Accountability for Cybersecurity – Yochai Corem, Cyberint
Cyberint CEO Yochai Corem explains how the National Cybersecurity Strategy outlined by the Biden Administration will eventually make every organization more accountable for cybersecurity so the time to act is now.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with yohai Karam. Who is CEO for cybering? And we're talking about the national cybersecurity strategy outlined by the Biden Administration and in particular.
The penalties that are being associated with some of these efforts there's increased calls for liability for developers. And there's also more penalties being proposed for how people manage data, you know, I welcome the show. Thank you very much.
Nice to be here. In your opinion. Does this go far enough or does go too far?
There's a lot of debate on both sides of the proverbial aisle. Unfortunately, we've seen more than 3,000 runs somewhere Techs in the last year 2022 many of them are focusing. The US each of those ransomware attacks is quoting causing Direct in Impact to the business of the tech company, but unfortunately as a lot of data is expected from the tech company also to a lot of its customers so the ripple effect or the second layer effect is within the tens of thousands of organizations.
When you look at the reasons why those attacks are successful you find out that really it's all about basic idea of cybersecurity in most cases. The the attackers are motivated by a financial gain. They're looking for the easy wins and thus they're going to the mid company that do not put a lot of focus on cybersecurity.
And they're able to get in and because dramatic damage and the question. I think that's what's by then Administration is trying to to ask itself and already gave the answer is how we motivate companies that cyber security is not within their DNA like this essential Institute, for example that look at security from the early days of burglaries all the way where we are today as a very important topic. It has positions budget in organization to support it.
How do we support other organizations to put cyber security more in their emphasis and that's this penalties and regulation. I think after trying different approaches in the last 10 years. I agree.
It's a good idea to take it forward. And of course it tries as many other questions about who who checks the regulation it is important. What are the penalties Etc.
But as to answer your question, I think it is a good idea to promote cyber security awareness and verify, this is mandatory. A lot of folks would have said historically at least that you know, we're punishing the victims here. These people got attacked by somebody else and now we're basically going on the turnaround and penalize them for essentially getting mugged walking down the street as it were so um, what is the right level of accountability for somebody these days I mean is that whole notion of we shouldn't blame the victim bygone because we all know they're at least some minimum level of security.
That should be put together with your thought. I don't think the right analogies we should put the burden on the victim the victim in this case is a service provider. It's a company.
That while holding your data, whether your company or individual they make a profit out of that. That's their business. And the question is when my daughter or my mother, I always like to look at them as a good examples of my my son and fathers.
There's no but when when they shop online or they do business online or even if my my teammates here in cyber right do a business online with another company. Do they need to think about cyber security the problem or they need to be sure or with high confidence sure that the supplier they work with? Is taking really good care of about their data about their business plans about the credit card about whatever they are sharing that.
So I think it is it is right to require from companies who make money. And from government agencies who give you service and you know part of what you give their your information to that they take the adequate measures that are are needed in order to people not think about cyber security as a consideration where they work with them. And if they will not do that, then they are not I don't want to do business with them.
And the question comes who would be the one defining so because again my father and my daughter cannot check Whether the bank to work with or social media, they put the Trust In are doing so enough. And I think this is the the role of the it's a good good place for the government to support just like they doing in other areas of verifying. We we can trust the surprise we're working with The question of course goes to what should be done and here we can learn from the experience again just in the last year of how many attacks were successful.
And what was the reason for those and then who needs to and what do you need to fix in order to reduce that? Some people might say that our parents and our children are part of the problem because they don't move their business when there is a breach and so there's not a lot of incentive for the providers or services to do the right thing because they're basically trying to offer the lowest price they can and so is it a matter of legislation or is it a matter of educating people to vote with their feet and force people to do the right thing with security by not using their services if they're insecure. I I will I think there is a certain level.
of Education that needs to be taken and definitely the government should put funds and programs to do so. however Not everything is on the hands of the people. The hackers are smart enough.
To be able to bypass the security protection of any any person even in cyberant. Maybe I give you a small secret. I do almost a monthly fishing simulations trying to simulate in attack and see how how my my team my employees will Will would they understand would they be able to classify this as an attack or not?
And believe in my team is reading the highest level of knowledge about fishing and cybersecurity in general. However, the people that execute the test for me again another team in the company are really good as well. And in most cases were able to fool some some employees.
So if you consume it and cyber security professional is full that's of course easy to full people that this is not their main business and they come with the trust their trust in the first place. So not everything should be on the shoulder of the of my of my daughter and father. We should verify that the companies we give the data to really take efforts more than today to verify their secure.
Right if that's the case then how do I know whether someone is actually being Reckless or just made a mistake? If you read some of the finer print in the document from the Biden Administration, they talk about safe harbors for people who have demonstrated some capability. So will we need to find ways to evaluate score and the risk level you associated with any given service?
You know, first of all, there are best practices. That's nothing new. We know hackers are trying to you know, the top three.
attack vectors in 2022 where fishing someone trying to imitate your brand and get your credentials second one will be account takeover. Someone find your account and we'll log in as you and then, you know navigate inside your organization and trying to collect what they want and third is vulnerabilities in Internet facing assets. This means that we know what are the main risks that most of the attack have most of the attacks are successful using those those attack vectors.
And we also what's the solution the solution for example is multi-factor authentication. So accounts that you employees are using and do not are not protected only by password. You know, it's not enough this the second Factor.
If you don't Implement sector second factors authentication in your systems, don't be surprised at your hair another really really clear cases and Employees leaving the company. And you didn't reset all the credentials. They left the company sit out there and someone now it's able to to use it in a malicious way.
So there is a standard policy to when it's employees check out check out or finish their their position to clean all of the accounts or the credentials and for that of course, you need during the the day to day to verify, you know, what are your employees are using these are best practices. That's not something no one needs to invent it. Someone into verify and push the organization.
I think this was the administration is trying to do to follow those best practices and verify their implemented and this requires a person for example, that will verify this is taking place and training to ask yourself where what are the common pitfalls? So I would not fall fall into them as well. So there are different ways to do it in writing risk rating is definitely a way that could give you some indication whether you're your customers are supplier.
Your partner is following those basic guidelines. And if not, you know, you say hi. This is a person I or a company I don't prefer not to do business with if I just to complete the answer if I looked at I think it was Verizon Rich report.
They published 62% of the text then I hope I quote it correctly. But this is around the number or happening from a third party or your partners. There's originating outside of your network from someone that you work with.
This is a huge huge risk. We need to verify the team that we are taking care of for another security. So each one take their own responsibility and we help one another on that and government here I think is doing the right thing is for my perspective.
Are we to a certain degree our own worst enemies because to your point a lot of the attack vectors are simple things like SQL injection things. We should know how to deal with and maybe you know, we need to take a look at ourselves in the mirror before we go any further. We do but you know, I I have companies.
Unfortunately, most of our days is you know, continuously monitoring organization maybe to say what's hybrid is doing so you understand a little bit. What's what's where I'm coming from. So we look from the outside on companies and scan them 24/7 to see any misconfiguration human errors and other things that hackers can try to utilize and they list to identify them before hacker will find a way to make bad use and the second thing we're looking at is in the open deep and dark web.
So hackers today are are very sophisticated organizations with people in different positions and they share and the Commerce with one another in data. And in the tech techniques and Etc. You can really go to schools school and how to hack and you know find different tools and buy malware as a services.
So it's a very big ecosystem. So we're trying to track all of that and see you know, if our customers data is for example founder give them an early warning. Someone has your credentials you need now to reset the password is a very basic remediation before the hacker can and make good use of that.
So we need to there's bit very simple way to track we can do a few cyber. You can do use other companies there are you know different solutions, but if you do not track 24 by 7 those mistakes that you need to assume your employees are doing your partners are doing then don't be surprised. So we're a software company with develop software.
So every time one of my employees put a new line of code. It could be a the result could be that an SQL injection could be a way that you know, I need to be aware of it and I need to plan the program to verify to check that now in a new version I upload. There's no SQL injection possible.
If I don't do that, then I'm reckless. Okay. So the question do I need to do it?
Every version answer is yes, actually, yes. Otherwise, you know, I live a window open for the attacker to use that and their techniques to do it today. It's not not something you Do we need to just kind of have a wholesale replacement of the applications?
We've built and the infrastructure we're using because a lot of this stuff is legacy and we weren't thinking through all these processes in the past. So maybe we need to just kind of have a massive campaign about you know, the great cybersecurity upgrade. The last campaign I remember was in about 2000.
I don't know. I think he also remember that hey, you know it was there was a reason that you know, and it took years years to plan for that and they know and then no one knows if the planning was a valuable or not. We're in a Content.
You know, the I think what you're suggesting I look at it as a little bit Legacy that we can plan three years ahead, you know a massive program and everything. It doesn't happen these days. We're in an Agile development type of environment.
There's step by step by step by step. So we need to create a continuous. cybersecurity program rather than to look for a radical check that will fix everything banks takes years to change their core infrastructure.
And what will tell the bank, you know, stop working. So the government by the way, the government can say hey, we want you to be always three versions. Not let you know update to the latest three verses from the current one.
That's that's a requirement could be push and we can request from the vendors to verify the continue patch and do cyber security programs for three versions from the current one, right? You know, so this is the type of window we give organizations to continuously progress in the systems, they use and verify no one uses Windows XP or Windows and e or other Known not. It's a versions that have no no security patches to and you know hackers can easily get into that.
That's a good regulation to pursue for example. Yeah, you're high. You looked at the document.
What's your best advice to folks the energy go forward here. What should they be doing? It get ready to comply.
I'm always amazed from how CEOs and you know other senior executive in the companies understand they need for cybersecurity after they've been hacked. And suddenly the budget are available. Suddenly.
The people are focused. I would say look at the document look at the administration requirements as a clear indication that today just like you lock the door and just like we put seatbelt in the car just like we have other security measures. This is mandatory and we cannot say and just like we pay taxes on the same level.
It's a mandatory activity without that will be out of business and the government, you know, pushes us directs us to do things. It doesn't tell us how to do it's still in our ends, you know, which Technologies to use which process to implement but we are accountable if we have not done anything just like we are accountable if we didn't pay taxes or we draw we drove while we are drunk. Okay, we can make this decision.
But if something happens we are accountable. So look at the document go to your nearest cyber security professional, you know, many maybe still thousands are missing but there are still many that you can approach and ask what's their advice what? This is a verify you have someone in the company that this is their responsibility.
That's you know, you can rely on someone that knows just like having in my Finance in my people. I can trust them which taxes to pay and how I know. I I follow the regulation in human capital similar cyber security.
You need to have this position and if someone understand someone you can consult with and we're understand this takes some efforts and budgets and unfortunately, it's better to do it in a proactive and preventative measure then be call your customers and say sorry our system are locked in a ransomware in all your data is now in the hands of I don't know foreign Nation. You don't want to be in this position and we know some some people actually went to jail because they're in a glitch in in this in this topic. So just understand this is a mandatory.
Capability need to have in-house today. All right, folks Sharon in here. You may not wind up one day being home in front of a congressional committee to explain yourself, but there's going to be somebody asking a lot more tougher questions soon.
So you might as well get ready for it now. Yo, hi. Thanks for being on the show.
I appreciate thank you for taking the time with me right and back to you guys in the student.