. Yeah.
He, he had an amazing resume, but he always said technology provides the answers, but it takes society 10 years. And this was pre-internet. Yep.
So let's take it in internet time. Yep. Five years, three years to catch up to technology.
So when we talk about things like ip Mm-Hmm. And, and stuff like this for ai, we're, we're three to five years out for figuring that out. Yeah.
And, and the problem is we're not, AI's not gonna sit here twiddling its fingers while we f Nope. It's building, it's building. I mean, I just heard one of the last sessions that the whole concept of, of Moore's law is not actually a technology concept.
It's an economics concept. Yeah. 'cause the faster things move, the more investment they'll get.
It's a flywheel, it keeps the whole thing. Right. It's a flywheel.
And, and so that flywheel's gonna keep spinning. Mm-Hmm. Spinning wheels got to go round.
So Success, it's already picking up momentum. Yep. And we'll catch up eventually, but it, we're always gonna be behind.
And I think once you realize that you live with it. Right. That's, that's how it is.
Yep. Alexandra, I want to thank you for coming on here today. Appreciate The opportunity For people who wanna find out more about Collin's Aviation, where can they go?
So you can check out Collin's Aerospace. Yeah. Collins Aerospace, not aviation.
Yep. com. And certainly feel free to reach out on, on LinkedIn as well.
Thank you. Alright, we're gonna take a break. Actually, we're not taking a break.
We're wrapping. What a great conference here at DigiCert Trust. I hope you've enjoyed it.
We will be replaying all of these live streamed interviews in the next two weeks or so on Text Drunk tv. So if you missed any, you could catch it there and they'll be available on demand, on Text Drunk TV as well. Until next time though, this is Alan Shimmel.
We're out.





