Adapting Cybersecurity to Economic Challenges – Ravid Circus, Seemplicity
Ravid Circus, chief product officer for Seemplicity, explains why the current challenging economic climate will require cybersecurity teams to change the way they collaborate.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Ravid Circus. Who's Chief Product Officer for Seemplicity and we're talking about the current state of cybersecurity because it seems like we're being overwhelmed. There's more vulnerabilities than ever.
There's not enough people to address this issue and the question at the end of the day becomes what's to be done about all this. So rabbit the balls in your court. How are we gonna save ourselves from ourselves?
Family and things like it's actually a very good question, you know being in this cybersecurity for for so many years. I think we kind of sing a big difference a big shifting things over the last few years. So if you would look on the world of you know, risk management or risk reduction, like six or seven years ago, it was all about vulnerability management, but if you look on these world today, you have vulnerability management and application security and cloud misconfiguration and Cloud work protection and success security and many many different programs that identify weaknesses vulnerabilities exposures in the security state of an organization and the security team probably the same security needs to handle a lot of that.
Now the big thing about it is that there are many programs. They each of them cover different layers of the security stack. Each of them has different score different formatting.
And the only thing that is common to all those tools is the fact that the security team cannot fix any of these the people that fix those problems are it developers devops and and and these people so security team are in a very that's what it's special place where they have the responsibility but don't of the authority they have the responsibility to get organization more secure, but they don't have the authority to do so because they cannot go and pay a machine. They cannot go and and reconfigure a cloud resource. So they're busy all day you driving remediation.
They're busy all day getting the people that can actually make those changes use the data that they come from the security tools and they're actually handling all day getting the findings for the tools to the people that can actually fix this problem and in many organization. This is done manually fragmentedly on a on a tour by too basis. So I think I think the big the big thing is that we have more tools more data, but the same security team that actually need To do the same things manually, so I don't know why we are surprising that it doesn't scale.
It seems like we're trying to enlist more people in the process that you see it operations teams taking over more security operations. You hear about the shift left to developers where they're gonna be more proactive. Is that how we're gonna deal with this ultimately is that we're gonna essentially deputize everybody we can find who can work on a cybersecurity policy.
So I think I think it's part of the solution but this part of the solution requires a lot of the Technology support this part of the solution requires making security more self-service than it used to be. So if you want to developer to fix security things by Zone, then he needs to have access to all that information. He needs to have transparency of that data and it doesn't need to become an expert in each and every one of the security tools that the organization has it needs to have more notion of yourself service.
So the organization can actually being able to let's correct democratize security being able to kind of move the responsibility to recover mediation from the people that are responsible to the security tools to the people there is possible to fix those now, I think the Big Iron is that if you look at it, no one can think about doing software development today without jira or one of the equivalent Technologies. One can think about doing it Services? Okay without service now or send us the one of the equivalent Services because those productivity platforms are the ones that enable that that serve service notion, but for the security team there is actually no such platform.
There is no such platform that sits and take the information from the different tools lives in the security to ecosystem. But also knows to create the notion of Self Service to those Operations Security operations developers the devops and whatever you so we are back to relying on separate desperate reports from different Tools in different formats. Something that is really the complete opposite of cell service to these groups trust each other.
I mean, it seems like the security people over the years have always thought of developers especially is maybe in the root cause of some of their issues and the IT apps guys don't have enough knowledge and don't pay enough attention. So, how do we can Get to the point where everybody is actually on the same team. So I think I think this way I would call it differently than trust.
I I do honestly believe that everyone in the organization wants the benefit of the organization. So I don't think that any of the people that needs to fix security issues. Don't fix them intentionally.
I do think that there is a lot of friction in that process and that friction is a result of too many Tools in too many security ratings in too many formats in too many alerts in too many changing of prioritization between today and tomorrow that at the end of the day put a lot of friction between the security teams that actually want to get things done and the people that actually executing those programs. So I think I think I think that friction is something which is a result of a manual processes of their of a result that the security process is not part of the day today of what the remediation teams are doing. Pretty much because it's not transparent for them.
It's not available for them. I you know, I'm coming from product management world. So my development teams has features that they want them to do.
They have bugs of things that need to be fixed, but they don't have a security background because we are not able to communicate them the security background because it's in too many different places too many different tools too many different formats. If we were able to create for them, you know one and distinct harmonized a security backlog. Then there was features there was bugs and there was security background and an engineering manager with a plan out how it's how it's going to to handle that.
The reality is that it's always some kind of a firefighting always some kind of a okay. This has become his priority. Let's stop everything and fix it right now.
So I think the problem is the friction and when that friction cause both sides to kind of stand still in Positions of you need to fix everything right now on the other side. We cannot stop everything to fix security things and no one moving on each side. So I think that the automations and technologies that we have in place today actually allows us to move away from that friction into more self-service normalized backlog of security something which is more transparent rather than the old-fashioned.
This is the latest alert list stop everything and fix those. Speaking of automation we hear a lot about AI machine learning algorithms. Are these things for real and what kind of expectations should we have or are they mainly you know yet another security tool or widget that everybody kind of promotes, but nobody uses.
And so I think that to say that the AI mnl and ml is not for real would be very very harsh. I do think that the I do think that the automation many times is in the small things and not on the big thing. It's not on necessarily applying some intelligence, but rather being able to to do a lot of the things that was manually in cumbersome and do that the rapidly invest I'll give you a quick example.
One of my customers was telling me story the other day with getting a finding about the issue on one of my code repositivities. It took me about two hours to find out the person that is responsible for that repository and ask that to fix that immediately. And then he told me so yeah that two hours that were gone.
But the day after another Finding came on the same repository, but this time I was on vacation in my in my colleague pick up this alert and he took him the same two hours to figure out that it's exactly same person. So, you know, I don't know if it's an artificially diligence or machine learning or whatever it is, but there is a lot of there is a lot of place for for savings and for Automation and for a orchestration of many of the day-to-day menu tasks that security teams are going as they are doing with the lack of centralized platform that will actually do all of that for them. And I think that Ai and ml is can augment or can extend a good process which is already automated.
It's not a replacement for for the lack of process. Are we seeing more vulnerabilities or is it just kind of a matter of the fact that we're discovering more vulnerabilities that have always been there, but we're just recognizing the issue as the scope that it really is. So I think there are few things here.
I think first of all the attack surface the potential Ducks surfaces grown explanation. So, you know, you know, there is vulnerabilities there is cloud these configuration. There is API security there is a security there is a lot of new technologies and a lot of new domains which potentially has exposures when their abilities findings things that that need to be fixed.
So, I think I think the world using today much more Technologies in different aspects than indeed in years ago. And for that extent, I think that Surface by definition is is bigger, I think that we the concerns and the knowledge around security and the awareness for security issue has been raised and you see programs like about these and and things like that that actually A encourage people to find more vulnerabilities. So we are in as industry encourage people and we are paying people to find vulnerabilities in our in our software, which is a good thing.
But I think that the the inability to fix is not related to the number of problems. It's more related to how you drive solutions and because many times those problems as you know, the same solution or or has a way to actually resolve that in a much more efficient and weaker way and therefore really don't think it's the amount of problems. I think it's really how how you handle the solution and how you drive the processes that will make those problems go away.
Are we accumulating a level of security technical debt? That's unsustainable because we have all these new platforms and new things to defend and we don't have enough people. So, you know, we could be at this for another decade.
Just trying to fix all the stuff. We already have never mind the stuff that we're going to add. Yeah, and I think it's a good question, and I'm not sure that they have.
The best answer for that. I do know that no when I practice security people was telling me when you have vulnerabilities, let's pray that we prioritize them based on whether they are already accessible from the internet whether there is a known exploit to those vulnerabilities whether we were able to validate that it's really vulnerable through with tax simulation or through append this thing, but that's it guys, but if we will progress but these three factors if the answer for one of them is yes, we have already in high risk. By The Physician if it's public or it's exploitable or it was validated.
It means that someone can actually use that and we kind of try to fix that after we have validated that it can be used. So no, no, you know. No it you know, it's not it's not is it to to see that we are actually in the constant firefighting just because we decide to fix something when it become overly important.
I think that one of the things that we as an interesting to do and I think that we have a couple of steps to do there is to be able to to better a to create a more sustainable Cadence in security limitations. So we will not fix all of them never we will never fix all But if an organization knows that on an average, it would take him two weeks two months two years whatever it is to recover from from in outbreak of specific vulnerability or something like that. Then the organization can also plan accordingly how he defends itself.
In the meantime. The problem is that it's very hard for Security leaders today to understand, you know from the second. I at this I I asked that to be fixed how long before the organization is completely empty and clear.
This is one of the things which are missing in the industry and measuring that will actually help us to understand better how we are going to get rid of that background or manage our life with that security there. What is that one thing that you see organization is doing over and over again? That just makes you shake your head and go.
I cannot believe that we're still wrestling with this issue. And if we just did this one thing we'd be halfway home. a spreadsheets, you know, it's kind of it's kind of funny and embarrassing on the same time because I part of that industry and I was practicing that myself for many many years, but One of the scissors that I talked with said if I will ever start another meeting and someone we said who has the latest version of the vulnerability spreadsheet.
I know I'm going to stop everything right the way but that's the reality. The reality is that it many many places. We are kind of accepting the fact that we need to do that manually manually in a very tedious way in spreadsheets rather than to look around us.
Look how they do that in software development how they do nothing. I can Services how they do that in sales how we do that in marketing in HR. All of those domains have productivity platforms.
Okay, only the security team for some reason doesn't have that. So maybe we need to think start thinking about that. Maybe we need to start thinking about security as a service pretty much as it and it said, is it service management?
Okay and actually start to look at that as a service and what we can do in order to enable that service organiz. if rather than just look on ourselves as Defenders, and I think this way might this thing might take you know, like a make a big difference in the way that organization are managing their security and sharing their Security State and driving other things for improving the security because the organization All right. Well, it sounds like a lot of security teams are still quote unquote Party In Like It's 1999 and maybe they need to come up a few decades.
Hey rabbit. Thanks being in the show. Thank you very much.
Enjoy it. All right back to you guys in the studio.